mailbox (formerly mailbox.org) vs Soverin

Compare mailbox (formerly mailbox.org) and Soverin on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365

Logo: mailbox (formerly mailbox.org)

mailbox (formerly mailbox.org)

Germany· Office Productivity Suite

Needs review

Shortlist mailbox when you need a German-operated email-plus-collaboration suite (Mail, Drive, Office, Meet, Admin/API) on dual Berlin sites with published BSI C5 Type 1 and ISO 27001 claims. Skip when you require free forever mail or default zero-knowledge for all messages—consider Proton Mail or Tuta instead.

German-operatedBerlin dual-site hostingPGP + S/MIMEBSI C5 Type 1 (claimed)ISO 27001 (claimed)Mail + Drive + Meet + Office
Logo: Soverin

Soverin

Netherlands· Email Services

Needs review

Shortlist Soverin when you want Dutch-operated, paid IMAP email with custom domains, unlimited aliases, and strong mail-auth standards without Google/Microsoft ads. Skip when you need zero-knowledge E2EE—consider Proton Mail or Tuta instead—or a full productivity suite (mailbox.org / Microsoft 365).

NL / EU operatedCustom domainsIMAP / CalDAVNo ads / no trackingISO 27001 (claimed)DANE / DNSSEC
mailbox (formerly mailbox.org) vs Soverin: Snapshot
FeatureLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: SoverinSoverin
Country of originGermanyNetherlands
CategoryOffice Productivity SuiteEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyNetherlands
Legal entityHeinlein Hosting GmbH (Berlin; CEO Peer Heinlein)Soverin B.V. (Amsterdam); owned by The Sharing Group / TSG Online (Dutch) as of September 2025 acquisition announcement
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyCore mailbox, Drive, and Meet on Heinlein-operated servers in German data centres in Berlin (two independent locations). Website analytics: self-hosted Matomo. Marketing site may embed Vimeo/YouTube. No public AWS/GCP/Azure product hosting region found for customer mail data.Vendor: EU-only processing; data in NL; self-operated Dutch DCs, no hyperscaler. TechRadar: 3 NL DCs. Core mail hosts on Soverin B.V. AS211993. External first-line support partner under DPA/NDA (country unpublished). HIBP k-anon password checks; Let’s Encrypt; domain DNSSEC partner. No AWS/GCP/Azure as primary mailbox hosts in public materials.
Summary

German paid digital workplace from Heinlein Hosting GmbH: secure email with PGP/S/MIME, Drive, browser Office, Meet, and business Admin on dual Berlin data centres.

Dutch privacy-first email hosting: custom domains, open IMAP/SMTP/CalDAV, 25 GB mailboxes, no ads or content scanning, servers operated in the Netherlands.

Tags
At a glance: mailbox (formerly mailbox.org) vs Soverin
At a glanceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: SoverinSoverin
HQBerlin, GermanyAmsterdam, Netherlands (Soverin B.V.)
Legal entityHeinlein Hosting GmbHNot listed
HostingOwn servers, dual independent Berlin sitesDutch data centres; vendor claims self-operated, no hyperscaler
ModelPaid subscription SaaS; trial available; no permanent free tierNot listed
Self-hostNo (managed SaaS)Not listed
Open standardsIMAP/SMTP, CalDAV/CardDAV, WebDAV, PGP, S/MIMENot listed
GroupNot listedThe Sharing Group / TSG Online (acq. Sep 2025)
ProtocolsNot listedIMAP, SMTP, CalDAV, CardDAV
StorageNot listed25 GB per mailbox (vendor-stated)
Self-host / OSSNot listedNo / No
Commercial modelNot listedAnnual prepaid; 30-day mailbox money-back; no free tier
Key capabilities: mailbox (formerly mailbox.org) vs Soverin
Key capabilitiesLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: SoverinSoverin
German-operatedYesYes
Berlin dual-site hostingYesNot listed
PGP + S/MIMEYesNot listed
BSI C5 Type 1 (claimed)YesNot listed
ISO 27001 (claimed)YesNot listed
Mail + Drive + Meet + OfficeYesNot listed
Custom domainsNot listedYes
IMAP / CalDAVNot listedYes
No ads / no trackingNot listedYes
ISO 27001 (claimed)Not listedYes
DANE / DNSSECNot listedYes

mailbox (formerly mailbox.org)

