Kolab Now vs Soverin

Compare Kolab Now and Soverin on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365

Logo: Kolab Now

Kolab Now

Switzerland· Groupware

Needs review

Shortlist when you want Swiss-operated, FOSS-based classical groupware (mail, CalDAV/CardDAV, ActiveSync, files, Collabora) on operator-owned Bern infrastructure. Skip when you need default zero-access E2EE mail, public ISO/SOC evidence, or mature video — consider Proton Mail/Tuta for E2EE mail or Google Workspace/Microsoft 365 for enterprise suite depth.

Swiss-operatedFOSS Kolab stackFull groupware suiteIMAP / CalDAV / ActiveSyncHosted in Bern (claimed)Optional PGP
Logo: Soverin

Soverin

Netherlands· Email Services

Needs review

Shortlist Soverin when you want Dutch-operated, paid IMAP email with custom domains, unlimited aliases, and strong mail-auth standards without Google/Microsoft ads. Skip when you need zero-knowledge E2EE—consider Proton Mail or Tuta instead—or a full productivity suite (mailbox.org / Microsoft 365).

NL / EU operatedCustom domainsIMAP / CalDAVNo ads / no trackingISO 27001 (claimed)DANE / DNSSEC
Kolab Now vs Soverin: Snapshot
FeatureLogo: Kolab NowKolab NowLogo: SoverinSoverin
Country of originSwitzerlandNetherlands
CategoryGroupwareEmail Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersSwitzerlandNetherlands
Legal entityApheleia IT AG (trade register CH-036.3.053.227-3; VAT CHE-149.254.861)Soverin B.V. (Amsterdam); owned by The Sharing Group / TSG Online (Dutch) as of September 2025 acquisition announcement
Governing lawSwiss law (see Terms of Service for contract details)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyPrimary mailbox/groupware hosting claimed on operator-controlled infrastructure in Bern, Switzerland (IBM OpenPOWER hypervisors, hardware-encrypted IBM storage, RHEL). No AWS/GCP/Azure hosting advertised for customer mail. Billing wallet supports PayPal, credit card, and EUR bank transfer — US-linked payment processors for payment data. Full subprocessor/backup register not published on pages reviewed.Vendor: EU-only processing; data in NL; self-operated Dutch DCs, no hyperscaler. TechRadar: 3 NL DCs. Core mail hosts on Soverin B.V. AS211993. External first-line support partner under DPA/NDA (country unpublished). HIBP k-anon password checks; Let’s Encrypt; domain DNSSEC partner. No AWS/GCP/Azure as primary mailbox hosts in public materials.
Summary

Swiss-hosted FOSS Kolab groupware from Apheleia IT AG: email, calendars, contacts, files and optional Collabora collab on operator infrastructure in Bern.

Dutch privacy-first email hosting: custom domains, open IMAP/SMTP/CalDAV, 25 GB mailboxes, no ads or content scanning, servers operated in the Netherlands.

Tags
At a glance: Kolab Now vs Soverin
At a glanceLogo: Kolab NowKolab NowLogo: SoverinSoverin
HQ / operatorApheleia IT AG, Bern, SwitzerlandNot listed
Product since2013 (Swiss-operated hosted Kolab)Not listed
HostingOperator rack in Bern; IBM OpenPOWER + encrypted storage (vendor FAQ)Dutch data centres; vendor claims self-operated, no hyperscaler
StackKolab FOSS; RHEL; open mail/groupware protocolsNot listed
Self-host this SKUNo (managed); Kolab suite is self-hostable separatelyNot listed
Commercial modelPaid modular subscriptions via prepaid wallet; trial monthAnnual prepaid; 30-day mailbox money-back; no free tier
HQNot listedAmsterdam, Netherlands (Soverin B.V.)
GroupNot listedThe Sharing Group / TSG Online (acq. Sep 2025)
ProtocolsNot listedIMAP, SMTP, CalDAV, CardDAV
StorageNot listed25 GB per mailbox (vendor-stated)
Self-host / OSSNot listedNo / No
Key capabilities: Kolab Now vs Soverin
Key capabilitiesLogo: Kolab NowKolab NowLogo: SoverinSoverin
Swiss-operatedYesNot listed
FOSS Kolab stackYesNot listed
Full groupware suiteYesNot listed
IMAP / CalDAV / ActiveSyncYesNot listed
Hosted in Bern (claimed)YesNot listed
Optional PGPYesNot listed
NL / EU operatedNot listedYes
Custom domainsNot listedYes
IMAP / CalDAVNot listedYes
No ads / no trackingNot listedYes
ISO 27001 (claimed)Not listedYes
DANE / DNSSECNot listedYes

Kolab Now

  • FOSS Kolab groupware with open clients

    Hosted Kolab stack: IMAP/SMTP mail, CalDAV/CardDAV calendars and contacts, tasks, notes, and WebDAV files. ActiveSync is available for mobile/Outlook-style sync on full groupware subscriptions. Teams keep standard desktop and mobile clients instead of a proprietary-only app.

