mailbox (formerly mailbox.org) vs Tuta

Compare mailbox (formerly mailbox.org) and Tuta on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365

Logo: mailbox (formerly mailbox.org)

mailbox (formerly mailbox.org)

Germany· Office Productivity Suite

Needs review

Shortlist mailbox when you need a German-operated email-plus-collaboration suite (Mail, Drive, Office, Meet, Admin/API) on dual Berlin sites with published BSI C5 Type 1 and ISO 27001 claims. Skip when you require free forever mail or default zero-knowledge for all messages—consider Proton Mail or Tuta instead.

German-operatedBerlin dual-site hostingPGP + S/MIMEBSI C5 Type 1 (claimed)ISO 27001 (claimed)Mail + Drive + Meet + Office
Logo: Tuta

Tuta

Germany· Email Services

Needs review

Shortlist when you need default end-to-end encrypted mail, calendar, and contacts under German law with post-quantum TutaCrypt and official multi-platform apps. Skip when teams must keep Outlook/Thunderbird via IMAP or need a full M365/Workspace suite—consider Proton Mail (Bridge) or mailbox.org instead.

Default mailbox E2EETutaCrypt post-quantumEU-operated (Germany)Open-source clientsDE data centers (claimed)No IMAP (by design)
mailbox (formerly mailbox.org) vs Tuta: Snapshot
FeatureLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: TutaTuta
Country of originGermanyGermany
CategoryOffice Productivity SuiteEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityHeinlein Hosting GmbH (Berlin; CEO Peer Heinlein)Tutao GmbH (HRB 208014, Hanover)
Governing lawNot listedGerman law / GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyCore mailbox, Drive, and Meet on Heinlein-operated servers in German data centres in Berlin (two independent locations). Website analytics: self-hosted Matomo. Marketing site may embed Vimeo/YouTube. No public AWS/GCP/Azure product hosting region found for customer mail data.Vendor states mailbox data is stored end-to-end encrypted on Tutao-operated servers in ISO 27001-certified data centers in Germany. No AWS/GCP/Azure primary hosting named on official security/privacy pages. Privacy statement discloses payment processing via PayPal (Europe) and banks for card/SEPA; no comprehensive public subprocessor list found for ops tools.
Summary

German paid digital workplace from Heinlein Hosting GmbH: secure email with PGP/S/MIME, Drive, browser Office, Meet, and business Admin on dual Berlin data centres.

German end-to-end encrypted email, calendar, and contacts from Tutao GmbH in Hanover—with post-quantum TutaCrypt, open-source clients, and freemium personal plus business plans.

Tags
At a glance: mailbox (formerly mailbox.org) vs Tuta
At a glanceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: TutaTuta
HQBerlin, GermanyHanover, Germany (Tutao GmbH)
Legal entityHeinlein Hosting GmbHNot listed
HostingOwn servers, dual independent Berlin sitesOwn servers in ISO 27001 data centers in Germany (vendor claim)
ModelPaid subscription SaaS; trial available; no permanent free tierNot listed
Self-hostNo (managed SaaS)Not listed
Open standardsIMAP/SMTP, CalDAV/CardDAV, WebDAV, PGP, S/MIMENot listed
ProductNot listedEncrypted email, calendar, contacts (SaaS)
Open sourceNot listedClients GPLv3 on GitHub; no productized self-host
ProtocolsNot listedNo IMAP/SMTP client access; official apps only
CryptoNot listedTutaCrypt hybrid (Kyber-1024 + X25519 + AES-256) for new accounts
Commercial modelNot listedFreemium personal + paid personal/business (no ads)
Key capabilities: mailbox (formerly mailbox.org) vs Tuta
Key capabilitiesLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: TutaTuta
German-operatedYesYes
Berlin dual-site hostingYesYes
PGP + S/MIMEYesNot listed
BSI C5 Type 1 (claimed)YesNot listed
ISO 27001 (claimed)YesNot listed
Mail + Drive + Meet + OfficeYesNot listed
Default mailbox E2EENot listedYes
TutaCrypt post-quantumNot listedYes
Open-source clientsNot listedYes
No IMAP (by design)Not listedYes

mailbox (formerly mailbox.org)

  • PGP Guard, S/MIME, and hardened mail transport

    Webmail Guard for PGP without extra software (or Mailvelope with local keys), S/MIME for sign/encrypt, 2FA and app passwords, multi-stage spam/virus rejection, plus public transport controls (DNSSEC, DANE, MTA-STS, DMARC/DKIM/SPF, TLS checker, @secure.mailbox.org aliases). Benefits security-minded teams that still need interoperable IMAP/SMTP; content is not zero-knowledge by default unless you encrypt.

