| Independent security / no-logs audit | ❌Not foundNo public third-party no-logs or mail-specific penetration audit PDF found for Cloud Mail; ISO ISMS certs are separate. | ❌Not foundNo public third-party no-logs or full security audit PDF located; privacy claims are first-party. |
|---|
| ISO 27001 | ⚠️Vendor claimedVendor certifications page: ISO/IEC 27001:2022, scope includes mail services; AXE REGISTER cert IT18-27702D (listed valid until 28 Nov 2027). Not independently re-verified in a public registry by this draft. | ⚠️Vendor claimedVendor states independently audited ISO 27001; certificates available on request via support@soverin.net. Not re-verified against a public registry entry in this pass. |
|---|
| ISO 27017 / 27018 (cloud) | ⚠️Vendor claimedPublished on certifications page as appendices to the ISO 27001 certificate; mail services in process scope. | Not listed |
|---|
| SOC 2 / SOC 3 | ❌Not foundNot listed on the public certifications page. | ❌Not foundNo SOC 2/3 claim found on primary pages reviewed. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedItalian controller entity, named DPO, privacy policy under GDPR; product marketed as GDPR-oriented; CISPE CoC adherence claimed. | ⚠️Vendor claimedNL entity; AVG-framed privacy statement; EU-only processing claimed; GDPR Proof messaging on recognitions page. |
|---|
| CISPE Code of Conduct | ⚠️Vendor claimedCertifications page: Seeweb cloud services adhere to CISPE; claims storage exclusively within European territories for covered services. | Not listed |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEuropeanStack assessment: EU entity, DHH European group, no known US parent; public hosting story is Seeweb EU DCs and CISPE EU territory claim; backups on Seeweb off-site DCs (Spectrum Protect software, not described as US cloud mailbox SaaS). Residual gaps: no full public subprocessor list; antispam uses external reputation services not named on the docs page. Not legal advice. | ⚠️PartialEuropeanStack assessment: low exposure path—Dutch Soverin B.V., Dutch The Sharing Group owner, claimed self-operated NL hosting without public AWS/GCP/Azure mailbox hosts. Partial because residual subprocessors (support partner jurisdiction, domain partners, HIBP hash checks) need buyer confirmation. Not legal advice. |
|---|
| Data processing agreement (B2B) | ❌Not foundNo downloadable product DPA found on the marketing site; general conditions reference GDPR processing and the privacy notice. Request Art. 28 terms for mail content before go-live. | ⚠️Vendor claimedPrivacy statement states it qualifies as an Article 28 AVG processing agreement; other DPAs expressly rejected. Confirm signed annex for enterprise use. |
|---|
| EU AI Act | —Not applicableCloud Mail is conventional email hosting, not an AI product. | —Not applicableEmail hosting product; vendor emphasises no AI scanning/mining of mailbox content for ads. |
|---|
| ISO 9001 / ISO 14001 | Not listed | ⚠️Vendor claimedVendor-claimed quality and environmental certifications; certificates on request. |
|---|
| NIS2 readiness | Not listed | ⚠️Vendor claimedVendor markets NIS2 Ready; buyer press also asserts NIS2 compliance—confirm evidence package. |
|---|
| NEN 7510 (healthcare NL) | Not listed | ⚠️PartialVendor states NEN 7510 certification is in progress, not completed. |
|---|