  • Private domains, multi-user cockpit, shared folders

    Primary account owners verify custom domains (DNS guides in the KB), add users under one wallet, and share mail folders, calendars, notes, and files inside the domain. Fits small businesses and families that need branded addresses and shared inboxes without Google Workspace.

  • Swiss own-rack hosting with PFS and header hygiene

    Operator FAQ places production systems in a Bern rack on IBM OpenPOWER with hardware-encrypted storage, RHEL, and segmented firewalls. TLS is described as end-to-end inside the platform with Perfect Forward Secrecy; outbound mail strips client IP and MUA identity from headers.

  • Sieve filters, DKIM, modular spam controls

    Server-side Sieve rules (folder, redirect, vacation, discard) run in the web client. Outbound DKIM is supported with CNAME delegation for private domains. Spam tagging is available; aggressive auto-junk is deliberately left to customer Sieve policy rather than opaque provider filtering.

  • Collabora Online files plus optional PGP and Kolab Meet

    Domain users can collaboratively edit documents/presentations via Collabora Online on shared files. Webmail can import PGP keys for optional message encryption (vendor warns keys on server are weaker than offline E2EE). Kolab Meet adds personal video rooms on groupware plans but remains public beta.

  • TOTP 2FA with an important client trade-off

    Time-based one-time passwords (e.g. Aegis) can be required for accounts. When 2FA is enabled for a user, vendor docs state non-web clients (IMAP, POP, ActiveSync, CalDAV/CardDAV, WebDAV) are blocked — evaluate this before mandating 2FA on mobile-heavy fleets.

Soverin

  • Custom domains with unlimited aliases

    Host mail on your own domain (bring existing or register through Soverin). Unlimited aliases—plus-addressing or domain names—deliver into one mailbox, plus optional random @sinenomine.email private aliases that hide the real address. Suits freelancers and SMEs who need brandable addresses without per-alias fees.

  • Open IMAP/SMTP plus CalDAV/CardDAV

    Use any standards-based client or device for mail, calendar, and contacts—no proprietary app required. Dashboard import helps migrate from other providers. Ideal when IT wants Thunderbird, Apple Mail, or Outlook without locking into a closed webmail ecosystem; not a zero-knowledge E2EE product by default.

  • Mail-path security: DANE, DKIM, DMARC, IP stripping

    Outbound and inbound paths use TLS; Soverin publishes and honours DANE/TLSA, signs with DKIM, publishes SPF/DMARC, enables DNSSEC on managed domains, and strips personal IP addresses from outbound headers. 2FA is available and can be admin-mandated. Buyers still need their own OpenPGP setup for end-to-end content secrecy with external parties.

  • 25 GB mailboxes with per-user encrypted backups

    Each mailbox includes a stated 25 GB quota covering mail, calendar, and contacts. Nightly backups use individually generated keys; Soverin states that emptying trash permanently deletes data and that leaving the service removes backups when the key is destroyed. Extra mailboxes can share storage for small teams.

  • Multi-mailbox and channel-friendly business use

    Purchase and assign additional mailboxes on a domain, with admin tooling for teams. Soverin markets to hosters, ISPs, MSPs, and independent professionals for multi-mailbox and white-label scenarios—useful when you want Dutch-operated email without building your own mail stack.

Assurance & compliance: Kolab Now vs Soverin
Assurance & complianceLogo: Kolab NowKolab NowLogo: SoverinSoverin
Independent security / no-logs audit
Not found

Vendor describes no content analytics and limited operational logs (up to six months). No public third-party no-logs or security audit PDF located.

Not found

No public third-party no-logs or full security audit PDF located; privacy claims are first-party.

ISO 27001
Not found

No public ISO 27001 certificate found on primary site/KB materials reviewed.

Vendor claimed

Vendor states independently audited ISO 27001; certificates available on request via support@soverin.net. Not re-verified against a public registry entry in this pass.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found.

