Mailfence vs Runbox

Compare Mailfence and Runbox on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Mailfence

Mailfence

Belgium· Email Services

Needs review

Shortlist Mailfence when you want Belgian-operated webmail with interoperable OpenPGP, digital signatures, and a light calendar/documents suite—plus optional business private-label or on-prem license. Skip when you need automatic closed E2EE without key management (consider Tuta), a large Swiss privacy ecosystem (Proton Mail), or a minimalist German mailbox (Posteo / mailbox.org).

EU-operated (Belgium)OpenPGP E2EEDigital signaturesMail + calendar + docsCustom domains (paid)B2B DPA available
Logo: Runbox

Runbox

Norway· Email Services

Needs review

Shortlist Runbox when you need Norwegian/EEA-hosted IMAP email with custom domains, ad-free subscription economics, and standard clients. Skip when you require default zero-access E2EE—consider Proton Mail or Tuta instead—or when you need a full Microsoft 365-style suite.

Norwegian email hostingIMAP / POP / SMTPCustom domains100% renewable (claimed)Runbox 7 open sourceOptional PGP / S/MIME
Mailfence vs Runbox: Snapshot
FeatureLogo: MailfenceMailfenceLogo: RunboxRunbox
Country of originBelgiumNorway
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersBelgiumNorway
Legal entityContactOffice Group sa, Avenue Franklin Roosevelt 47b, B-1050 Brussels (BE 0466.241.584)Runbox Solutions AS
Governing lawBelgian law; Brussels courts (Terms of Use)Norwegian law; Personal Data Act implementing GDPR (EEA)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary production servers described as located in Belgium under Mailfence operational control (no intermediary managing servers per security page). No public AWS/GCP/Azure subprocessor list found. Backups stored in locations separate from offices/main DC (providers not named). Payment-card processing path not fully published.Core email and account content: servers in Oslo (StackInfra) under Norwegian jurisdiction; systems management Copyleft Solutions AS (Norway). Optional third parties per privacy policy: Stripe, PayPal, Coinbase (US payments); Enom (US domains); Gandi (FR); Domeneshop (NO); JaguarPC (US default web hosting, Norway option); NodePing (US, status page). No known US parent.
Summary

Belgian secure email suite with browser-side OpenPGP encryption, digital signatures, calendar, documents, and optional custom domains under ContactOffice Group SA.

Norwegian subscription email hosting from Runbox Solutions AS: Oslo-hosted IMAP mailboxes, custom domains, CalDAV/CardDAV, and optional PGP. Ad-free; not default zero-access.

Tags
At a glance: Mailfence vs Runbox
At a glanceLogo: MailfenceMailfenceLogo: RunboxRunbox
HQ / entityBrussels — ContactOffice Group sa (BE 0466.241.584)Not listed
Product launchMailfence brand ~2013; ContactOffice lineage since 1999Not listed
CryptoOpenPGP E2EE + digital signatures; optional password-encrypted messagesNot listed
HostingVendor-operated servers in Belgium (per security page)Email: StackInfra Oslo; optional web hosting may default US
Open sourceNo (front-end OSS planned; not current)Partial (Runbox 7 web app); not self-hosted
Self-hostSaaS default; Business license for large on-prem deploymentsNot listed
Commercial modelFree tier + prepaid paid plans; Business packaging (see vendor site)Paid subscription + trial (no permanent free tier)
Independent auditNo public audit PDF foundNot listed
HQNot listedOslo, Norway
Legal entityNot listedRunbox Solutions AS (orgnr 996877027)
FoundedNot listedService since 2000; current AS form 2011
Key capabilities: Mailfence vs Runbox
Key capabilitiesLogo: MailfenceMailfenceLogo: RunboxRunbox
EU-operated (Belgium)YesNot listed
OpenPGP E2EEYesNot listed
Digital signaturesYesNot listed
Mail + calendar + docsYesNot listed
Custom domains (paid)YesNot listed
B2B DPA availableYesNot listed
Norwegian email hostingNot listedYes
IMAP / POP / SMTPNot listedYes
Custom domainsNot listedYes
100% renewable (claimed)Not listedYes
Runbox 7 open sourceNot listedYes
Optional PGP / S/MIMENot listedYes

