Swissnode vs Tuta

Compare Swissnode and Tuta on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Google Workspace, Microsoft 365

Logo: Swissnode

Swissnode

Switzerland· Email Services

Needs review

Shortlist Swissnode for lean European cPanel domain email plus shared web or KVM VPS when Spain/EU residency is acceptable and you do not need enterprise compliance packs. Skip when you require live Swiss territorial hosting, E2EE mail, or published DPA/subprocessor inventories—consider Hostpoint, Infomaniak, or Proton Mail instead.

cPanel domain emailKVM VPSSpain data center (vendor)Optional Cloudflare CDNSMB hosting packages
Logo: Tuta

Tuta

Germany· Email Services

Needs review

Shortlist when you need default end-to-end encrypted mail, calendar, and contacts under German law with post-quantum TutaCrypt and official multi-platform apps. Skip when teams must keep Outlook/Thunderbird via IMAP or need a full M365/Workspace suite—consider Proton Mail (Bridge) or mailbox.org instead.

Default mailbox E2EETutaCrypt post-quantumEU-operated (Germany)Open-source clientsDE data centers (claimed)No IMAP (by design)
Swissnode vs Tuta: Snapshot
FeatureLogo: SwissnodeSwissnodeLogo: TutaTuta
Country of originSwitzerlandGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersSwitzerlandGermany
Legal entitySwissnode (legal form/registry name not clearly published on marketing site)Tutao GmbH (HRB 208014, Hanover)
Governing lawNot clearly stated on marketing pages; confirm in contract (CH contact vs ES ops)German law / GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyVendor states primary hosting moved to a Spain data center after Swiss DC closure; homepage cites Spanish privacy laws. Site IP geolocates to Spain (Ipcore Datacenters). Optional Cloudflare CDN on web plans (US-group). Off-site backup provider not named. No public subprocessor inventory.Vendor states mailbox data is stored end-to-end encrypted on Tutao-operated servers in ISO 27001-certified data centers in Germany. No AWS/GCP/Azure primary hosting named on official security/privacy pages. Privacy statement discloses payment processing via PayPal (Europe) and banks for card/SEPA; no comprehensive public subprocessor list found for ops tools.
Summary

European cPanel email, shared web hosting, and KVM VPS under the Swissnode brand—vendor-stated Spain data center after Swiss DC closure, with optional Cloudflare CDN on web plans.

German end-to-end encrypted email, calendar, and contacts from Tutao GmbH in Hanover—with post-quantum TutaCrypt, open-source clients, and freemium personal plus business plans.

Tags
At a glance: Swissnode vs Tuta
At a glanceLogo: SwissnodeSwissnodeLogo: TutaTuta
Contact addressBinzallee 6, 8055 Zurich, CH (public contact page)Not listed
Footer / ops addressMutilva Baja, Navarra, SpainNot listed
Primary hosting (vendor)Spain data center after Swiss DC closureNot listed
Core productsDomain email, cPanel web hosting, KVM VPSNot listed
Control panelscPanel (shared); Virtualizor (VPS)Not listed
Open sourceNoClients GPLv3 on GitHub; no productized self-host
Self-hosted productNo (provider-hosted; VPS gives root on rented VM)Not listed
Commercial modelPackage tiers (monthly/yearly); optional antispam add-onFreemium personal + paid personal/business (no ads)
HQNot listedHanover, Germany (Tutao GmbH)
ProductNot listedEncrypted email, calendar, contacts (SaaS)
HostingNot listedOwn servers in ISO 27001 data centers in Germany (vendor claim)
ProtocolsNot listedNo IMAP/SMTP client access; official apps only
CryptoNot listedTutaCrypt hybrid (Kyber-1024 + X25519 + AES-256) for new accounts
Key capabilities: Swissnode vs Tuta
Key capabilitiesLogo: SwissnodeSwissnodeLogo: TutaTuta
cPanel domain emailYesNot listed
KVM VPSYesNot listed
Spain data center (vendor)YesNot listed
Optional Cloudflare CDNYesNot listed
SMB hosting packagesYesNot listed
Default mailbox E2EENot listedYes
TutaCrypt post-quantumNot listedYes
EU-operated (Germany)Not listedYes
Open-source clientsNot listedYes
DE data centers (claimed)Not listedYes
No IMAP (by design)Not listedYes

Swissnode

  • Domain email on cPanel (IMAP/POP/SMTP)

    Business mailboxes on your domain with secure webmail, SpamAssassin-style spam control, virus filtering, DKIM, calendars/contacts, autoresponders, forwarders, filters, and mailing lists on mid-tier plans—protocol-compatible with Outlook, Apple Mail, and mobile clients.