  • Drive on dual independent Berlin sites

    Cloud files on the provider's own German infrastructure with two independent Berlin locations, WebDAV, mobile apps, guest share links, expandable quota, and optional client-side OpenPGP encryption of stored files. Fits teams replacing consumer cloud drives while keeping residency claims concrete; confirm plan quotas on the official site.

  • Browser Office with CalDAV and CardDAV

    Edit common office formats in the browser, share calendars and contacts via open CalDAV/CardDAV standards, plus tasks, notes, polls, and TLS-secured XMPP chat. Aimed at SMEs and schools that want collaboration without a full Microsoft desktop stack; advanced Excel macros and deep Office add-ins are not the target.

  • Meet video hosted in German data centres

    Browser-based conferencing integrated with calendar and mail: link invites for external guests, breakout rooms, screen share, chat, surveys, and moderator controls. Privacy documentation references the OpenTalk stack; sessions run through mailbox's German data centres. Evaluate E2EE defaults and recording policies against your meeting compliance needs.

  • Business Admin console and automation API

    Central management of domains, mailboxes, quotas, spam/virus settings, IP allowlists, and backups, with an HTTP API for larger orgs and resellers (api.mailbox.org). Supports onboarding help and partner-assisted migration. Better for multi-seat German operations than pure consumer inboxes; not a full IdP replacement without SSO design work.

Tuta

  • Default E2EE for mail, subjects, and attachments

    Between Tuta users, messages encrypt automatically including subject lines, bodies, and attachments. External recipients can use a shared password for end-to-end threads without installing software. Contacts and calendars use the same zero-access model; only delivery metadata (addresses, timestamps) stays readable by design.

  • TutaCrypt post-quantum hybrid cryptography

    New accounts use TutaCrypt: Kyber-1024 KEM plus X25519 ECDH with AES-256, targeting harvest-now-decrypt-later risks. Protocol details are published; existing accounts migrate as key rotation rolls out. Tuta intentionally avoids PGP so subjects and non-mail features can stay encrypted and algorithms can be upgraded in-product.

  • Zero-knowledge calendar with private reminders

    Calendar events—including times, titles, locations, and attendees—are end-to-end encrypted. Reminders are pushed as encrypted payloads and fired locally so servers are not told when an event starts. Sharing stays encrypted; invites can go out via mail, optionally password-protected for externals.

  • Open-source multi-platform clients (no IMAP)

    Web, Android (Play and F-Droid), iOS, Windows, macOS, and Linux clients are published under GPLv3 on GitHub. Desktop builds are signed for verification. There is no IMAP/SMTP bridge: third-party mail apps cannot connect, which preserves encryption at rest but forces a client switch for Outlook/Thunderbird holdouts.

  • Business domains, admin console, and whitelabel

    Paid business plans add custom domains, aliases, shared mailboxes, multi-admin roles, password/2FA resets, catch-all, templates, and optional branding/login on your own site. Vendor-stated uptime SLA and a GDPR order-processing agreement support B2B procurement—confirm current plan matrix on tuta.com.

Assurance & compliance: mailbox (formerly mailbox.org) vs Tuta
Assurance & complianceLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: TutaTuta
Independent security / no-logs audit
Not found

No public independent no-logs audit PDF found; operational transparency reports and BSI/ISO artefacts instead

Vendor claimed

Vendor states SySS GmbH penetration testing before public release; not a continuously published annual no-logs audit PDF on the marketing site.

