Kolab Now vs Proton Mail

Compare Kolab Now and Proton Mail on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Google Workspace, Microsoft 365

Logo: Kolab Now

Kolab Now

Switzerland· Groupware

Needs review

Shortlist when you want Swiss-operated, FOSS-based classical groupware (mail, CalDAV/CardDAV, ActiveSync, files, Collabora) on operator-owned Bern infrastructure. Skip when you need default zero-access E2EE mail, public ISO/SOC evidence, or mature video — consider Proton Mail/Tuta for E2EE mail or Google Workspace/Microsoft 365 for enterprise suite depth.

Swiss-operatedFOSS Kolab stackFull groupware suiteIMAP / CalDAV / ActiveSyncHosted in Bern (claimed)Optional PGP
Logo: Proton Mail

Proton Mail

Switzerland· Email Services

Needs review

Shortlist Proton Mail when you want Swiss-jurisdiction, zero-access encrypted email with open-source clients, custom domains, Bridge for desktop mailers, and a public DPA. Skip when you need free-tier IMAP Bridge, fully self-hosted FOSS mail on your own servers, or Workspace-class collaboration depth—consider Tuta, Posteo, or Mailfence among EU peers, or stay on Google/Microsoft if suite lock-in wins.

E2EE + zero-accessSwiss-operatedBridge (IMAP/SMTP)Open-source clientsISO 27001 & SOC 2 (claimed)Public B2B DPA
Kolab Now vs Proton Mail: Snapshot
FeatureLogo: Kolab NowKolab NowLogo: Proton MailProton Mail
Country of originSwitzerlandSwitzerland
CategoryGroupwareEmail Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersSwitzerlandSwitzerland
Legal entityApheleia IT AG (trade register CH-036.3.053.227-3; VAT CHE-149.254.861)Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland (EU representative: Proton Europe sàrl, Luxembourg)
Governing lawSwiss law (see Terms of Service for contract details)Swiss law (Terms; Geneva courts for business/non-US consumer disputes as stated in Terms)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyPrimary mailbox/groupware hosting claimed on operator-controlled infrastructure in Bern, Switzerland (IBM OpenPOWER hypervisors, hardware-encrypted IBM storage, RHEL). No AWS/GCP/Azure hosting advertised for customer mail. Billing wallet supports PayPal, credit card, and EUR bank transfer — US-linked payment processors for payment data. Full subprocessor/backup register not published on pages reviewed.Primary mail storage on Proton-owned servers in Switzerland (vendor security pages). Not marketed as AWS/GCP/Azure inbox hosting. Public privacy policy lists US-group processors for support and payments (Zendesk; Chargebee, Stripe, PayPal) and group support processing in North Macedonia and Taiwan; HubSpot noted for business sales inquiries.
Summary

Swiss-hosted FOSS Kolab groupware from Apheleia IT AG: email, calendars, contacts, files and optional Collabora collab on operator infrastructure in Bern.

Swiss end-to-end encrypted email from Proton AG: zero-access inbox storage, open-source clients, custom domains, and Bridge for desktop IMAP clients.

Tags
At a glance: Kolab Now vs Proton Mail
At a glanceLogo: Kolab NowKolab NowLogo: Proton MailProton Mail
HQ / operatorApheleia IT AG, Bern, SwitzerlandNot listed
Product since2013 (Swiss-operated hosted Kolab)Not listed
HostingOperator rack in Bern; IBM OpenPOWER + encrypted storage (vendor FAQ)Not listed
StackKolab FOSS; RHEL; open mail/groupware protocolsNot listed
Self-host this SKUNo (managed); Kolab suite is self-hostable separatelyNot listed
Commercial modelPaid modular subscriptions via prepaid wallet; trial monthFreemium + paid consumer and business seats
HQNot listedPlan-les-Ouates (Geneva), Switzerland
Legal entityNot listedProton AG (CHE-354.686.492); Proton Foundation supervision
Hosting modelNot listedProton-owned hardware in Switzerland (vendor claim)
Self-hostNot listedNo (SaaS); clients open source
BridgeNot listedPaid plans that include Mail
Key capabilities: Kolab Now vs Proton Mail
Key capabilitiesLogo: Kolab NowKolab NowLogo: Proton MailProton Mail
Swiss-operatedYesYes
FOSS Kolab stackYesNot listed
Full groupware suiteYesNot listed
IMAP / CalDAV / ActiveSyncYesNot listed
Hosted in Bern (claimed)YesNot listed
Optional PGPYesNot listed
E2EE + zero-accessNot listedYes
Bridge (IMAP/SMTP)Not listedYes
Open-source clientsNot listedYes
ISO 27001 & SOC 2 (claimed)Not listedYes
Public B2B DPANot listedYes

