Runbox vs Tuta

Compare Runbox and Tuta on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Outlook.com

Logo: Runbox

Runbox

Norway· Email Services

Needs review

Shortlist Runbox when you need Norwegian/EEA-hosted IMAP email with custom domains, ad-free subscription economics, and standard clients. Skip when you require default zero-access E2EE—consider Proton Mail or Tuta instead—or when you need a full Microsoft 365-style suite.

Norwegian email hostingIMAP / POP / SMTPCustom domains100% renewable (claimed)Runbox 7 open sourceOptional PGP / S/MIME
Logo: Tuta

Tuta

Germany· Email Services

Needs review

Shortlist when you need default end-to-end encrypted mail, calendar, and contacts under German law with post-quantum TutaCrypt and official multi-platform apps. Skip when teams must keep Outlook/Thunderbird via IMAP or need a full M365/Workspace suite—consider Proton Mail (Bridge) or mailbox.org instead.

Default mailbox E2EETutaCrypt post-quantumEU-operated (Germany)Open-source clientsDE data centers (claimed)No IMAP (by design)
Runbox vs Tuta: Snapshot
FeatureLogo: RunboxRunboxLogo: TutaTuta
Country of originNorwayGermany
CategoryEmail ServicesEmail Services
Open sourceYesYes
Self-hostedNoNo
HeadquartersNorwayGermany
Legal entityRunbox Solutions ASTutao GmbH (HRB 208014, Hanover)
Governing lawNorwegian law; Personal Data Act implementing GDPR (EEA)German law / GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyCore email and account content: servers in Oslo (StackInfra) under Norwegian jurisdiction; systems management Copyleft Solutions AS (Norway). Optional third parties per privacy policy: Stripe, PayPal, Coinbase (US payments); Enom (US domains); Gandi (FR); Domeneshop (NO); JaguarPC (US default web hosting, Norway option); NodePing (US, status page). No known US parent.Vendor states mailbox data is stored end-to-end encrypted on Tutao-operated servers in ISO 27001-certified data centers in Germany. No AWS/GCP/Azure primary hosting named on official security/privacy pages. Privacy statement discloses payment processing via PayPal (Europe) and banks for card/SEPA; no comprehensive public subprocessor list found for ops tools.
Summary

Norwegian subscription email hosting from Runbox Solutions AS: Oslo-hosted IMAP mailboxes, custom domains, CalDAV/CardDAV, and optional PGP. Ad-free; not default zero-access.

German end-to-end encrypted email, calendar, and contacts from Tutao GmbH in Hanover—with post-quantum TutaCrypt, open-source clients, and freemium personal plus business plans.

Tags
At a glance: Runbox vs Tuta
At a glanceLogo: RunboxRunboxLogo: TutaTuta
HQOslo, NorwayHanover, Germany (Tutao GmbH)
Legal entityRunbox Solutions AS (orgnr 996877027)Not listed
FoundedService since 2000; current AS form 2011Not listed
HostingEmail: StackInfra Oslo; optional web hosting may default USOwn servers in ISO 27001 data centers in Germany (vendor claim)
Open sourcePartial (Runbox 7 web app); not self-hostedClients GPLv3 on GitHub; no productized self-host
Commercial modelPaid subscription + trial (no permanent free tier)Freemium personal + paid personal/business (no ads)
ProductNot listedEncrypted email, calendar, contacts (SaaS)
ProtocolsNot listedNo IMAP/SMTP client access; official apps only
CryptoNot listedTutaCrypt hybrid (Kyber-1024 + X25519 + AES-256) for new accounts
Key capabilities: Runbox vs Tuta
Key capabilitiesLogo: RunboxRunboxLogo: TutaTuta
Norwegian email hostingYesNot listed
IMAP / POP / SMTPYesNot listed
Custom domainsYesNot listed
100% renewable (claimed)YesNot listed
Runbox 7 open sourceYesNot listed
Optional PGP / S/MIMEYesNot listed
Default mailbox E2EENot listedYes
TutaCrypt post-quantumNot listedYes
EU-operated (Germany)Not listedYes
Open-source clientsNot listedYes
DE data centers (claimed)Not listedYes
No IMAP (by design)Not listedYes

Runbox

  • Norwegian-hosted IMAP email with full-disk encryption

    Mailboxes live on servers Runbox places in a StackInfra facility in Oslo under Norwegian jurisdiction, with full-disk encryption at rest and TLS (including PFS) in transit. Access via IMAP, POP, SMTP, or Runbox 7 webmail suits teams that need standard clients rather than a proprietary-only app.