  • cPanel web hosting with Softaculous and LiteSpeed PHP

    Shared and reseller web plans with datacenter SSDs, free panel SSL, multi-PHP, SSH above entry tiers, and Softaculous one-click apps—aimed at brochure sites, WordPress, and small PHP apps rather than container platforms.

  • KVM VPS with RAID-10 enterprise SSDs

    Root-level Linux VPS via KVM, enterprise SSDs, RAID-10 arrays, fixed per-VPS network allotments, and Virtualizor-style management for teams that outgrow shared hosting but still want package SKUs.

  • Optional Cloudflare CDN from the control panel

    Web plans advertise easy Cloudflare integration to cache static assets near visitors—useful for performance, with the tradeoff that enabled CDN traffic can traverse a US-group network path.

  • Backup cadence for VPS (vendor-stated)

    Marketing states daily on-site and weekly off-site VPS backups with rebuilds measured in minutes to an hour after failure—restore SLAs and off-site provider identity should be confirmed in the contract.

Tuta

  • Default E2EE for mail, subjects, and attachments

    Between Tuta users, messages encrypt automatically including subject lines, bodies, and attachments. External recipients can use a shared password for end-to-end threads without installing software. Contacts and calendars use the same zero-access model; only delivery metadata (addresses, timestamps) stays readable by design.

  • TutaCrypt post-quantum hybrid cryptography

    New accounts use TutaCrypt: Kyber-1024 KEM plus X25519 ECDH with AES-256, targeting harvest-now-decrypt-later risks. Protocol details are published; existing accounts migrate as key rotation rolls out. Tuta intentionally avoids PGP so subjects and non-mail features can stay encrypted and algorithms can be upgraded in-product.

  • Zero-knowledge calendar with private reminders

    Calendar events—including times, titles, locations, and attendees—are end-to-end encrypted. Reminders are pushed as encrypted payloads and fired locally so servers are not told when an event starts. Sharing stays encrypted; invites can go out via mail, optionally password-protected for externals.

  • Open-source multi-platform clients (no IMAP)

    Web, Android (Play and F-Droid), iOS, Windows, macOS, and Linux clients are published under GPLv3 on GitHub. Desktop builds are signed for verification. There is no IMAP/SMTP bridge: third-party mail apps cannot connect, which preserves encryption at rest but forces a client switch for Outlook/Thunderbird holdouts.

  • Business domains, admin console, and whitelabel

    Paid business plans add custom domains, aliases, shared mailboxes, multi-admin roles, password/2FA resets, catch-all, templates, and optional branding/login on your own site. Vendor-stated uptime SLA and a GDPR order-processing agreement support B2B procurement—confirm current plan matrix on tuta.com.

Assurance & compliance: Swissnode vs Tuta
Assurance & complianceLogo: SwissnodeSwissnodeLogo: TutaTuta
Independent security / no-logs audit
Not found

No public independent audit report found on swissnode.ch.

Vendor claimed

Vendor states SySS GmbH penetration testing before public release; not a continuously published annual no-logs audit PDF on the marketing site.

ISO 27001
Not found

No ISO 27001 claim located on official product/security pages.

Partial

Official pages claim data centers are ISO 27001 certified; does not clearly establish a public Tutao GmbH organizational ISO 27001 certificate.

SOC 2 / SOC 3
Not found

No SOC 2/3 claim found.

Not found

No SOC 2/3 report located on security, business, or privacy pages.

GDPR / EU data protection
Partial

Spain/EU hosting supports EU data-protection analysis, and homepage references Spanish privacy laws; usable privacy policy/DPA text not published on site. Customer remains controller for lawful basis.

Vendor claimed

German controller Tutao GmbH; privacy statement cites GDPR; DPO published; DE storage claimed.

