Proton Mail vs Runbox

Compare Proton Mail and Runbox on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Proton Mail

Proton Mail

Switzerland· Email Services

Needs review

Shortlist Proton Mail when you want Swiss-jurisdiction, zero-access encrypted email with open-source clients, custom domains, Bridge for desktop mailers, and a public DPA. Skip when you need free-tier IMAP Bridge, fully self-hosted FOSS mail on your own servers, or Workspace-class collaboration depth—consider Tuta, Posteo, or Mailfence among EU peers, or stay on Google/Microsoft if suite lock-in wins.

E2EE + zero-accessSwiss-operatedBridge (IMAP/SMTP)Open-source clientsISO 27001 & SOC 2 (claimed)Public B2B DPA
Logo: Runbox

Runbox

Norway· Email Services

Needs review

Shortlist Runbox when you need Norwegian/EEA-hosted IMAP email with custom domains, ad-free subscription economics, and standard clients. Skip when you require default zero-access E2EE—consider Proton Mail or Tuta instead—or when you need a full Microsoft 365-style suite.

Norwegian email hostingIMAP / POP / SMTPCustom domains100% renewable (claimed)Runbox 7 open sourceOptional PGP / S/MIME
Proton Mail vs Runbox: Snapshot
FeatureLogo: Proton MailProton MailLogo: RunboxRunbox
Country of originSwitzerlandNorway
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersSwitzerlandNorway
Legal entityProton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland (EU representative: Proton Europe sàrl, Luxembourg)Runbox Solutions AS
Governing lawSwiss law (Terms; Geneva courts for business/non-US consumer disputes as stated in Terms)Norwegian law; Personal Data Act implementing GDPR (EEA)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyPrimary mail storage on Proton-owned servers in Switzerland (vendor security pages). Not marketed as AWS/GCP/Azure inbox hosting. Public privacy policy lists US-group processors for support and payments (Zendesk; Chargebee, Stripe, PayPal) and group support processing in North Macedonia and Taiwan; HubSpot noted for business sales inquiries.Core email and account content: servers in Oslo (StackInfra) under Norwegian jurisdiction; systems management Copyleft Solutions AS (Norway). Optional third parties per privacy policy: Stripe, PayPal, Coinbase (US payments); Enom (US domains); Gandi (FR); Domeneshop (NO); JaguarPC (US default web hosting, Norway option); NodePing (US, status page). No known US parent.
Summary

Swiss end-to-end encrypted email from Proton AG: zero-access inbox storage, open-source clients, custom domains, and Bridge for desktop IMAP clients.

Norwegian subscription email hosting from Runbox Solutions AS: Oslo-hosted IMAP mailboxes, custom domains, CalDAV/CardDAV, and optional PGP. Ad-free; not default zero-access.

Tags
At a glance: Proton Mail vs Runbox
At a glanceLogo: Proton MailProton MailLogo: RunboxRunbox
HQPlan-les-Ouates (Geneva), SwitzerlandOslo, Norway
Legal entityProton AG (CHE-354.686.492); Proton Foundation supervisionRunbox Solutions AS (orgnr 996877027)
Hosting modelProton-owned hardware in Switzerland (vendor claim)Not listed
Self-hostNo (SaaS); clients open sourceNot listed
Commercial modelFreemium + paid consumer and business seatsPaid subscription + trial (no permanent free tier)
BridgePaid plans that include MailNot listed
FoundedNot listedService since 2000; current AS form 2011
HostingNot listedEmail: StackInfra Oslo; optional web hosting may default US
Open sourceNot listedPartial (Runbox 7 web app); not self-hosted
Key capabilities: Proton Mail vs Runbox
Key capabilitiesLogo: Proton MailProton MailLogo: RunboxRunbox
E2EE + zero-accessYesNot listed
Swiss-operatedYesNot listed
Bridge (IMAP/SMTP)YesNot listed
Open-source clientsYesNot listed
ISO 27001 & SOC 2 (claimed)YesNot listed
Public B2B DPAYesNot listed
Norwegian email hostingNot listedYes
IMAP / POP / SMTPNot listedYes
Custom domainsNot listedYes
100% renewable (claimed)Not listedYes
Runbox 7 open sourceNot listedYes
Optional PGP / S/MIMENot listedYes

Proton Mail

  • Zero-access inbox encryption by default

    Bodies and attachments are encrypted so Proton states it lacks keys to read stored mail. Proton-to-Proton traffic is end-to-end encrypted automatically; external recipients need password-protected messages or PGP/WKD for comparable content protection. Subject lines are not fully E2EE under OpenPGP header rules.