  • Custom domains, aliases, and multi-account admin

    Host mail on your own domain, manage sub-accounts from a main account, and use many aliases on Runbox domains plus unlimited aliases on customer domains. Plus-addressing and filters help separate identities without running separate mailboxes.

  • CalDAV/CardDAV plus optional PGP or S/MIME

    Integrated calendar and contacts sync over CalDAV and CardDAV with common desktop and mobile apps. End-to-end confidentiality is user-controlled via PGP or S/MIME—not zero-access by default—so operators can still index mail for search and scan for malware.

  • Ad-free, subscription-funded privacy model

    Runbox states it does not show ads, does not use third-party trackers such as Google Analytics, and only scans messages for spam/virus protection—not advertising. Revenue is subscription-based with a public trial period, aligning incentives away from data-mining free mail.

  • Runbox 7 open-source webmail on hydropowered infra

    The Runbox 7 web client is published on GitHub for inspection; the hosted server stack remains largely proprietary. Email infrastructure is advertised as 100% certified renewable electricity in Norway, with additional company offset claims—useful for sustainability procurement checklists.

Tuta

  • Default E2EE for mail, subjects, and attachments

    Between Tuta users, messages encrypt automatically including subject lines, bodies, and attachments. External recipients can use a shared password for end-to-end threads without installing software. Contacts and calendars use the same zero-access model; only delivery metadata (addresses, timestamps) stays readable by design.

  • TutaCrypt post-quantum hybrid cryptography

    New accounts use TutaCrypt: Kyber-1024 KEM plus X25519 ECDH with AES-256, targeting harvest-now-decrypt-later risks. Protocol details are published; existing accounts migrate as key rotation rolls out. Tuta intentionally avoids PGP so subjects and non-mail features can stay encrypted and algorithms can be upgraded in-product.

  • Zero-knowledge calendar with private reminders

    Calendar events—including times, titles, locations, and attendees—are end-to-end encrypted. Reminders are pushed as encrypted payloads and fired locally so servers are not told when an event starts. Sharing stays encrypted; invites can go out via mail, optionally password-protected for externals.

  • Open-source multi-platform clients (no IMAP)

    Web, Android (Play and F-Droid), iOS, Windows, macOS, and Linux clients are published under GPLv3 on GitHub. Desktop builds are signed for verification. There is no IMAP/SMTP bridge: third-party mail apps cannot connect, which preserves encryption at rest but forces a client switch for Outlook/Thunderbird holdouts.

  • Business domains, admin console, and whitelabel

    Paid business plans add custom domains, aliases, shared mailboxes, multi-admin roles, password/2FA resets, catch-all, templates, and optional branding/login on your own site. Vendor-stated uptime SLA and a GDPR order-processing agreement support B2B procurement—confirm current plan matrix on tuta.com.

Assurance & compliance: Runbox vs Tuta
Assurance & complianceLogo: RunboxRunboxLogo: TutaTuta
Independent security / no-logs audit
Not found

Vendor claims minimal logging and short retention windows; no public independent audit report found

Vendor claimed

Vendor states SySS GmbH penetration testing before public release; not a continuously published annual no-logs audit PDF on the marketing site.

ISO 27001
Not found

No Runbox ISO 27001 certificate found on primary pages (power supplier ISO 14001 is environmental, not info-sec)

Partial

Official pages claim data centers are ISO 27001 certified; does not clearly establish a public Tutao GmbH organizational ISO 27001 certificate.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report located

Not found

No SOC 2/3 report located on security, business, or privacy pages.