  • PGP Guard, S/MIME, and hardened mail transport

    Webmail Guard for PGP without extra software (or Mailvelope with local keys), S/MIME for sign/encrypt, 2FA and app passwords, multi-stage spam/virus rejection, plus public transport controls (DNSSEC, DANE, MTA-STS, DMARC/DKIM/SPF, TLS checker, @secure.mailbox.org aliases). Benefits security-minded teams that still need interoperable IMAP/SMTP; content is not zero-knowledge by default unless you encrypt.

  • Drive on dual independent Berlin sites

    Cloud files on the provider's own German infrastructure with two independent Berlin locations, WebDAV, mobile apps, guest share links, expandable quota, and optional client-side OpenPGP encryption of stored files. Fits teams replacing consumer cloud drives while keeping residency claims concrete; confirm plan quotas on the official site.

  • Browser Office with CalDAV and CardDAV

    Edit common office formats in the browser, share calendars and contacts via open CalDAV/CardDAV standards, plus tasks, notes, polls, and TLS-secured XMPP chat. Aimed at SMEs and schools that want collaboration without a full Microsoft desktop stack; advanced Excel macros and deep Office add-ins are not the target.

  • Meet video hosted in German data centres

    Browser-based conferencing integrated with calendar and mail: link invites for external guests, breakout rooms, screen share, chat, surveys, and moderator controls. Privacy documentation references the OpenTalk stack; sessions run through mailbox's German data centres. Evaluate E2EE defaults and recording policies against your meeting compliance needs.

  • Business Admin console and automation API

    Central management of domains, mailboxes, quotas, spam/virus settings, IP allowlists, and backups, with an HTTP API for larger orgs and resellers (api.mailbox.org). Supports onboarding help and partner-assisted migration. Better for multi-seat German operations than pure consumer inboxes; not a full IdP replacement without SSO design work.

Soverin

  • Custom domains with unlimited aliases

    Host mail on your own domain (bring existing or register through Soverin). Unlimited aliases—plus-addressing or domain names—deliver into one mailbox, plus optional random @sinenomine.email private aliases that hide the real address. Suits freelancers and SMEs who need brandable addresses without per-alias fees.

  • Open IMAP/SMTP plus CalDAV/CardDAV

    Use any standards-based client or device for mail, calendar, and contacts—no proprietary app required. Dashboard import helps migrate from other providers. Ideal when IT wants Thunderbird, Apple Mail, or Outlook without locking into a closed webmail ecosystem; not a zero-knowledge E2EE product by default.

  • Mail-path security: DANE, DKIM, DMARC, IP stripping

    Outbound and inbound paths use TLS; Soverin publishes and honours DANE/TLSA, signs with DKIM, publishes SPF/DMARC, enables DNSSEC on managed domains, and strips personal IP addresses from outbound headers. 2FA is available and can be admin-mandated. Buyers still need their own OpenPGP setup for end-to-end content secrecy with external parties.

  • 25 GB mailboxes with per-user encrypted backups

    Each mailbox includes a stated 25 GB quota covering mail, calendar, and contacts. Nightly backups use individually generated keys; Soverin states that emptying trash permanently deletes data and that leaving the service removes backups when the key is destroyed. Extra mailboxes can share storage for small teams.

  • Multi-mailbox and channel-friendly business use

    Purchase and assign additional mailboxes on a domain, with admin tooling for teams. Soverin markets to hosters, ISPs, MSPs, and independent professionals for multi-mailbox and white-label scenarios—useful when you want Dutch-operated email without building your own mail stack.

Assurance & compliance: mailbox (formerly mailbox.org) vs Soverin
Assurance & complianceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: SoverinSoverin
Independent security / no-logs audit
Not found

No public independent no-logs audit PDF found; operational transparency reports and BSI/ISO artefacts instead

Not found

No public third-party no-logs or full security audit PDF located; privacy claims are first-party.

