mailbox (formerly mailbox.org) vs Proton Mail

Compare mailbox (formerly mailbox.org) and Proton Mail on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365

Logo: mailbox (formerly mailbox.org)

mailbox (formerly mailbox.org)

Germany· Office Productivity Suite

Needs review

Shortlist mailbox when you need a German-operated email-plus-collaboration suite (Mail, Drive, Office, Meet, Admin/API) on dual Berlin sites with published BSI C5 Type 1 and ISO 27001 claims. Skip when you require free forever mail or default zero-knowledge for all messages—consider Proton Mail or Tuta instead.

German-operatedBerlin dual-site hostingPGP + S/MIMEBSI C5 Type 1 (claimed)ISO 27001 (claimed)Mail + Drive + Meet + Office
Logo: Proton Mail

Proton Mail

Switzerland· Email Services

Needs review

Shortlist Proton Mail when you want Swiss-jurisdiction, zero-access encrypted email with open-source clients, custom domains, Bridge for desktop mailers, and a public DPA. Skip when you need free-tier IMAP Bridge, fully self-hosted FOSS mail on your own servers, or Workspace-class collaboration depth—consider Tuta, Posteo, or Mailfence among EU peers, or stay on Google/Microsoft if suite lock-in wins.

E2EE + zero-accessSwiss-operatedBridge (IMAP/SMTP)Open-source clientsISO 27001 & SOC 2 (claimed)Public B2B DPA
mailbox (formerly mailbox.org) vs Proton Mail: Snapshot
FeatureLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: Proton MailProton Mail
Country of originGermanySwitzerland
CategoryOffice Productivity SuiteEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanySwitzerland
Legal entityHeinlein Hosting GmbH (Berlin; CEO Peer Heinlein)Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland (EU representative: Proton Europe sàrl, Luxembourg)
Governing lawNot listedSwiss law (Terms; Geneva courts for business/non-US consumer disputes as stated in Terms)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyCore mailbox, Drive, and Meet on Heinlein-operated servers in German data centres in Berlin (two independent locations). Website analytics: self-hosted Matomo. Marketing site may embed Vimeo/YouTube. No public AWS/GCP/Azure product hosting region found for customer mail data.Primary mail storage on Proton-owned servers in Switzerland (vendor security pages). Not marketed as AWS/GCP/Azure inbox hosting. Public privacy policy lists US-group processors for support and payments (Zendesk; Chargebee, Stripe, PayPal) and group support processing in North Macedonia and Taiwan; HubSpot noted for business sales inquiries.
Summary

German paid digital workplace from Heinlein Hosting GmbH: secure email with PGP/S/MIME, Drive, browser Office, Meet, and business Admin on dual Berlin data centres.

Swiss end-to-end encrypted email from Proton AG: zero-access inbox storage, open-source clients, custom domains, and Bridge for desktop IMAP clients.

Tags
At a glance: mailbox (formerly mailbox.org) vs Proton Mail
At a glanceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: Proton MailProton Mail
HQBerlin, GermanyPlan-les-Ouates (Geneva), Switzerland
Legal entityHeinlein Hosting GmbHProton AG (CHE-354.686.492); Proton Foundation supervision
HostingOwn servers, dual independent Berlin sitesNot listed
ModelPaid subscription SaaS; trial available; no permanent free tierNot listed
Self-hostNo (managed SaaS)No (SaaS); clients open source
Open standardsIMAP/SMTP, CalDAV/CardDAV, WebDAV, PGP, S/MIMENot listed
Hosting modelNot listedProton-owned hardware in Switzerland (vendor claim)
Commercial modelNot listedFreemium + paid consumer and business seats
BridgeNot listedPaid plans that include Mail
Key capabilities: mailbox (formerly mailbox.org) vs Proton Mail
Key capabilitiesLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: Proton MailProton Mail
German-operatedYesNot listed
Berlin dual-site hostingYesNot listed
PGP + S/MIMEYesNot listed
BSI C5 Type 1 (claimed)YesNot listed
ISO 27001 (claimed)YesNot listed
Mail + Drive + Meet + OfficeYesNot listed
E2EE + zero-accessNot listedYes
Swiss-operatedNot listedYes
Bridge (IMAP/SMTP)Not listedYes
Open-source clientsNot listedYes
ISO 27001 & SOC 2 (claimed)Not listedYes
Public B2B DPANot listedYes

mailbox (formerly mailbox.org)

