Inbox.eu vs Tuta

Compare Inbox.eu and Tuta on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Google Workspace, Microsoft 365

Logo: Inbox.eu

Inbox.eu

Latvia· Email Services

Needs review

Shortlist Inbox.eu when you need Latvia-hosted, ad-free SME email with large included storage, custom domains, IMAP clients, and business SSO under an EU operator. Skip when you require zero-knowledge E2E crypto or published ISO/SOC audits—consider Proton Mail, Tuta, Posteo, or mailbox.org instead.

EU-operated (Latvia)100 GB mail + filesCustom domainsIMAP / SMTPSAML / LDAP SSOTLS, not ZK E2E
Logo: Tuta

Tuta

Germany· Email Services

Needs review

Shortlist when you need default end-to-end encrypted mail, calendar, and contacts under German law with post-quantum TutaCrypt and official multi-platform apps. Skip when teams must keep Outlook/Thunderbird via IMAP or need a full M365/Workspace suite—consider Proton Mail (Bridge) or mailbox.org instead.

Default mailbox E2EETutaCrypt post-quantumEU-operated (Germany)Open-source clientsDE data centers (claimed)No IMAP (by design)
Inbox.eu vs Tuta: Snapshot
FeatureLogo: Inbox.euInbox.euLogo: TutaTuta
Country of originLatviaGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersLatviaGermany
Legal entitySIA INBOKSS (Inbokss Ltd), reg. no. 40003560720, Matrozu street 15-2, Riga, LV-1048Tutao GmbH (HRB 208014, Hanover)
Governing lawRepublic of Latvia / EU GDPRGerman law / GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyMailbox/file data: vendor claims own servers in Latvia (Riga DC, EN 50600-3) with live multi-copy backups and no EU exit. Web property privacy policy lists Google Analytics, Meta Pixel, Gemius, AdBox, InMobi CMP, and hCaptcha—US/global SaaS for analytics, ads, consent, and bot defence. No public full mail-path subprocessor register found.Vendor states mailbox data is stored end-to-end encrypted on Tutao-operated servers in ISO 27001-certified data centers in Germany. No AWS/GCP/Azure primary hosting named on official security/privacy pages. Privacy statement discloses payment processing via PayPal (Europe) and banks for card/SEPA; no comprehensive public subprocessor list found for ops tools.
Summary

Latvia-based hosted email from SIA INBOKSS with ad-free personal and business mailboxes, custom domains, large integrated file storage, calendar/contacts, and mobile apps.

German end-to-end encrypted email, calendar, and contacts from Tutao GmbH in Hanover—with post-quantum TutaCrypt, open-source clients, and freemium personal plus business plans.

Tags
At a glance: Inbox.eu vs Tuta
At a glanceLogo: Inbox.euInbox.euLogo: TutaTuta
HQRiga, Latvia (EU)Hanover, Germany (Tutao GmbH)
Legal entitySIA INBOKSS (reg. 40003560720)Not listed
Product sinceInbokss 1998; Inbox.eu brand from 2011Not listed
HostingVendor-claimed own servers in Latvia; multi-server backupsOwn servers in ISO 27001 data centers in Germany (vendor claim)
Open sourceNoClients GPLv3 on GitHub; no productized self-host
Self-hostNoNot listed
Commercial modelPrepaid personal/business premium; time-limited trialFreemium personal + paid personal/business (no ads)
ProductNot listedEncrypted email, calendar, contacts (SaaS)
ProtocolsNot listedNo IMAP/SMTP client access; official apps only
CryptoNot listedTutaCrypt hybrid (Kyber-1024 + X25519 + AES-256) for new accounts
Key capabilities: Inbox.eu vs Tuta
Key capabilitiesLogo: Inbox.euInbox.euLogo: TutaTuta
EU-operated (Latvia)YesYes
100 GB mail + filesYesNot listed
Custom domainsYesNot listed
IMAP / SMTPYesNot listed
SAML / LDAP SSOYesNot listed
TLS, not ZK E2EYesNot listed
Default mailbox E2EENot listedYes
TutaCrypt post-quantumNot listedYes
Open-source clientsNot listedYes
DE data centers (claimed)Not listedYes
No IMAP (by design)Not listedYes

Inbox.eu

  • 100 GB mailbox plus integrated Files storage

    Premium accounts include a large combined email-and-files quota (business adds domain-level shared storage). Files supports multi-gigabyte uploads, share links, parallel downloads, and WebDAV mounting on desktop—useful for SMEs that want drive-like sharing without a separate vendor.

