Cloud Mail vs Soverin

Compare Cloud Mail and Soverin on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365, Outlook.com

Logo: Cloud Mail

Cloud Mail

Italy· Email Services

Needs review

Shortlist Cloud Mail when you need Italian-operated, managed domain email with Plesk, Roundcube, CalDAV/CardDAV, and pre-delivery antispam on Seeweb infrastructure. Skip when you need end-to-end encrypted / zero-access mail (consider Proton Mail or Tuta) or a full Workspace/365 productivity suite (Google Workspace / Microsoft 365).

Managed domain emailPlesk administrationCalDAV / CardDAVISO 27001 (claimed)CISPE CoC (claimed)Italian / EU operator
Logo: Soverin

Soverin

Netherlands· Email Services

Needs review

Shortlist Soverin when you want Dutch-operated, paid IMAP email with custom domains, unlimited aliases, and strong mail-auth standards without Google/Microsoft ads. Skip when you need zero-knowledge E2EE—consider Proton Mail or Tuta instead—or a full productivity suite (mailbox.org / Microsoft 365).

NL / EU operatedCustom domainsIMAP / CalDAVNo ads / no trackingISO 27001 (claimed)DANE / DNSSEC
Cloud Mail vs Soverin: Snapshot
FeatureLogo: Cloud MailCloud MailLogo: SoverinSoverin
Country of originItalyNetherlands
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersItalyNetherlands
Legal entitySeeweb S.r.l. (VAT IT02043220603), Via Armando Vona 66, 03100 FrosinoneSoverin B.V. (Amsterdam); owned by The Sharing Group / TSG Online (Dutch) as of September 2025 acquisition announcement
Governing lawItaly / EU (forum of Frosinone referenced in general conditions)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencySeeweb-operated European infrastructure (proprietary DCs in Milan and Frosinone; group facilities also listed in Lugano, Zurich, Sofia). Cloud Mail backups: daily off-site to another Seeweb data center using IBM Spectrum Protect software. CISPE materials claim European territorial storage for covered cloud services. No public AWS/GCP/Azure hosting path found for this product.Vendor: EU-only processing; data in NL; self-operated Dutch DCs, no hyperscaler. TechRadar: 3 NL DCs. Core mail hosts on Soverin B.V. AS211993. External first-line support partner under DPA/NDA (country unpublished). HIBP k-anon password checks; Let’s Encrypt; domain DNSSEC partner. No AWS/GCP/Azure as primary mailbox hosts in public materials.
Summary

Seeweb’s managed professional domain email: Plesk admin, Roundcube webmail, CalDAV/CardDAV, pre-delivery antispam, and daily off-site backups on Italian/EU infrastructure.

Dutch privacy-first email hosting: custom domains, open IMAP/SMTP/CalDAV, 25 GB mailboxes, no ads or content scanning, servers operated in the Netherlands.

Tags
At a glance: Cloud Mail vs Soverin
At a glanceLogo: Cloud MailCloud MailLogo: SoverinSoverin
HQFrosinone, Italy (Seeweb S.r.l.)Amsterdam, Netherlands (Soverin B.V.)
GroupDHH (Euronext Growth Milan) since 2020The Sharing Group / TSG Online (acq. Sep 2025)
Product typeManaged domain email hostingNot listed
Admin / webmailPlesk + RoundcubeNot listed
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVIMAP, SMTP, CalDAV, CardDAV
Open source productNo (managed service; Roundcube is the webmail UI)Not listed
Self-hosted productNoNot listed
Commercial modelPaid storage/mailbox packs; domain required; WhiteLabel availableAnnual prepaid; 30-day mailbox money-back; no free tier
HostingNot listedDutch data centres; vendor claims self-operated, no hyperscaler
StorageNot listed25 GB per mailbox (vendor-stated)
Self-host / OSSNot listedNo / No
Key capabilities: Cloud Mail vs Soverin
Key capabilitiesLogo: Cloud MailCloud MailLogo: SoverinSoverin
Managed domain emailYesNot listed
Plesk administrationYesNot listed
CalDAV / CardDAVYesNot listed
ISO 27001 (claimed)YesYes
CISPE CoC (claimed)YesNot listed
Italian / EU operatorYesNot listed
NL / EU operatedNot listedYes
Custom domainsNot listedYes
IMAP / CalDAVNot listedYes
No ads / no trackingNot listedYes
DANE / DNSSECNot listedYes

Cloud Mail

  • Plesk domain mail admin (mailboxes, aliases, forwards)

    One admin account manages mailboxes, passwords, aliases, forwards, and auto-replies in Plesk, with quota/usage visibility per account. Suited to SMEs and resellers who want classic hosting-style control without running their own MTA.

