eclipso Mail Europe vs Proton Mail

Compare eclipso Mail Europe and Proton Mail on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365, Outlook.com

Logo: eclipso Mail Europe

eclipso Mail Europe

Germany· Email Services

Needs review

Shortlist when you want German-hosted mail with direct IMAP/SMTP, optional OpenPGP/S/MIME free on all tiers, prepaid freemium cost control, and a small business suite (drive, calendar, hybrid SMS/fax/post). Skip when you need zero-access defaults, published ISO/SOC audits, or large-enterprise identity—consider Posteo, Tuta, Proton Mail, or mailbox.org instead.

Germany-hosted (claimed)OpenPGP + S/MIMEIMAP/SMTP nativePrepaid freemiumOwner-operated DEBusiness DPA (Art. 28)
Logo: Proton Mail

Proton Mail

Switzerland· Email Services

Needs review

Shortlist Proton Mail when you want Swiss-jurisdiction, zero-access encrypted email with open-source clients, custom domains, Bridge for desktop mailers, and a public DPA. Skip when you need free-tier IMAP Bridge, fully self-hosted FOSS mail on your own servers, or Workspace-class collaboration depth—consider Tuta, Posteo, or Mailfence among EU peers, or stay on Google/Microsoft if suite lock-in wins.

E2EE + zero-accessSwiss-operatedBridge (IMAP/SMTP)Open-source clientsISO 27001 & SOC 2 (claimed)Public B2B DPA
eclipso Mail Europe vs Proton Mail: Snapshot
FeatureLogo: eclipso Mail Europeeclipso Mail EuropeLogo: Proton MailProton Mail
Country of originGermanySwitzerland
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanySwitzerland
Legal entityClaus-Peter Beringer (eclipso Mail Europe), Grubstr. 9b, 95445 BayreuthProton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland (EU representative: Proton Europe sàrl, Luxembourg)
Governing lawGerman / EU law (GDPR, BDSG); BayLDA supervisory authority named in privacy noticeSwiss law (Terms; Geneva courts for business/non-US consumer disputes as stated in Terms)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyPrimary hosting claimed exclusively in Germany; privacy policy names Speedloc Datacenter (Görlitz) with AVV. Optional SMS/fax/post: Commify Germany, CM.com Germany, letterei.de (all DE). Payments: Stripe Payments Europe and PayPal (Europe). Site: Google reCAPTCHA; marketing ad partners documented; Matomo self-hosted analytics.Primary mail storage on Proton-owned servers in Switzerland (vendor security pages). Not marketed as AWS/GCP/Azure inbox hosting. Public privacy policy lists US-group processors for support and payments (Zendesk; Chargebee, Stripe, PayPal) and group support processing in North Macedonia and Taiwan; HubSpot noted for business sales inquiries.
Summary

Owner-operated German email and cloud suite with IMAP, optional OpenPGP/S/MIME, prepaid freemium, Drive/organizer, and hybrid SMS/fax/post—hosted in Germany.

Swiss end-to-end encrypted email from Proton AG: zero-access inbox storage, open-source clients, custom domains, and Bridge for desktop IMAP clients.

Tags
At a glance: eclipso Mail Europe vs Proton Mail
At a glanceLogo: eclipso Mail Europeeclipso Mail EuropeLogo: Proton MailProton Mail
HQBayreuth, GermanyPlan-les-Ouates (Geneva), Switzerland
Legal entityClaus-Peter Beringer (owner-operated)Proton AG (CHE-354.686.492); Proton Foundation supervision
Founded2003 (vendor)Not listed
HostingGermany; Speedloc Datacenter (Görlitz) named in privacy policyNot listed
Open sourceNoNot listed
Self-hostedNo (SaaS)Not listed
Commercial modelFreemail (ad-supported) + prepaid paid tiersFreemium + paid consumer and business seats
EncryptionOptional OpenPGP + S/MIME; TLS in transitNot listed
Hosting modelNot listedProton-owned hardware in Switzerland (vendor claim)
Self-hostNot listedNo (SaaS); clients open source
BridgeNot listedPaid plans that include Mail
Key capabilities: eclipso Mail Europe vs Proton Mail
Key capabilitiesLogo: eclipso Mail Europeeclipso Mail EuropeLogo: Proton MailProton Mail
Germany-hosted (claimed)YesNot listed
OpenPGP + S/MIMEYesNot listed
IMAP/SMTP nativeYesNot listed
Prepaid freemiumYesNot listed
Owner-operated DEYesNot listed
Business DPA (Art. 28)YesNot listed
E2EE + zero-accessNot listedYes
Swiss-operatedNot listedYes
Bridge (IMAP/SMTP)Not listedYes
Open-source clientsNot listedYes
ISO 27001 & SOC 2 (claimed)Not listedYes
Public B2B DPANot listedYes