  • Custom domains with business admin panel

    Business email lets you host unlimited domain mailboxes after DNS/MX validation, with admin controls for users, aliases, catch-all, and domain settings. A public demo of the admin experience is available for evaluation before signup.

  • Standard protocols plus mobile apps

    Full IMAP, POP3, and SMTP (with TLS) for Thunderbird, Outlook, and other clients; calendar and contacts sync; official apps on iOS and Android. Fits teams that refuse webmail lock-in.

  • TLS, 2FA, spam filtering, and business SSO

    Transport encryption with TLS 1.2+, optional two-factor authentication, multi-filter spam/malware scanning, and Business SSO via SAML 2.0 or LDAP (including common IdPs such as Azure AD and Google Workspace). This is hosted-email security, not zero-knowledge E2E.

  • Migration support and human multilingual help

    Documented IMAP/CSV migration paths from Gmail and other providers, plus real-person support in English and Baltic languages rather than chatbot-only queues—material for SMEs without a dedicated mail ops team.

Tuta

  • Default E2EE for mail, subjects, and attachments

    Between Tuta users, messages encrypt automatically including subject lines, bodies, and attachments. External recipients can use a shared password for end-to-end threads without installing software. Contacts and calendars use the same zero-access model; only delivery metadata (addresses, timestamps) stays readable by design.

  • TutaCrypt post-quantum hybrid cryptography

    New accounts use TutaCrypt: Kyber-1024 KEM plus X25519 ECDH with AES-256, targeting harvest-now-decrypt-later risks. Protocol details are published; existing accounts migrate as key rotation rolls out. Tuta intentionally avoids PGP so subjects and non-mail features can stay encrypted and algorithms can be upgraded in-product.

  • Zero-knowledge calendar with private reminders

    Calendar events—including times, titles, locations, and attendees—are end-to-end encrypted. Reminders are pushed as encrypted payloads and fired locally so servers are not told when an event starts. Sharing stays encrypted; invites can go out via mail, optionally password-protected for externals.

  • Open-source multi-platform clients (no IMAP)

    Web, Android (Play and F-Droid), iOS, Windows, macOS, and Linux clients are published under GPLv3 on GitHub. Desktop builds are signed for verification. There is no IMAP/SMTP bridge: third-party mail apps cannot connect, which preserves encryption at rest but forces a client switch for Outlook/Thunderbird holdouts.

  • Business domains, admin console, and whitelabel

    Paid business plans add custom domains, aliases, shared mailboxes, multi-admin roles, password/2FA resets, catch-all, templates, and optional branding/login on your own site. Vendor-stated uptime SLA and a GDPR order-processing agreement support B2B procurement—confirm current plan matrix on tuta.com.

Assurance & compliance: Inbox.eu vs Tuta
Assurance & complianceLogo: Inbox.euInbox.euLogo: TutaTuta
Independent security / no-logs audit
Not found

No public third-party audit PDF or no-logs attestation located on security/help pages.

Vendor claimed

Vendor states SySS GmbH penetration testing before public release; not a continuously published annual no-logs audit PDF on the marketing site.

ISO 27001
Not found

No ISO 27001 certificate or registry entry found on official site.

Partial

Official pages claim data centers are ISO 27001 certified; does not clearly establish a public Tutao GmbH organizational ISO 27001 certificate.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced on official site.

Not found

No SOC 2/3 report located on security, business, or privacy pages.