  • Roundcube webmail + IMAP/POP3/SMTP on mail.truemail.it

    Users access mail via Roundcube (webmail.truemail.it) or standard clients. Docs publish IMAP/POP3/SMTP endpoints with STARTTLS and SSL port options for Outlook, Thunderbird, Apple Mail, and mobile. CalDAV and CardDAV cover calendar and contacts sync.

  • Managed pre-delivery antispam/antivirus (no default spam folder)

    Centralized filters check sender IP/domain behaviour and content before the message is accepted. Rejected spam is returned to the sender rather than filed in a default spam mailbox; false positives are handled via ticket or report@postmaster.seeweb.it. Accuracy is not claimed to be 100%.

  • Daily off-site backups (IBM Spectrum Protect, 30-day history)

    Incremental daily backups run to a remote Seeweb data center using IBM Spectrum Protect software. Deleted mail can be requested for recovery within about 30 days; restores recover the backed-up set rather than individual selected messages, so IMAP is recommended.

  • Scalable domain packs + WhiteLabel resale

    Plans scale from small 5 GB / 5-mailbox packs through large multi-hundred-GB packs with matching mailbox counts (up to on the order of 1,280 mailboxes). A domain is required at activation. WhiteLabel supports partners who resell branded mail on Seeweb’s managed stack.

Soverin

  • Custom domains with unlimited aliases

    Host mail on your own domain (bring existing or register through Soverin). Unlimited aliases—plus-addressing or domain names—deliver into one mailbox, plus optional random @sinenomine.email private aliases that hide the real address. Suits freelancers and SMEs who need brandable addresses without per-alias fees.

  • Open IMAP/SMTP plus CalDAV/CardDAV

    Use any standards-based client or device for mail, calendar, and contacts—no proprietary app required. Dashboard import helps migrate from other providers. Ideal when IT wants Thunderbird, Apple Mail, or Outlook without locking into a closed webmail ecosystem; not a zero-knowledge E2EE product by default.

  • Mail-path security: DANE, DKIM, DMARC, IP stripping

    Outbound and inbound paths use TLS; Soverin publishes and honours DANE/TLSA, signs with DKIM, publishes SPF/DMARC, enables DNSSEC on managed domains, and strips personal IP addresses from outbound headers. 2FA is available and can be admin-mandated. Buyers still need their own OpenPGP setup for end-to-end content secrecy with external parties.

  • 25 GB mailboxes with per-user encrypted backups

    Each mailbox includes a stated 25 GB quota covering mail, calendar, and contacts. Nightly backups use individually generated keys; Soverin states that emptying trash permanently deletes data and that leaving the service removes backups when the key is destroyed. Extra mailboxes can share storage for small teams.

  • Multi-mailbox and channel-friendly business use

    Purchase and assign additional mailboxes on a domain, with admin tooling for teams. Soverin markets to hosters, ISPs, MSPs, and independent professionals for multi-mailbox and white-label scenarios—useful when you want Dutch-operated email without building your own mail stack.

Assurance & compliance: Cloud Mail vs Soverin
Assurance & complianceLogo: Cloud MailCloud MailLogo: SoverinSoverin
Independent security / no-logs audit
Not found

No public third-party no-logs or mail-specific penetration audit PDF found for Cloud Mail; ISO ISMS certs are separate.

Not found

No public third-party no-logs or full security audit PDF located; privacy claims are first-party.

ISO 27001
Vendor claimed

Vendor certifications page: ISO/IEC 27001:2022, scope includes mail services; AXE REGISTER cert IT18-27702D (listed valid until 28 Nov 2027). Not independently re-verified in a public registry by this draft.

Vendor claimed

Vendor states independently audited ISO 27001; certificates available on request via support@soverin.net. Not re-verified against a public registry entry in this pass.

ISO 27017 / 27018 (cloud)
Vendor claimed

Published on certifications page as appendices to the ISO 27001 certificate; mail services in process scope.

