| Independent security / no-logs audit | ❌Not foundNo public third-party security or no-logs audit report found for RAIDBOXES Emails on primary pages. | ❌Not foundNo public third-party no-logs or full security audit PDF located; privacy claims are first-party. |
|---|
| ISO 27001 | ❌Not foundNo company-wide ISO 27001 certificate for Raidboxes GmbH found on product/security pages; AWS region ISO mentions are not RAIDBOXES certs. | ⚠️Vendor claimedVendor states independently audited ISO 27001; certificates available on request via support@soverin.net. Not re-verified against a public registry entry in this pass. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo public SOC 2/3 report located for RAIDBOXES Emails. | ❌Not foundNo SOC 2/3 claim found on primary pages reviewed. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedGerman controller (Raidboxes GmbH); product claims DE server locations and GDPR-aligned deletion; online DPA available. Confirm active mail stack vs privacy-policy mailbox.org listing. | ⚠️Vendor claimedNL entity; AVG-framed privacy statement; EU-only processing claimed; GDPR Proof messaging on recognitions page. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU/German entity, no known US parent (team.blue BE group). Medium residual exposure via US-group platform subprocessors (AWS/DigitalOcean for online offer hosting; Intercom, Chargebee, Google tooling, Mailgun, etc.). Mail content path claimed DE-only. Not legal advice. | ⚠️PartialEuropeanStack assessment: low exposure path—Dutch Soverin B.V., Dutch The Sharing Group owner, claimed self-operated NL hosting without public AWS/GCP/Azure mailbox hosts. Partial because residual subprocessors (support partner jurisdiction, domain partners, HIBP hash checks) need buyer confirmation. Not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedOnline AV/DPA flow at raidboxes.io/en/dpa/ and DocuSign TOM path documented in help centre. | ⚠️Vendor claimedPrivacy statement states it qualifies as an Article 28 AVG processing agreement; other DPAs expressly rejected. Confirm signed annex for enterprise use. |
|---|
| EU AI Act | —Not applicableDomain email hosting product, not an AI system offering. | —Not applicableEmail hosting product; vendor emphasises no AI scanning/mining of mailbox content for ads. |
|---|
| B Corp certification | ⚠️Vendor claimedRaidboxes GmbH listed as Certified B Corporation on B Lab directory; impact certification, not an information-security audit. | Not listed |
|---|
| ISO 9001 / ISO 14001 | Not listed | ⚠️Vendor claimedVendor-claimed quality and environmental certifications; certificates on request. |
|---|
| NIS2 readiness | Not listed | ⚠️Vendor claimedVendor markets NIS2 Ready; buyer press also asserts NIS2 compliance—confirm evidence package. |
|---|
| NEN 7510 (healthcare NL) | Not listed | ⚠️PartialVendor states NEN 7510 certification is in progress, not completed. |
|---|