Not found

No SOC 2/3 claim found on primary pages reviewed.

GDPR / EU data protection
Vendor claimed

Swiss operator; KB GDPR article asserts customer data ownership, no ad analytics, export/delete paths, and Swiss warrant process for third-party access. Confirm DPA/ToS for EU controllers.

Vendor claimed

NL entity; AVG-framed privacy statement; EU-only processing claimed; GDPR Proof messaging on recognitions page.

US CLOUD Act exposure (indicative)
Partial

Swiss entity / no known US parent; mail claimed on Bern own-infra (not hyperscaler). Partial residual exposure via PayPal/card payment processors and unpublished full subprocessor list. Not legal advice.

Partial

EuropeanStack assessment: low exposure path—Dutch Soverin B.V., Dutch The Sharing Group owner, claimed self-operated NL hosting without public AWS/GCP/Azure mailbox hosts. Partial because residual subprocessors (support partner jurisdiction, domain partners, HIBP hash checks) need buyer confirmation. Not legal advice.

Data processing agreement (B2B)
Not found

No public standalone DPA download located on marketing/KB pages in this pass; may exist in ToS or on request — confirm before B2B processing.

Vendor claimed

Privacy statement states it qualifies as an Article 28 AVG processing agreement; other DPAs expressly rejected. Confirm signed annex for enterprise use.

EU AI Act
Not applicable

Groupware/email product; not an AI system offering.

Not applicable

Email hosting product; vendor emphasises no AI scanning/mining of mailbox content for ads.

ISO 9001 / ISO 14001Not listed
Vendor claimed

Vendor-claimed quality and environmental certifications; certificates on request.

NIS2 readinessNot listed
Vendor claimed

Vendor markets NIS2 Ready; buyer press also asserts NIS2 compliance—confirm evidence package.

NEN 7510 (healthcare NL)Not listed
Partial

Vendor states NEN 7510 certification is in progress, not completed.

Considerations & known limitations: Kolab Now vs Soverin
Considerations & known limitationsLogo: Kolab NowKolab NowLogo: SoverinSoverin
Mail not zero-access by default
Medium

Unlike Proton/Tuta defaults, ordinary stored mail is provider-accessible for protocol delivery unless users apply PGP or another client E2EE scheme. Material for threat models that assume provider compromise or compelled access to plaintext.

Not listed
2FA blocks non-web clients
Medium

Documented behaviour: enabling TOTP 2FA confines the user to the web client and blocks IMAP/ActiveSync/CalDAV and related protocols. Breaks many mobile/Outlook deployments if applied naively.

Not listed
Limited public compliance pack
Medium

No public ISO/SOC certs, independent audit, or subprocessor register found. Procurement must rely on vendor FAQs, ToS, and direct questions — slower security review than certified EU SaaS peers.

Not listed
US-linked payment processors
Low

Wallet top-ups via PayPal and credit cards introduce US-group payment processors for billing data even when mailboxes stay in Switzerland. Scope is payment metadata, not IMAP content, but still relevant to transfer inventories.

Not listed
Kolab Meet still beta
Low

Voice/video rooms are labelled public beta; vendor notes support may be limited. Do not treat as a Zoom/Teams replacement for critical meetings.

Not listed
Not zero-knowledge E2EE by defaultNot listed
Medium

Unlike Proton/Tuta, Soverin is a classic IMAP host. Provider infrastructure can process content for delivery and spam filtering. Practical impact: unsuitable as a drop-in for policies that require provider-blind encryption without extra client crypto.

Unnamed external support partnerNot listed
Medium

Privacy statement discloses a first-line support partner with limited account data under DPA/NDA, but does not publish the partner name or country. Practical impact: add an open diligence item for any regulated workload.

ISO certificates not self-serve publicNot listed
Low

ISO 27001/9001/14001 are claimed with certificates via support rather than a public PDF registry link found in research. Practical impact: procurement should request current attestations before treating certs as verified.

2025 group acquisitionNot listed
Low

The Sharing Group acquisition may change subprocessors, tooling, or brand packaging over time even if continuity is promised. Practical impact: re-check DPA and hosting annex annually.

Email-centric supportNot listed
Low

Public materials emphasise human Dutch-team email support; TechRadar notes no live chat or phone. Practical impact: large orgs needing 24/7 phone SLAs may find coverage thin.

