Infomaniak kMail vs Posteo

Compare Infomaniak kMail and Posteo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Infomaniak kMail

Infomaniak kMail

Switzerland· Email Services

Needs review

Shortlist when you need Swiss-hosted professional email with custom domains, IMAP/CalDAV, suite bundling (kSuite), and operator-owned DCs. Skip when zero-access client-side E2EE or full self-host is mandatory—consider Proton Mail (E2EE) or a self-hosted stack instead.

Swiss-hosted mailCustom domainsIMAP / CalDAVOSS mobile clientsISO 27001 (claimed)Optional send encryption
Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Infomaniak kMail vs Posteo: Snapshot
FeatureLogo: Infomaniak kMailInfomaniak kMailLogo: PosteoPosteo
Country of originSwitzerlandGermany
CategoryEmail ServicesEmail Services
Open sourceYesYes
Self-hostedNoNo
HeadquartersSwitzerlandGermany
Legal entityInfomaniak Network SA (Rue Eugène Marziano 25, 1227 Les Acacias, Geneva; CH-660.0.059.996-1; IDE CHE-103.167.648)Posteo e.K., Methfesselstr. 38, 10965 Berlin
Governing lawNot listedGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyPrimary mail hosting on Infomaniak-operated Swiss data centres (Geneva/Zurich region; Swiss Hosting label claimed); dual-DC backups in Switzerland. Confidentiality policy names payment partners (e.g. PayPal, Checkout) and other ancillary third parties for account/billing/measurement—not AWS/GCP/Azure as primary mail hosts in public materials.Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).
Summary

Swiss-hosted professional email, contacts and calendars from Infomaniak Network SA—custom domains, open protocols, optional encryption, part of kSuite.

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Tags
At a glance: Infomaniak kMail vs Posteo
At a glanceLogo: Infomaniak kMailInfomaniak kMailLogo: PosteoPosteo
HQGeneva, Switzerland (Les Acacias)Berlin, Germany
Legal entityInfomaniak Network SAPosteo e.K. (HRA 47592 B)
HostingOwn Swiss data centres; dual-site mailbox backupsSelf-operated servers in Germany
Open sourceMobile clients GPL-3.0; backend SaaSNot listed
Self-hostNo (hosted only)No (hosted service)
Commercial modelFree my kSuite tier; paid kSuite / Mail Service seatsPrepaid paid service; no free tier
ProtocolsNot listedIMAP, POP3, SMTP, CalDAV, CardDAV
FoundedNot listed2009
EnergyNot listed100% green energy (Green Planet Energy, claimed)
Key capabilities: Infomaniak kMail vs Posteo
Key capabilitiesLogo: Infomaniak kMailInfomaniak kMailLogo: PosteoPosteo
Swiss-hosted mailYesNot listed
Custom domainsYesNot listed
IMAP / CalDAVYesYes
OSS mobile clientsYesNot listed
ISO 27001 (claimed)YesNot listed
Optional send encryptionYesNot listed
Self-operated DE serversNot listedYes
Data-minimising signupNot listedYes
BSI TR-03108 (verified)Not listedYes
Optional crypto mail storageNot listedYes
Ad-free, user-fundedNot listedYes

Infomaniak kMail

  • Custom-domain mail with IMAP, CalDAV and CardDAV

    Host name@your-domain addresses with standard IMAP/SMTP plus CalDAV/CardDAV so Thunderbird, Apple Mail, Outlook and other clients stay usable. Paid kSuite/Mail Service tiers add multi-mailbox management, aliases/categories, signatures and team admin; free my kSuite is limited to one address without aliases.

  • One-click send-time encryption (OpenPGP / ECC / AES)

    Optional encryption at send uses OpenPGP, ECC and AES-256-GCM; Infomaniak-to-Infomaniak is automatic after auth, while external recipients often open a password-protected secure page. Private keys stay on Infomaniak infrastructure—useful for sensitive sends, but not zero-access client-side E2EE with user-held keys.

  • Open-source Infomaniak Mail mobile clients

    Official iOS and Android mail apps are published on GitHub under GPL-3.0 for local inspection and contribution. The hosted mail backend remains Infomaniak SaaS only—there is no supported self-hosted server stack for kMail.

  • Swiss dual-DC backups, SPF/DKIM/DMARC and antivirus

    Mailboxes are backed up across Swiss data centres with vendor-stated restore windows around 30 days; anti-spam/antivirus plus domain authentication (SPF, DKIM, DMARC) are standard. Availability claims (e.g. high uptime for essential services) should be checked against the current SLA for your plan.

  • Sovereign AI assist (Euria) inside the mailbox

    In-product AI can help draft, correct, translate and process mail context; Infomaniak states messages sent to its AI are processed in Switzerland and not stored for other purposes. Treat AI features as operator-side processing of content you choose to submit—not as end-to-end private AI.