Kolab Now

  • FOSS Kolab groupware with open clients

    Hosted Kolab stack: IMAP/SMTP mail, CalDAV/CardDAV calendars and contacts, tasks, notes, and WebDAV files. ActiveSync is available for mobile/Outlook-style sync on full groupware subscriptions. Teams keep standard desktop and mobile clients instead of a proprietary-only app.

  • Private domains, multi-user cockpit, shared folders

    Primary account owners verify custom domains (DNS guides in the KB), add users under one wallet, and share mail folders, calendars, notes, and files inside the domain. Fits small businesses and families that need branded addresses and shared inboxes without Google Workspace.

  • Swiss own-rack hosting with PFS and header hygiene

    Operator FAQ places production systems in a Bern rack on IBM OpenPOWER with hardware-encrypted storage, RHEL, and segmented firewalls. TLS is described as end-to-end inside the platform with Perfect Forward Secrecy; outbound mail strips client IP and MUA identity from headers.

  • Sieve filters, DKIM, modular spam controls

    Server-side Sieve rules (folder, redirect, vacation, discard) run in the web client. Outbound DKIM is supported with CNAME delegation for private domains. Spam tagging is available; aggressive auto-junk is deliberately left to customer Sieve policy rather than opaque provider filtering.

  • Collabora Online files plus optional PGP and Kolab Meet

    Domain users can collaboratively edit documents/presentations via Collabora Online on shared files. Webmail can import PGP keys for optional message encryption (vendor warns keys on server are weaker than offline E2EE). Kolab Meet adds personal video rooms on groupware plans but remains public beta.

  • TOTP 2FA with an important client trade-off

    Time-based one-time passwords (e.g. Aegis) can be required for accounts. When 2FA is enabled for a user, vendor docs state non-web clients (IMAP, POP, ActiveSync, CalDAV/CardDAV, WebDAV) are blocked — evaluate this before mandating 2FA on mobile-heavy fleets.

Proton Mail

  • Zero-access inbox encryption by default

    Bodies and attachments are encrypted so Proton states it lacks keys to read stored mail. Proton-to-Proton traffic is end-to-end encrypted automatically; external recipients need password-protected messages or PGP/WKD for comparable content protection. Subject lines are not fully E2EE under OpenPGP header rules.

  • Proton Mail Bridge for desktop IMAP clients

    Paid plans that include Mail can run Bridge locally to connect Outlook, Thunderbird, or Apple Mail over IMAP/SMTP while encrypting and decrypting on the device. Free accounts use official web/mobile/desktop apps instead of Bridge.

  • Custom domains, aliases, and business admin

    Paid and business tiers support custom domains, extra addresses, catch-all and groups, hide-my-email aliases, and org admin for seats, storage, and retention policies. Suits teams leaving Google/Microsoft who still need branded addresses.

  • Open-source clients with published audits

    Web, mobile, and desktop clients are published on GitHub with third-party audit reports linked from Proton’s open-source page. The hosted mail backend is not offered as self-hosted FOSS—audit client trust, not full server reproducibility.

  • Tracker blocking, PhishGuard, and Sentinel

    Built-in tracker protection, phishing heuristics, link confirmation, SPF/DKIM/DMARC for custom domains, hardware-key 2FA, and optional Proton Sentinel monitoring for high-risk accounts. Complements encryption with everyday abuse defenses.

Assurance & compliance: Kolab Now vs Proton Mail
Assurance & complianceLogo: Kolab NowKolab NowLogo: Proton MailProton Mail
Independent security / no-logs audit
Not found

Vendor describes no content analytics and limited operational logs (up to six months). No public third-party no-logs or security audit PDF located.

Vendor claimed

Open-source clients with published third-party audit reports (web/desktop links on open-source page). Not a classic VPN no-logs court test; transparency report covers legal orders for accessible account data.

ISO 27001
Not found

No public ISO 27001 certificate found on primary site/KB materials reviewed.

Vendor claimed

Vendor announces ISO 27001 certification after external audit completed 2 May 2024; Trust Center links a certificate download. Confirm scope and validity at procurement time.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found.