eclipso Mail Europe

  • Native OpenPGP and S/MIME in every plan

    OpenPGP (RFC 4880/9580) key wizard and import work in webmail and apps, free from Freemail upward; S/MIME accepts user-supplied X.509 certificates for business clients. E2EE only applies when both sides use it—plain IMAP mail is not zero-access by default. Private keys for webmail PGP are held in the account under a passphrase for multi-device use.

  • Standard IMAP, POP3, SMTP plus CalDAV/CardDAV

    Direct protocol access for Thunderbird, Outlook, Apple Mail, and mobile clients without a bridge product. Calendar and contacts sync via CalDAV/CardDAV; Premium and Business add WebDAV for the cloud drive. Suits teams that refuse locked-in web-only mail.

  • German-hosted suite: mail, drive, organizer

    One account covers webmail, eclipso Drive file storage with link sharing, Media Center, calendar, address book, notes, and tasks. Vendor claims exclusive Germany data centres (privacy policy names Speedloc Datacenter, Görlitz). Storage and address limits scale by prepaid tariff; WebDAV and higher quotas need paid tiers.

  • Prepaid freemium with optional hybrid channels

    Freemail signs up without credit card or phone number and is ad-supported; paid Connect/Premium/Business terms are prepaid and end automatically after a reminder. Credits enable SMS, fax, and hybrid physical post through named German gateways—useful for crafts and SMEs still on those channels.

  • Business domain and Art. 28 DPA on Business plan

    Business includes a custom mail domain option, higher alias counts, daily send limits suitable for small campaigns, and an in-product Art. 28 GDPR DPA download per vendor docs. Not a full enterprise workspace: no public SCIM/SSO pack or multi-org admin model documented.

Proton Mail

  • Zero-access inbox encryption by default

    Bodies and attachments are encrypted so Proton states it lacks keys to read stored mail. Proton-to-Proton traffic is end-to-end encrypted automatically; external recipients need password-protected messages or PGP/WKD for comparable content protection. Subject lines are not fully E2EE under OpenPGP header rules.

  • Proton Mail Bridge for desktop IMAP clients

    Paid plans that include Mail can run Bridge locally to connect Outlook, Thunderbird, or Apple Mail over IMAP/SMTP while encrypting and decrypting on the device. Free accounts use official web/mobile/desktop apps instead of Bridge.

  • Custom domains, aliases, and business admin

    Paid and business tiers support custom domains, extra addresses, catch-all and groups, hide-my-email aliases, and org admin for seats, storage, and retention policies. Suits teams leaving Google/Microsoft who still need branded addresses.

  • Open-source clients with published audits

    Web, mobile, and desktop clients are published on GitHub with third-party audit reports linked from Proton’s open-source page. The hosted mail backend is not offered as self-hosted FOSS—audit client trust, not full server reproducibility.

  • Tracker blocking, PhishGuard, and Sentinel

    Built-in tracker protection, phishing heuristics, link confirmation, SPF/DKIM/DMARC for custom domains, hardware-key 2FA, and optional Proton Sentinel monitoring for high-risk accounts. Complements encryption with everyday abuse defenses.

Assurance & compliance: eclipso Mail Europe vs Proton Mail
Assurance & complianceLogo: eclipso Mail Europeeclipso Mail EuropeLogo: Proton MailProton Mail
Independent security / no-logs audit
Not found

No public third-party security or no-logs audit PDF located on official pages

Vendor claimed

Open-source clients with published third-party audit reports (web/desktop links on open-source page). Not a classic VPN no-logs court test; transparency report covers legal orders for accessible account data.