  • Proton Mail Bridge for desktop IMAP clients

    Paid plans that include Mail can run Bridge locally to connect Outlook, Thunderbird, or Apple Mail over IMAP/SMTP while encrypting and decrypting on the device. Free accounts use official web/mobile/desktop apps instead of Bridge.

  • Custom domains, aliases, and business admin

    Paid and business tiers support custom domains, extra addresses, catch-all and groups, hide-my-email aliases, and org admin for seats, storage, and retention policies. Suits teams leaving Google/Microsoft who still need branded addresses.

  • Open-source clients with published audits

    Web, mobile, and desktop clients are published on GitHub with third-party audit reports linked from Proton’s open-source page. The hosted mail backend is not offered as self-hosted FOSS—audit client trust, not full server reproducibility.

  • Tracker blocking, PhishGuard, and Sentinel

    Built-in tracker protection, phishing heuristics, link confirmation, SPF/DKIM/DMARC for custom domains, hardware-key 2FA, and optional Proton Sentinel monitoring for high-risk accounts. Complements encryption with everyday abuse defenses.

Runbox

  • Norwegian-hosted IMAP email with full-disk encryption

    Mailboxes live on servers Runbox places in a StackInfra facility in Oslo under Norwegian jurisdiction, with full-disk encryption at rest and TLS (including PFS) in transit. Access via IMAP, POP, SMTP, or Runbox 7 webmail suits teams that need standard clients rather than a proprietary-only app.

  • Custom domains, aliases, and multi-account admin

    Host mail on your own domain, manage sub-accounts from a main account, and use many aliases on Runbox domains plus unlimited aliases on customer domains. Plus-addressing and filters help separate identities without running separate mailboxes.

  • CalDAV/CardDAV plus optional PGP or S/MIME

    Integrated calendar and contacts sync over CalDAV and CardDAV with common desktop and mobile apps. End-to-end confidentiality is user-controlled via PGP or S/MIME—not zero-access by default—so operators can still index mail for search and scan for malware.

  • Ad-free, subscription-funded privacy model

    Runbox states it does not show ads, does not use third-party trackers such as Google Analytics, and only scans messages for spam/virus protection—not advertising. Revenue is subscription-based with a public trial period, aligning incentives away from data-mining free mail.

  • Runbox 7 open-source webmail on hydropowered infra

    The Runbox 7 web client is published on GitHub for inspection; the hosted server stack remains largely proprietary. Email infrastructure is advertised as 100% certified renewable electricity in Norway, with additional company offset claims—useful for sustainability procurement checklists.

Assurance & compliance: Proton Mail vs Runbox
Assurance & complianceLogo: Proton MailProton MailLogo: RunboxRunbox
Independent security / client audits
Vendor claimed

Open-source clients with published third-party audit reports (web/desktop links on open-source page). Not a classic VPN no-logs court test; transparency report covers legal orders for accessible account data.

Not found

Vendor claims minimal logging and short retention windows; no public independent audit report found

ISO 27001
Vendor claimed

Vendor announces ISO 27001 certification after external audit completed 2 May 2024; Trust Center links a certificate download. Confirm scope and validity at procurement time.

Not found

No Runbox ISO 27001 certificate found on primary pages (power supplier ISO 14001 is environmental, not info-sec)

SOC 2 / SOC 3
Vendor claimed

Vendor announces first SOC 2 Type II attestation (July 2025 blog). Report typically under NDA—request from vendor for diligence files.

