Posteo vs Runbox

Compare Posteo and Runbox on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Logo: Runbox

Runbox

Norway· Email Services

Needs review

Shortlist Runbox when you need Norwegian/EEA-hosted IMAP email with custom domains, ad-free subscription economics, and standard clients. Skip when you require default zero-access E2EE—consider Proton Mail or Tuta instead—or when you need a full Microsoft 365-style suite.

Norwegian email hostingIMAP / POP / SMTPCustom domains100% renewable (claimed)Runbox 7 open sourceOptional PGP / S/MIME
Posteo vs Runbox: Snapshot
FeatureLogo: PosteoPosteoLogo: RunboxRunbox
Country of originGermanyNorway
CategoryEmail ServicesEmail Services
Open sourceYesYes
Self-hostedNoNo
HeadquartersGermanyNorway
Legal entityPosteo e.K., Methfesselstr. 38, 10965 BerlinRunbox Solutions AS
Governing lawGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)Norwegian law; Personal Data Act implementing GDPR (EEA)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencySelf-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).Core email and account content: servers in Oslo (StackInfra) under Norwegian jurisdiction; systems management Copyleft Solutions AS (Norway). Optional third parties per privacy policy: Stripe, PayPal, Coinbase (US payments); Enom (US domains); Gandi (FR); Domeneshop (NO); JaguarPC (US default web hosting, Norway option); NodePing (US, status page). No known US parent.
Summary

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Norwegian subscription email hosting from Runbox Solutions AS: Oslo-hosted IMAP mailboxes, custom domains, CalDAV/CardDAV, and optional PGP. Ad-free; not default zero-access.

Tags
At a glance: Posteo vs Runbox
At a glanceLogo: PosteoPosteoLogo: RunboxRunbox
HQBerlin, GermanyOslo, Norway
Legal entityPosteo e.K. (HRA 47592 B)Runbox Solutions AS (orgnr 996877027)
HostingSelf-operated servers in GermanyEmail: StackInfra Oslo; optional web hosting may default US
Commercial modelPrepaid paid service; no free tierPaid subscription + trial (no permanent free tier)
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVNot listed
Self-hostNo (hosted service)Not listed
Founded2009Service since 2000; current AS form 2011
Energy100% green energy (Green Planet Energy, claimed)Not listed
Open sourceNot listedPartial (Runbox 7 web app); not self-hosted
Key capabilities: Posteo vs Runbox
Key capabilitiesLogo: PosteoPosteoLogo: RunboxRunbox
Self-operated DE serversYesNot listed
Data-minimising signupYesNot listed
IMAP / CalDAV / CardDAVYesNot listed
BSI TR-03108 (verified)YesNot listed
Optional crypto mail storageYesNot listed
Ad-free, user-fundedYesNot listed
Norwegian email hostingNot listedYes
IMAP / POP / SMTPNot listedYes
Custom domainsNot listedYes
100% renewable (claimed)Not listedYes
Runbox 7 open sourceNot listedYes
Optional PGP / S/MIMENot listedYes

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Runbox

  • Norwegian-hosted IMAP email with full-disk encryption

    Mailboxes live on servers Runbox places in a StackInfra facility in Oslo under Norwegian jurisdiction, with full-disk encryption at rest and TLS (including PFS) in transit. Access via IMAP, POP, SMTP, or Runbox 7 webmail suits teams that need standard clients rather than a proprietary-only app.

  • Custom domains, aliases, and multi-account admin

    Host mail on your own domain, manage sub-accounts from a main account, and use many aliases on Runbox domains plus unlimited aliases on customer domains. Plus-addressing and filters help separate identities without running separate mailboxes.

  • CalDAV/CardDAV plus optional PGP or S/MIME

    Integrated calendar and contacts sync over CalDAV and CardDAV with common desktop and mobile apps. End-to-end confidentiality is user-controlled via PGP or S/MIME—not zero-access by default—so operators can still index mail for search and scan for malware.

  • Ad-free, subscription-funded privacy model

    Runbox states it does not show ads, does not use third-party trackers such as Google Analytics, and only scans messages for spam/virus protection—not advertising. Revenue is subscription-based with a public trial period, aligning incentives away from data-mining free mail.

  • Runbox 7 open-source webmail on hydropowered infra

    The Runbox 7 web client is published on GitHub for inspection; the hosted server stack remains largely proprietary. Email infrastructure is advertised as 100% certified renewable electricity in Norway, with additional company offset claims—useful for sustainability procurement checklists.