Not listed
SOC 2 / SOC 3
Not found

Not listed on the public certifications page.

Not found

No SOC 2/3 claim found on primary pages reviewed.

GDPR / EU data protection
Vendor claimed

Italian controller entity, named DPO, privacy policy under GDPR; product marketed as GDPR-oriented; CISPE CoC adherence claimed.

Vendor claimed

NL entity; AVG-framed privacy statement; EU-only processing claimed; GDPR Proof messaging on recognitions page.

CISPE Code of Conduct
Vendor claimed

Certifications page: Seeweb cloud services adhere to CISPE; claims storage exclusively within European territories for covered services.

Not listed
US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, DHH European group, no known US parent; public hosting story is Seeweb EU DCs and CISPE EU territory claim; backups on Seeweb off-site DCs (Spectrum Protect software, not described as US cloud mailbox SaaS). Residual gaps: no full public subprocessor list; antispam uses external reputation services not named on the docs page. Not legal advice.

Partial

EuropeanStack assessment: low exposure path—Dutch Soverin B.V., Dutch The Sharing Group owner, claimed self-operated NL hosting without public AWS/GCP/Azure mailbox hosts. Partial because residual subprocessors (support partner jurisdiction, domain partners, HIBP hash checks) need buyer confirmation. Not legal advice.

Data processing agreement (B2B)
Not found

No downloadable product DPA found on the marketing site; general conditions reference GDPR processing and the privacy notice. Request Art. 28 terms for mail content before go-live.

Vendor claimed

Privacy statement states it qualifies as an Article 28 AVG processing agreement; other DPAs expressly rejected. Confirm signed annex for enterprise use.

EU AI Act
Not applicable

Cloud Mail is conventional email hosting, not an AI product.

Not applicable

Email hosting product; vendor emphasises no AI scanning/mining of mailbox content for ads.

ISO 9001 / ISO 14001Not listed
Vendor claimed

Vendor-claimed quality and environmental certifications; certificates on request.

NIS2 readinessNot listed
Vendor claimed

Vendor markets NIS2 Ready; buyer press also asserts NIS2 compliance—confirm evidence package.

NEN 7510 (healthcare NL)Not listed
Partial

Vendor states NEN 7510 certification is in progress, not completed.

Considerations & known limitations: Cloud Mail vs Soverin
Considerations & known limitationsLogo: Cloud MailCloud MailLogo: SoverinSoverin
Subprocessor / antispam feed list not public
Medium

Docs mention reputation services for antispam but do not publish a complete subprocessor table. Procurement should request the current list and transfer safeguards.

Not listed
Backup restore is set-based, not single-message
Low

30-day off-site history is useful, but restores recover the backed-up set; plan operational recovery expectations and prefer IMAP.

Not listed
Pre-delivery reject without default spam folder
Low

Strong filtering can block legitimate senders; there is no user-visible spam quarantine by default—use tickets/reporting workflows.

Not listed
Not zero-access / E2EE-first mail
Medium

Provider-managed conventional mail. Choose encrypted peers if the threat model assumes a compromised host provider.

Not listed
B2B DPA not prominent on site
Medium

Treat contract/DPA negotiation as a gate for regulated workloads until Art. 28 terms and roles (controller/processor for mailbox content) are signed.

Not listed
Not zero-knowledge E2EE by defaultNot listed
Medium

Unlike Proton/Tuta, Soverin is a classic IMAP host. Provider infrastructure can process content for delivery and spam filtering. Practical impact: unsuitable as a drop-in for policies that require provider-blind encryption without extra client crypto.

Unnamed external support partnerNot listed
Medium

Privacy statement discloses a first-line support partner with limited account data under DPA/NDA, but does not publish the partner name or country. Practical impact: add an open diligence item for any regulated workload.

ISO certificates not self-serve publicNot listed
Low

ISO 27001/9001/14001 are claimed with certificates via support rather than a public PDF registry link found in research. Practical impact: procurement should request current attestations before treating certs as verified.

2025 group acquisitionNot listed
Low

The Sharing Group acquisition may change subprocessors, tooling, or brand packaging over time even if continuity is promised. Practical impact: re-check DPA and hosting annex annually.

