Sulu
Sulu GmbH ·sulu.io· As of: 2026-07-30
Our verdict
The same holds here: a content system is table stakes, not an edge. What differs from a hosted service is not the function but where the cost lands. There is no licence fee; in return you carry the operation.
Who it fits
Solo
not suitable
Without someone who owns PHP operations, updates and backups, a self-hosted system is the wrong choice. The licence you save costs weekends.
Mid-market
suitable
Works as soon as an agency or an in-house developer permanently owns operations. Multiple sites and languages then come without a surcharge.
Enterprise
suitable
Tenants, languages and permissions can be modelled in-house and the data never leaves the building. That is exactly where hosted services become expensive or impermissible.
Buy, switch or build
Off-the-shelf
Content system as a hosted service
Operations, updates and availability sit with the vendor; the bill arrives monthly and grows with seats and usage. The scrutiny moves from server maintenance to contract review.
AI-native
No meaningful AI-native replacement
There is no AI-native category for content systems, only AI features inside existing ones. The comparison therefore runs between hosted service and self-hosting.
Build it yourself
Run Sulu yourself
This is the build-it-yourself route for content, and a well-covered one: no custom code for the basics, no licence, full data sovereignty. It fails not because of the software but because nobody permanently owns operations.
Our advice
- Solo: Skip it. Operations cost more time than a hosted service costs money.
- Mid-market: Take it if operations are settled and data sovereignty is an argument in your sales.
- Enterprise: A strong candidate as soon as tenant separation or data sovereignty is the requirement.
Who is behind it
Staying power: Established
Sulu GmbH funds itself. No venture capital is on record, and the 2024 accounts show total assets of EUR 509,511 against EUR 432,311 in equity, an equity ratio of roughly 85 percent, with only EUR 36,239 in liabilities. Since nominal share capital is just EUR 35,000, almost all of that equity is retained earnings, which points to a business that has paid its own way across eight years; ownership is documented as 75 percent Schoenberger Holding GmbH and 25 percent managing director Thomas Schedler. One qualification matters: established here means durable, not large. The code has been public under the MIT licence since 2013 and is actively maintained, which softens the migration risk, but the team is very small and continuity rests on a handful of people.
- Legal form and commercial register entry: Sulu GmbH, register number FN 495861h, Landesgericht Feldkirch, registered on 31.07.2018, share capital EUR 35,000, registered office Gütlestraße 7a, 6850 Dornbirn, Austria · Source · As of 2026-07-30
- Ownership structure: Schoenberger Holding GmbH 75 percent, Thomas Schedler (managing director) 25 percent; Rainer Schoenherr holds power of procuration. No acquisition and no outside shareholder discernible. · Source · As of 2026-07-30
- 2024 annual accounts: Balance sheet total EUR 509,510.86, equity EUR 432,311.03 (equity ratio around 85 percent), liabilities EUR 36,239; filed on 20.03.2025 · Source · As of 2024-12-31
- Funding without venture capital: Revenue from the partner programme, from services and from a planned Sulu.ai offering; an explicit statement that development is funded by customers rather than investors and that the MIT licence stays. No funding round findable. · Source · As of 2025-06-25
- Who holds the code: The core repository sulu/sulu sits in the GitHub organisation sulu under the MIT licence, created on 18.10.2013, last commit pushed on 27.07.2026, 1,344 stars, not archived · Source · As of 2026-07-27
- Maintenance and release cadence: Major version 3.0.0 released on 26.11.2025; on 17.07.2026 patch 3.0.8 and patch 2.6.25 for the previous line shipped on the same day, so the older line is still being served · Source · As of 2026-07-17
Cost of leaving: Low
The software is MIT-licensed and the content sits in your own database. Switching is a data migration, not a negotiation.