GDPR / EU data protection
Vendor claimed

EU (Latvia) controller SIA INBOKSS; vendor states 100% GDPR compliance and Latvia hosting. Confirm DPA and subprocessors for your workload.

Vendor claimed

German controller Tutao GmbH; privacy statement cites GDPR; DPO published; DE storage claimed.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent; mail claimed on own Latvia servers. Residual medium exposure via US-group web SaaS in privacy policy (Google Analytics, Meta Pixel, hCaptcha, InMobi). Not legal advice.

Partial

EU entity, no known US parent, primary mailbox hosting claimed as own DE servers—not AWS/GCP/Azure. Payment may use PayPal (Europe). Assessment is low exposure for content with residual billing/processor unknowns; not a vendor 'safe' claim. Not legal advice.

Data processing agreement (B2B)
Not found

TOS mentions controller/processor roles under GDPR, but no standalone public DPA download found—request in writing.

Vendor claimed

Security/business materials state an Order Processing Agreement (Auftragsverarbeitung) is provided for GDPR; obtain signed version via sales—no public self-serve DPA URL confirmed.

EU AI Act
Not applicable

Conventional email hosting; not an AI-system product.

Not applicable

Encrypted email/calendar product; vendor states it does not plan AI that processes user communications for model training.

Considerations & known limitations: Inbox.eu vs Tuta
Considerations & known limitationsLogo: Inbox.euInbox.euLogo: TutaTuta
No public ISO/SOC or independent audit
Medium

Enterprise RFPs that require cert packs will stall until the vendor supplies private assurance materials.

Not listed
Not zero-knowledge E2E mail
Medium

Operator-controlled storage with TLS in transit; legal-process access is acknowledged. Do not shortlist as a Proton/Tuta crypto peer.

Not listed
US-group tools on website privacy path
Medium

Google Analytics, Meta Pixel, hCaptcha, and InMobi appear in the privacy policy even while mail is marketed as Latvia-only—align transfer assessments and cookies consent with this split.

Not listed
Public DPA / subprocessor list gap
Medium

Processor language exists in TOS, but buyers still need a signed DPA and current subprocessors for regulated personal data.

Not listed
Operator also runs ad-supported portals
Low

Inbokss group products include advertising-supported regional portals; verify contractually that paid Inbox.eu mailboxes stay ad-free and outside portal ad profiling.

Not listed
No IMAP/SMTP third-party clientsNot listed
High

Desktop and mobile holdouts cannot stay on Outlook/Thunderbird/Apple Mail. Plan full client migration or pick a standards-based alternative.

Weaker protection to non-Tuta recipientsNot listed
Medium

Without a shared password, external mail is ordinary SMTP (TLS in transit). Only Tuta-to-Tuta and password-protected external threads are true E2EE.

Hosted service, not on-prem mailNot listed
Medium

Open-source clients help inspectability, but mailboxes still depend on Tutao's German SaaS backend, uptime, and German legal process.

Data-center ISO vs company ISMSNot listed
Low

ISO 27001 wording refers to data centers. Do not tick 'vendor ISO 27001 certified' on questionnaires without the actual Tutao certificate.

Limited public subprocessor inventoryNot listed
Medium

Privacy policy covers payments (e.g. PayPal Europe) but lacks a detailed live subprocessor register. Request the DPA annex for DPIA completeness.

German court orders on accessible dataNot listed
Low

Transparency reports show regular German requests. Stored E2EE content stays undecryptable by Tutao; real-time monitoring can expose newly arriving unencrypted SMTP mail. Align expectations with counsel.