Vendor claimed

Vendor announces first SOC 2 Type II attestation (July 2025 blog). Report typically under NDA—request from vendor for diligence files.

GDPR / EU data protection
Vendor claimed

Swiss operator; KB GDPR article asserts customer data ownership, no ad analytics, export/delete paths, and Swiss warrant process for third-party access. Confirm DPA/ToS for EU controllers.

Vendor claimed

Swiss controller/processor with EU representative; public DPA; GDPR materials for business. Adequacy/transfer mechanisms documented for non-adequate destinations.

US CLOUD Act exposure (indicative)
Partial

Swiss entity / no known US parent; mail claimed on Bern own-infra (not hyperscaler). Partial residual exposure via PayPal/card payment processors and unpublished full subprocessor list. Not legal advice.

Partial

Swiss entity / no known US parent; inbox content on Proton-owned Swiss hardware with zero-access design. Partial exposure remains via US SaaS subprocessors (Zendesk support; Stripe/Chargebee/PayPal payments) and any account metadata Proton can access under Swiss process. Not legal advice.

Data processing agreement (B2B)
Not found

No public standalone DPA download located on marketing/KB pages in this pass; may exist in ToS or on request — confirm before B2B processing.

Vendor claimed

Public DPA at proton.me/legal/dpa forms part of terms when Proton acts as processor; Swiss law, Geneva jurisdiction; general authorization for listed subprocessors.

EU AI Act
Not applicable

Groupware/email product; not an AI system offering.

Not applicable

Core product is encrypted email. Optional Scribe assistant is ancillary; not an AI-centric offering for this catalog entry.

Considerations & known limitations: Kolab Now vs Proton Mail
Considerations & known limitationsLogo: Kolab NowKolab NowLogo: Proton MailProton Mail
Mail not zero-access by default
Medium

Unlike Proton/Tuta defaults, ordinary stored mail is provider-accessible for protocol delivery unless users apply PGP or another client E2EE scheme. Material for threat models that assume provider compromise or compelled access to plaintext.

Not listed
2FA blocks non-web clients
Medium

Documented behaviour: enabling TOTP 2FA confines the user to the web client and blocks IMAP/ActiveSync/CalDAV and related protocols. Breaks many mobile/Outlook deployments if applied naively.

Not listed
Limited public compliance pack
Medium

No public ISO/SOC certs, independent audit, or subprocessor register found. Procurement must rely on vendor FAQs, ToS, and direct questions — slower security review than certified EU SaaS peers.

Not listed
US-linked payment processors
Low

Wallet top-ups via PayPal and credit cards introduce US-group payment processors for billing data even when mailboxes stay in Switzerland. Scope is payment metadata, not IMAP content, but still relevant to transfer inventories.

Not listed
Kolab Meet still beta
Low

Voice/video rooms are labelled public beta; vendor notes support may be limited. Do not treat as a Zoom/Teams replacement for critical meetings.

Not listed
Weaker defaults outside ProtonNot listed
Medium

Mail to Gmail/Outlook/others is not E2EE unless password-protected or PGP/WKD is used. Subject lines are not fully E2EE. Train users or you only protect the Proton-stored copy.

US support and payment processorsNot listed
Medium

Zendesk, Chargebee, Stripe, and PayPal appear in the public processor list. They should not see zero-access message bodies, but support content and billing data can touch US-group services—document this in DPIAs.

Bridge requires paid MailNot listed
Low

Desktop IMAP/SMTP via Bridge is not available on free accounts. Budget seats for users who refuse the official apps.

Hosted service, not self-hosted FOSS mailNot listed
Medium

Open-source clients improve inspectability but you still depend on Proton’s operated backend, uptime, and Swiss legal process. Unsuitable if policy mandates customer-operated mail servers.

Swiss legal orders on accessible dataNot listed
Low

Transparency reports show thousands of yearly legal orders for Mail with many complied. Bodies stay encrypted; recovery emails, IPs (when retained for abuse), and similar metadata may still be in scope. Align expectations with counsel.