ISO 27001
Vendor claimed

Vendor states ISO/IEC 27001:2022 on certified-quality and press pages; request current certificate in diligence

Partial

Official pages claim data centers are ISO 27001 certified; does not clearly establish a public Tutao GmbH organizational ISO 27001 certificate.

SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on primary security/cert pages

Not found

No SOC 2/3 report located on security, business, or privacy pages.

BSI C5
Vendor claimed

Vendor press (7 Jan 2026): BSI C5 Type 1 attestation for mailbox; confirm type, scope, and period

Not listed
GDPR / EU data protection
Vendor claimed

German controller Heinlein Hosting GmbH; DE hosting; detailed privacy notice; DPO privacy@mailbox.org

Vendor claimed

German controller Tutao GmbH; privacy statement cites GDPR; DPO published; DE storage claimed.

US CLOUD Act exposure (indicative)
Partial

EU/German entity, no known US parent, self-operated Berlin hosting for core data—no AWS/GCP/Azure product region found. Residual: marketing embeds (Vimeo/YouTube) and possible external payment services. Indicative assessment only, not legal advice.

Partial

EU entity, no known US parent, primary mailbox hosting claimed as own DE servers—not AWS/GCP/Azure. Payment may use PayPal (Europe). Assessment is low exposure for content with residual billing/processor unknowns; not a vendor 'safe' claim. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Business knowledge base: customers can conclude a DPA online; historic AVV portal for business accounts

Vendor claimed

Security/business materials state an Order Processing Agreement (Auftragsverarbeitung) is provided for GDPR; obtain signed version via sales—no public self-serve DPA URL confirmed.

EU AI Act
Not applicable

Email/collaboration suite, not an AI product core

Not applicable

Encrypted email/calendar product; vendor states it does not plan AI that processes user communications for model training.

Considerations & known limitations: mailbox (formerly mailbox.org) vs Tuta
Considerations & known limitationsLogo: mailbox (formerly mailbox.org)mailbox (formerly mailbox.org)Logo: TutaTuta
Mail is not zero-knowledge by default
Medium

Without PGP/S/MIME, stored message content remains operator-accessible under legal process. Practical impact: train users or mandate Guard/S/MIME for confidential traffic.

Not listed
C5 Type 1 is point-in-time
Low

Type 1 attestations describe design/implementation at a point in time. Re-check type (1 vs 2), scope, and renewal dates for public-sector RFPs.

Not listed
Payment and edge processors need confirmation
Low

Core hosting is self-operated DE, but privacy text references external payment services; marketing embeds US video hosts. Ask for the current processor list with the DPA.

Not listed
Not a full Microsoft 365 ecosystem substitute
Medium

Browser Office and Meet cover common collaboration; deep desktop macros, Graph automations, and third-party M365 marketplaces will not map 1:1.

Not listed
No customer self-host option
Low

Organisations that must operate mail on their own iron need another stack; mailbox is multi-tenant SaaS.

Not listed
No IMAP/SMTP third-party clientsNot listed
High

Desktop and mobile holdouts cannot stay on Outlook/Thunderbird/Apple Mail. Plan full client migration or pick a standards-based alternative.

Weaker protection to non-Tuta recipientsNot listed
Medium

Without a shared password, external mail is ordinary SMTP (TLS in transit). Only Tuta-to-Tuta and password-protected external threads are true E2EE.

Hosted service, not on-prem mailNot listed
Medium

Open-source clients help inspectability, but mailboxes still depend on Tutao's German SaaS backend, uptime, and German legal process.

Data-center ISO vs company ISMSNot listed
Low

ISO 27001 wording refers to data centers. Do not tick 'vendor ISO 27001 certified' on questionnaires without the actual Tutao certificate.

Limited public subprocessor inventoryNot listed
Medium

Privacy policy covers payments (e.g. PayPal Europe) but lacks a detailed live subprocessor register. Request the DPA annex for DPIA completeness.

German court orders on accessible dataNot listed
Low

Transparency reports show regular German requests. Stored E2EE content stays undecryptable by Tutao; real-time monitoring can expose newly arriving unencrypted SMTP mail. Align expectations with counsel.

