Markdown platform
HedgeDoc, its database and configuration are deployed reproducibly and updated through controlled procedures.
We design, install and operate HedgeDoc as a collaborative Markdown platform - including database, upload storage, identity integration, backups and clearly defined service levels.
The following are trademarks of their respective owners: HedgeDoc (the HedgeDoc project). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.
HedgeDoc combines a browser-based Markdown editor with real-time collaborative editing. Teams can create notes, technical documentation, diagrams and presentations and share them through graduated note permissions.
WZ-IT designs more than the application itself. We align the reverse proxy, database, upload storage, authentication, email delivery, monitoring, backups and recovery with your existing infrastructure and required access model.
We inventory the version, database, notes, uploads, authentication paths, domain and dependencies of an existing HedgeDoc, CodiMD or older HackMD installation and plan the test migration and cutover.
The migration depth depends on the source system and its version. Before a migration or upgrade, we review the official release notes and validate data, permissions, media and authentication in a test run.
Production HedgeDoc operations connect the application, database, real-time connections, upload storage, authentication and email delivery. We design and operate these components as one platform while taking the selected release branch into account.
HedgeDoc, its database and configuration are deployed reproducibly and updated through controlled procedures.
Collaborative editing, note permissions and WebSocket connections are designed around teams and access paths.
Local accounts or documented external login methods, email delivery and upload storage are integrated in a controlled way.
Monitoring, updates, consistent backups and restore tests cover the application, database, media and configuration.
We distinguish platform operations, content organisation and business approvals transparently.
| Area | Responsibility | Scope and boundaries |
|---|---|---|
| Architecture and deployment | WZ-IT | HedgeDoc, database, reverse proxy, TLS, WebSocket paths, upload storage and reproducible deployment. |
| Runtime and updates | WZ-IT | Maintenance of the agreed release branch with release-note review, backups and controlled updates. |
| Monitoring and backups | WZ-IT | Monitoring and consistent protection of the database, media, configuration and agreed secrets. |
| Migration and release selection | Shared | WZ-IT assesses data and version paths; the customer confirms required functions, test data and approval of the target system. |
| Identity and note permissions | Shared | We configure supported login methods and technical permissions; the intended access model is agreed together. |
| Content and sharing decisions | Customer | The customer remains responsible for note content, permitted user groups, publications, retention and deletion rules. |
| Integrations and customisations | Optional WZ-IT service | Import tools, identity integrations and additional automation are specified as a separate project module. |
Edit notes collaboratively in the browser and merge changes from multiple participants in real time.
Share notes with graduated read and write permissions, review previous revisions and restore them when required.
Extend Markdown content with supported diagrams and embedded content or present it as slides using reveal.js.
Configure local accounts or supported external sign-in methods such as SAML and OAuth-based providers for the required access model.
Store image uploads in the file system or through supported S3, MinIO or Azure storage targets, depending on the architecture.
Monitor the application, database and uploads, protect them with versioned backups and apply updates through tested maintenance and recovery procedures.
A clearly defined operating scope instead of an opaque hosting flat fee.
Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.
We also design custom HedgeDoc architectures, integrations and migrations. Contact us for a technical assessment.
One managed standard HedgeDoc application is included in the Starter workload. Every service level also includes flexible expert time for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
User count alone is not enough. Concurrent editors, note size, WebSocket connections, uploads, diagrams and external login methods shape compute, database and storage requirements.
| Usage scenario | Technical starting point | Key factors |
|---|---|---|
| Small team with internal Markdown notes | S or M, PostgreSQL | A suitable starting point for few concurrent editors and a manageable upload volume. |
| Multiple teams with media and external login | M or L, PostgreSQL, separate upload storage | Concurrent editing, media volume and authentication paths are assessed beforehand. |
| Many parallel sessions or a substantial migration | L or custom sizing | WebSocket load, database, upload paths, import volume and release compatibility shape the target design. |
| Business-critical or particularly isolated environment | Custom architecture | Recovery objectives, redundancy, private access and the behaviour of active real-time sessions are designed separately. |
Data migration, special identity integrations, separate environments and complex storage or redundancy architectures are not included in the general workload price.
HedgeDoc can run as a managed workload or in a customer environment. The release branch, login methods and upload storage are assessed beforehand.
Dedicated workload with agreed compute, upload storage, backups, monitoring and service level.
Operations in the customer's account with existing network, email, storage and identity services integrated.
Integration with customer servers, virtualisation, database, directory and backup infrastructure.
Access to internal identity and storage services over defined private connections, NetBird or VPN.
HedgeDoc connects browser sessions with notes, uploads and login services. Access, WebSocket connections, data storage and recovery are therefore designed as one end-to-end data path.
Internal or external users, shared notes, presentations and shared links.
TLS, domain, proxy headers, WebSocket paths, protection rules and optional private access.
Local accounts or documented SAML and OAuth-based login methods together with graduated note permissions.
Markdown editor, real-time editing, revisions, diagrams, presentations and media references.
Notes, users, revisions and configuration on a supported database selected for the target environment.
File system or documented S3, MinIO or Azure targets with agreed capacity and backup coverage.
External login services, email delivery, status and metrics endpoints and operational alerting.
Before production, we document the release branch, authentication paths, default permissions, upload target, backup scope and a tested recovery procedure.
Answers about licensing, release branches, migration, login, permissions and operations.
Yes. The HedgeDoc source code is released under AGPLv3. The official repository and its licence notices are authoritative. The HedgeDoc logo has separate usage rules; WZ-IT is an independent service provider.
The official project currently describes HedgeDoc 1.x as stable and maintenance-only and HedgeDoc 2 as a rewrite that is not yet feature-complete. Before deployment, we review the current project status, required functions and release notes and select the target branch together instead of treating a development state as production-ready by default.
In principle, yes, but not every version path is officially guaranteed. The HedgeDoc migration notes identify safe paths only for certain older CodiMD and HackMD versions. We therefore inventory the version, database, notes, uploads and authentication and run a test migration before cutover.
HedgeDoc documents local accounts, SAML and several OAuth-based providers. We validate the specific provider, required attributes and group rules against the selected release branch; this does not imply a blanket enterprise RBAC promise.
HedgeDoc 1.x distinguishes owners, signed-in users and guests and provides several note modes (permissions documentation). We configure default permissions and anonymous use around the agreed model; business sharing decisions remain with the customer.
The database, upload storage, configuration and relevant secrets must be considered consistently. We protect the agreed data and test recovery because a database dump without media and operating parameters does not recreate a complete instance.
Redundant infrastructure can be designed, but real-time sessions, WebSocket connections, the database and upload storage must be tested together. We derive the architecture from recovery and availability objectives and do not make a blanket HA promise for every release branch.
Whether you run HedgeDoc in-house or need to host confidentiality-professional data §203-ready - we build, operate and maintain HedgeDoc on an encrypted on-site server. Data never leaves the building in cleartext.
See HedgeDoc on-premise
These solutions are often used together with HedgeDoc
These solutions offer similar functionalities and can be evaluated together
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
