CryptPad, and what an EU public body already deploys
A government ministry writing documents in a suite whose server cannot read them is not a proposal. It is a deployment, it has been running for years, and none of it is ours.
What it is
A collaborative office suite where the encryption happens in your browser and the server holds ciphertext. Documents, spreadsheets, shared editing in real time, and an operator who is structurally unable to read any of it.
Open source, maintained by a team at a company that has been building open-source software since 2004. Funded first by a French state research grant, then by a run of European public research programmes, then by subscribers and donations.
Why it belongs on a pod site
Because it is an existence proof for the thing this whole category argues about, and it arrived without a token, a foundation, or a funding round.
The argument for user-controlled data usually runs into the same objection: fine in principle, but nobody deploys it, and institutions in particular will not. A public body using it for real work answers that objection with a fact rather than a rebuttal.
It also answers it in a way that has nothing to do with us. We did not build it, we are not integrated with it, and it does not use anything of ours.
The mechanism is different from a pod's, and worth keeping straight
The server cannot read the documents because the keys never reach it. That is the same provider-independent property named in 2007, applied to collaborative editing, which is harder than applying it to storage because two people have to edit the same document at once.
A pod does not do that. Pod content is not encrypted at all, and what a pod offers instead is per-resource, per-agent permissions the server enforces. Different mechanism, different guarantee, and against an operator who reads your files theirs is the one that holds.
What our own brief got wrong
The note this page was built from names a German municipal deployment. Public sources did not corroborate it, so it does not appear above.
That is the fourth time in two runs that a fact in our own competitor notes has failed checking. The pattern is worth stating plainly: secondhand records about other people rot, and ours rot at the same rate as anyone's. Where a claim did not verify, this estate prints nothing rather than hedging.
What is thin here, said rather than padded
This page rests on one short internal scorecard plus a check against public material. It is the thinnest page in this run and the brief that commissioned it says so.
Publishing a short honest page is the right response to a thin source. Stretching it with adjectives would be the wrong one, and a reader can tell the difference.