GDPR / EU data protection
Vendor claimed

Norwegian entity; Personal Data Act implements GDPR; appointed DPO; privacy policy documents rights and retention

Vendor claimed

German controller Tutao GmbH; privacy statement cites GDPR; DPO published; DE storage claimed.

US CLOUD Act exposure (indicative)
Partial

No known US parent; core email in Norway. Medium/partial because privacy policy lists US third parties (Stripe, PayPal, Coinbase, Enom, JaguarPC web hosting default, NodePing). Not legal advice.

Partial

EU entity, no known US parent, primary mailbox hosting claimed as own DE servers—not AWS/GCP/Azure. Payment may use PayPal (Europe). Assessment is low exposure for content with residual billing/processor unknowns; not a vendor 'safe' claim. Not legal advice.

Data processing agreement (B2B)
Not found

Processor DPA with Copyleft is mentioned; no public customer-facing B2B DPA template found—ask sales/support

Vendor claimed

Security/business materials state an Order Processing Agreement (Auftragsverarbeitung) is provided for GDPR; obtain signed version via sales—no public self-serve DPA URL confirmed.

EU AI Act
Not applicable

Email hosting product; vendor states no intrusive AI for ad profiling

Not applicable

Encrypted email/calendar product; vendor states it does not plan AI that processes user communications for model training.

Considerations & known limitations: Runbox vs Tuta
Considerations & known limitationsLogo: RunboxRunboxLogo: TutaTuta
Not default zero-access encryption
Medium

Unlike Proton/Tuta, Runbox can access stored mail for spam/virus scanning, indexing, and lawful process. Use PGP/S/MIME when E2EE is required.

Not listed
US vendors on optional product paths
Medium

Payments (Stripe/PayPal/Coinbase), domain registrar Enom, and default JaguarPC web hosting introduce US processors. Keep web hosting in Norway and minimize US payment data if policy requires.

Not listed
No public ISO 27001 / SOC 2 / independent audit
Medium

Assurance relies on vendor policy, Norwegian law, and facility claims. Regulated buyers may need NDA evidence or on-site questionnaire.

Not listed
Partial open source only
Low

Runbox 7 webmail is open source; mail backend is proprietary SaaS—no self-host path.

Not listed
Post-closure and backup retention
Low

Privacy policy defines multi-month content retention and backup windows after closure (and longer account-info retention for bookkeeping). Request immediate deletion if policy requires faster wipe.

Not listed
No IMAP/SMTP third-party clientsNot listed
High

Desktop and mobile holdouts cannot stay on Outlook/Thunderbird/Apple Mail. Plan full client migration or pick a standards-based alternative.

Weaker protection to non-Tuta recipientsNot listed
Medium

Without a shared password, external mail is ordinary SMTP (TLS in transit). Only Tuta-to-Tuta and password-protected external threads are true E2EE.

Hosted service, not on-prem mailNot listed
Medium

Open-source clients help inspectability, but mailboxes still depend on Tutao's German SaaS backend, uptime, and German legal process.

Data-center ISO vs company ISMSNot listed
Low

ISO 27001 wording refers to data centers. Do not tick 'vendor ISO 27001 certified' on questionnaires without the actual Tutao certificate.

Limited public subprocessor inventoryNot listed
Medium

Privacy policy covers payments (e.g. PayPal Europe) but lacks a detailed live subprocessor register. Request the DPA annex for DPIA completeness.

German court orders on accessible dataNot listed
Low

Transparency reports show regular German requests. Stored E2EE content stays undecryptable by Tutao; real-time monitoring can expose newly arriving unencrypted SMTP mail. Align expectations with counsel.