Fit

mailbox (formerly mailbox.org)

Best fit when

  • German or EU orgs replacing Gmail/Microsoft 365 for mail and light collaboration under German law
  • Teams that need IMAP/SMTP plus CalDAV/CardDAV and optional custom domains
  • Buyers that will use PGP Guard or S/MIME deliberately for sensitive mail
  • SMEs and schools wanting Drive, browser Office, and Meet without a US hyperscaler
  • Organisations that need multi-seat Admin, DPA, and an automation API

Poor fit when

  • Users who need a permanent free tier
  • Buyers requiring default zero-knowledge mail for every user without crypto setup
  • Teams that must self-host the full stack on their own infrastructure
  • Enterprises whose workflows depend on deep Microsoft Graph or Google Workspace add-ons

Consider instead when

  • When: You need default end-to-end encrypted mail as the primary product

    Consider: Proton Mail or Tuta

    Stronger E2EE-first posture; lighter full workplace suite than mailbox

  • When: You want minimal German privacy email without Drive/Office/Meet

    Consider: Posteo

    Leaner mailbox; fewer collaboration modules

  • When: You need full desktop Office parity and global SaaS integrations

    Consider: Microsoft 365 (incumbent) with separate residency controls

    Different risk and ecosystem tradeoff—not an EU peer

Tuta

Best fit when

  • Teams that will standardize on Tuta's official web/mobile/desktop clients for default zero-access email
  • Orgs prioritizing subject-line encryption, encrypted calendar, and post-quantum hybrid crypto under German jurisdiction
  • SMEs needing custom domains, aliases, shared mailboxes, and multi-admin controls without running their own mail servers
  • Journalists, NGOs, and privacy-led departments that value F-Droid builds, no Google Push dependency, and ad-free operation
  • Buyers who want open-source client auditability plus a freemium path for personal trial before business seats

Poor fit when

  • Hard requirement for IMAP/SMTP in Outlook, Thunderbird, Apple Mail, or third-party automation
  • On-prem / customer-operated mail server mandates (no productized self-host for the backend)
  • Workflows that depend on first-class PGP or S/MIME interoperability with external partners
  • Primary need is full Google Workspace or Microsoft 365 collaboration (Drive, Meet, deep Outlook) rather than encrypted mail first

Consider instead when

  • When: Users must keep desktop IMAP clients or need Bridge-style Outlook integration

    Consider: Proton Mail (Bridge on paid plans) or mailbox.org / Posteo / Soverin

    Those options trade Tuta's automatic subject E2EE model for standards-based access

  • When: You need a broader German digital workplace (Drive, Office, video) with optional PGP

    Consider: mailbox.org

    Stronger suite breadth; different default encryption depth than Tuta's full zero-access mailbox

  • When: Swiss jurisdiction and multi-product privacy suite (VPN, drive, pass) matter more than German HQ

    Consider: Proton Mail

    Compare Bridge, ecosystem lock-in, and published cert posture side by side

  • When: Belgian OpenPGP-centric suite with browser crypto and classic protocols is preferred

    Consider: Mailfence

    Different encryption UX (PGP-oriented) versus Tuta's automatic proprietary stack

Open questions for due diligence

mailbox (formerly mailbox.org)

  • What is the exact current BSI C5 scope, type, and validity period on the attestation document?
  • Which payment processors and any other subprocessors appear in the live AVV annex?
  • What is the default Meet encryption mode (TLS-only vs optional E2EE) for your plan, and is recording available?
  • Which SSO/IdP integrations are supported for your business tier beyond generic SSO mentions?

Tuta

  • Will Tutao provide a current signed AVV/DPA with a full subprocessor list (DNS, billing, support, CDN if any)?
  • Is there a current organizational ISO 27001 or SOC 2 report for Tutao GmbH, or only facility-level data-center certification?
  • What is the documented status of TutaCrypt key rotation for all legacy accounts in your tenant?
  • Are any US-group cloud services used for backups, DNS, or support tooling beyond payment processors named in the privacy statement?
  • For business rollout: migration tooling limits (EML/MBOX import on desktop) and dual-running period with legacy IMAP hosts?