Mailfence

  • Browser-side OpenPGP end-to-end encryption

    Encrypt outbound mail in the browser with the OpenPGP standard so intermediaries—including Mailfence when messages are properly E2EE—cannot read ciphertext. Fully interoperable with other OpenPGP tools (e.g. Thunderbird/GnuPG). Optional password-encrypted messages cover recipients who do not use PGP. Unencrypted mail still sits on servers in the normal webmail model.

  • Digital signatures and multi-key OpenPGP keystore

    Sign messages for authenticity and integrity, and manage keys in-product: generate, import, export, publish, and hold multiple key pairs without browser plug-ins. Default generated keys are 4096-bit per the threat-model page. Passphrase protection of private keys limits crypto operations if only the account password is compromised.

  • Mail, calendar, documents, and groups in one account

    Beyond inbox: shareable calendars, online document storage/editing, and contact groups for collaboration without bolting on a separate US suite. Storage and alias limits scale by plan; free accounts remain suitable only for light personal use.

  • Custom domains, aliases, and mail protocols on paid tiers

    Higher plans add custom domains with SPF/DKIM/DMARC-oriented setup, larger alias counts, and classic client access (POP, IMAP, SMTP) plus ActiveSync where listed. Entry-level free accounts focus on web/PWA/apps rather than full protocol parity—verify the live plan matrix before procurement.

  • Business admin: API, SSO, private label, optional on-prem license

    Mailfence for Business offers control-panel and XML-RPC API user provisioning, SSO and directory hooks (LDAP/AD/CAS), branding, and Belgian cloud hosting with SLA language—or a license to run on customer Linux servers for large deployments. Fit for orgs that need Belgian hosting with admin automation, not a consumer-only mailbox.

Runbox

  • Norwegian-hosted IMAP email with full-disk encryption

    Mailboxes live on servers Runbox places in a StackInfra facility in Oslo under Norwegian jurisdiction, with full-disk encryption at rest and TLS (including PFS) in transit. Access via IMAP, POP, SMTP, or Runbox 7 webmail suits teams that need standard clients rather than a proprietary-only app.

  • Custom domains, aliases, and multi-account admin

    Host mail on your own domain, manage sub-accounts from a main account, and use many aliases on Runbox domains plus unlimited aliases on customer domains. Plus-addressing and filters help separate identities without running separate mailboxes.

  • CalDAV/CardDAV plus optional PGP or S/MIME

    Integrated calendar and contacts sync over CalDAV and CardDAV with common desktop and mobile apps. End-to-end confidentiality is user-controlled via PGP or S/MIME—not zero-access by default—so operators can still index mail for search and scan for malware.

  • Ad-free, subscription-funded privacy model

    Runbox states it does not show ads, does not use third-party trackers such as Google Analytics, and only scans messages for spam/virus protection—not advertising. Revenue is subscription-based with a public trial period, aligning incentives away from data-mining free mail.

  • Runbox 7 open-source webmail on hydropowered infra

    The Runbox 7 web client is published on GitHub for inspection; the hosted server stack remains largely proprietary. Email infrastructure is advertised as 100% certified renewable electricity in Norway, with additional company offset claims—useful for sustainability procurement checklists.

Assurance & compliance: Mailfence vs Runbox
Assurance & complianceLogo: MailfenceMailfenceLogo: RunboxRunbox
Independent security / no-logs audit
Not found

No public third-party audit PDF found. Vendor mentions security specialists, bug bounty activity, and inspection openness—not a substitute for a published audit. Privacy policy documents operational metadata collection (not zero-logs).

Not found

Vendor claims minimal logging and short retention windows; no public independent audit report found

ISO 27001
Not found

No Mailfence ISO 27001 certificate claim found on primary security/GDPR/company pages.

