Logo: Kolab Now

Kolab Now

Swiss-hosted FOSS Kolab groupware from Apheleia IT AG: email, calendars, contacts, files and optional Collabora collab on operator infrastructure in Bern.

Open source

Kolab Now is a Swiss-hosted email and groupware service operated by Apheleia IT AG in Bern. The public site describes secure accounts with calendars, address books, video conferencing, and file storage, owned and operated in Switzerland since 2013.

It exists as the managed offering of the Kolab free and open-source communication stack for individuals and small organisations that do not want to run servers themselves. A primary account owner can enable mailbox-only or full groupware per user and attach private domains.

The concrete differentiator is that FOSS Kolab stack on operator infrastructure in Bern, with optional Collabora collaboration, rather than a proprietary webmail silo.

Swiss-operatedFOSS Kolab stackFull groupware suiteIMAP / CalDAV / ActiveSyncHosted in Bern (claimed)Optional PGP

Shortlist when you want Swiss-operated, FOSS-based classical groupware (mail, CalDAV/CardDAV, ActiveSync, files, Collabora) on operator-owned Bern infrastructure. Skip when you need default zero-access E2EE mail, public ISO/SOC evidence, or mature video — consider Proton Mail/Tuta for E2EE mail or Google Workspace/Microsoft 365 for enterprise suite depth.

Key capabilities

Hosted Kolab stack: IMAP/SMTP mail, CalDAV/CardDAV calendars and contacts, tasks, notes, and WebDAV files. ActiveSync is available for mobile/Outlook-style sync on full groupware subscriptions. Teams keep standard desktop and mobile clients instead of a proprietary-only app.

Primary account owners verify custom domains (DNS guides in the KB), add users under one wallet, and share mail folders, calendars, notes, and files inside the domain. Fits small businesses and families that need branded addresses and shared inboxes without Google Workspace.

Operator FAQ places production systems in a Bern rack on IBM OpenPOWER with hardware-encrypted storage, RHEL, and segmented firewalls. TLS is described as end-to-end inside the platform with Perfect Forward Secrecy; outbound mail strips client IP and MUA identity from headers.

Server-side Sieve rules (folder, redirect, vacation, discard) run in the web client. Outbound DKIM is supported with CNAME delegation for private domains. Spam tagging is available; aggressive auto-junk is deliberately left to customer Sieve policy rather than opaque provider filtering.

Domain users can collaboratively edit documents/presentations via Collabora Online on shared files. Webmail can import PGP keys for optional message encryption (vendor warns keys on server are weaker than offline E2EE). Kolab Meet adds personal video rooms on groupware plans but remains public beta.

Time-based one-time passwords (e.g. Aegis) can be required for accounts. When 2FA is enabled for a user, vendor docs state non-web clients (IMAP, POP, ActiveSync, CalDAV/CardDAV, WebDAV) are blocked — evaluate this before mandating 2FA on mobile-heavy fleets.

At a glance

HQ / operator
Apheleia IT AG, Bern, Switzerland
Product since
2013 (Swiss-operated hosted Kolab)
Hosting
Operator rack in Bern; IBM OpenPOWER + encrypted storage (vendor FAQ)
Stack
Kolab FOSS; RHEL; open mail/groupware protocols
Self-host this SKU
No (managed); Kolab suite is self-hostable separately
Commercial model
Paid modular subscriptions via prepaid wallet; trial month

Best fit when

  • Small teams and professional practices that need shared mailboxes, calendars, and private domains under Swiss jurisdiction
  • Buyers who prioritise open standards (IMAP, CalDAV/CardDAV, ActiveSync, WebDAV) and FOSS components over proprietary lock-in
  • Organisations that will accept provider-accessible mail at rest and apply PGP/S/MIME themselves for sensitive threads
  • Users leaving Google Workspace who want groupware depth without US Big Tech mail custody
  • Account owners comfortable with prepaid wallet billing and modular per-user subscriptions

Poor fit when

  • Requirements for default end-to-end encrypted mail with zero provider access (prefer Proton Mail or Tuta)
  • Enterprises that need public ISO 27001/SOC 2 packs, signed DPAs, and a published subprocessor list on day one
  • Fleets that must combine TOTP 2FA with IMAP/ActiveSync clients on the same user (documented mutual exclusion)
  • Orgs treating video conferencing as a core, production-grade service (Kolab Meet is still beta)
  • Buyers seeking a permanent free tier or consumer-grade onboarding polish comparable to Gmail

Consider instead when

  • When: You need default zero-access / E2EE email more than ActiveSync groupware

    Consider: Proton Mail or Tuta

    Stronger default cryptography story; thinner classical groupware/ActiveSync depth than Kolab Now.

  • When: You want privacy-focused German email without full suite complexity

    Consider: Posteo

    Leaner privacy mail; not a Collabora + shared-domain groupware suite.

  • When: You need Google/Microsoft-class admin scale, apps marketplace, and compliance certifications

    Consider: Google Workspace or Microsoft 365

    Far larger ecosystems; US-centric custody and CLOUD Act profile differ sharply.