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Assurance & compliance: Infomaniak kMail vs Posteo
Assurance & complianceLogo: Infomaniak kMailInfomaniak kMailLogo: PosteoPosteo
Independent security / no-logs audit
Not found

Bug bounty and ISO ISMS claimed; no public independent no-logs audit of mailbox content found. Encryption is optional and keys remain with Infomaniak.

Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

ISO 27001
Vendor claimed

Vendor publishes ISO 27001:2022 certificate (certified since 2018 per certifications page); downloadable PDF and SoA references.

Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

SOC 2 / SOC 3
Not found

Not listed among published certifications (ISO 27001/9001/14001/50001, B Corp, Swiss labels).

Not found

No SOC 2/3 report advertised on primary pages.

GDPR / EU data protection
Vendor claimed

Swiss entity; GDPR and Swiss FADP commitments on legal pages; DPO listed; Swiss hosting of service data claimed.

Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

US CLOUD Act exposure (indicative)
Partial

Swiss Infomaniak Network SA, no known US parent, own Swiss DCs for mail—not a claimed clean bill. Account payments via partners such as PayPal/Checkout (US-group) per confidentiality policy. Indicative only; not legal advice.

Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable DPA linked from trust centre (Data_Processing_Agreement (DPA).pdf).

Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

EU AI Act
Not applicable

Euria AI assist exists inside mail; product is primarily email/hosting, not an AI-system vendor offering.

Not applicable

Conventional email/PIM service; not an AI product.

BSI TR-03108 Secure Email TransportNot listed
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Considerations & known limitations: Infomaniak kMail vs Posteo
Considerations & known limitationsLogo: Infomaniak kMailInfomaniak kMailLogo: PosteoPosteo
Encryption is not zero-access by default
Medium

Optional send encryption keeps private keys on Infomaniak infrastructure. Operators with warrant or insider access to the platform may still access unencrypted stored mail. Practical impact: do not treat kMail as a zero-knowledge vault for all messages.

Not listed
SaaS-only mail backend
Low

No official self-host for the mail service; exit means IMAP export/migration. OSS clients do not equal portable server stack.

Not listed
Free tier residency and feature caps
Low

my kSuite requires OECD residency and phone verification; no aliases, limited storage, enforced free signature. Unsuitable as free global professional mail.

Not listed
Limited public mail-path subprocessor table
Low

Hosting is own Swiss DCs per vendor docs; confidentiality policy lists payment and marketing-class third parties. Procurement should request a current subprocessor list for mailbox content paths.

Not listed
No HDS health-hosting cert
Medium

Vendor FAQ states French HDS certification is not planned—material for French health-sector workloads.

Not listed
No custom domainsNot listed
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Encryption is layered, not default E2EENot listed
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

No customer Art. 28 DPANot listed
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Password loss risk with crypto featuresNot listed
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Payment processors outside pure DE mail pathNot listed
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Fit

Infomaniak kMail

Best fit when

  • SMEs and associations wanting Swiss-hosted name@domain email with standard IMAP clients
  • Teams that prefer an integrated kSuite workspace (mail + drive + meet) under one Swiss operator
  • Orgs that need a published B2B DPA, dual-site Swiss backups, and SPF/DKIM/DMARC on domains
  • Buyers who value open-source mobile clients even if the mail backend is SaaS-only
  • Individuals in OECD countries open to free my kSuite with known feature and residency limits

Poor fit when

  • Requirements for default zero-access E2EE with user-held keys on every message
  • Need to self-host the mail server stack (kMail is SaaS-only)
  • French HDS health-data hosting (vendor states HDS certification is not planned)
  • Free-tier signup outside OECD residency / without mobile verification
  • Very large estates that need more than kSuite's published per-offer user ceiling without a custom deal

Consider instead when

  • When: You need zero-access end-to-end encryption as the default mail model

    Consider: Proton Mail

    Different trust model: client-side E2EE vs Infomaniak operator-held keys for optional encryption

  • When: You want European hosted mail with a different encryption or non-profit posture

    Consider: Mailfence or Posteo

    Compare encryption UX, storage model, and commercial terms on each vendor site

  • When: You need full control of the MTA and storage stack

    Consider: Self-hosted mail (e.g. mailcow/Stalwart) or a host that publishes server software

    Infomaniak mobile apps are OSS; the hosted service is not self-hostable

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Open questions for due diligence

Infomaniak kMail

  • Request the current subprocessor list scoped to Infomaniak Mail mailbox content (not only account billing).
  • Confirm whether optional encryption is fully rolled out on mobile apps for your required clients.
  • Validate seat ceilings, SLA, and restore RPO/RTO against your RTO targets for the chosen kSuite/Mail plan.
  • For regulated sectors: map FADP/GDPR DPA clauses and any sector addenda (FINMA mapping exists; HDS does not).

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?