Fit

Kolab Now

Best fit when

  • Small teams and professional practices that need shared mailboxes, calendars, and private domains under Swiss jurisdiction
  • Buyers who prioritise open standards (IMAP, CalDAV/CardDAV, ActiveSync, WebDAV) and FOSS components over proprietary lock-in
  • Organisations that will accept provider-accessible mail at rest and apply PGP/S/MIME themselves for sensitive threads
  • Users leaving Google Workspace who want groupware depth without US Big Tech mail custody
  • Account owners comfortable with prepaid wallet billing and modular per-user subscriptions

Poor fit when

  • Requirements for default end-to-end encrypted mail with zero provider access (prefer Proton Mail or Tuta)
  • Enterprises that need public ISO 27001/SOC 2 packs, signed DPAs, and a published subprocessor list on day one
  • Fleets that must combine TOTP 2FA with IMAP/ActiveSync clients on the same user (documented mutual exclusion)
  • Orgs treating video conferencing as a core, production-grade service (Kolab Meet is still beta)
  • Buyers seeking a permanent free tier or consumer-grade onboarding polish comparable to Gmail

Consider instead when

  • When: You need default zero-access / E2EE email more than ActiveSync groupware

    Consider: Proton Mail or Tuta

    Stronger default cryptography story; thinner classical groupware/ActiveSync depth than Kolab Now.

  • When: You want privacy-focused German email without full suite complexity

    Consider: Posteo

    Leaner privacy mail; not a Collabora + shared-domain groupware suite.

  • When: You need Google/Microsoft-class admin scale, apps marketplace, and compliance certifications

    Consider: Google Workspace or Microsoft 365

    Far larger ecosystems; US-centric custody and CLOUD Act profile differ sharply.

  • When: You want full self-host control of the same FOSS stack

    Consider: Self-hosted Kolab (kolab.org) or Nextcloud plus a mail stack

    More operational burden; Apheleia also sells Kolab professional services.

Proton Mail

Best fit when

  • Teams that need default end-to-end / zero-access encryption without running their own mail stack
  • Orgs that want Swiss legal venue and documented resistance to direct foreign data demands
  • Businesses migrating branded domains off Gmail/Outlook with Easy Switch and Bridge for desktop holdouts
  • Security-conscious professionals who value open-source clients, published audits, and hardware-key 2FA
  • Buyers who need a public DPA plus vendor-claimed ISO 27001 / SOC 2 Type II for questionnaires

Poor fit when

  • Fully self-hosted requirements (Proton Mail is SaaS; clients are open source, not a full on-prem mail server)
  • Desktop IMAP on free accounts only—Bridge needs a paid plan that includes Mail
  • Workflows that depend on unencrypted-looking mail to external parties who will not use password links or PGP
  • Teams that primarily need full Microsoft 365 / Google Workspace collaboration depth rather than encrypted mail first

Consider instead when

  • When: You want German E2EE email with a different crypto product surface and may not need Proton’s full ecosystem

    Consider: Tuta

    Compare desktop interoperability and business admin maturity side by side.

  • When: You want ad-free European mail with strong transport privacy but do not require zero-access E2EE for all stored content

    Consider: Posteo

    Different threat model: Posteo is privacy-forward without Proton’s zero-access default.

  • When: You need OpenPGP-centric mail with classic collaboration extras under Belgian operation

    Consider: Mailfence

    Weigh automatic Proton-to-Proton E2EE UX versus Mailfence’s model.

  • When: Collaboration suite depth and ecosystem lock-in outweigh encryption defaults

    Consider: Google Workspace or Microsoft 365

    Accept US-provider jurisdiction and scanning/processing models as tradeoffs.

Open questions for due diligence

Kolab Now

  • Will Apheleia sign a GDPR Art. 28 DPA and provide a current subprocessor list (including backups, monitoring, and payment processors) under NDA if needed?
  • What is the current imprint address and governing ToS URL for contract annexes (product footer vs apheleia-it.ch addresses differ)?
  • Is there any ISO 27001, SOC 2, or independent penetration-test summary available to customers on request?
  • How are backups and disaster recovery stored (same Bern facility only, or additional sites/providers)?
  • For regulated workloads: what is the practical process and historical volume of Swiss lawful-access requests affecting customer content?

Proton Mail

  • What exact data-center sites and any non-Swiss regions apply to your tenant’s mailbox replicas today?
  • Will Proton provide the full SOC 2 Type II report under NDA and confirm ISO 27001 certificate scope/expiry for your questionnaire?
  • For business orgs: which users will be private vs non-private, and how will admin recovery work with zero-access constraints?
  • Which external partners must receive E2EE content, and will they accept password-protected messages or PGP?