Cloud Mail vs Tuta

Compare Cloud Mail and Tuta on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Google Workspace, Microsoft 365, Outlook.com

Logo: Cloud Mail

Cloud Mail

Italy· Email Services

Needs review

Shortlist Cloud Mail when you need Italian-operated, managed domain email with Plesk, Roundcube, CalDAV/CardDAV, and pre-delivery antispam on Seeweb infrastructure. Skip when you need end-to-end encrypted / zero-access mail (consider Proton Mail or Tuta) or a full Workspace/365 productivity suite (Google Workspace / Microsoft 365).

Managed domain emailPlesk administrationCalDAV / CardDAVISO 27001 (claimed)CISPE CoC (claimed)Italian / EU operator
Logo: Tuta

Tuta

Germany· Email Services

Needs review

Shortlist when you need default end-to-end encrypted mail, calendar, and contacts under German law with post-quantum TutaCrypt and official multi-platform apps. Skip when teams must keep Outlook/Thunderbird via IMAP or need a full M365/Workspace suite—consider Proton Mail (Bridge) or mailbox.org instead.

Default mailbox E2EETutaCrypt post-quantumEU-operated (Germany)Open-source clientsDE data centers (claimed)No IMAP (by design)
Cloud Mail vs Tuta: Snapshot
FeatureLogo: Cloud MailCloud MailLogo: TutaTuta
Country of originItalyGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersItalyGermany
Legal entitySeeweb S.r.l. (VAT IT02043220603), Via Armando Vona 66, 03100 FrosinoneTutao GmbH (HRB 208014, Hanover)
Governing lawItaly / EU (forum of Frosinone referenced in general conditions)German law / GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencySeeweb-operated European infrastructure (proprietary DCs in Milan and Frosinone; group facilities also listed in Lugano, Zurich, Sofia). Cloud Mail backups: daily off-site to another Seeweb data center using IBM Spectrum Protect software. CISPE materials claim European territorial storage for covered cloud services. No public AWS/GCP/Azure hosting path found for this product.Vendor states mailbox data is stored end-to-end encrypted on Tutao-operated servers in ISO 27001-certified data centers in Germany. No AWS/GCP/Azure primary hosting named on official security/privacy pages. Privacy statement discloses payment processing via PayPal (Europe) and banks for card/SEPA; no comprehensive public subprocessor list found for ops tools.
Summary

Seeweb’s managed professional domain email: Plesk admin, Roundcube webmail, CalDAV/CardDAV, pre-delivery antispam, and daily off-site backups on Italian/EU infrastructure.

German end-to-end encrypted email, calendar, and contacts from Tutao GmbH in Hanover—with post-quantum TutaCrypt, open-source clients, and freemium personal plus business plans.

Tags
At a glance: Cloud Mail vs Tuta
At a glanceLogo: Cloud MailCloud MailLogo: TutaTuta
HQFrosinone, Italy (Seeweb S.r.l.)Hanover, Germany (Tutao GmbH)
GroupDHH (Euronext Growth Milan) since 2020Not listed
Product typeManaged domain email hostingNot listed
Admin / webmailPlesk + RoundcubeNot listed
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVNo IMAP/SMTP client access; official apps only
Open source productNo (managed service; Roundcube is the webmail UI)Not listed
Self-hosted productNoNot listed
Commercial modelPaid storage/mailbox packs; domain required; WhiteLabel availableFreemium personal + paid personal/business (no ads)
ProductNot listedEncrypted email, calendar, contacts (SaaS)
HostingNot listedOwn servers in ISO 27001 data centers in Germany (vendor claim)
Open sourceNot listedClients GPLv3 on GitHub; no productized self-host
CryptoNot listedTutaCrypt hybrid (Kyber-1024 + X25519 + AES-256) for new accounts
Key capabilities: Cloud Mail vs Tuta
Key capabilitiesLogo: Cloud MailCloud MailLogo: TutaTuta
Managed domain emailYesNot listed
Plesk administrationYesNot listed
CalDAV / CardDAVYesNot listed
ISO 27001 (claimed)YesNot listed
CISPE CoC (claimed)YesNot listed
Italian / EU operatorYesNot listed
Default mailbox E2EENot listedYes
TutaCrypt post-quantumNot listedYes
EU-operated (Germany)Not listedYes
Open-source clientsNot listedYes
DE data centers (claimed)Not listedYes
No IMAP (by design)Not listedYes

Cloud Mail

  • Plesk domain mail admin (mailboxes, aliases, forwards)

    One admin account manages mailboxes, passwords, aliases, forwards, and auto-replies in Plesk, with quota/usage visibility per account. Suited to SMEs and resellers who want classic hosting-style control without running their own MTA.