Not found

No Runbox ISO 27001 certificate found on primary pages (power supplier ISO 14001 is environmental, not info-sec)

SOC 2 / SOC 3
Not found
Not found

No public SOC 2/3 report located

GDPR / EU data protection
Vendor claimed

Belgian controller/processor materials; dedicated GDPR page and technical/organisational measures overview. Confirm roles in your DPA.

Vendor claimed

Norwegian entity; Personal Data Act implements GDPR; appointed DPO; privacy policy documents rights and retention

US CLOUD Act exposure (indicative)
Partial

EU entity (ContactOffice Group sa), no known US parent; servers claimed self-operated in Belgium without named US hyperscaler hosts. No formal public subprocessor inventory; payment processors not named. Assessment residual: partial transparency on data path. Not legal advice.

Partial

No known US parent; core email in Norway. Medium/partial because privacy policy lists US third parties (Stripe, PayPal, Coinbase, Enom, JaguarPC web hosting default, NodePing). Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable DPA linked from the GDPR page for organisational customers.

Not found

Processor DPA with Copyleft is mentioned; no public customer-facing B2B DPA template found—ask sales/support

EU AI Act
Not applicable

Email/collaboration suite; not an AI system under typical procurement framing.

Not applicable

Email hosting product; vendor states no intrusive AI for ad profiling

Considerations & known limitations: Mailfence vs Runbox
Considerations & known limitationsLogo: MailfenceMailfenceLogo: RunboxRunbox
No public independent security audit
Medium

If vendor risk requires a published audit letter, ISO 27001, or SOC 2, treat Mailfence as incomplete until evidence is obtained offline or under NDA.

Not listed
Closed-source SaaS
Medium

Cannot independently review server code or default-self-host like some FOSS mail stacks. Business on-prem license is a commercial path, not community self-host docs.

Not listed
E2EE is opt-in OpenPGP, not automatic
Medium

Clear-text messages are operator-readable at rest. Users must encrypt/sign deliberately; training and policy matter for regulated content.

Not listed
Operational metadata retention
Low

Privacy policy lists IP, message-IDs, addresses, subjects, and related fields for operations, abuse control, and legal process—not a zero-logs design.

Not listed
Limited public subprocessor inventory
Low

Strong first-party claims of internal hosting, but no AWS-style public subprocessor table; confirm payment and support tooling in procurement.

Not listed
US CLOUD Act (indicative)
Low

No known US parent; Belgian self-operated hosting narrative. Residual unknown payment/SaaS paths. Not a legal safe harbour guarantee.

Not listed
Not default zero-access encryptionNot listed
Medium

Unlike Proton/Tuta, Runbox can access stored mail for spam/virus scanning, indexing, and lawful process. Use PGP/S/MIME when E2EE is required.

US vendors on optional product pathsNot listed
Medium

Payments (Stripe/PayPal/Coinbase), domain registrar Enom, and default JaguarPC web hosting introduce US processors. Keep web hosting in Norway and minimize US payment data if policy requires.

No public ISO 27001 / SOC 2 / independent auditNot listed
Medium

Assurance relies on vendor policy, Norwegian law, and facility claims. Regulated buyers may need NDA evidence or on-site questionnaire.

Partial open source onlyNot listed
Low

Runbox 7 webmail is open source; mail backend is proprietary SaaS—no self-host path.

Post-closure and backup retentionNot listed
Low

Privacy policy defines multi-month content retention and backup windows after closure (and longer account-info retention for bookkeeping). Request immediate deletion if policy requires faster wipe.

