Posteo vs Soverin

Compare Posteo and Soverin on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Posteo

Posteo

Germany· Email Services

Needs review

Shortlist when you want a paid German mailbox on self-operated servers, open protocols (IMAP/CalDAV), and extreme data minimisation (no inventory data, unlinked payments). Skip when you need custom domains, default E2EE without setup, multi-seat enterprise admin, or an Art. 28 DPA—consider Proton Mail, Tuta, mailbox.org, or Mailfence instead.

Self-operated DE serversData-minimising signupIMAP / CalDAV / CardDAVBSI TR-03108 (verified)Optional crypto mail storageAd-free, user-funded
Logo: Soverin

Soverin

Netherlands· Email Services

Needs review

Shortlist Soverin when you want Dutch-operated, paid IMAP email with custom domains, unlimited aliases, and strong mail-auth standards without Google/Microsoft ads. Skip when you need zero-knowledge E2EE—consider Proton Mail or Tuta instead—or a full productivity suite (mailbox.org / Microsoft 365).

NL / EU operatedCustom domainsIMAP / CalDAVNo ads / no trackingISO 27001 (claimed)DANE / DNSSEC
Posteo vs Soverin: Snapshot
FeatureLogo: PosteoPosteoLogo: SoverinSoverin
Country of originGermanyNetherlands
CategoryEmail ServicesEmail Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersGermanyNetherlands
Legal entityPosteo e.K., Methfesselstr. 38, 10965 BerlinSoverin B.V. (Amsterdam); owned by The Sharing Group / TSG Online (Dutch) as of September 2025 acquisition announcement
Governing lawGerman / EU law (GDPR, BDSG, telecom secrecy / TTDSG as applicable)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencySelf-operated infrastructure; stored mail and backups in Germany (Frankfurt, Bielefeld, Berlin DCs per privacy materials). No AWS/GCP/Azure listed for mailbox hosting. Payment top-ups may use PayPal/card networks (unlinked from accounts per Posteo).Vendor: EU-only processing; data in NL; self-operated Dutch DCs, no hyperscaler. TechRadar: 3 NL DCs. Core mail hosts on Soverin B.V. AS211993. External first-line support partner under DPA/NDA (country unpublished). HIBP k-anon password checks; Let’s Encrypt; domain DNSSEC partner. No AWS/GCP/Azure as primary mailbox hosts in public materials.
Summary

Independent Berlin email provider with self-operated German servers, data-minimising signup, open-standard clients, and layered optional encryption—not a free-tier ad network.

Dutch privacy-first email hosting: custom domains, open IMAP/SMTP/CalDAV, 25 GB mailboxes, no ads or content scanning, servers operated in the Netherlands.

Tags
At a glance: Posteo vs Soverin
At a glanceLogo: PosteoPosteoLogo: SoverinSoverin
HQBerlin, GermanyAmsterdam, Netherlands (Soverin B.V.)
Legal entityPosteo e.K. (HRA 47592 B)Not listed
HostingSelf-operated servers in GermanyDutch data centres; vendor claims self-operated, no hyperscaler
Commercial modelPrepaid paid service; no free tierAnnual prepaid; 30-day mailbox money-back; no free tier
ProtocolsIMAP, POP3, SMTP, CalDAV, CardDAVIMAP, SMTP, CalDAV, CardDAV
Self-hostNo (hosted service)Not listed
Founded2009Not listed
Energy100% green energy (Green Planet Energy, claimed)Not listed
GroupNot listedThe Sharing Group / TSG Online (acq. Sep 2025)
StorageNot listed25 GB per mailbox (vendor-stated)
Self-host / OSSNot listedNo / No
Key capabilities: Posteo vs Soverin
Key capabilitiesLogo: PosteoPosteoLogo: SoverinSoverin
Self-operated DE serversYesNot listed
Data-minimising signupYesNot listed
IMAP / CalDAV / CardDAVYesNot listed
BSI TR-03108 (verified)YesNot listed
Optional crypto mail storageYesNot listed
Ad-free, user-fundedYesNot listed
NL / EU operatedNot listedYes
Custom domainsNot listedYes
IMAP / CalDAVNot listedYes
No ads / no trackingNot listedYes
ISO 27001 (claimed)Not listedYes
DANE / DNSSECNot listedYes

Posteo

  • Signup without identity data; payments unlinked

    Accounts can be created without name, address, or phone. Posteo's payment system (bank transfer codes, cash, card, PayPal) is designed so payment identifiers are not stored against the mailbox. Practical limit: recovery options you add yourself and how you fund the prepaid balance still affect anonymity in the real world.