Fit

Kolab Now

Best fit when

  • Small teams and professional practices that need shared mailboxes, calendars, and private domains under Swiss jurisdiction
  • Buyers who prioritise open standards (IMAP, CalDAV/CardDAV, ActiveSync, WebDAV) and FOSS components over proprietary lock-in
  • Organisations that will accept provider-accessible mail at rest and apply PGP/S/MIME themselves for sensitive threads
  • Users leaving Google Workspace who want groupware depth without US Big Tech mail custody
  • Account owners comfortable with prepaid wallet billing and modular per-user subscriptions

Poor fit when

  • Requirements for default end-to-end encrypted mail with zero provider access (prefer Proton Mail or Tuta)
  • Enterprises that need public ISO 27001/SOC 2 packs, signed DPAs, and a published subprocessor list on day one
  • Fleets that must combine TOTP 2FA with IMAP/ActiveSync clients on the same user (documented mutual exclusion)
  • Orgs treating video conferencing as a core, production-grade service (Kolab Meet is still beta)
  • Buyers seeking a permanent free tier or consumer-grade onboarding polish comparable to Gmail

Consider instead when

  • When: You need default zero-access / E2EE email more than ActiveSync groupware

    Consider: Proton Mail or Tuta

    Stronger default cryptography story; thinner classical groupware/ActiveSync depth than Kolab Now.

  • When: You want privacy-focused German email without full suite complexity

    Consider: Posteo

    Leaner privacy mail; not a Collabora + shared-domain groupware suite.

  • When: You need Google/Microsoft-class admin scale, apps marketplace, and compliance certifications

    Consider: Google Workspace or Microsoft 365

    Far larger ecosystems; US-centric custody and CLOUD Act profile differ sharply.

  • When: You want full self-host control of the same FOSS stack

    Consider: Self-hosted Kolab (kolab.org) or Nextcloud plus a mail stack

    More operational burden; Apheleia also sells Kolab professional services.

Soverin

Best fit when

  • Individuals and freelancers who want a paid European mailbox on their own domain with any standard mail client
  • SMEs needing several mailboxes, aliases, and CalDAV/CardDAV without adopting Google Workspace or Microsoft 365
  • Teams prioritising Dutch jurisdiction and claimed no-hyperscaler hosting over zero-knowledge E2EE
  • Hosters/ISPs/MSPs evaluating white-label or multi-mailbox Dutch email
  • Buyers who value DANE, DKIM/DMARC, DNSSEC, and IP-header stripping on an open-standards stack

Poor fit when

  • Organisations that require default zero-access / E2EE mail against the provider (use Proton Mail or Tuta)
  • Users seeking a free tier, anonymous cash-only signup, or purely self-hosted open-source mail servers
  • Enterprises needing SSO, eDiscovery archives, phone support SLAs, or a full office suite in one vendor
  • Workloads that depend on US-region mailbox hosting or hyperscale global PoPs

Consider instead when

  • When: You need zero-knowledge E2EE and a privacy-first mobile/web ecosystem

    Consider: Proton Mail or Tuta

    Trade open IMAP convenience for stronger default content secrecy vs the provider.

  • When: You want German-hosted paid mail with broader office-style add-ons

    Consider: mailbox.org or Posteo

    Compare storage, admin features, and payment anonymity (Posteo) against Soverin’s domain/alias model.

  • When: You need Google- or Microsoft-class collaboration and global free consumer mail

    Consider: Gmail or Microsoft 365 / Outlook.com

    Different risk and advertising model; not EU-sovereignty substitutes.

Open questions for due diligence

Kolab Now

  • Will Apheleia sign a GDPR Art. 28 DPA and provide a current subprocessor list (including backups, monitoring, and payment processors) under NDA if needed?
  • What is the current imprint address and governing ToS URL for contract annexes (product footer vs apheleia-it.ch addresses differ)?
  • Is there any ISO 27001, SOC 2, or independent penetration-test summary available to customers on request?
  • How are backups and disaster recovery stored (same Bern facility only, or additional sites/providers)?
  • For regulated workloads: what is the practical process and historical volume of Swiss lawful-access requests affecting customer content?

Soverin

  • What is the legal name and country of the first-line support partner, and is a current subprocessor list available under NDA?
  • Can Soverin provide the latest ISO 27001/9001/14001 certificates and scope statements without delay?
  • After The Sharing Group acquisition, are any new group companies (e.g. Mijndomein, Greenhost, Leafcloud tooling) in the mailbox data path?
  • Is NEN 7510 certification complete for healthcare use cases, or still in progress?
  • Which domain registrar(s) handle customer DNSSEC, and where are registry data stored?