Fit

Mailfence

Best fit when

  • You need OpenPGP interoperability and digital signatures from a European webmail, not only proprietary E2EE
  • Belgian legal entity and self-described self-operated Belgian hosting are procurement requirements
  • Teams want mail plus calendar/documents/groups without moving to Microsoft 365 or Google Workspace
  • You need custom domains, aliases, and classic clients (IMAP/POP/ActiveSync) on paid tiers
  • Business buyers evaluating private-label, API provisioning, SSO/directory integration, or large-scale on-prem license

Poor fit when

  • Security policy requires a published independent security audit, ISO 27001, or SOC 2 from the email vendor
  • You want fully open-source server/client stacks you can fork and self-host as default
  • Every message must be automatically E2EE with no OpenPGP key UX (Tuta-style)
  • You need Microsoft-class DLP, eDiscovery, compliance archives, and deep SaaS integrations
  • Zero-logs marketing is a hard requirement (Mailfence documents operational metadata collection)

Consider instead when

  • When: You want automatic encryption for all messages with minimal key management

    Consider: Tuta

    Different crypto model; less OpenPGP interop emphasis than Mailfence.

  • When: You want a larger Swiss privacy suite brand and ecosystem apps

    Consider: Proton Mail

    Trade Belgian ContactOffice ownership and PGP-centric UX for Proton’s broader product family.

  • When: You want a lean German ad-free mailbox without suite features

    Consider: Posteo or mailbox.org

    Simpler mailbox posture; different admin/domain/crypto tradeoffs.

  • When: You need full Google/Microsoft productivity and compliance tooling

    Consider: Microsoft 365 or Google Workspace (accept US-cloud risk) or EU office suites if residency is the driver

    Mailfence is not a drop-in M365 replacement.

Runbox

Best fit when

  • Teams that want Oslo-hosted mailboxes under Runbox Solutions AS and Norwegian law, with full IMAP client freedom
  • Organizations needing custom domains, multi-account admin, and generous alias patterns without self-hosting an MTA
  • Buyers who prioritize subscription-funded, ad-free email over free ad-supported Gmail/Outlook tiers
  • Procurement that values renewable-energy data-center claims and Ethical Consumer Best Buy style ESG signals
  • Users comfortable managing optional PGP/S/MIME when message-level E2EE is needed for specific threads

Poor fit when

  • Requirements for default zero-access encryption where the provider cannot read mailbox content (prefer Proton Mail or Tuta)
  • Need for a fully self-hosted or fully open-source mail server stack
  • Heavy dependence on Microsoft 365 collaboration (Teams, SharePoint, advanced Exchange) rather than plain email hosting
  • Mandatory public ISO 27001 or SOC 2 evidence before shortlist—none found on public Runbox pages in this research pass
  • Optional product paths (default US web hosting via JaguarPC) when a strict no-US-vendor rule covers every SKU

Consider instead when

  • When: You need default end-to-end / zero-access encryption for all messages

    Consider: Proton Mail or Tuta

    Runbox uses optional PGP/S/MIME; operator can access stored mail for filtering and lawful process

  • When: You want a German privacy-oriented host with similar sustainability positioning

    Consider: Posteo

    Compare jurisdiction (DE vs NO), domain limits, and feature depth

  • When: You need Belgian email with integrated collaboration extras

    Consider: Mailfence

    Different encryption defaults and product scope

  • When: You need global free-tier convenience and suite lock-in

    Consider: Gmail or Outlook.com / Microsoft 365

    Accept US jurisdiction and ad/suite economics tradeoffs

Open questions for due diligence

Mailfence

  • Will Mailfence provide a current written subprocessor list (including payment processors and any backup locations) for a company account?
  • Is any independent security assessment available under NDA for regulated buyers?
  • For Business on-prem license: exact minimum scale, support model, update cadence, and cryptographic feature parity vs SaaS?
  • Which plan tiers currently include IMAP/POP/ActiveSync and custom-domain limits for our user count?
  • How are disaster-recovery backup sites jurisdictions documented in the signed DPA annex?

Runbox

  • Will Runbox sign a customer-facing B2B DPA listing all subprocessors for your tenant configuration?
  • Can optional web hosting and domain registration be restricted to EEA-only providers for your account?
  • Is any independent penetration test or SOC/ISO report available under NDA?
  • What is the current employee ownership share and any non-EU shareholding since the 2018 figure on the About page?
  • Confirm backup geography (privacy policy: secure servers separate from main system—are they also Norway-only?)