Hive
Steady weekly shipping, with Jira write-back the one release that changes what Hive is.
A side-by-side editorial comparison of Document360 and SOGo — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | Document360 | SOGo |
|---|---|---|
| Sector | Collab | Collab |
| Velocity score | 6.3 | 2.5 |
| Sparks · 30d | 1 | 0 |
| Top themes | api, oauth, mcp, knowledge base | groupware, self-hosted, security, webmail |
| Last editorial update | 4d ago | 2h ago |
| Website | — | Visit → |
Document360 rebuilds its public API and turns docs into an agent-readable surface.
Document360 ships a dated release every two to four weeks and the last six months have been dominated by two threads: making the knowledge base machine-consumable, and hardening enterprise access control. The AI thread runs from the March MCP server through publishing and workflow tools in June and per-reader-group AI restrictions this month; the access thread runs SCIM provisioning, multiple JWT configurations, and reader permission inheritance. This release adds a ground-up API v3 with OAuth 2.0 and scoped keys.
SOGo's release notes have become a vulnerability disclosure channel with a version number attached.
SOGo is a self-hosted groupware suite — webmail, calendaring and contacts — maintained by Alinto. Four of the last six releases exist primarily to fix security vulnerabilities: XSS through malicious mail, SQL injection, OpenID impersonation, script execution via theme and hint query parameters. The newest, 5.12.10, fixes four more and states that all previous versions are affected, with CVE identifiers still pending at publication.
Document360 ships a dated release every two to four weeks and the last six months have been dominated by two threads: making the knowledge base machine-consumable, and hardening enterprise access control. The AI thread runs from the March MCP server through publishing and workflow tools in June and per-reader-group AI restrictions this month; the access thread runs SCIM provisioning, multiple JWT configurations, and reader permission inheritance. This release adds a ground-up API v3 with OAuth 2.0 and scoped keys.
The product is being rebuilt around programmatic access rather than portal usage. MCP made the knowledge base writable by an assistant, llms.txt made it discoverable to crawlers, copy-as-Markdown and open-in-ChatGPT made articles portable, and API v3 now gives all of that a permission-aware substrate the old v1/v2 endpoints could not support. The same permission model is showing up on the reader side too — Eddy AI features are now gated per reader group — so authorization is becoming the shared spine across API, AI, and reader access.
Expect the advanced API v3 endpoints to keep expanding as a paid add-on and the MCP server to be re-plumbed onto v3's scoped-key model, since MCP currently sits outside the new authorization scheme. A v1/v2 deprecation notice is the other likely follow-up.
SOGo is a self-hosted groupware suite — webmail, calendaring and contacts — maintained by Alinto. Four of the last six releases exist primarily to fix security vulnerabilities: XSS through malicious mail, SQL injection, OpenID impersonation, script execution via theme and hint query parameters. The newest, 5.12.10, fixes four more and states that all previous versions are affected, with CVE identifiers still pending at publication.
The pattern is a codebase whose input-handling surface is being systematically probed, largely by the community reporting to the project's bug address, and patched in batches. Release numbering has stopped being reliable as a timeline — 5.12.7 shipped after 5.12.8 — so version order tells you nothing about what a deployment contains. The two non-security releases in this window were both regression repairs from the security releases that preceded them, which is the cost of shipping fixes at this cadence.
Given four security batches in five months and CVE identifiers still being assigned retroactively, another batch on the same cadence is the most likely next release, with a regression patch following it.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Document360 or SOGo.
Steady weekly shipping, with Jira write-back the one release that changes what Hive is.
GitHub is standardising the agent layer it doesn't own, while the model roster churns underneath.
Staffbase's public feed is employer branding, not product — the release signal isn't here.
A nightly canary train where the AI platform work hides between dependency bumps
pagedown is down to one small fix a year, mostly absorbing changes from elsewhere.
After three quiet years, tufte 0.15 finally lets Tufte-style documents cross-reference.
See all Document360 alternatives → · See all SOGo alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Document360 is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Document360 is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top Document360 alternatives in Collab are ranked by recent ship velocity. Browse the "Document360 alternatives" section above for the current picks, or visit /alternatives/document360 for the full list with editorial commentary on each.
Top SOGo alternatives in Collab are ranked by recent ship velocity. Browse the "SOGo alternatives" section above for the current picks, or visit /alternatives/sogo for the full list with editorial commentary on each.