Assurance & compliance: Posteo vs Runbox
Assurance & complianceLogo: PosteoPosteoLogo: RunboxRunbox
Independent security / no-logs audit
Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

Not found

Vendor claims minimal logging and short retention windows; no public independent audit report found

ISO 27001
Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

Not found

No Runbox ISO 27001 certificate found on primary pages (power supplier ISO 14001 is environmental, not info-sec)

SOC 2 / SOC 3
Not found

No SOC 2/3 report advertised on primary pages.

Not found

No public SOC 2/3 report located

GDPR / EU data protection
Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

Vendor claimed

Norwegian entity; Personal Data Act implements GDPR; appointed DPO; privacy policy documents rights and retention

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Partial

No known US parent; core email in Norway. Medium/partial because privacy policy lists US third parties (Stripe, PayPal, Coinbase, Enom, JaguarPC web hosting default, NodePing). Not legal advice.

Data processing agreement (B2B)
Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

Not found

Processor DPA with Copyleft is mentioned; no public customer-facing B2B DPA template found—ask sales/support

EU AI Act
Not applicable

Conventional email/PIM service; not an AI product.

Not applicable

Email hosting product; vendor states no intrusive AI for ad profiling

BSI TR-03108 Secure Email Transport
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Not listed
Considerations & known limitations: Posteo vs Runbox
Considerations & known limitationsLogo: PosteoPosteoLogo: RunboxRunbox
No custom domains
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Not listed
Encryption is layered, not default E2EE
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

Not listed
No customer Art. 28 DPA
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Not listed
Password loss risk with crypto features
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Not listed
Payment processors outside pure DE mail path
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Not listed
Not default zero-access encryptionNot listed
Medium

Unlike Proton/Tuta, Runbox can access stored mail for spam/virus scanning, indexing, and lawful process. Use PGP/S/MIME when E2EE is required.

US vendors on optional product pathsNot listed
Medium

Payments (Stripe/PayPal/Coinbase), domain registrar Enom, and default JaguarPC web hosting introduce US processors. Keep web hosting in Norway and minimize US payment data if policy requires.

No public ISO 27001 / SOC 2 / independent auditNot listed
Medium

Assurance relies on vendor policy, Norwegian law, and facility claims. Regulated buyers may need NDA evidence or on-site questionnaire.

Partial open source onlyNot listed
Low

Runbox 7 webmail is open source; mail backend is proprietary SaaS—no self-host path.

Post-closure and backup retentionNot listed
Low

Privacy policy defines multi-month content retention and backup windows after closure (and longer account-info retention for bookkeeping). Request immediate deletion if policy requires faster wipe.

Fit

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Runbox

Best fit when

  • Teams that want Oslo-hosted mailboxes under Runbox Solutions AS and Norwegian law, with full IMAP client freedom
  • Organizations needing custom domains, multi-account admin, and generous alias patterns without self-hosting an MTA
  • Buyers who prioritize subscription-funded, ad-free email over free ad-supported Gmail/Outlook tiers
  • Procurement that values renewable-energy data-center claims and Ethical Consumer Best Buy style ESG signals
  • Users comfortable managing optional PGP/S/MIME when message-level E2EE is needed for specific threads

Poor fit when

  • Requirements for default zero-access encryption where the provider cannot read mailbox content (prefer Proton Mail or Tuta)
  • Need for a fully self-hosted or fully open-source mail server stack
  • Heavy dependence on Microsoft 365 collaboration (Teams, SharePoint, advanced Exchange) rather than plain email hosting
  • Mandatory public ISO 27001 or SOC 2 evidence before shortlist—none found on public Runbox pages in this research pass
  • Optional product paths (default US web hosting via JaguarPC) when a strict no-US-vendor rule covers every SKU

Consider instead when

  • When: You need default end-to-end / zero-access encryption for all messages

    Consider: Proton Mail or Tuta

    Runbox uses optional PGP/S/MIME; operator can access stored mail for filtering and lawful process

  • When: You want a German privacy-oriented host with similar sustainability positioning

    Consider: Posteo

    Compare jurisdiction (DE vs NO), domain limits, and feature depth

  • When: You need Belgian email with integrated collaboration extras

    Consider: Mailfence

    Different encryption defaults and product scope

  • When: You need global free-tier convenience and suite lock-in

    Consider: Gmail or Outlook.com / Microsoft 365

    Accept US jurisdiction and ad/suite economics tradeoffs

Open questions for due diligence

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?

Runbox

  • Will Runbox sign a customer-facing B2B DPA listing all subprocessors for your tenant configuration?
  • Can optional web hosting and domain registration be restricted to EEA-only providers for your account?
  • Is any independent penetration test or SOC/ISO report available under NDA?
  • What is the current employee ownership share and any non-EU shareholding since the 2018 figure on the About page?
  • Confirm backup geography (privacy policy: secure servers separate from main system—are they also Norway-only?)