Kolab Now vs Posteo

Compare Kolab Now and Posteo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail

Logo: Kolab Now

Kolab Now

Switzerland· Groupware

Needs review

Shortlist when you want Swiss-operated, FOSS-based classical groupware (mail, CalDAV/CardDAV, ActiveSync, files, Collabora) on operator-owned Bern infrastructure. Skip when you need default zero-access E2EE mail, public ISO/SOC evidence, or mature video — consider Proton Mail/Tuta for E2EE mail or Google Workspace/Microsoft 365 for enterprise suite depth.

Swiss-operatedFOSS Kolab stackFull groupware suiteIMAP / CalDAV / ActiveSyncHosted in Bern (claimed)Optional PGP
Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Kolab Now vs Posteo: Snapshot
FeatureLogo: Kolab NowKolab NowLogo: PosteoPosteo
Country of originSwitzerlandGermany
CategoryGroupwareEmail Services
Open sourceYesYes
Self-hostedNoNo
HeadquartersSwitzerlandGermany
Legal entityApheleia IT AG (trade register CH-036.3.053.227-3; VAT CHE-149.254.861)Posteo e.K., Methfesselstr. 38, 10965 Berlin
Governing lawSwiss law (see Terms of Service for contract details)German / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyPrimary mailbox/groupware hosting claimed on operator-controlled infrastructure in Bern, Switzerland (IBM OpenPOWER hypervisors, hardware-encrypted IBM storage, RHEL). No AWS/GCP/Azure hosting advertised for customer mail. Billing wallet supports PayPal, credit card, and EUR bank transfer — US-linked payment processors for payment data. Full subprocessor/backup register not published on pages reviewed.Self-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).
Summary

Swiss-hosted FOSS Kolab groupware from Apheleia IT AG: email, calendars, contacts, files and optional Collabora collab on operator infrastructure in Bern.

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Tags
At a glance: Kolab Now vs Posteo
At a glanceLogo: Kolab NowKolab NowLogo: PosteoPosteo
HQ / operatorApheleia IT AG, Bern, SwitzerlandNot listed
Product since2013 (Swiss-operated hosted Kolab)Not listed
HostingOperator rack in Bern; IBM OpenPOWER + encrypted storage (vendor FAQ)Self-operated servers in Germany
StackKolab FOSS; RHEL; open mail/groupware protocolsNot listed
Self-host this SKUNo (managed); Kolab suite is self-hostable separatelyNot listed
Commercial modelPaid modular subscriptions via prepaid wallet; trial monthPrepaid paid service; no free tier
HQNot listedBerlin, Germany
Legal entityNot listedPosteo e.K. (HRA 47592 B)
ProtocolsNot listedIMAP, POP3, SMTP, CalDAV, CardDAV
Self-hostNot listedNo (hosted service)
FoundedNot listed2009
EnergyNot listed100% green energy (Green Planet Energy, claimed)
Key capabilities: Kolab Now vs Posteo
Key capabilitiesLogo: Kolab NowKolab NowLogo: PosteoPosteo
Swiss-operatedYesNot listed
FOSS Kolab stackYesNot listed
Full groupware suiteYesNot listed
IMAP / CalDAV / ActiveSyncYesYes
Hosted in Bern (claimed)YesNot listed
Optional PGPYesNot listed
Self-operated DE serversNot listedYes
Data-minimising signupNot listedYes
BSI TR-03108 (verified)Not listedYes
Optional crypto mail storageNot listedYes
Ad-free, user-fundedNot listedYes

Kolab Now

  • FOSS Kolab groupware with open clients

    Hosted Kolab stack: IMAP/SMTP mail, CalDAV/CardDAV calendars and contacts, tasks, notes, and WebDAV files. ActiveSync is available for mobile/Outlook-style sync on full groupware subscriptions. Teams keep standard desktop and mobile clients instead of a proprietary-only app.

  • Private domains, multi-user cockpit, shared folders

    Primary account owners verify custom domains (DNS guides in the KB), add users under one wallet, and share mail folders, calendars, notes, and files inside the domain. Fits small businesses and families that need branded addresses and shared inboxes without Google Workspace.

  • Swiss own-rack hosting with PFS and header hygiene

    Operator FAQ places production systems in a Bern rack on IBM OpenPOWER with hardware-encrypted storage, RHEL, and segmented firewalls. TLS is described as end-to-end inside the platform with Perfect Forward Secrecy; outbound mail strips client IP and MUA identity from headers.

  • Sieve filters, DKIM, modular spam controls

    Server-side Sieve rules (folder, redirect, vacation, discard) run in the web client. Outbound DKIM is supported with CNAME delegation for private domains. Spam tagging is available; aggressive auto-junk is deliberately left to customer Sieve policy rather than opaque provider filtering.

  • Collabora Online files plus optional PGP and Kolab Meet

    Domain users can collaboratively edit documents/presentations via Collabora Online on shared files. Webmail can import PGP keys for optional message encryption (vendor warns keys on server are weaker than offline E2EE). Kolab Meet adds personal video rooms on groupware plans but remains public beta.

  • TOTP 2FA with an important client trade-off

    Time-based one-time passwords (e.g. Aegis) can be required for accounts. When 2FA is enabled for a user, vendor docs state non-web clients (IMAP, POP, ActiveSync, CalDAV/CardDAV, WebDAV) are blocked — evaluate this before mandating 2FA on mobile-heavy fleets.