Fit

Runbox

Best fit when

  • Teams that want Oslo-hosted mailboxes under Runbox Solutions AS and Norwegian law, with full IMAP client freedom
  • Organizations needing custom domains, multi-account admin, and generous alias patterns without self-hosting an MTA
  • Buyers who prioritize subscription-funded, ad-free email over free ad-supported Gmail/Outlook tiers
  • Procurement that values renewable-energy data-center claims and Ethical Consumer Best Buy style ESG signals
  • Users comfortable managing optional PGP/S/MIME when message-level E2EE is needed for specific threads

Poor fit when

  • Requirements for default zero-access encryption where the provider cannot read mailbox content (prefer Proton Mail or Tuta)
  • Need for a fully self-hosted or fully open-source mail server stack
  • Heavy dependence on Microsoft 365 collaboration (Teams, SharePoint, advanced Exchange) rather than plain email hosting
  • Mandatory public ISO 27001 or SOC 2 evidence before shortlist—none found on public Runbox pages in this research pass
  • Optional product paths (default US web hosting via JaguarPC) when a strict no-US-vendor rule covers every SKU

Consider instead when

  • When: You need default end-to-end / zero-access encryption for all messages

    Consider: Proton Mail or Tuta

    Runbox uses optional PGP/S/MIME; operator can access stored mail for filtering and lawful process

  • When: You want a German privacy-oriented host with similar sustainability positioning

    Consider: Posteo

    Compare jurisdiction (DE vs NO), domain limits, and feature depth

  • When: You need Belgian email with integrated collaboration extras

    Consider: Mailfence

    Different encryption defaults and product scope

  • When: You need global free-tier convenience and suite lock-in

    Consider: Gmail or Outlook.com / Microsoft 365

    Accept US jurisdiction and ad/suite economics tradeoffs

Tuta

Best fit when

  • Teams that will standardize on Tuta's official web/mobile/desktop clients for default zero-access email
  • Orgs prioritizing subject-line encryption, encrypted calendar, and post-quantum hybrid crypto under German jurisdiction
  • SMEs needing custom domains, aliases, shared mailboxes, and multi-admin controls without running their own mail servers
  • Journalists, NGOs, and privacy-led departments that value F-Droid builds, no Google Push dependency, and ad-free operation
  • Buyers who want open-source client auditability plus a freemium path for personal trial before business seats

Poor fit when

  • Hard requirement for IMAP/SMTP in Outlook, Thunderbird, Apple Mail, or third-party automation
  • On-prem / customer-operated mail server mandates (no productized self-host for the backend)
  • Workflows that depend on first-class PGP or S/MIME interoperability with external partners
  • Primary need is full Google Workspace or Microsoft 365 collaboration (Drive, Meet, deep Outlook) rather than encrypted mail first

Consider instead when

  • When: Users must keep desktop IMAP clients or need Bridge-style Outlook integration

    Consider: Proton Mail (Bridge on paid plans) or mailbox.org / Posteo / Soverin

    Those options trade Tuta's automatic subject E2EE model for standards-based access

  • When: You need a broader German digital workplace (Drive, Office, video) with optional PGP

    Consider: mailbox.org

    Stronger suite breadth; different default encryption depth than Tuta's full zero-access mailbox

  • When: Swiss jurisdiction and multi-product privacy suite (VPN, drive, pass) matter more than German HQ

    Consider: Proton Mail

    Compare Bridge, ecosystem lock-in, and published cert posture side by side

  • When: Belgian OpenPGP-centric suite with browser crypto and classic protocols is preferred

    Consider: Mailfence

    Different encryption UX (PGP-oriented) versus Tuta's automatic proprietary stack

Open questions for due diligence

Runbox

  • Will Runbox sign a customer-facing B2B DPA listing all subprocessors for your tenant configuration?
  • Can optional web hosting and domain registration be restricted to EEA-only providers for your account?
  • Is any independent penetration test or SOC/ISO report available under NDA?
  • What is the current employee ownership share and any non-EU shareholding since the 2018 figure on the About page?
  • Confirm backup geography (privacy policy: secure servers separate from main system—are they also Norway-only?)

Tuta

  • Will Tutao provide a current signed AVV/DPA with a full subprocessor list (DNS, billing, support, CDN if any)?
  • Is there a current organizational ISO 27001 or SOC 2 report for Tutao GmbH, or only facility-level data-center certification?
  • What is the documented status of TutaCrypt key rotation for all legacy accounts in your tenant?
  • Are any US-group cloud services used for backups, DNS, or support tooling beyond payment processors named in the privacy statement?
  • For business rollout: migration tooling limits (EML/MBOX import on desktop) and dual-running period with legacy IMAP hosts?