WZ-IT Logo

Open source for professional secrecy holders

Timo WevelsiepTimo WevelsiepUpdated: 27.08.2026

Editorial note: Versions, commands and prices may change. Please verify critical steps independently before production use. This guide does not replace individual consulting.

Want to use Nextcloud, n8n, Paperless-ngx, Keycloak or another application with professional secrets? Request Managed Open Source for professional secrecy holders.

Open-source software makes it possible to run applications on selected infrastructure, inspect source code and data formats, and reduce dependency on a single SaaS vendor. That control is valuable for professional secrecy holders. Open source alone does not make an application secure or automatically suitable for Section 203 processing.

The complete operating model matters: application, edition, data flows, administrative access, updates, backups, support and participating providers.

Where open source can create real advantages

Depending on the project, open source provides several design choices:

  • operation on selected cloud, dedicated or on-premises infrastructure
  • controllable network and administrative paths
  • customer-controlled domains, identities and keys
  • data export in documented formats
  • integration with existing systems
  • a change of operator without replacing the entire product
  • technical inspection of source code and dependencies

These options need to be used deliberately. An unchanged default installation with a public admin interface, weak roles and untested backups does not realise the advantages.

Application groups and typical assessment questions

Collaboration and files

Examples include Nextcloud, ownCloud, Seafile and collaborative editors. Review:

  • share links and external guests
  • permission inheritance and groups
  • versions, trash and retention
  • office, preview and search services
  • mobile apps and desktop synchronisation
  • complete file and database recovery

Document management

Paperless-ngx, Mayan EDMS and other DMS platforms process document content, OCR data and metadata. Import paths, email mailboxes, OCR components, full-text indexes and exports are also inside the trust boundary.

Automation

n8n, Activepieces and comparable platforms connect many third-party systems. The risk is not limited to the workflow server. Credentials, execution data, webhooks and target systems determine where business information travels.

Identity and access

Keycloak, Authentik, ZITADEL or NetBird can provide central identities and access. The platform itself needs particularly well-protected administrative and recovery paths because a compromised identity system can open access to many downstream applications.

AI and knowledge systems

Open WebUI, AnythingLLM, Qdrant, pgvector and other components can store documents, embeddings and chat histories. Model endpoint, knowledge sources, permissions and logging need to be assessed together. Local AI for professional secrecy holders covers AI-specific questions.

Licensing and managed hosting are separate questions

“Open source” describes licence rights, not automatic permission for every commercial operating model. Projects use different licences and editions. Some allow managed-service operation under their open-source terms, while others provide additional enterprise capabilities or require a commercial agreement for particular hosting models.

Before a proposal, clarify:

  • Which edition is required?
  • Which licence applies to the deployed version?
  • Are SSO, audit or multi-tenancy available only commercially?
  • May the software be provided to third parties as a service?
  • Who procures and holds a required subscription or licence?
  • How will licence changes be monitored during updates?

WZ-IT can include licence selection and procurement in the scope. Technical suitability and licensing rights are assessed separately.

What turns an installation into a managed service

A production application needs more than Docker Compose or a Helm chart. Depending on scope, the operating model includes:

  1. Architecture: sizing, database, storage, networking and dependencies.
  2. Hardening: minimal public endpoints, MFA, roles and secrets.
  3. Integration: SSO, email, DNS, APIs and existing data sources.
  4. Monitoring: availability, resources, jobs and application checks.
  5. Updates: a controlled test, approval and rollback path.
  6. Backup: data, files, configuration and tested recovery.
  7. Operations: responsibilities, response, documentation and handover.

For professional secrets, the technical scope must also align with the intended provider and obligation chain.

Standard application or individual assessment?

An established, relatively stateless service can start from a repeatable operating standard. A complex DMS, multi-tenant automation platform or stack of several applications is more likely to require an assessment.

Useful information includes:

  • application and required edition
  • user count, data volume and integrations
  • data types and external users
  • existing installation or new build
  • desired operating location
  • availability and recovery requirements

The application and technology catalogue shows the current portfolio. Applications outside the catalogue can also be reviewed technically.

Migration from existing SaaS or self-hosting

A change should cover more than files and database export. A complete migration plan includes users, roles, shares, automations, integrations, history and retention.

A controlled sequence consists of:

  1. inventory and export assessment
  2. target architecture and mapping
  3. test migration with quantity and user-journey checks
  4. cutover with maintenance window and rollback point
  5. handover into monitoring, backup and update operations

The result is not only reachable, but operable.

Sources

Rather have it operated?

You'd rather not run Section 203 & Managed Cloud yourself? WZ-IT handles setup, operations and maintenance - privacy-focused from Germany.

Enquiry

Assess the application and operating model

Describe the application, data types, and current situation. We will assess which technical starting point fits the intended operations without obligation.

How should we get back to you?

Frequently Asked Questions

Answers to the most important questions

No. Open code and self-hosting create control options, but do not replace secure configuration, updates, permissions, backups and operating processes.

Projects differ technically and in licensing. Edition, licence, supported deployment model, integrations and operational maturity need to be reviewed first.

Common areas include collaboration, document management, automation, identity, knowledge systems, databases and internal AI. The concrete process is decisive.

No. Depending on the target model, it can run on customer-owned infrastructure, in a controlled cloud or in a hybrid arrangement.

Managed operations define responsibilities, update paths, monitoring, backup assurance and response in an individual scope.

Contact

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Email
[email protected]
Arrange a callback

Callback

Arrange a callback

Leave your number and we will call back — at the latest on the next business day.

For a longer conversation you can book an appointment instead.

Companies worldwide trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • Maho Management
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
1/3 - Topic Selection33%

What is your inquiry about?

First select the service area that best matches your project.