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Assurance & compliance: Kolab Now vs Posteo
Assurance & complianceLogo: Kolab NowKolab NowLogo: PosteoPosteo
Independent security / no-logs audit
Not found

Vendor describes no content analytics and limited operational logs (up to six months). No public third-party no-logs or security audit PDF located.

Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

ISO 27001
Not found

No public ISO 27001 certificate found on primary site/KB materials reviewed.

Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found.

Not found

No SOC 2/3 report advertised on primary pages.

GDPR / EU data protection
Vendor claimed

Swiss operator; KB GDPR article asserts customer data ownership, no ad analytics, export/delete paths, and Swiss warrant process for third-party access. Confirm DPA/ToS for EU controllers.

Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

US CLOUD Act exposure (indicative)
Partial

Swiss entity / no known US parent; mail claimed on Bern own-infra (not hyperscaler). Partial residual exposure via PayPal/card payment processors and unpublished full subprocessor list. Not legal advice.

Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Data processing agreement (B2B)
Not found

No public standalone DPA download located on marketing/KB pages in this pass; may exist in ToS or on request — confirm before B2B processing.

Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

EU AI Act
Not applicable

Groupware/email product; not an AI system offering.

Not applicable

Conventional email/PIM service; not an AI product.

BSI TR-03108 Secure Email TransportNot listed
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Considerations & known limitations: Kolab Now vs Posteo
Considerations & known limitationsLogo: Kolab NowKolab NowLogo: PosteoPosteo
Mail not zero-access by default
Medium

Unlike Proton/Tuta defaults, ordinary stored mail is provider-accessible for protocol delivery unless users apply PGP or another client E2EE scheme. Material for threat models that assume provider compromise or compelled access to plaintext.

Not listed
2FA blocks non-web clients
Medium

Documented behaviour: enabling TOTP 2FA confines the user to the web client and blocks IMAP/ActiveSync/CalDAV and related protocols. Breaks many mobile/Outlook deployments if applied naively.

Not listed
Limited public compliance pack
Medium

No public ISO/SOC certs, independent audit, or subprocessor register found. Procurement must rely on vendor FAQs, ToS, and direct questions — slower security review than certified EU SaaS peers.

Not listed
US-linked payment processors
Low

Wallet top-ups via PayPal and credit cards introduce US-group payment processors for billing data even when mailboxes stay in Switzerland. Scope is payment metadata, not IMAP content, but still relevant to transfer inventories.

Not listed
Kolab Meet still beta
Low

Voice/video rooms are labelled public beta; vendor notes support may be limited. Do not treat as a Zoom/Teams replacement for critical meetings.

Not listed
No custom domainsNot listed
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Encryption is layered, not default E2EENot listed
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

No customer Art. 28 DPANot listed
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Password loss risk with crypto featuresNot listed
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Payment processors outside pure DE mail pathNot listed
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Fit

Kolab Now

Best fit when

  • Small teams and professional practices that need shared mailboxes, calendars, and private domains under Swiss jurisdiction
  • Buyers who prioritise open standards (IMAP, CalDAV/CardDAV, ActiveSync, WebDAV) and FOSS components over proprietary lock-in
  • Organisations that will accept provider-accessible mail at rest and apply PGP/S/MIME themselves for sensitive threads
  • Users leaving Google Workspace who want groupware depth without US Big Tech mail custody
  • Account owners comfortable with prepaid wallet billing and modular per-user subscriptions

Poor fit when

  • Requirements for default end-to-end encrypted mail with zero provider access (prefer Proton Mail or Tuta)
  • Enterprises that need public ISO 27001/SOC 2 packs, signed DPAs, and a published subprocessor list on day one
  • Fleets that must combine TOTP 2FA with IMAP/ActiveSync clients on the same user (documented mutual exclusion)
  • Orgs treating video conferencing as a core, production-grade service (Kolab Meet is still beta)
  • Buyers seeking a permanent free tier or consumer-grade onboarding polish comparable to Gmail

Consider instead when

  • When: You need default zero-access / E2EE email more than ActiveSync groupware

    Consider: Proton Mail or Tuta

    Stronger default cryptography story; thinner classical groupware/ActiveSync depth than Kolab Now.

  • When: You want privacy-focused German email without full suite complexity

    Consider: Posteo

    Leaner privacy mail; not a Collabora + shared-domain groupware suite.

  • When: You need Google/Microsoft-class admin scale, apps marketplace, and compliance certifications

    Consider: Google Workspace or Microsoft 365

    Far larger ecosystems; US-centric custody and CLOUD Act profile differ sharply.

  • When: You want full self-host control of the same FOSS stack

    Consider: Self-hosted Kolab (kolab.org) or Nextcloud plus a mail stack

    More operational burden; Apheleia also sells Kolab professional services.

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Open questions for due diligence

Kolab Now

  • Will Apheleia sign a GDPR Art. 28 DPA and provide a current subprocessor list (including backups, monitoring, and payment processors) under NDA if needed?
  • What is the current imprint address and governing ToS URL for contract annexes (product footer vs apheleia-it.ch addresses differ)?
  • Is there any ISO 27001, SOC 2, or independent penetration-test summary available to customers on request?
  • How are backups and disaster recovery stored (same Bern facility only, or additional sites/providers)?
  • For regulated workloads: what is the practical process and historical volume of Swiss lawful-access requests affecting customer content?

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?