  • PGP Guard, S/MIME, and hardened mail transport

    Webmail Guard for PGP without extra software (or Mailvelope with local keys), S/MIME for sign/encrypt, 2FA and app passwords, multi-stage spam/virus rejection, plus public transport controls (DNSSEC, DANE, MTA-STS, DMARC/DKIM/SPF, TLS checker, @secure.mailbox.org aliases). Benefits security-minded teams that still need interoperable IMAP/SMTP; content is not zero-knowledge by default unless you encrypt.

  • Drive on dual independent Berlin sites

    Cloud files on the provider's own German infrastructure with two independent Berlin locations, WebDAV, mobile apps, guest share links, expandable quota, and optional client-side OpenPGP encryption of stored files. Fits teams replacing consumer cloud drives while keeping residency claims concrete; confirm plan quotas on the official site.

  • Browser Office with CalDAV and CardDAV

    Edit common office formats in the browser, share calendars and contacts via open CalDAV/CardDAV standards, plus tasks, notes, polls, and TLS-secured XMPP chat. Aimed at SMEs and schools that want collaboration without a full Microsoft desktop stack; advanced Excel macros and deep Office add-ins are not the target.

  • Meet video hosted in German data centres

    Browser-based conferencing integrated with calendar and mail: link invites for external guests, breakout rooms, screen share, chat, surveys, and moderator controls. Privacy documentation references the OpenTalk stack; sessions run through mailbox's German data centres. Evaluate E2EE defaults and recording policies against your meeting compliance needs.

  • Business Admin console and automation API

    Central management of domains, mailboxes, quotas, spam/virus settings, IP allowlists, and backups, with an HTTP API for larger orgs and resellers (api.mailbox.org). Supports onboarding help and partner-assisted migration. Better for multi-seat German operations than pure consumer inboxes; not a full IdP replacement without SSO design work.

Proton Mail

  • Zero-access inbox encryption by default

    Bodies and attachments are encrypted so Proton states it lacks keys to read stored mail. Proton-to-Proton traffic is end-to-end encrypted automatically; external recipients need password-protected messages or PGP/WKD for comparable content protection. Subject lines are not fully E2EE under OpenPGP header rules.

  • Proton Mail Bridge for desktop IMAP clients

    Paid plans that include Mail can run Bridge locally to connect Outlook, Thunderbird, or Apple Mail over IMAP/SMTP while encrypting and decrypting on the device. Free accounts use official web/mobile/desktop apps instead of Bridge.

  • Custom domains, aliases, and business admin

    Paid and business tiers support custom domains, extra addresses, catch-all and groups, hide-my-email aliases, and org admin for seats, storage, and retention policies. Suits teams leaving Google/Microsoft who still need branded addresses.

  • Open-source clients with published audits

    Web, mobile, and desktop clients are published on GitHub with third-party audit reports linked from Proton’s open-source page. The hosted mail backend is not offered as self-hosted FOSS—audit client trust, not full server reproducibility.

  • Tracker blocking, PhishGuard, and Sentinel

    Built-in tracker protection, phishing heuristics, link confirmation, SPF/DKIM/DMARC for custom domains, hardware-key 2FA, and optional Proton Sentinel monitoring for high-risk accounts. Complements encryption with everyday abuse defenses.

Assurance & compliance: mailbox (formerly mailbox.org) vs Proton Mail
Assurance & complianceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: Proton MailProton Mail
Independent security / no-logs audit
Not found

No public independent no-logs audit PDF found; operational transparency reports and BSI/ISO artefacts instead

Vendor claimed

Open-source clients with published third-party audit reports (web/desktop links on open-source page). Not a classic VPN no-logs court test; transparency report covers legal orders for accessible account data.

