| Enbox |
DIDs (did:dht default; jwk/web) |
Typed JSON records under declarative protocols; local DWN + sync to remote nodes |
Yes — protocol-level, per record type (key agreement + JWE); local vault encrypts keys |
Protocol rules + permission grants with delegated decryption keys; revocation follows sync |
Yes — Docker; SQLite/MySQL/PostgreSQL |
Bun/TypeScript · Apache-2.0 |
| Web5 / DWN-SDK |
DIDs (did:dht default) |
Records under protocols; DAG-CBOR/IPLD; query filters |
Yes (designed) — per-message keys, HKDF along protocol paths, X25519/AES-GCM |
Protocol $actions rules, roles; permissions protocol largely unfinished |
Embeddable TS server (LevelDB); no surviving hosted service |
TypeScript (+ dormant Kt/Go/Swift/Rust) · Apache-2.0 |
| Solid |
WebID + Solid-OIDC |
RDF / Linked Data in LDP containers |
No — pod operator sees plaintext; client-side encryption breaks server features |
WebACL / ACP, per-resource (not per-field) |
Yes — CSS (MIT) via npx/Docker; enthusiast-grade |
TypeScript (CSS), proprietary ESS · MIT / commercial |
| ATProto PDS |
did:plc (Bluesky-run directory) or did:web |
Signed repository: Merkle Search Tree of records typed by Lexicons; blobs by CID |
No — public by design; "Spaces" add ACLs, explicitly not encryption |
OAuth 2.1 profile; repo is world-readable |
Yes — excellent; Docker installer, cheap VM, CAR export, account migration |
TypeScript + Go · MIT/Apache-2.0 |
| remoteStorage |
user@host via WebFinger |
Folder/document tree; JSON docs + binaries; per-category conventions |
No — plaintext on server; TLS in transit only |
OAuth bearer tokens scoped per category (r/rw) |
Yes — Armadietto (Node), php-remote-storage, 5apps hosted |
JavaScript · MIT (client); Armadietto has no license file |
| Cozy Cloud |
Instance account (email, 2FA); OAuth2 for apps |
CouchDB JSON docs typed by "doctypes"; Mango queries; virtual FS |
Partial — Cozy Pass is zero-knowledge (Bitwarden-compatible); files/doctypes are not E2E |
Per-doctype permissions declared by apps; sandboxed konnectors |
Yes — Go server + CouchDB, Docker image |
Go + JS/TS clients · AGPL-3.0 |
| Perkeep |
Local keys (age; historically GPG) — no global identity |
Content-addressed blobs; permanodes + signed claims; search index |
Optional — client-side encrypted blob storage (age, v0.12) |
Single-user model; whole-server auth; per-item share links |
Yes — exclusively; single Go binary |
Go · Apache-2.0 |
| Personium |
Cell per person; accounts/roles; PKI trans-cell tokens |
Boxes per app; WebDAV collections + OData structured data |
No — HTTPS/PKI in transit, XML token signatures |
Role-based ACLs within and across cells |
Yes — Java/Tomcat + Elasticsearch, Docker/Ansible |
Java · Apache-2.0 |
| Verida |
DIDs (custom did:vda, Polygon-anchored) |
Encrypted JSON datastores per app context; CouchDB-style replication |
Yes — NaCl keys, user-held keyring |
Consent-based app access per context |
Partial — open-source storage node (stale since Apr 2025) |
TypeScript · ISC |
| Ceramic |
DIDs (did:pkh, did:key) |
Append-only signed event streams; ComposeDB added GraphQL models (dead) |
No — streams public unless apps add encryption |
Authorship signatures; no read ACLs at protocol level |
Yes — Ceramic One (Rust node) is now the only way to run it |
Rust node + JS client · MIT |
| Fission |
did:key + UCAN capability tokens |
WNFS: encrypted, content-addressed file system on IPFS (file-centric) |
Yes — zero-knowledge private partition, client-side keys |
UCAN capability delegation (lives on via ucan-wg) |
Protocol open; polished DX depended on the dead hosted service |
TypeScript/Rust/Haskell · Apache-2.0 |
| Meeco |
W3C VCs + DIDs; OpenID issuance/presentation; eIDAS 2.0 aligned |
Encrypted vault + verifiable-credential exchange (SVX) |
Yes — zero-knowledge E2E vault |
Consent flows, enterprise key management |
Commercial — "your cloud, on-prem, or managed" |
Proprietary (some open SDKs) |
| digi.me |
Account-based; consent certificates |
Personal data library; normalized imports (health, finance, social) |
Yes — client-side encryption, user-held keys |
Purpose-limited consent-based sharing |
No — hosted platform, proprietary |
Proprietary |
| Nextcloud |
Server account (SSO/LDAP optional) |
File-centric: WebDAV files, calendar, contacts, apps |
Mostly no — optional server-side encryption; E2E app covers designated folders only |
Server-side share permissions; admin-trust model |
Yes — the category benchmark; huge ecosystem |
PHP (+ Go components) · AGPL-3.0 |