Does Euro-Office send data to an external, third-party server?

I am interested in giving Euro-Office a try, since I’ve had some issues recently with the Collabora-based NextCloud Office setup. However, I would love more clarification about whether Euro-Office documents are sent to a third-party server, or if everything will just stay on my own NextCloud AIO server (along with the devices on which I access my AIO instance).

I’m asking this because, on the office selection page, the box for the Collabora-powered NextCloud Office option mentions that ā€œdocuments never leave your server.ā€ However, this note isn’t present for NextCloud office, which simply states ā€œgood securityā€ instead.

Does this mean that Euro-Office relies on a separate, third-party server or data center (like Google Drive, Microsoft 365, etc.?) I’m doubting that’s the case, but I just wanted to double check. Thank you!

tbh I really dunno. But let me tell you if it would send out documents or data to an external server that would be a real bummer and somehow contradict the idea of owning your data, completely

I highly doubt it, as well. In fact, I’m pretty sure that’s not the case.

I think this part of the comparison just isn’t done very well, and in my opinion there are two problems with it:

  1. It mixes security and privacy/data sovereignty into a single point, even though those are different concepts and should probably be evaluated separately.

  2. It explicitly states that documents never leave your server for one product, but doesn’t make the same statement for the other. That naturally implies to readers that the situation might be different for the other product.

That said, security and privacy/data sovereignty are, of course, closely related. After all, data can ā€œleave the serverā€ in different ways. Either it is intentionally processed on third-party infrastructure (which, as I said, I don’t believe is the case here), or it becomes accessible because of a security vulnerability, for example, if your server is compromised and someone gains unauthorized access to your documents.

And yeah, at this early stage of the fork, they probably just haven’t completed any proper security audits yet, which may be why they only feel comfortable describing the security as ā€œgood.ā€ However, if they had used a separate bullet point for privacy/data sovereignty instead of mixing it together with security, they could still have stated that documents never leave your server, thereby avoiding this kind of misunderstanding. :wink:

In Nextcloud AIO, both Collabora and Euro-Office are implemented as Docker services:

And is therefore executed on your Server. The document only leaves the server if you use an external document service like tab.digital, Cloud42 etc. (in this example for Collabora).

Yes, and if you use a provider for everything, including Nextcloud. your documents will never actually be on ā€œyourā€ server. :wink:

In my opinion, the comparison should look something like this (I’ve highlighted the changes in bold)

EuroOffice Collabora
Good Nextcloud integration Best Nextcloud integration
Open Source Open Source
Best performance Good performance
Limited ODF compatibility Best ODF compatibility
Best Microsoft Office compatibility Good Microsoft Office compatibility
Good security Best security
Full data sovereignty: documents don’t leave your server Full data sovereignty: documents don’t leave your server

I would remove that entirely. The screenshot is from Nextcloud AIO, there’s no need to mention it explicitly because it’s already implied. Nextcloud AIO is a self-hosting solution.

Yes, that would actually be even better, and ideally they would also remove the ā€œSecurityā€ part altogether, unless maybe one of the products actually has a specific security feature that the other one doesn’t. In that case, that feature should be explicitly mentioned instead of being summarized in a vague label.

…unless, of course, one is actually insecure—but then it probably shouldn’t be shipped in the first place. :wink:

Cc @jospoortvliet

Btw. more or less the same thing is also shown in the ā€œAppsā€ section of Nextcloud itself, although maybe slightly less confusing, since the ā€œSecurityā€ part is not mentioned for Euro-Office at all, which makes it feel less like a direct 1:1 comparison.

The underlying problem remains: security and privacy/data sovereignty are being confused. The question also arises as to why Collabora is described as offering the ā€˜best support for legacy files’, while Euro-Office is described as offering the ā€˜best Microsoft compatibility’. Isn’t that basically the same thing? And if not, what exactly are ā€œlegacy filesā€? :wink:

I don’t think any of the office applications share the docs with ā€œthird party serversā€ but there is an important difference in the architecture. While Collabora renders the doc on the server and only sends ā€œpicturesā€ to the client (technically not really true but easier to understand) both OnlyOffice and EuroOffice send the full document to the client which renders it locally and makes ā€œdocument leave the serverā€. first approach is beneficial for full control e.g.ā€œsecure viewā€ and watermarks are enforced server-side and for this reason IMO is more controlled.. client-side rendering results in less server-client communication and feels faster - especially on long-latency networks..

Collabora has a good writeup comparing with OnlyOffice (most should apply to EO now) Comparing Collabora with OnlyOffice - Collabora Online and Collabora Office

Ok those would indeed be additional security features then. So I’d say something like the following might be better:

Euro-Office Collabora
Good security Enhanced security features like secure view and watermarks

or maybe…

Euro-Office Collabora
Client-side rendering Server-side rendering with enhanced security features

Thanks for the input, everyone! It sounds like both options are solid from a security standpoint.

@all ā€œissueā€ will be taken care of, as my behind-the-scenes-contact just stated