Eviworx
Guide · vendor-neutral

Comparing ticketing systems: open source or commercial on-premise ITSM? Ten questions that decide.

Whether you are replacing a helpdesk tool or introducing your first ticketing system: product names are interchangeable, the questions are not. This checklist helps mid-sized IT departments make offers comparable — whichever vendor you end up choosing.

Four models, four cost logics

Most offers on the market fall into one of these patterns. None is better per se — but each shifts cost and responsibility somewhere else.

Open source, no contract Open source with support subscription Commercial, on-premise SaaS
License cost nonenone; subscription for support and often add-on moduleslicense per agent, user or sitesubscription per agent per month
Security updates community; check commitment and durationvendor, usually current version onlyvendor, contractualvendor, automatic
Operation & backups youyou, partly with helpyou, with vendor supportprovider
Data sovereignty entirely yoursentirely yoursentirely yourswith the provider, under a processing agreement
Source code openopenusually closedclosed
Typical pitfalls add-on packages for ITSM processes, outdated community editions, no response timessubscription tiers with limits on agents or assets, SSO only at extra costfewer languages, smaller community, price on request onlydependence on availability and pricing policy, data location

The ten questions for every vendor

Ask them in writing and get the answers in writing. What impresses in the demo rarely ends up in the contract.

1. Who delivers security updates — and for how long?

Which versions get patches, is there a published lifecycle policy, and what happens to a free edition when the vendor changes strategy?

Ask: “Which version will still receive security updates in three years, and what will that cost?”

2. What does it really cost over three years?

License plus support plus operating hours plus add-on modules. Watch for limits in subscription tiers: maximum agents, maximum assets, features only from the next tier up.

Ask: “Please quote 20 agents, 1,500 assets, SSO and support with response times — as a total per year.”

3. How is it operated?

Are containers officially supported or merely tolerated? Which database is mandatory? How does an update work, how a rollback? Is there a multi-instance option?

Ask: “Show me the system requirements and an update log of the last version.”

4. Are incident, problem and change in the core?

Some systems are customer-service tools with a ticket function; ITSM processes come as an add-on or not at all. For IT operations you need all three processes, linked to each other.

Ask: “Which processes are included without an add-on module, and how are they connected?”

5. Where do assets, licenses and contracts live?

In the core, as a plugin, or in a third-party system with an interface? Are there limits on the number of assets? Handover records, stocktaking, notice periods — or just a list?

Ask: “Show me the path of a notebook from purchase to return.”

6. How do users sign in?

Single sign-on with your directory (Entra ID, SAML, OIDC) natively or via a plugin at extra cost? Can multi-factor authentication be enforced, per role?

Ask: “SSO with our Entra ID — what needs to be licensed and installed for that?”

7. How robust is the traceability?

An audit log that administrators can edit is of little use in an audit. Ask whether entries are chained, whether the chain can be verified, and whether that applies to all objects or only the admin area.

Ask: “How do I prove that an audit entry was not altered afterwards?”

8. How do email and self-service enter the system?

Mailboxes via IMAP and Microsoft 365, matching replies to the right case, protection against out-of-office loops, forms with required fields and approvals.

Ask: “What happens to a reply to a ticket that has since been merged?”

9. How do I get out again?

Export formats, direct database access, license model (per agent, concurrent, per user) and notice periods. Vendor lock-in is not created by closed code but by missing exports.

Ask: “Please give me a full export of the demo data in an open format.”

10. Who is the vendor — and where?

Registered office, legal form, support language and hours, governing law. When self-hosting, the vendor is not a processor for the operation; still clarify whether telemetry or license checks send data outside.

Ask: “Which outbound connections does the installation make, and what is transmitted?”

How Eviworx answers the ten questions

So that you can measure us with the same list as everyone else. Eviworx is a commercial on-premise ITSM and the source code is not open — that is part of the honest answer.

  1. Eviworx delivers security updates as part of the subscription; container images are scanned for known vulnerabilities in our registry.
  2. Public pricing from €299 per month, all modules included, billed by active agents; tickets, assets and end users unlimited.
  3. Container platform with 12 services on PostgreSQL 17 and Redis, officially via Docker Compose, multi-instance operation with distributed locks.
  4. Tickets, sub-tickets, incidents, problems and changes in the core, linked to each other and to assets and knowledge articles.
  5. Asset management with eleven lifecycle statuses, handover record as PDF with QR code, stocktaking by scan; licenses, contracts and cost centers without an add-on module.
  6. Single sign-on with Microsoft Entra ID and TOTP multi-factor authentication with backup codes in the core; role model with visibility scoping.
  7. Audit history SHA-256 chained for all objects, chain verifiable; viewing sensitive values such as license keys is logged.
  8. Mailboxes via IMAP and Microsoft 365, replies matched by headers, ticket number and history, loop protection for out-of-office replies, forms with server-side validation and approvals.
  9. Exports as CSV, XLSX and PDF, data-subject access export as JSON, direct access to your own PostgreSQL database; billing per active agent.
  10. Eviworx Software UG (haftungsbeschränkt), Neu-Isenburg near Frankfurt, support in German and English; offline license activation for networks without internet access.

Eviworx supports you with architecture and processes in meeting GDPR and NIS2 requirements. This does not constitute a certification or a legally binding declaration of conformity.

Frequently asked questions about selection

Is open source automatically cheaper? +

The license costs nothing, the operation does: installation, updates, security patches, backups and monitoring are on you or a service provider. Many open-source vendors sell support subscriptions for exactly that. Add up license, support and operating hours over three years, then you are comparing like with like.

How do I recognise a product that is being phased out? +

By how it handles security updates. Ask which versions the vendor patches, for how long, and whether there is a published lifecycle policy. A “community edition” without an update commitment is a risk, not a gift.

Do I need asset management in the ticketing system? +

If your IT hands out hardware, counts licenses and renews contracts: yes. A ticket about a device is worth far more when the device sits in the same system with serial number, user, contract and history. Separate tools create the gaps that show up in audits.

What about GDPR when self-hosting? +

When you run the system in your own infrastructure, no cloud provider processes your data, so no data processing agreement is needed for the operation itself. Responsibility for access control, deletion concept and evidence stays with you. Check what the product brings for that: role model, access and erasure functions, audit history.

Want to go through the list with us?

30 minutes, your ten questions, our answers on the live system — or a 30-day trial in your own environment.