  • Roundcube webmail + IMAP/POP3/SMTP on mail.truemail.it

    Users access mail via Roundcube (webmail.truemail.it) or standard clients. Docs publish IMAP/POP3/SMTP endpoints with STARTTLS and SSL port options for Outlook, Thunderbird, Apple Mail, and mobile. CalDAV and CardDAV cover calendar and contacts sync.

  • Managed pre-delivery antispam/antivirus (no default spam folder)

    Centralized filters check sender IP/domain behaviour and content before the message is accepted. Rejected spam is returned to the sender rather than filed in a default spam mailbox; false positives are handled via ticket or report@postmaster.seeweb.it. Accuracy is not claimed to be 100%.

  • Daily off-site backups (IBM Spectrum Protect, 30-day history)

    Incremental daily backups run to a remote Seeweb data center using IBM Spectrum Protect software. Deleted mail can be requested for recovery within about 30 days; restores recover the backed-up set rather than individual selected messages, so IMAP is recommended.

  • Scalable domain packs + WhiteLabel resale

    Plans scale from small 5 GB / 5-mailbox packs through large multi-hundred-GB packs with matching mailbox counts (up to on the order of 1,280 mailboxes). A domain is required at activation. WhiteLabel supports partners who resell branded mail on Seeweb’s managed stack.

Tuta

  • Default E2EE for mail, subjects, and attachments

    Between Tuta users, messages encrypt automatically including subject lines, bodies, and attachments. External recipients can use a shared password for end-to-end threads without installing software. Contacts and calendars use the same zero-access model; only delivery metadata (addresses, timestamps) stays readable by design.

  • TutaCrypt post-quantum hybrid cryptography

    New accounts use TutaCrypt: Kyber-1024 KEM plus X25519 ECDH with AES-256, targeting harvest-now-decrypt-later risks. Protocol details are published; existing accounts migrate as key rotation rolls out. Tuta intentionally avoids PGP so subjects and non-mail features can stay encrypted and algorithms can be upgraded in-product.

  • Zero-knowledge calendar with private reminders

    Calendar events—including times, titles, locations, and attendees—are end-to-end encrypted. Reminders are pushed as encrypted payloads and fired locally so servers are not told when an event starts. Sharing stays encrypted; invites can go out via mail, optionally password-protected for externals.

  • Open-source multi-platform clients (no IMAP)

    Web, Android (Play and F-Droid), iOS, Windows, macOS, and Linux clients are published under GPLv3 on GitHub. Desktop builds are signed for verification. There is no IMAP/SMTP bridge: third-party mail apps cannot connect, which preserves encryption at rest but forces a client switch for Outlook/Thunderbird holdouts.

  • Business domains, admin console, and whitelabel

    Paid business plans add custom domains, aliases, shared mailboxes, multi-admin roles, password/2FA resets, catch-all, templates, and optional branding/login on your own site. Vendor-stated uptime SLA and a GDPR order-processing agreement support B2B procurement—confirm current plan matrix on tuta.com.

Assurance & compliance: Cloud Mail vs Tuta
Assurance & complianceLogo: Cloud MailCloud MailLogo: TutaTuta
Independent security / no-logs audit
Not found

No public third-party no-logs or mail-specific penetration audit PDF found for Cloud Mail; ISO ISMS certs are separate.

Vendor claimed

Vendor states SySS GmbH penetration testing before public release; not a continuously published annual no-logs audit PDF on the marketing site.

ISO 27001
Vendor claimed

Vendor certifications page: ISO/IEC 27001:2022, scope includes mail services; AXE REGISTER cert IT18-27702D (listed valid until 28 Nov 2027). Not independently re-verified in a public registry by this draft.

Partial

Official pages claim data centers are ISO 27001 certified; does not clearly establish a public Tutao GmbH organizational ISO 27001 certificate.