Not found

No public SOC 2/3 report located

GDPR / EU data protection
Vendor claimed

Swiss controller/processor with EU representative; public DPA; GDPR materials for business. Adequacy/transfer mechanisms documented for non-adequate destinations.

Vendor claimed

Norwegian entity; Personal Data Act implements GDPR; appointed DPO; privacy policy documents rights and retention

US CLOUD Act exposure (indicative)
Partial

Swiss entity / no known US parent; inbox content on Proton-owned Swiss hardware with zero-access design. Partial exposure remains via US SaaS subprocessors (Zendesk support; Stripe/Chargebee/PayPal payments) and any account metadata Proton can access under Swiss process. Not legal advice.

Partial

No known US parent; core email in Norway. Medium/partial because privacy policy lists US third parties (Stripe, PayPal, Coinbase, Enom, JaguarPC web hosting default, NodePing). Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Public DPA at proton.me/legal/dpa forms part of terms when Proton acts as processor; Swiss law, Geneva jurisdiction; general authorization for listed subprocessors.

Not found

Processor DPA with Copyleft is mentioned; no public customer-facing B2B DPA template found—ask sales/support

EU AI Act
Not applicable

Core product is encrypted email. Optional Scribe assistant is ancillary; not an AI-centric offering for this catalog entry.

Not applicable

Email hosting product; vendor states no intrusive AI for ad profiling

Considerations & known limitations: Proton Mail vs Runbox
Considerations & known limitationsLogo: Proton MailProton MailLogo: RunboxRunbox
Weaker defaults outside Proton
Medium

Mail to Gmail/Outlook/others is not E2EE unless password-protected or PGP/WKD is used. Subject lines are not fully E2EE. Train users or you only protect the Proton-stored copy.

Not listed
US support and payment processors
Medium

Zendesk, Chargebee, Stripe, and PayPal appear in the public processor list. They should not see zero-access message bodies, but support content and billing data can touch US-group services—document this in DPIAs.

Not listed
Bridge requires paid Mail
Low

Desktop IMAP/SMTP via Bridge is not available on free accounts. Budget seats for users who refuse the official apps.

Not listed
Hosted service, not self-hosted FOSS mail
Medium

Open-source clients improve inspectability but you still depend on Proton’s operated backend, uptime, and Swiss legal process. Unsuitable if policy mandates customer-operated mail servers.

Not listed
Swiss legal orders on accessible data
Low

Transparency reports show thousands of yearly legal orders for Mail with many complied. Bodies stay encrypted; recovery emails, IPs (when retained for abuse), and similar metadata may still be in scope. Align expectations with counsel.

Not listed
Not default zero-access encryptionNot listed
Medium

Unlike Proton/Tuta, Runbox can access stored mail for spam/virus scanning, indexing, and lawful process. Use PGP/S/MIME when E2EE is required.

US vendors on optional product pathsNot listed
Medium

Payments (Stripe/PayPal/Coinbase), domain registrar Enom, and default JaguarPC web hosting introduce US processors. Keep web hosting in Norway and minimize US payment data if policy requires.

No public ISO 27001 / SOC 2 / independent auditNot listed
Medium

Assurance relies on vendor policy, Norwegian law, and facility claims. Regulated buyers may need NDA evidence or on-site questionnaire.

Partial open source onlyNot listed
Low

Runbox 7 webmail is open source; mail backend is proprietary SaaS—no self-host path.

Post-closure and backup retentionNot listed
Low

Privacy policy defines multi-month content retention and backup windows after closure (and longer account-info retention for bookkeeping). Request immediate deletion if policy requires faster wipe.