  • Optional crypto mail storage for the whole mailbox

    One setting encrypts stored messages—including metadata—with a key protected by the account password (RSA/AES/HMAC/bcrypt design; Dovecot plugin). Posteo states it cannot disable crypto storage once enabled and cites a Cure53 review. Limit: this is server-side encryption at rest after delivery, not sender-to-recipient E2EE, and losing the password can mean losing access to encrypted data.

  • TLS, DANE, and BSI-certified secure transport

    Access is TLS-only with PFS, HSTS, and DANE/TLSA. Optional TLS-sending/receiving guarantees refuse delivery over cleartext peer links. Posteo holds BSI TR-03108 v2 Secure Email Transport certification (BSI-K-TR-0745-2025). Transport quality still depends on the remote provider's stack.

  • CalDAV/CardDAV with optional password encryption

    Calendars and contacts sync via open standards and can be AES-encrypted in Posteo's database so the provider cannot read them when the feature is on. Trade-off: encrypted calendars cannot be shared the same way, and password reset without the old secret can lock you out of encrypted PIM data.

  • In-house migration without third-party movers

    Posteo's own migration tool pulls mail (and often contacts/calendars) over encrypted links from previous providers without routing through a third-party migration SaaS. Quota: a limited number of migrations per account, with an optional collector for ongoing fetch from the old box.

Soverin

  • Custom domains with unlimited aliases

    Host mail on your own domain (bring existing or register through Soverin). Unlimited aliases—plus-addressing or domain names—deliver into one mailbox, plus optional random @sinenomine.email private aliases that hide the real address. Suits freelancers and SMEs who need brandable addresses without per-alias fees.

  • Open IMAP/SMTP plus CalDAV/CardDAV

    Use any standards-based client or device for mail, calendar, and contacts—no proprietary app required. Dashboard import helps migrate from other providers. Ideal when IT wants Thunderbird, Apple Mail, or Outlook without locking into a closed webmail ecosystem; not a zero-knowledge E2EE product by default.

  • Mail-path security: DANE, DKIM, DMARC, IP stripping

    Outbound and inbound paths use TLS; Soverin publishes and honours DANE/TLSA, signs with DKIM, publishes SPF/DMARC, enables DNSSEC on managed domains, and strips personal IP addresses from outbound headers. 2FA is available and can be admin-mandated. Buyers still need their own OpenPGP setup for end-to-end content secrecy with external parties.

  • 25 GB mailboxes with per-user encrypted backups

    Each mailbox includes a stated 25 GB quota covering mail, calendar, and contacts. Nightly backups use individually generated keys; Soverin states that emptying trash permanently deletes data and that leaving the service removes backups when the key is destroyed. Extra mailboxes can share storage for small teams.

  • Multi-mailbox and channel-friendly business use

    Purchase and assign additional mailboxes on a domain, with admin tooling for teams. Soverin markets to hosters, ISPs, MSPs, and independent professionals for multi-mailbox and white-label scenarios—useful when you want Dutch-operated email without building your own mail stack.

Assurance & compliance: Posteo vs Soverin
Assurance & complianceLogo: PosteoPosteoLogo: SoverinSoverin
Independent security / no-logs audit
Partial

BfDI on-site privacy inspection (2016) confirmed data-minimisation / no inventory IP model (public PDF). Crypto mail storage: vendor cites Cure53 multi-level audit; full public report not located. Not a continuous independent no-logs certification programme.

Not found

No public third-party no-logs or full security audit PDF located; privacy claims are first-party.

ISO 27001
Not found

No ISO 27001 claim found on primary Posteo security/privacy pages.

Vendor claimed

Vendor states independently audited ISO 27001; certificates available on request via support@soverin.net. Not re-verified against a public registry entry in this pass.

SOC 2 / SOC 3
Not found

No SOC 2/3 report advertised on primary pages.