ISO 27017 / 27018 (cloud)
Vendor claimed

Published on certifications page as appendices to the ISO 27001 certificate; mail services in process scope.

Not listed
SOC 2 / SOC 3
Not found

Not listed on the public certifications page.

Not found

No SOC 2/3 report located on security, business, or privacy pages.

GDPR / EU data protection
Vendor claimed

Italian controller entity, named DPO, privacy policy under GDPR; product marketed as GDPR-oriented; CISPE CoC adherence claimed.

Vendor claimed

German controller Tutao GmbH; privacy statement cites GDPR; DPO published; DE storage claimed.

CISPE Code of Conduct
Vendor claimed

Certifications page: Seeweb cloud services adhere to CISPE; claims storage exclusively within European territories for covered services.

Not listed
US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, DHH European group, no known US parent; public hosting story is Seeweb EU DCs and CISPE EU territory claim; backups on Seeweb off-site DCs (Spectrum Protect software, not described as US cloud mailbox SaaS). Residual gaps: no full public subprocessor list; antispam uses external reputation services not named on the docs page. Not legal advice.

Partial

EU entity, no known US parent, primary mailbox hosting claimed as own DE servers—not AWS/GCP/Azure. Payment may use PayPal (Europe). Assessment is low exposure for content with residual billing/processor unknowns; not a vendor 'safe' claim. Not legal advice.

Data processing agreement (B2B)
Not found

No downloadable product DPA found on the marketing site; general conditions reference GDPR processing and the privacy notice. Request Art. 28 terms for mail content before go-live.

Vendor claimed

Security/business materials state an Order Processing Agreement (Auftragsverarbeitung) is provided for GDPR; obtain signed version via sales—no public self-serve DPA URL confirmed.

EU AI Act
Not applicable

Cloud Mail is conventional email hosting, not an AI product.

Not applicable

Encrypted email/calendar product; vendor states it does not plan AI that processes user communications for model training.

Considerations & known limitations: Cloud Mail vs Tuta
Considerations & known limitationsLogo: Cloud MailCloud MailLogo: TutaTuta
Subprocessor / antispam feed list not public
Medium

Docs mention reputation services for antispam but do not publish a complete subprocessor table. Procurement should request the current list and transfer safeguards.

Medium

Privacy policy covers payments (e.g. PayPal Europe) but lacks a detailed live subprocessor register. Request the DPA annex for DPIA completeness.

Backup restore is set-based, not single-message
Low

30-day off-site history is useful, but restores recover the backed-up set; plan operational recovery expectations and prefer IMAP.

Not listed
Pre-delivery reject without default spam folder
Low

Strong filtering can block legitimate senders; there is no user-visible spam quarantine by default—use tickets/reporting workflows.

Not listed
Not zero-access / E2EE-first mail
Medium

Provider-managed conventional mail. Choose encrypted peers if the threat model assumes a compromised host provider.

Not listed
B2B DPA not prominent on site
Medium

Treat contract/DPA negotiation as a gate for regulated workloads until Art. 28 terms and roles (controller/processor for mailbox content) are signed.

Not listed
No IMAP/SMTP third-party clientsNot listed
High

Desktop and mobile holdouts cannot stay on Outlook/Thunderbird/Apple Mail. Plan full client migration or pick a standards-based alternative.

Weaker protection to non-Tuta recipientsNot listed
Medium

Without a shared password, external mail is ordinary SMTP (TLS in transit). Only Tuta-to-Tuta and password-protected external threads are true E2EE.

Hosted service, not on-prem mailNot listed
Medium

Open-source clients help inspectability, but mailboxes still depend on Tutao's German SaaS backend, uptime, and German legal process.

Data-center ISO vs company ISMSNot listed
Low

ISO 27001 wording refers to data centers. Do not tick 'vendor ISO 27001 certified' on questionnaires without the actual Tutao certificate.

German court orders on accessible dataNot listed
Low

Transparency reports show regular German requests. Stored E2EE content stays undecryptable by Tutao; real-time monitoring can expose newly arriving unencrypted SMTP mail. Align expectations with counsel.