Fit

Inbox.eu

Best fit when

  • SMEs wanting branded domain email without Google Workspace or Microsoft 365 suite lock-in
  • Teams that standardise on Thunderbird, Outlook, or other IMAP/SMTP clients
  • Buyers prioritising large included mailbox and file quotas plus WebDAV sharing
  • Organisations that need business SSO (SAML 2.0 or LDAP) without a separate SSO SKU
  • Users seeking an ad-free paid European mailbox with human support in English and Baltic languages

Poor fit when

  • RFPs that require published ISO 27001, SOC 2, or independent security/no-logs audit reports
  • Threat models that assume the provider cannot access plaintext mail (zero-knowledge E2E)
  • Buyers needing a downloadable public DPA and full mail-path subprocessor register before any sales contact
  • Teams that need a full office suite (docs, sheets, meetings) rather than email-plus-files

Consider instead when

  • When: You need open or heavily audited zero-knowledge end-to-end encrypted mail

    Consider: Proton Mail or Tuta

    Different crypto posture than TLS-hosted conventional mail

  • When: You prefer German jurisdiction and a long-standing privacy-host reputation

    Consider: Posteo or mailbox.org

    Often leaner storage; strong EU privacy positioning

  • When: You already depend on Docs/Drive/Meet or full Microsoft 365 collaboration

    Consider: Google Workspace or Microsoft 365

    Inbox.eu is not a suite replacement

  • When: You want Belgian dual-key / open-source-oriented secure mail

    Consider: Mailfence

    Different feature and crypto tradeoffs

Tuta

Best fit when

  • Teams that will standardize on Tuta's official web/mobile/desktop clients for default zero-access email
  • Orgs prioritizing subject-line encryption, encrypted calendar, and post-quantum hybrid crypto under German jurisdiction
  • SMEs needing custom domains, aliases, shared mailboxes, and multi-admin controls without running their own mail servers
  • Journalists, NGOs, and privacy-led departments that value F-Droid builds, no Google Push dependency, and ad-free operation
  • Buyers who want open-source client auditability plus a freemium path for personal trial before business seats

Poor fit when

  • Hard requirement for IMAP/SMTP in Outlook, Thunderbird, Apple Mail, or third-party automation
  • On-prem / customer-operated mail server mandates (no productized self-host for the backend)
  • Workflows that depend on first-class PGP or S/MIME interoperability with external partners
  • Primary need is full Google Workspace or Microsoft 365 collaboration (Drive, Meet, deep Outlook) rather than encrypted mail first

Consider instead when

  • When: Users must keep desktop IMAP clients or need Bridge-style Outlook integration

    Consider: Proton Mail (Bridge on paid plans) or mailbox.org / Posteo / Soverin

    Those options trade Tuta's automatic subject E2EE model for standards-based access

  • When: You need a broader German digital workplace (Drive, Office, video) with optional PGP

    Consider: mailbox.org

    Stronger suite breadth; different default encryption depth than Tuta's full zero-access mailbox

  • When: Swiss jurisdiction and multi-product privacy suite (VPN, drive, pass) matter more than German HQ

    Consider: Proton Mail

    Compare Bridge, ecosystem lock-in, and published cert posture side by side

  • When: Belgian OpenPGP-centric suite with browser crypto and classic protocols is preferred

    Consider: Mailfence

    Different encryption UX (PGP-oriented) versus Tuta's automatic proprietary stack

Open questions for due diligence

Inbox.eu

  • Will SIA INBOKSS sign your organisation's DPA and provide a current subprocessor list limited to production mail/file paths?
  • Are there private ISO, SOC, or penetration-test reports available under NDA?
  • Which backup media/locations and any non-EU operational tooling (support remote access, payments) process personal data?
  • Does business SSO support your exact IdP configuration (SAML attributes / LDAP schema) without custom engineering fees?

Tuta

  • Will Tutao provide a current signed AVV/DPA with a full subprocessor list (DNS, billing, support, CDN if any)?
  • Is there a current organizational ISO 27001 or SOC 2 report for Tutao GmbH, or only facility-level data-center certification?
  • What is the documented status of TutaCrypt key rotation for all legacy accounts in your tenant?
  • Are any US-group cloud services used for backups, DNS, or support tooling beyond payment processors named in the privacy statement?
  • For business rollout: migration tooling limits (EML/MBOX import on desktop) and dual-running period with legacy IMAP hosts?