ISO 27001
Not found

No ISO 27001 claim found on official security/about pages at research time

Vendor claimed

Vendor announces ISO 27001 certification after external audit completed 2 May 2024; Trust Center links a certificate download. Confirm scope and validity at procurement time.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced on official site

Vendor claimed

Vendor announces first SOC 2 Type II attestation (July 2025 blog). Report typically under NDA—request from vendor for diligence files.

GDPR / EU data protection
Vendor claimed

German controller, DPO contact, BayLDA authority, GDPR rights language in privacy policy; servers claimed in Germany

Vendor claimed

Swiss controller/processor with EU representative; public DPA; GDPR materials for business. Adequacy/transfer mechanisms documented for non-adequate destinations.

US CLOUD Act exposure (indicative)
Partial

EU/DE owner-operated entity with DE hosting (Speedloc), but Stripe, PayPal, and Google reCAPTCHA/ad tooling introduce US-group processing paths for payment and website data. Not legal advice.

Partial

Swiss entity / no known US parent; inbox content on Proton-owned Swiss hardware with zero-access design. Partial exposure remains via US SaaS subprocessors (Zendesk support; Stripe/Chargebee/PayPal payments) and any account metadata Proton can access under Swiss process. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Art. 28 DPA described as included and downloadable on Business plan; confirm for lower tiers

Vendor claimed

Public DPA at proton.me/legal/dpa forms part of terms when Proton acts as processor; Swiss law, Geneva jurisdiction; general authorization for listed subprocessors.

EU AI Act
Not applicable

Email/cloud suite; not an AI system product

Not applicable

Core product is encrypted email. Optional Scribe assistant is ancillary; not an AI-centric offering for this catalog entry.

Considerations & known limitations: eclipso Mail Europe vs Proton Mail
Considerations & known limitationsLogo: eclipso Mail Europeeclipso Mail EuropeLogo: Proton MailProton Mail
Not zero-access by default
Medium

Without OpenPGP/S/MIME, mailbox content is accessible to the operator like traditional IMAP hosts. Webmail PGP private keys are stored in-account under a passphrase—review threat model vs pure local keys.

Not listed
US-group payment and site tooling
Medium

Stripe, PayPal, Google reCAPTCHA, and documented ad partners process personal data outside pure DE mailbox hosting. Material for CLOUD Act and transfer diligence even if mail servers stay in Germany.

Not listed
No public ISO/SOC or independent audit
Medium

Security assurance is first-party documentation only. Regulated buyers will need questionnaires, AVVs, and possibly on-request evidence.

Not listed
Freemail is ad-supported
Low

Free tier includes advertising as a service component. Paid tiers are marketed as ad-free; verify current footer/banner behaviour on the live product.

Not listed
Owner-operated scale limits
Low

Independent DE operator (not VC-backed hyperscale). Expect SME-grade support hours and product depth rather than global enterprise SLAs.

Not listed
Weaker defaults outside ProtonNot listed
Medium

Mail to Gmail/Outlook/others is not E2EE unless password-protected or PGP/WKD is used. Subject lines are not fully E2EE. Train users or you only protect the Proton-stored copy.

US support and payment processorsNot listed
Medium

Zendesk, Chargebee, Stripe, and PayPal appear in the public processor list. They should not see zero-access message bodies, but support content and billing data can touch US-group services—document this in DPIAs.

Bridge requires paid MailNot listed
Low

Desktop IMAP/SMTP via Bridge is not available on free accounts. Budget seats for users who refuse the official apps.

Hosted service, not self-hosted FOSS mailNot listed
Medium

Open-source clients improve inspectability but you still depend on Proton’s operated backend, uptime, and Swiss legal process. Unsuitable if policy mandates customer-operated mail servers.

Swiss legal orders on accessible dataNot listed
Low

Transparency reports show thousands of yearly legal orders for Mail with many complied. Bodies stay encrypted; recovery emails, IPs (when retained for abuse), and similar metadata may still be in scope. Align expectations with counsel.

