Can I ask a probably naive question - is self-hosting the main requirement? Or are there other certifications that are required in addition to ensure, for example, that it doesn't phone home with your data? Or is all of that covered by the fact that you self-host and are in control of outbound traffic?
Not the person you're replying to, but in my case it must be self-hosted and be able to function while completely offline (and therefore no phoning home).