Regulation and data
| Data processing agreement | Not required when you host it yourself; with the managed Sulu.cloud offering the processing relationship arises with Upsun, whose agreement is publishedIf you host it yourself, no content goes to a processor. A contract is then needed with your own hosting provider, not with Sulu GmbH. That shifts the review rather than removing it. Since 18 February 2026 there is also a managed offering, Sulu.cloud, and it explicitly runs on SymfonyCloud, that is Upsun, for which a separate Upsun account is required. The data processing agreement then comes from Upsun and is published at https://upsun.com/trust-center/privacy/dpa/. We found no contract template of Sulu GmbH's own; we looked in the privacy notices at https://sulu.io/privacy-and-legal-notices, in the imprint and on the cloud and AI product pages.Source · As of 2026-07-30 |
|---|---|
| Storage location | Freely chosen when you host it yourself; for Sulu.cloud, Upsun offers EU regions including Germany, France, Ireland and SwedenWhen you run it yourself, storage location is the operator's decision. That defuses the most common sticking point in German procurement from the start. If you take Sulu.cloud, you choose the region when the project is created. Upsun lists de-2 in Germany on Google, fr-3 in France on OVH, fr-4 in France on Azure, eu in Ireland on AWS and eu-5 in Sweden on AWS, among others. In its privacy statements Upsun commits that a project's data never leaves the chosen region unless you deliberately request an additional cluster elsewhere; see https://upsun.com/trust-center/privacy/.Source · As of 2026-07-30 |
| Subprocessors | None for the content when self-hosted; for Sulu.cloud, Upsun keeps a dated subprocessor list in which three services sit in the United StatesWhen you host it yourself, subprocessors only appear through your own choice of hosting, search or image processing. With Sulu.cloud the chain is in the open. In its list dated 23 September 2025 Upsun names AWS, Microsoft Azure, Google Cloud, OVHcloud and IBM Cloud for hosting and storage, plus Fastly for CDN and WAF in the United States, Zendesk for support in the EU, Sentry for application monitoring in the United States, SendGrid for email delivery in the United States and Platform.sh entities for support. Those three US services remain in play even when the project region is inside the EU.Source · As of 2025-09-23 |
| Third-country transfer | Does not arise when operated inside the EU; possible via US subprocessors with Sulu.cloud, where Upsun relies on the EU standard contractual clausesWhen you host it yourself this is a consequence of your own operating decision, not of the software. For Sulu.cloud, Upsun's commitment applies that project data does not leave the chosen region; for transfers out of the European Economic Area Upsun explicitly relies on the EU standard contractual clauses where no adequacy decision applies. Sulu.ai has to be assessed separately: depending on the model provider you select, content can go to OpenAI, Anthropic or Google, and Sulu GmbH says nothing about the transfer route for that.Source · As of 2026-07-30 |
| Training on customer data | No transfer to the software maker in the base installation; with Sulu.ai content goes to the model provider you select, and there is no public commitment against trainingWith no data leaving, there is no training question. It returns the moment Sulu.ai is connected. That offering has been available since 3 February 2026, is attached to an existing installation with a single key, and lets you choose between OpenAI, Anthropic, Mistral, Google and DeepL, plus a model class described as European and built on Mistral. We found no explicit statement that customer content is not used for training; we checked https://sulu.io/ai, https://sulu.io/sulu-ai, the launch post and the privacy notices from October 2019. Anyone adopting Sulu.ai has to obtain that commitment in writing.Source · As of 2026-02-03 |
| Retention and deletion | Your own responsibility; deleted records sit in the application's trash with no expiry until somebody empties itRetention, deletion and backups are set and owed by the operator. One detail matters for deletion practice: Sulu ships a TrashBundle that keeps deleted records together with the data needed to restore them and only removes them for good when prompted. The documentation provides no automatic expiry. A deletion policy therefore has to state when the trash is emptied, otherwise the record outlives your own retention limit.Source · As of 2026-07-30 |