Fit

eclipso Mail Europe

Best fit when

  • Individuals and freelancers who want German mail with Thunderbird/Outlook IMAP and optional OpenPGP without a bridge
  • SMEs needing a custom domain, German server claims, and an Art. 28 DPA on the Business plan
  • Buyers who prefer prepaid terms that end automatically over auto-renewing Big Tech suites
  • Users who still send SMS, fax, or hybrid physical post from the same account
  • Teams migrating from Gmail/Outlook that value CalDAV/CardDAV and a bundled drive/organizer

Poor fit when

  • Orgs that require zero-access architecture where the provider never stores decryptable mailbox keys by default
  • Enterprises needing public ISO 27001/SOC 2 reports, SCIM/SSO, or multi-tenant admin
  • Buyers who refuse any US-group payment or website tooling (Stripe, PayPal, Google reCAPTCHA/ads)
  • Users seeking open-source or self-hosted mail only

Consider instead when

  • When: You want a simple paid-only German privacy mailbox without freemium advertising

    Consider: Posteo

    Posteo is ad-free paid; eclipso differentiates with freemail and hybrid channels

  • When: You prioritise always-on encryption over standard IMAP clients

    Consider: Tuta or Proton Mail

    Tuta uses proprietary E2EE clients; Proton needs Bridge for full IMAP-style access

  • When: You need a broader paid German workplace suite with stronger enterprise packaging

    Consider: mailbox (formerly mailbox.org)

    Compare admin, audit, and collaboration depth on current vendor docs

  • When: You need Google/Microsoft collaboration depth more than EU operator control

    Consider: Gmail or Microsoft 365

    Different jurisdiction and data-use models

Proton Mail

Best fit when

  • Teams that need default end-to-end / zero-access encryption without running their own mail stack
  • Orgs that want Swiss legal venue and documented resistance to direct foreign data demands
  • Businesses migrating branded domains off Gmail/Outlook with Easy Switch and Bridge for desktop holdouts
  • Security-conscious professionals who value open-source clients, published audits, and hardware-key 2FA
  • Buyers who need a public DPA plus vendor-claimed ISO 27001 / SOC 2 Type II for questionnaires

Poor fit when

  • Fully self-hosted requirements (Proton Mail is SaaS; clients are open source, not a full on-prem mail server)
  • Desktop IMAP on free accounts only—Bridge needs a paid plan that includes Mail
  • Workflows that depend on unencrypted-looking mail to external parties who will not use password links or PGP
  • Teams that primarily need full Microsoft 365 / Google Workspace collaboration depth rather than encrypted mail first

Consider instead when

  • When: You want German E2EE email with a different crypto product surface and may not need Proton’s full ecosystem

    Consider: Tuta

    Compare desktop interoperability and business admin maturity side by side.

  • When: You want ad-free European mail with strong transport privacy but do not require zero-access E2EE for all stored content

    Consider: Posteo

    Different threat model: Posteo is privacy-forward without Proton’s zero-access default.

  • When: You need OpenPGP-centric mail with classic collaboration extras under Belgian operation

    Consider: Mailfence

    Weigh automatic Proton-to-Proton E2EE UX versus Mailfence’s model.

  • When: Collaboration suite depth and ecosystem lock-in outweigh encryption defaults

    Consider: Google Workspace or Microsoft 365

    Accept US-provider jurisdiction and scanning/processing models as tradeoffs.

Open questions for due diligence

eclipso Mail Europe

  • Can non-Business tariffs obtain a signed Art. 28 DPA and full subprocessor list on request?
  • Is Speedloc the sole host for mailbox content (not only the marketing site), and are backup/DR locations exclusively in Germany?
  • Are independent penetration tests or ISO plans available under NDA for enterprise buyers?
  • What exact data minimisation applies to freemail advertising versus paid ad-free tiers (inbox content vs account metadata)?
  • How are OpenPGP private keys encrypted at rest in the account store, and is export/deletion documented for offboarding?

Proton Mail

  • What exact data-center sites and any non-Swiss regions apply to your tenant’s mailbox replicas today?
  • Will Proton provide the full SOC 2 Type II report under NDA and confirm ISO 27001 certificate scope/expiry for your questionnaire?
  • For business orgs: which users will be private vs non-private, and how will admin recovery work with zero-access constraints?
  • Which external partners must receive E2EE content, and will they accept password-protected messages or PGP?