Email-centric supportNot listed
Low

Public materials emphasise human Dutch-team email support; TechRadar notes no live chat or phone. Practical impact: large orgs needing 24/7 phone SLAs may find coverage thin.

Fit

Cloud Mail

Best fit when

  • SMEs and freelancers needing custom-domain business mail without a full Google/Microsoft suite
  • Teams that want classic IMAP/SMTP clients plus Roundcube webmail and CalDAV/CardDAV
  • Resellers seeking WhiteLabel managed mail on a European host
  • Organizations already using Seeweb compute/hosting that want mail in the same vendor relationship
  • Buyers prioritizing Italian legal entity, published ISO scopes that include mail, and CISPE-oriented residency messaging

Poor fit when

  • Threat models that require default end-to-end encryption or zero-access provider architecture
  • Need for full collaborative office suites, deep directory SSO, or Graph/Workspace app ecosystems
  • Teams that must self-host the MTA stack rather than buy managed mail
  • Procurement that requires a public SOC 2 report or a fully published subprocessor list before first contact

Consider instead when

  • When: You need zero-access / end-to-end encrypted mailboxes as the primary control

    Consider: Proton Mail or Tuta

    Different product class: E2EE-first vs conventional managed IMAP hosting

  • When: You need mail plus full productivity suite and global enterprise ecosystem

    Consider: Google Workspace or Microsoft 365

    Trade EU-operator focus for suite breadth and US-jurisdiction diligence

  • When: You want another European professional domain-mail host for comparison

    Consider: Migadu, Mailfence, or Combell E-mail

    Compare admin model, spam handling, restore RPO, and contract artifacts

Soverin

Best fit when

  • Individuals and freelancers who want a paid European mailbox on their own domain with any standard mail client
  • SMEs needing several mailboxes, aliases, and CalDAV/CardDAV without adopting Google Workspace or Microsoft 365
  • Teams prioritising Dutch jurisdiction and claimed no-hyperscaler hosting over zero-knowledge E2EE
  • Hosters/ISPs/MSPs evaluating white-label or multi-mailbox Dutch email
  • Buyers who value DANE, DKIM/DMARC, DNSSEC, and IP-header stripping on an open-standards stack

Poor fit when

  • Organisations that require default zero-access / E2EE mail against the provider (use Proton Mail or Tuta)
  • Users seeking a free tier, anonymous cash-only signup, or purely self-hosted open-source mail servers
  • Enterprises needing SSO, eDiscovery archives, phone support SLAs, or a full office suite in one vendor
  • Workloads that depend on US-region mailbox hosting or hyperscale global PoPs

Consider instead when

  • When: You need zero-knowledge E2EE and a privacy-first mobile/web ecosystem

    Consider: Proton Mail or Tuta

    Trade open IMAP convenience for stronger default content secrecy vs the provider.

  • When: You want German-hosted paid mail with broader office-style add-ons

    Consider: mailbox.org or Posteo

    Compare storage, admin features, and payment anonymity (Posteo) against Soverin’s domain/alias model.

  • When: You need Google- or Microsoft-class collaboration and global free consumer mail

    Consider: Gmail or Microsoft 365 / Outlook.com

    Different risk and advertising model; not EU-sovereignty substitutes.

Open questions for due diligence

Cloud Mail

  • Will Seeweb provide a signed Art. 28 DPA and current subprocessor list for Cloud Mail content?
  • Which data center hosts a given Cloud Mail instance (Italy vs other European Seeweb/group sites), and can residency be constrained contractually?
  • Which external reputation / antispam intelligence providers are used, and where do they process metadata?
  • Is there a SOC 2, independent penetration test summary, or customer-available audit package under NDA?
  • What are exact SLA credits, RPO/RTO for mail, and support tier inclusions for pure Cloud Mail (vs Global Support for servers)?

Soverin

  • What is the legal name and country of the first-line support partner, and is a current subprocessor list available under NDA?
  • Can Soverin provide the latest ISO 27001/9001/14001 certificates and scope statements without delay?
  • After The Sharing Group acquisition, are any new group companies (e.g. Mijndomein, Greenhost, Leafcloud tooling) in the mailbox data path?
  • Is NEN 7510 certification complete for healthcare use cases, or still in progress?
  • Which domain registrar(s) handle customer DNSSEC, and where are registry data stored?