Not found

No SOC 2/3 claim found on primary pages reviewed.

GDPR / EU data protection
Vendor claimed

German entity; privacy policy cites GDPR/BDSG/telecom secrecy; DPO published; BfDI inspection history.

Vendor claimed

NL entity; AVG-framed privacy statement; EU-only processing claimed; GDPR Proof messaging on recognitions page.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: German e.K., no known US parent, self-operated DE hosting with no public US-cloud mailbox subprocessors → indicative exposure low. Status is partial (not a clean bill): payment rails and lawful German disclosure remain. Not legal advice.

Partial

EuropeanStack assessment: low exposure path—Dutch Soverin B.V., Dutch The Sharing Group owner, claimed self-operated NL hosting without public AWS/GCP/Azure mailbox hosts. Partial because residual subprocessors (support partner jurisdiction, domain partners, HIBP hash checks) need buyer confirmation. Not legal advice.

Data processing agreement (B2B)
Not found

Vendor states it is not an Art. 28 processor as a public electronic communications service and does not offer customer DPAs.

Vendor claimed

Privacy statement states it qualifies as an Article 28 AVG processing agreement; other DPAs expressly rejected. Confirm signed annex for enterprise use.

EU AI Act
Not applicable

Conventional email/PIM service; not an AI product.

Not applicable

Email hosting product; vendor emphasises no AI scanning/mining of mailbox content for ads.

BSI TR-03108 Secure Email Transport
Verified

BSI certificate BSI-K-TR-0745-2025 (OpenSource Security GmbH audit; valid through 2030 per BSI listing).

Not listed
ISO 9001 / ISO 14001Not listed
Vendor claimed

Vendor-claimed quality and environmental certifications; certificates on request.

NIS2 readinessNot listed
Vendor claimed

Vendor markets NIS2 Ready; buyer press also asserts NIS2 compliance—confirm evidence package.

NEN 7510 (healthcare NL)Not listed
Partial

Vendor states NEN 7510 certification is in progress, not completed.

Considerations & known limitations: Posteo vs Soverin
Considerations & known limitationsLogo: PosteoPosteoLogo: SoverinSoverin
No custom domains
High

Posteo will not host your own domain. Organisations needing brand continuity or provider portability via DNS must pick another host or self-host.

Not listed
Encryption is layered, not default E2EE
Medium

Without crypto mail storage, inbound encryption, or client-side PGP/S/MIME, Posteo can process mailbox content like a normal provider. Lawful intercept (TKU) and seizures remain possible under German process; transparency reports show content releases do occur under court order.

Not listed
No customer Art. 28 DPA
Medium

Procurement checklists that require a signed processor agreement will stall. Posteo argues telecom special law applies instead; validate with legal counsel for your use case.

Not listed
Password loss risk with crypto features
Medium

Crypto mail storage and encrypted calendars/contacts depend on the account password; Posteo cannot recover plaintext if that secret is lost after encryption is enabled.

Not listed
Payment processors outside pure DE mail path
Low

Optional PayPal/card top-ups involve non-German commercial processors even though Posteo says it does not link payment identity to the mailbox. Cash/bank-code paths reduce that linkage further.

Not listed
Not zero-knowledge E2EE by defaultNot listed
Medium

Unlike Proton/Tuta, Soverin is a classic IMAP host. Provider infrastructure can process content for delivery and spam filtering. Practical impact: unsuitable as a drop-in for policies that require provider-blind encryption without extra client crypto.

Unnamed external support partnerNot listed
Medium

Privacy statement discloses a first-line support partner with limited account data under DPA/NDA, but does not publish the partner name or country. Practical impact: add an open diligence item for any regulated workload.

ISO certificates not self-serve publicNot listed
Low

ISO 27001/9001/14001 are claimed with certificates via support rather than a public PDF registry link found in research. Practical impact: procurement should request current attestations before treating certs as verified.

2025 group acquisitionNot listed
Low

The Sharing Group acquisition may change subprocessors, tooling, or brand packaging over time even if continuity is promised. Practical impact: re-check DPA and hosting annex annually.

Email-centric supportNot listed
Low

Public materials emphasise human Dutch-team email support; TechRadar notes no live chat or phone. Practical impact: large orgs needing 24/7 phone SLAs may find coverage thin.