ISO 27001
Vendor claimed

Vendor states ISO/IEC 27001:2022 on certified-quality and press pages; request current certificate in diligence

Vendor claimed

Vendor states independently audited ISO 27001; certificates available on request via support@soverin.net. Not re-verified against a public registry entry in this pass.

SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on primary security/cert pages

Not found

No SOC 2/3 claim found on primary pages reviewed.

BSI C5
Vendor claimed

Vendor press (7 Jan 2026): BSI C5 Type 1 attestation for mailbox; confirm type, scope, and period

Not listed
GDPR / EU data protection
Vendor claimed

German controller Heinlein Hosting GmbH; DE hosting; detailed privacy notice; DPO privacy@mailbox.org

Vendor claimed

NL entity; AVG-framed privacy statement; EU-only processing claimed; GDPR Proof messaging on recognitions page.

US CLOUD Act exposure (indicative)
Partial

EU/German entity, no known US parent, self-operated Berlin hosting for core data—no AWS/GCP/Azure product region found. Residual: marketing embeds (Vimeo/YouTube) and possible external payment services. Indicative assessment only, not legal advice.

Partial

EuropeanStack assessment: low exposure path—Dutch Soverin B.V., Dutch The Sharing Group owner, claimed self-operated NL hosting without public AWS/GCP/Azure mailbox hosts. Partial because residual subprocessors (support partner jurisdiction, domain partners, HIBP hash checks) need buyer confirmation. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Business knowledge base: customers can conclude a DPA online; historic AVV portal for business accounts

Vendor claimed

Privacy statement states it qualifies as an Article 28 AVG processing agreement; other DPAs expressly rejected. Confirm signed annex for enterprise use.

EU AI Act
Not applicable

Email/collaboration suite, not an AI product core

Not applicable

Email hosting product; vendor emphasises no AI scanning/mining of mailbox content for ads.

ISO 9001 / ISO 14001Not listed
Vendor claimed

Vendor-claimed quality and environmental certifications; certificates on request.

NIS2 readinessNot listed
Vendor claimed

Vendor markets NIS2 Ready; buyer press also asserts NIS2 compliance—confirm evidence package.

NEN 7510 (healthcare NL)Not listed
Partial

Vendor states NEN 7510 certification is in progress, not completed.

Considerations & known limitations: mailbox (formerly mailbox.org) vs Soverin
Considerations & known limitationsLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: SoverinSoverin
Mail is not zero-knowledge by default
Medium

Without PGP/S/MIME, stored message content remains operator-accessible under legal process. Practical impact: train users or mandate Guard/S/MIME for confidential traffic.

Not listed
C5 Type 1 is point-in-time
Low

Type 1 attestations describe design/implementation at a point in time. Re-check type (1 vs 2), scope, and renewal dates for public-sector RFPs.

Not listed
Payment and edge processors need confirmation
Low

Core hosting is self-operated DE, but privacy text references external payment services; marketing embeds US video hosts. Ask for the current processor list with the DPA.

Not listed
Not a full Microsoft 365 ecosystem substitute
Medium

Browser Office and Meet cover common collaboration; deep desktop macros, Graph automations, and third-party M365 marketplaces will not map 1:1.

Not listed
No customer self-host option
Low

Organisations that must operate mail on their own iron need another stack; mailbox is multi-tenant SaaS.

Not listed
Not zero-knowledge E2EE by defaultNot listed
Medium

Unlike Proton/Tuta, Soverin is a classic IMAP host. Provider infrastructure can process content for delivery and spam filtering. Practical impact: unsuitable as a drop-in for policies that require provider-blind encryption without extra client crypto.

Unnamed external support partnerNot listed
Medium

Privacy statement discloses a first-line support partner with limited account data under DPA/NDA, but does not publish the partner name or country. Practical impact: add an open diligence item for any regulated workload.

ISO certificates not self-serve publicNot listed
Low

ISO 27001/9001/14001 are claimed with certificates via support rather than a public PDF registry link found in research. Practical impact: procurement should request current attestations before treating certs as verified.