ISO 27001
Vendor claimed

Vendor states ISO/IEC 27001:2022 on certified-quality and press pages; request current certificate in diligence

Vendor claimed

Vendor announces ISO 27001 certification after external audit completed 2 May 2024; Trust Center links a certificate download. Confirm scope and validity at procurement time.

SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on primary security/cert pages

Vendor claimed

Vendor announces first SOC 2 Type II attestation (July 2025 blog). Report typically under NDA—request from vendor for diligence files.

BSI C5
Vendor claimed

Vendor press (7 Jan 2026): BSI C5 Type 1 attestation for mailbox; confirm type, scope, and period

Not listed
GDPR / EU data protection
Vendor claimed

German controller Heinlein Hosting GmbH; DE hosting; detailed privacy notice; DPO privacy@mailbox.org

Vendor claimed

Swiss controller/processor with EU representative; public DPA; GDPR materials for business. Adequacy/transfer mechanisms documented for non-adequate destinations.

US CLOUD Act exposure (indicative)
Partial

EU/German entity, no known US parent, self-operated Berlin hosting for core data—no AWS/GCP/Azure product region found. Residual: marketing embeds (Vimeo/YouTube) and possible external payment services. Indicative assessment only, not legal advice.

Partial

Swiss entity / no known US parent; inbox content on Proton-owned Swiss hardware with zero-access design. Partial exposure remains via US SaaS subprocessors (Zendesk support; Stripe/Chargebee/PayPal payments) and any account metadata Proton can access under Swiss process. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Business knowledge base: customers can conclude a DPA online; historic AVV portal for business accounts

Vendor claimed

Public DPA at proton.me/legal/dpa forms part of terms when Proton acts as processor; Swiss law, Geneva jurisdiction; general authorization for listed subprocessors.

EU AI Act
Not applicable

Email/collaboration suite, not an AI product core

Not applicable

Core product is encrypted email. Optional Scribe assistant is ancillary; not an AI-centric offering for this catalog entry.

Considerations & known limitations: mailbox (formerly mailbox.org) vs Proton Mail
Considerations & known limitationsLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: Proton MailProton Mail
Mail is not zero-knowledge by default
Medium

Without PGP/S/MIME, stored message content remains operator-accessible under legal process. Practical impact: train users or mandate Guard/S/MIME for confidential traffic.

Not listed
C5 Type 1 is point-in-time
Low

Type 1 attestations describe design/implementation at a point in time. Re-check type (1 vs 2), scope, and renewal dates for public-sector RFPs.

Not listed
Payment and edge processors need confirmation
Low

Core hosting is self-operated DE, but privacy text references external payment services; marketing embeds US video hosts. Ask for the current processor list with the DPA.

Not listed
Not a full Microsoft 365 ecosystem substitute
Medium

Browser Office and Meet cover common collaboration; deep desktop macros, Graph automations, and third-party M365 marketplaces will not map 1:1.

Not listed
No customer self-host option
Low

Organisations that must operate mail on their own iron need another stack; mailbox is multi-tenant SaaS.

Not listed
Weaker defaults outside ProtonNot listed
Medium

Mail to Gmail/Outlook/others is not E2EE unless password-protected or PGP/WKD is used. Subject lines are not fully E2EE. Train users or you only protect the Proton-stored copy.

US support and payment processorsNot listed
Medium

Zendesk, Chargebee, Stripe, and PayPal appear in the public processor list. They should not see zero-access message bodies, but support content and billing data can touch US-group services—document this in DPIAs.

Bridge requires paid MailNot listed
Low

Desktop IMAP/SMTP via Bridge is not available on free accounts. Budget seats for users who refuse the official apps.

Hosted service, not self-hosted FOSS mailNot listed
Medium

Open-source clients improve inspectability but you still depend on Proton’s operated backend, uptime, and Swiss legal process. Unsuitable if policy mandates customer-operated mail servers.