Fit

Posteo

Best fit when

  • Individuals and small teams who want German jurisdiction and open-standard clients without Google or Microsoft mail
  • Users prioritising anonymous or low-identity signup and prepaid funding without linking payments to the mailbox
  • Organisations that accept posteo.* addresses and value no ads, no tracking, and published transparency reports
  • Operators who want optional full-mailbox encryption at rest (crypto mail storage) plus PGP/S/MIME tooling
  • Buyers who need BSI-aligned secure email transport certification rather than US SOC 2 paperwork

Poor fit when

  • Anyone requiring custom domains or branded organisational addresses
  • Teams that need default zero-access E2EE for every message without enabling optional layers
  • Procurement processes that mandate a signed Art. 28 DPA, SOC 2, or ISO 27001 from the vendor
  • Large enterprises needing multi-seat admin, shared domain policies, or deep Microsoft/Google workspace integration

Consider instead when

  • When: You need default end-to-end encryption and a broader encrypted suite

    Consider: Proton Mail or Tuta

    Posteo is IMAP-first with optional crypto layers; Proton/Tuta lead with zero-access defaults.

  • When: You need custom domains or richer business mail hosting

    Consider: mailbox.org or Mailfence

    Posteo deliberately refuses own domains to avoid inventory-data obligations.

  • When: You need free-tier consumer mail tightly integrated with docs and chat

    Consider: Gmail or Outlook.com

    Trade privacy posture and EU self-operation for ecosystem convenience.

Soverin

Best fit when

  • Individuals and freelancers who want a paid European mailbox on their own domain with any standard mail client
  • SMEs needing several mailboxes, aliases, and CalDAV/CardDAV without adopting Google Workspace or Microsoft 365
  • Teams prioritising Dutch jurisdiction and claimed no-hyperscaler hosting over zero-knowledge E2EE
  • Hosters/ISPs/MSPs evaluating white-label or multi-mailbox Dutch email
  • Buyers who value DANE, DKIM/DMARC, DNSSEC, and IP-header stripping on an open-standards stack

Poor fit when

  • Organisations that require default zero-access / E2EE mail against the provider (use Proton Mail or Tuta)
  • Users seeking a free tier, anonymous cash-only signup, or purely self-hosted open-source mail servers
  • Enterprises needing SSO, eDiscovery archives, phone support SLAs, or a full office suite in one vendor
  • Workloads that depend on US-region mailbox hosting or hyperscale global PoPs

Consider instead when

  • When: You need zero-knowledge E2EE and a privacy-first mobile/web ecosystem

    Consider: Proton Mail or Tuta

    Trade open IMAP convenience for stronger default content secrecy vs the provider.

  • When: You want German-hosted paid mail with broader office-style add-ons

    Consider: mailbox.org or Posteo

    Compare storage, admin features, and payment anonymity (Posteo) against Soverin’s domain/alias model.

  • When: You need Google- or Microsoft-class collaboration and global free consumer mail

    Consider: Gmail or Microsoft 365 / Outlook.com

    Different risk and advertising model; not EU-sovereignty substitutes.

Open questions for due diligence

Posteo

  • Does your counsel accept Posteo's position that no Art. 28 DPA is required for occupational use?
  • Will posteo.de / .net / .com addresses meet your brand, deliverability, and anti-spoofing requirements without custom domains?
  • Which encryption layers (crypto mail storage, inbound PGP/S/MIME, client E2EE) will your users actually enable and support?
  • Do you need ISO 27001/SOC 2 artefacts that Posteo does not publish?
  • Is BSI TR-03108 transport certification sufficient for your sector's secure-email checklist?

Soverin

  • What is the legal name and country of the first-line support partner, and is a current subprocessor list available under NDA?
  • Can Soverin provide the latest ISO 27001/9001/14001 certificates and scope statements without delay?
  • After The Sharing Group acquisition, are any new group companies (e.g. Mijndomein, Greenhost, Leafcloud tooling) in the mailbox data path?
  • Is NEN 7510 certification complete for healthcare use cases, or still in progress?
  • Which domain registrar(s) handle customer DNSSEC, and where are registry data stored?