US CLOUD Act exposure (indicative)
Partial

No known US parent; primary host Spain/EU. Optional Cloudflare CDN is a US-group subprocessor for web static delivery; off-site backups and other SaaS paths not published. Not a clean low-exposure bill; not legal advice.

Partial

EU entity, no known US parent, primary mailbox hosting claimed as own DE servers—not AWS/GCP/Azure. Payment may use PayPal (Europe). Assessment is low exposure for content with residual billing/processor unknowns; not a vendor 'safe' claim. Not legal advice.

Data processing agreement (B2B)
Not found

No public DPA download or B2B processing terms found; request in writing.

Vendor claimed

Security/business materials state an Order Processing Agreement (Auftragsverarbeitung) is provided for GDPR; obtain signed version via sales—no public self-serve DPA URL confirmed.

EU AI Act
Not applicable

Commodity hosting/email/VPS, not an AI product.

Not applicable

Encrypted email/calendar product; vendor states it does not plan AI that processes user communications for model training.

Swiss territorial hosting
Partial

Vendor discloses Swiss DC closed; operations from Spain DC. Contact still Zurich. Do not treat as CH-only residency.

Not listed
Considerations & known limitations: Swissnode vs Tuta
Considerations & known limitationsLogo: SwissnodeSwissnodeLogo: TutaTuta
Swiss brand vs Spain hosting
High

Product pages state the Swiss data center closed and services run in Spain; homepage cites Spanish privacy laws. Buyers assuming Zurich colocation from the brand or older materials will mis-classify risk and contractual residency.

Not listed
Empty privacy pages / no public DPA or certs
High

Privacy and cookie URLs do not present substantive policy text; ISO/SOC and DPA artifacts were not found. Regulated or enterprise buyers face a heavy offline diligence burden.

Not listed
Optional Cloudflare CDN (US-group)
Medium

Web hosting markets Cloudflare integration from cPanel. Enabling CDN can place static content on a US-group network path even when origin is Spain—document this in transfer assessments.

Not listed
Off-site backup provider not named
Medium

Daily on-site and weekly off-site backups are claimed for VPS, but the off-site location/provider is not published—ask before trusting disaster-recovery or residency narratives.

Not listed
Aging marketing surface
Low

Public site still shows 2013–2018 copyright and sparse modern trust pages; may signal limited investment in public assurance UX even if infrastructure remains operational.

Not listed
No IMAP/SMTP third-party clientsNot listed
High

Desktop and mobile holdouts cannot stay on Outlook/Thunderbird/Apple Mail. Plan full client migration or pick a standards-based alternative.

Weaker protection to non-Tuta recipientsNot listed
Medium

Without a shared password, external mail is ordinary SMTP (TLS in transit). Only Tuta-to-Tuta and password-protected external threads are true E2EE.

Hosted service, not on-prem mailNot listed
Medium

Open-source clients help inspectability, but mailboxes still depend on Tutao's German SaaS backend, uptime, and German legal process.

Data-center ISO vs company ISMSNot listed
Low

ISO 27001 wording refers to data centers. Do not tick 'vendor ISO 27001 certified' on questionnaires without the actual Tutao certificate.

Limited public subprocessor inventoryNot listed
Medium

Privacy policy covers payments (e.g. PayPal Europe) but lacks a detailed live subprocessor register. Request the DPA annex for DPIA completeness.

German court orders on accessible dataNot listed
Low

Transparency reports show regular German requests. Stored E2EE content stays undecryptable by Tutao; real-time monitoring can expose newly arriving unencrypted SMTP mail. Align expectations with counsel.

Fit

Swissnode

Best fit when

  • Freelancers and micro-SMBs wanting domain IMAP/POP mail with spam filtering and webmail on cPanel
  • Agencies/resellers needing simple shared web packages (Softaculous, multi-PHP, free panel SSL) plus optional VPS upgrade path
  • Teams that prefer standard mail protocols over migrating into Microsoft 365 or Google Workspace
  • Buyers comfortable with Spain/EU hosting under a .ch brand and Swiss contact details
  • Workloads where package-tier hosting and KVM root access matter more than published ISO/SOC packs

Poor fit when

  • Organizations that hard-require Swiss (CH) server residency or nFADP narratives assuming Zurich colocation
  • Procurement needing public DPA, full subprocessor lists, ISO 27001, or SOC 2 on the vendor site
  • Teams needing end-to-end encrypted mail or zero-access webmail (choose Proton-class products)
  • Enterprises expecting Microsoft 365-class collaboration, compliance archives, and admin tooling
  • Buyers who shortlisted the brand solely for “Swiss data center” marketing that product pages no longer support

Consider instead when

  • When: You need Swiss-resident email/office with a broader product catalog and clearer CH hosting claims

    Consider: Hostpoint E-Mail & Cloud Office or Infomaniak kMail

    Fuller Swiss platforms; better when territorial Switzerland is non-negotiable.