Swiss legal orders on accessible dataNot listed
Low

Transparency reports show thousands of yearly legal orders for Mail with many complied. Bodies stay encrypted; recovery emails, IPs (when retained for abuse), and similar metadata may still be in scope. Align expectations with counsel.

Fit

mailbox (formerly mailbox.org)

Best fit when

  • German or EU orgs replacing Gmail/Microsoft 365 for mail and light collaboration under German law
  • Teams that need IMAP/SMTP plus CalDAV/CardDAV and optional custom domains
  • Buyers that will use PGP Guard or S/MIME deliberately for sensitive mail
  • SMEs and schools wanting Drive, browser Office, and Meet without a US hyperscaler
  • Organisations that need multi-seat Admin, DPA, and an automation API

Poor fit when

  • Users who need a permanent free tier
  • Buyers requiring default zero-knowledge mail for every user without crypto setup
  • Teams that must self-host the full stack on their own infrastructure
  • Enterprises whose workflows depend on deep Microsoft Graph or Google Workspace add-ons

Consider instead when

  • When: You need default end-to-end encrypted mail as the primary product

    Consider: Proton Mail or Tuta

    Stronger E2EE-first posture; lighter full workplace suite than mailbox

  • When: You want minimal German privacy email without Drive/Office/Meet

    Consider: Posteo

    Leaner mailbox; fewer collaboration modules

  • When: You need full desktop Office parity and global SaaS integrations

    Consider: Microsoft 365 (incumbent) with separate residency controls

    Different risk and ecosystem tradeoff—not an EU peer

Proton Mail

Best fit when

  • Teams that need default end-to-end / zero-access encryption without running their own mail stack
  • Orgs that want Swiss legal venue and documented resistance to direct foreign data demands
  • Businesses migrating branded domains off Gmail/Outlook with Easy Switch and Bridge for desktop holdouts
  • Security-conscious professionals who value open-source clients, published audits, and hardware-key 2FA
  • Buyers who need a public DPA plus vendor-claimed ISO 27001 / SOC 2 Type II for questionnaires

Poor fit when

  • Fully self-hosted requirements (Proton Mail is SaaS; clients are open source, not a full on-prem mail server)
  • Desktop IMAP on free accounts only—Bridge needs a paid plan that includes Mail
  • Workflows that depend on unencrypted-looking mail to external parties who will not use password links or PGP
  • Teams that primarily need full Microsoft 365 / Google Workspace collaboration depth rather than encrypted mail first

Consider instead when

  • When: You want German E2EE email with a different crypto product surface and may not need Proton’s full ecosystem

    Consider: Tuta

    Compare desktop interoperability and business admin maturity side by side.

  • When: You want ad-free European mail with strong transport privacy but do not require zero-access E2EE for all stored content

    Consider: Posteo

    Different threat model: Posteo is privacy-forward without Proton’s zero-access default.

  • When: You need OpenPGP-centric mail with classic collaboration extras under Belgian operation

    Consider: Mailfence

    Weigh automatic Proton-to-Proton E2EE UX versus Mailfence’s model.

  • When: Collaboration suite depth and ecosystem lock-in outweigh encryption defaults

    Consider: Google Workspace or Microsoft 365

    Accept US-provider jurisdiction and scanning/processing models as tradeoffs.

Open questions for due diligence

mailbox (formerly mailbox.org)

  • What is the exact current BSI C5 scope, type, and validity period on the attestation document?
  • Which payment processors and any other subprocessors appear in the live AVV annex?
  • What is the default Meet encryption mode (TLS-only vs optional E2EE) for your plan, and is recording available?
  • Which SSO/IdP integrations are supported for your business tier beyond generic SSO mentions?

Proton Mail

  • What exact data-center sites and any non-Swiss regions apply to your tenant’s mailbox replicas today?
  • Will Proton provide the full SOC 2 Type II report under NDA and confirm ISO 27001 certificate scope/expiry for your questionnaire?
  • For business orgs: which users will be private vs non-private, and how will admin recovery work with zero-access constraints?
  • Which external partners must receive E2EE content, and will they accept password-protected messages or PGP?