| Certifications | None for the software, and none findable for Sulu GmbH itself; for Sulu.cloud the evidence comes from Upsun, with ISO 27001, SOC 2 Type 2 and PCI DSS Level 1Self-hosted software carries no operating certificates. Evidence comes from your own operation or your hosting provider. We found no security or trust page of Sulu GmbH's own carrying audit reports; we looked on sulu.io, in the privacy notices, in the imprint and through web search. What does exist is a published security policy in the core repository: reports go to security@sulu.io, and only versions from 2.6.0 upwards are supported. For the managed offering, Upsun's certifications apply and are listed at https://upsun.com/trust-center/. They cover the platform, not the application.Source · As of 2026-07-30 |
| EU AI Act, Article 50 | Not engaged in the base installation; with Sulu.ai the Article 50 transparency duty arises for the operatorWithout connected AI features no Article 50 transparency duty arises. Sulu.ai is precisely such a feature, since it produces text, metadata, alt text and translations. The duty then sits with the operator of the website, not with the maker of the software. Sulu GmbH says nothing about the AI Act on its AI pages; we checked https://sulu.io/ai, https://sulu.io/sulu-ai and the launch post of 3 February 2026.Source · As of 2026-07-30 |
| Audit logging | Built into the core: Sulu ships an ActivityBundle that records events with type, resource and user in your own databaseBecause application and database are under your control, auditability is a question of implementation rather than of pricing tier. Sulu supplies the basis: the ActivityBundle sits in the core package alongside the Admin, Security and Trash bundles and stores activities through Doctrine in your own database by default. Two settings have to be chosen deliberately, because the adapter can be set to null, which switches storage off, and an event's payload is only written when persist_payload is enabled. The default is off.Source · As of 2026-07-30 |
What it really costs
Entry price
The software is free under the MIT licence. You pay for support, consulting, training and development; we found no public price list for those.
Source · As of2026-07-30
What gets expensive
Operations. Servers, updates, backups, security fixes and the person who is reachable when something breaks. Anyone who fails to budget for that has not saved money, only deferred the bill.
What it displaces
- Licence cost of a hosted content system
- Dependence on a vendor's storage location
Interfaces
- Symfony application
- Your own database
- REST extensions in your own code
At Convios: Trialled by us
We reviewed Sulu and did not choose it for our own sites, because editing across two domains is simpler from a hosted system. That verdict applies to our case, not in general.
Alternatives
Evidence
- 1.MIT licence, vendor Sulu GmbH, nature of the paid offerings · As of 2026-07-30
- 2.Registered office in Dornbirn, register number FN 495861h, managing director Thomas Schedler, ownership split 75 to 25 · As of 2026-07-30
- 3.The published privacy notices date from October 2019, cover only Sulu's own website, name MailChimp and Google Analytics in the United States and contain no data processing agreement · As of 2026-07-30
- 4.Security policy of the core repository: reports go to security@sulu.io, and only versions from 2.6.0 upwards are supported · As of 2026-07-30
- 5.Sulu.cloud is Sulu running on SymfonyCloud, that is Upsun; Upsun operates the infrastructure and a separate Upsun account is required · As of 2026-07-30
- 6.Announcement of the managed Sulu.cloud offering on 18 February 2026, available with a trial period · As of 2026-02-18
- 7.Upsun publishes a data processing agreement and binds its subprocessors through it · As of 2026-07-30
- 8.Upsun subprocessor list dated 23 September 2025, including Fastly, Sentry and SendGrid in the United States · As of 2025-09-23
- 9.Upsun's commitment that project data does not leave the chosen region, and its reliance on the EU standard contractual clauses for transfers out of the European Economic Area · As of 2026-07-30
- 10.Upsun EU regions: de-2 Germany, fr-3 and fr-4 France, eu Ireland, eu-5 Sweden · As of 2026-07-30
- 11.Certifications of the Upsun platform: ISO 27001, SOC 2 Type 2, PCI DSS Level 1 · As of 2026-07-30
- 12.Sulu.ai available since 3 February 2026, connected with a single key, with a choice of OpenAI, Anthropic, Mistral, Google and DeepL and a European model class built on Mistral · As of 2026-02-03
- 13.The ActivityBundle and TrashBundle sit in the core package alongside the Admin and Security bundles · As of 2026-07-30
- 14.Logging defaults to Doctrine, the adapter can be set to null to switch it off, and persist_payload defaults to off · As of 2026-07-30
- 15.The TrashBundle keeps deleted records for restoration and has no automatic expiry · As of 2026-07-30
Last reviewed: 2026-07-30byDr. Oliver Gausmann, Convios GmbH
Details out of date? Let us know.