Fit

Cloud Mail

Best fit when

  • SMEs and freelancers needing custom-domain business mail without a full Google/Microsoft suite
  • Teams that want classic IMAP/SMTP clients plus Roundcube webmail and CalDAV/CardDAV
  • Resellers seeking WhiteLabel managed mail on a European host
  • Organizations already using Seeweb compute/hosting that want mail in the same vendor relationship
  • Buyers prioritizing Italian legal entity, published ISO scopes that include mail, and CISPE-oriented residency messaging

Poor fit when

  • Threat models that require default end-to-end encryption or zero-access provider architecture
  • Need for full collaborative office suites, deep directory SSO, or Graph/Workspace app ecosystems
  • Teams that must self-host the MTA stack rather than buy managed mail
  • Procurement that requires a public SOC 2 report or a fully published subprocessor list before first contact

Consider instead when

  • When: You need zero-access / end-to-end encrypted mailboxes as the primary control

    Consider: Proton Mail or Tuta

    Different product class: E2EE-first vs conventional managed IMAP hosting

  • When: You need mail plus full productivity suite and global enterprise ecosystem

    Consider: Google Workspace or Microsoft 365

    Trade EU-operator focus for suite breadth and US-jurisdiction diligence

  • When: You want another European professional domain-mail host for comparison

    Consider: Migadu, Mailfence, or Combell E-mail

    Compare admin model, spam handling, restore RPO, and contract artifacts

Tuta

Best fit when

  • Teams that will standardize on Tuta's official web/mobile/desktop clients for default zero-access email
  • Orgs prioritizing subject-line encryption, encrypted calendar, and post-quantum hybrid crypto under German jurisdiction
  • SMEs needing custom domains, aliases, shared mailboxes, and multi-admin controls without running their own mail servers
  • Journalists, NGOs, and privacy-led departments that value F-Droid builds, no Google Push dependency, and ad-free operation
  • Buyers who want open-source client auditability plus a freemium path for personal trial before business seats

Poor fit when

  • Hard requirement for IMAP/SMTP in Outlook, Thunderbird, Apple Mail, or third-party automation
  • On-prem / customer-operated mail server mandates (no productized self-host for the backend)
  • Workflows that depend on first-class PGP or S/MIME interoperability with external partners
  • Primary need is full Google Workspace or Microsoft 365 collaboration (Drive, Meet, deep Outlook) rather than encrypted mail first

Consider instead when

  • When: Users must keep desktop IMAP clients or need Bridge-style Outlook integration

    Consider: Proton Mail (Bridge on paid plans) or mailbox.org / Posteo / Soverin

    Those options trade Tuta's automatic subject E2EE model for standards-based access

  • When: You need a broader German digital workplace (Drive, Office, video) with optional PGP

    Consider: mailbox.org

    Stronger suite breadth; different default encryption depth than Tuta's full zero-access mailbox

  • When: Swiss jurisdiction and multi-product privacy suite (VPN, drive, pass) matter more than German HQ

    Consider: Proton Mail

    Compare Bridge, ecosystem lock-in, and published cert posture side by side

  • When: Belgian OpenPGP-centric suite with browser crypto and classic protocols is preferred

    Consider: Mailfence

    Different encryption UX (PGP-oriented) versus Tuta's automatic proprietary stack

Open questions for due diligence

Cloud Mail

  • Will Seeweb provide a signed Art. 28 DPA and current subprocessor list for Cloud Mail content?
  • Which data center hosts a given Cloud Mail instance (Italy vs other European Seeweb/group sites), and can residency be constrained contractually?
  • Which external reputation / antispam intelligence providers are used, and where do they process metadata?
  • Is there a SOC 2, independent penetration test summary, or customer-available audit package under NDA?
  • What are exact SLA credits, RPO/RTO for mail, and support tier inclusions for pure Cloud Mail (vs Global Support for servers)?

Tuta

  • Will Tutao provide a current signed AVV/DPA with a full subprocessor list (DNS, billing, support, CDN if any)?
  • Is there a current organizational ISO 27001 or SOC 2 report for Tutao GmbH, or only facility-level data-center certification?
  • What is the documented status of TutaCrypt key rotation for all legacy accounts in your tenant?
  • Are any US-group cloud services used for backups, DNS, or support tooling beyond payment processors named in the privacy statement?
  • For business rollout: migration tooling limits (EML/MBOX import on desktop) and dual-running period with legacy IMAP hosts?