  • When: You need end-to-end encrypted mail and open-source clients rather than cPanel hosting

    Consider: Proton Mail

    Different product class: E2EE vs classic hosted IMAP.

  • When: You need full collaboration suites, admin compliance tooling, and ecosystem apps

    Consider: Microsoft 365 or Google Workspace (US-group control planes)

    Richer features; different jurisdiction/CLOUD Act profile.

  • When: You want a larger EU hosting group with broader cloud SKUs

    Consider: IONOS or OVHcloud

    Scale and catalog depth over niche Swissnode packaging.

Tuta

Best fit when

  • Teams that will standardize on Tuta's official web/mobile/desktop clients for default zero-access email
  • Orgs prioritizing subject-line encryption, encrypted calendar, and post-quantum hybrid crypto under German jurisdiction
  • SMEs needing custom domains, aliases, shared mailboxes, and multi-admin controls without running their own mail servers
  • Journalists, NGOs, and privacy-led departments that value F-Droid builds, no Google Push dependency, and ad-free operation
  • Buyers who want open-source client auditability plus a freemium path for personal trial before business seats

Poor fit when

  • Hard requirement for IMAP/SMTP in Outlook, Thunderbird, Apple Mail, or third-party automation
  • On-prem / customer-operated mail server mandates (no productized self-host for the backend)
  • Workflows that depend on first-class PGP or S/MIME interoperability with external partners
  • Primary need is full Google Workspace or Microsoft 365 collaboration (Drive, Meet, deep Outlook) rather than encrypted mail first

Consider instead when

  • When: Users must keep desktop IMAP clients or need Bridge-style Outlook integration

    Consider: Proton Mail (Bridge on paid plans) or mailbox.org / Posteo / Soverin

    Those options trade Tuta's automatic subject E2EE model for standards-based access

  • When: You need a broader German digital workplace (Drive, Office, video) with optional PGP

    Consider: mailbox.org

    Stronger suite breadth; different default encryption depth than Tuta's full zero-access mailbox

  • When: Swiss jurisdiction and multi-product privacy suite (VPN, drive, pass) matter more than German HQ

    Consider: Proton Mail

    Compare Bridge, ecosystem lock-in, and published cert posture side by side

  • When: Belgian OpenPGP-centric suite with browser crypto and classic protocols is preferred

    Consider: Mailfence

    Different encryption UX (PGP-oriented) versus Tuta's automatic proprietary stack

Open questions for due diligence

Swissnode

  • What is the exact legal entity (registry name, UID/CHE or Spanish NIF) and governing law on the customer contract?
  • Will Swissnode sign a B2B DPA and publish a current subprocessor list (spam filter, backups, payment, support tools)?
  • Exact Spain facility (Ipcore or other) and whether any secondary regions exist for mail, web, and VPS separately?
  • Where are weekly off-site backups stored, and under which provider’s control?
  • Is Cloudflare mandatory, optional, or default for web plans, and can customers disable it for pure Spain origin delivery?
  • What uptime SLA, restore RPO/RTO, and support hours are contractual vs marketing (99.5% backbone claim on homepage)?

Tuta

  • Will Tutao provide a current signed AVV/DPA with a full subprocessor list (DNS, billing, support, CDN if any)?
  • Is there a current organizational ISO 27001 or SOC 2 report for Tutao GmbH, or only facility-level data-center certification?
  • What is the documented status of TutaCrypt key rotation for all legacy accounts in your tenant?
  • Are any US-group cloud services used for backups, DNS, or support tooling beyond payment processors named in the privacy statement?
  • For business rollout: migration tooling limits (EML/MBOX import on desktop) and dual-running period with legacy IMAP hosts?