  • When: You want full self-host control of the same FOSS stack

    Consider: Self-hosted Kolab (kolab.org) or Nextcloud plus a mail stack

    More operational burden; Apheleia also sells Kolab professional services.

Jurisdiction & ownership

Legal entity
Apheleia IT AG (trade register CH-036.3.053.227-3; VAT CHE-149.254.861)
Governing law
Swiss law (see Terms of Service for contract details)
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
Primary mailbox/groupware hosting claimed on operator-controlled infrastructure in Bern, Switzerland (IBM OpenPOWER hypervisors, hardware-encrypted IBM storage, RHEL). No AWS/GCP/Azure hosting advertised for customer mail. Billing wallet supports PayPal, credit card, and EUR bank transfer — US-linked payment processors for payment data. Full subprocessor/backup register not published on pages reviewed.

No known US corporate parent on public operator materials. CLOUD Act exposure scored medium (not low) because payment rails include PayPal/card networks and no complete public subprocessor list was found; content hosting claims remain Swiss own-infra. Indicative only — not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumMail not zero-access by default

    Unlike Proton/Tuta defaults, ordinary stored mail is provider-accessible for protocol delivery unless users apply PGP or another client E2EE scheme. Material for threat models that assume provider compromise or compelled access to plaintext.

  • Medium2FA blocks non-web clients

    Documented behaviour: enabling TOTP 2FA confines the user to the web client and blocks IMAP/ActiveSync/CalDAV and related protocols. Breaks many mobile/Outlook deployments if applied naively.

  • MediumLimited public compliance pack

    No public ISO/SOC certs, independent audit, or subprocessor register found. Procurement must rely on vendor FAQs, ToS, and direct questions — slower security review than certified EU SaaS peers.

  • LowUS-linked payment processors

    Wallet top-ups via PayPal and credit cards introduce US-group payment processors for billing data even when mailboxes stay in Switzerland. Scope is payment metadata, not IMAP content, but still relevant to transfer inventories.

  • LowKolab Meet still beta

    Voice/video rooms are labelled public beta; vendor notes support may be limited. Do not treat as a Zoom/Teams replacement for critical meetings.

Open questions for due diligence

  • Will Apheleia sign a GDPR Art. 28 DPA and provide a current subprocessor list (including backups, monitoring, and payment processors) under NDA if needed?
  • What is the current imprint address and governing ToS URL for contract annexes (product footer vs apheleia-it.ch addresses differ)?
  • Is there any ISO 27001, SOC 2, or independent penetration-test summary available to customers on request?
  • How are backups and disaster recovery stored (same Bern facility only, or additional sites/providers)?
  • For regulated workloads: what is the practical process and historical volume of Swiss lawful-access requests affecting customer content?

Frequently Asked Questions

No. Transport uses TLS with Perfect Forward Secrecy, and storage is described as hardware-encrypted at rest on the operator's Bern infrastructure, but ordinary mailbox content is accessible to the service for IMAP/web delivery unless you apply client-side PGP (or another client E2EE workflow). The web client can store PGP keys for convenience; the vendor notes that true E2EE still depends on client-held keys and that server-held keys add risk. Choose Proton Mail or Tuta if default zero-access mail is non-negotiable.

Not at the same time for a given user, according to current Kolab Now docs. Enabling 2FA for a user is documented as restricting access to the web client only and blocking IMAP, POP, ActiveSync, CalDAV, CardDAV, and WebDAV. Onboarding material also notes 2FA and ActiveSync as mutually exclusive subscription choices in the cockpit. Plan either web-centric 2FA or protocol clients with strong passwords/app-specific controls — not both on one mailbox.

Apheleia IT AG (Swiss company; trade register CH-036.3.053.227-3) operates Kolab Now. Infrastructure FAQ material places servers in Bern, Switzerland, on operator-controlled IBM OpenPOWER systems with hardware-encrypted storage — not a marketed multi-region hyperscaler footprint. Confirm current imprint address and Terms of Service at signup; operator website and product footer addresses have differed over time (Bern locations).

Paid subscription components (mailbox, optional groupware, storage and domain add-ons) billed from a wallet balance. New accounts are described as free for an initial trial month; afterwards usage is charged against prepaid credit, with one-time top-ups or auto-top-up via credit card, PayPal, or bank transfer (bank rails described in EUR). There is no permanent free tier. Always re-check the live pricing page and wallet docs before purchase — figures change and are not repeated here.

Outbound mail is DKIM-signed; private domains should publish the documented DKIM CNAMEs. Greylisting can be enabled in account settings. Spam is not aggressively auto-removed by default — the KB expects customers to build Sieve rules on X-Spam-* headers. Message size limit is documented around 30 MB on arrival (headers included); the user guide mentions attachment UX up to roughly 60 MB in compose — treat the server message limit as the hard constraint for interoperability.

As of this research pass: no public ISO 27001/SOC 2 certificate or independent no-logs audit PDF was found on primary pages. GDPR posture is explained in a knowledge-base article (customer data ownership, no ad analytics, log retention, deletion). A formal B2B DPA download and subprocessor register were not located on the marketing site (the main site is an SPA; legal docs may appear only after login or on request). Add these as open procurement questions before enterprise rollout.