2025 group acquisitionNot listed
Low

The Sharing Group acquisition may change subprocessors, tooling, or brand packaging over time even if continuity is promised. Practical impact: re-check DPA and hosting annex annually.

Email-centric supportNot listed
Low

Public materials emphasise human Dutch-team email support; TechRadar notes no live chat or phone. Practical impact: large orgs needing 24/7 phone SLAs may find coverage thin.

Fit

mailbox (formerly mailbox.org)

Best fit when

  • German or EU orgs replacing Gmail/Microsoft 365 for mail and light collaboration under German law
  • Teams that need IMAP/SMTP plus CalDAV/CardDAV and optional custom domains
  • Buyers that will use PGP Guard or S/MIME deliberately for sensitive mail
  • SMEs and schools wanting Drive, browser Office, and Meet without a US hyperscaler
  • Organisations that need multi-seat Admin, DPA, and an automation API

Poor fit when

  • Users who need a permanent free tier
  • Buyers requiring default zero-knowledge mail for every user without crypto setup
  • Teams that must self-host the full stack on their own infrastructure
  • Enterprises whose workflows depend on deep Microsoft Graph or Google Workspace add-ons

Consider instead when

  • When: You need default end-to-end encrypted mail as the primary product

    Consider: Proton Mail or Tuta

    Stronger E2EE-first posture; lighter full workplace suite than mailbox

  • When: You want minimal German privacy email without Drive/Office/Meet

    Consider: Posteo

    Leaner mailbox; fewer collaboration modules

  • When: You need full desktop Office parity and global SaaS integrations

    Consider: Microsoft 365 (incumbent) with separate residency controls

    Different risk and ecosystem tradeoff—not an EU peer

Soverin

Best fit when

  • Individuals and freelancers who want a paid European mailbox on their own domain with any standard mail client
  • SMEs needing several mailboxes, aliases, and CalDAV/CardDAV without adopting Google Workspace or Microsoft 365
  • Teams prioritising Dutch jurisdiction and claimed no-hyperscaler hosting over zero-knowledge E2EE
  • Hosters/ISPs/MSPs evaluating white-label or multi-mailbox Dutch email
  • Buyers who value DANE, DKIM/DMARC, DNSSEC, and IP-header stripping on an open-standards stack

Poor fit when

  • Organisations that require default zero-access / E2EE mail against the provider (use Proton Mail or Tuta)
  • Users seeking a free tier, anonymous cash-only signup, or purely self-hosted open-source mail servers
  • Enterprises needing SSO, eDiscovery archives, phone support SLAs, or a full office suite in one vendor
  • Workloads that depend on US-region mailbox hosting or hyperscale global PoPs

Consider instead when

  • When: You need zero-knowledge E2EE and a privacy-first mobile/web ecosystem

    Consider: Proton Mail or Tuta

    Trade open IMAP convenience for stronger default content secrecy vs the provider.

  • When: You want German-hosted paid mail with broader office-style add-ons

    Consider: mailbox.org or Posteo

    Compare storage, admin features, and payment anonymity (Posteo) against Soverin’s domain/alias model.

  • When: You need Google- or Microsoft-class collaboration and global free consumer mail

    Consider: Gmail or Microsoft 365 / Outlook.com

    Different risk and advertising model; not EU-sovereignty substitutes.

Open questions for due diligence

mailbox (formerly mailbox.org)

  • What is the exact current BSI C5 scope, type, and validity period on the attestation document?
  • Which payment processors and any other subprocessors appear in the live AVV annex?
  • What is the default Meet encryption mode (TLS-only vs optional E2EE) for your plan, and is recording available?
  • Which SSO/IdP integrations are supported for your business tier beyond generic SSO mentions?

Soverin

  • What is the legal name and country of the first-line support partner, and is a current subprocessor list available under NDA?
  • Can Soverin provide the latest ISO 27001/9001/14001 certificates and scope statements without delay?
  • After The Sharing Group acquisition, are any new group companies (e.g. Mijndomein, Greenhost, Leafcloud tooling) in the mailbox data path?
  • Is NEN 7510 certification complete for healthcare use cases, or still in progress?
  • Which domain registrar(s) handle customer DNSSEC, and where are registry data stored?