Fit

Proton Mail

Best fit when

  • Teams that need default end-to-end / zero-access encryption without running their own mail stack
  • Orgs that want Swiss legal venue and documented resistance to direct foreign data demands
  • Businesses migrating branded domains off Gmail/Outlook with Easy Switch and Bridge for desktop holdouts
  • Security-conscious professionals who value open-source clients, published audits, and hardware-key 2FA
  • Buyers who need a public DPA plus vendor-claimed ISO 27001 / SOC 2 Type II for questionnaires

Poor fit when

  • Fully self-hosted requirements (Proton Mail is SaaS; clients are open source, not a full on-prem mail server)
  • Desktop IMAP on free accounts only—Bridge needs a paid plan that includes Mail
  • Workflows that depend on unencrypted-looking mail to external parties who will not use password links or PGP
  • Teams that primarily need full Microsoft 365 / Google Workspace collaboration depth rather than encrypted mail first

Consider instead when

  • When: You want German E2EE email with a different crypto product surface and may not need Proton’s full ecosystem

    Consider: Tuta

    Compare desktop interoperability and business admin maturity side by side.

  • When: You want ad-free European mail with strong transport privacy but do not require zero-access E2EE for all stored content

    Consider: Posteo

    Different threat model: Posteo is privacy-forward without Proton’s zero-access default.

  • When: You need OpenPGP-centric mail with classic collaboration extras under Belgian operation

    Consider: Mailfence

    Weigh automatic Proton-to-Proton E2EE UX versus Mailfence’s model.

  • When: Collaboration suite depth and ecosystem lock-in outweigh encryption defaults

    Consider: Google Workspace or Microsoft 365

    Accept US-provider jurisdiction and scanning/processing models as tradeoffs.

Runbox

Best fit when

  • Teams that want Oslo-hosted mailboxes under Runbox Solutions AS and Norwegian law, with full IMAP client freedom
  • Organizations needing custom domains, multi-account admin, and generous alias patterns without self-hosting an MTA
  • Buyers who prioritize subscription-funded, ad-free email over free ad-supported Gmail/Outlook tiers
  • Procurement that values renewable-energy data-center claims and Ethical Consumer Best Buy style ESG signals
  • Users comfortable managing optional PGP/S/MIME when message-level E2EE is needed for specific threads

Poor fit when

  • Requirements for default zero-access encryption where the provider cannot read mailbox content (prefer Proton Mail or Tuta)
  • Need for a fully self-hosted or fully open-source mail server stack
  • Heavy dependence on Microsoft 365 collaboration (Teams, SharePoint, advanced Exchange) rather than plain email hosting
  • Mandatory public ISO 27001 or SOC 2 evidence before shortlist—none found on public Runbox pages in this research pass
  • Optional product paths (default US web hosting via JaguarPC) when a strict no-US-vendor rule covers every SKU

Consider instead when

  • When: You need default end-to-end / zero-access encryption for all messages

    Consider: Proton Mail or Tuta

    Runbox uses optional PGP/S/MIME; operator can access stored mail for filtering and lawful process

  • When: You want a German privacy-oriented host with similar sustainability positioning

    Consider: Posteo

    Compare jurisdiction (DE vs NO), domain limits, and feature depth

  • When: You need Belgian email with integrated collaboration extras

    Consider: Mailfence

    Different encryption defaults and product scope

  • When: You need global free-tier convenience and suite lock-in

    Consider: Gmail or Outlook.com / Microsoft 365

    Accept US jurisdiction and ad/suite economics tradeoffs

Open questions for due diligence

Proton Mail

  • What exact data-center sites and any non-Swiss regions apply to your tenant’s mailbox replicas today?
  • Will Proton provide the full SOC 2 Type II report under NDA and confirm ISO 27001 certificate scope/expiry for your questionnaire?
  • For business orgs: which users will be private vs non-private, and how will admin recovery work with zero-access constraints?
  • Which external partners must receive E2EE content, and will they accept password-protected messages or PGP?

Runbox

  • Will Runbox sign a customer-facing B2B DPA listing all subprocessors for your tenant configuration?
  • Can optional web hosting and domain registration be restricted to EEA-only providers for your account?
  • Is any independent penetration test or SOC/ISO report available under NDA?
  • What is the current employee ownership share and any non-EU shareholding since the 2018 figure on the About page?
  • Confirm backup geography (privacy policy: secure servers separate from main system—are they also Norway-only?)