Logo: Proton Mail

Proton Mail

Swiss end-to-end encrypted email from Proton AG: zero-access inbox storage, open-source clients, custom domains, and Bridge for desktop IMAP clients.

Proton Mail is the encrypted email product of Proton AG, a Swiss company headquartered in Plan-les-Ouates (Geneva) and supervised by the non-profit Proton Foundation. It provides web, mobile, and desktop clients, plus optional Proton Mail Bridge so paid accounts can keep using Outlook, Thunderbird, or Apple Mail while encryption and decryption stay on the user side.

It exists as a Swiss alternative to Gmail-class inboxes that can scan mail for ads or training. Messages between Proton addresses are end-to-end encrypted by default. Mail stored in the inbox uses zero-access encryption: Proton states it does not hold keys that would let operators read message bodies or attachments.

The concrete differentiator is that zero-access inbox plus Bridge, custom domains, and hide-my-email aliases on a freemium Swiss account, without turning the inbox into an advertising surface.

E2EE + zero-accessSwiss-operatedBridge (IMAP/SMTP)Open-source clientsISO 27001 & SOC 2 (claimed)Public B2B DPA

Shortlist Proton Mail when you want Swiss-jurisdiction, zero-access encrypted email with open-source clients, custom domains, Bridge for desktop mailers, and a public DPA. Skip when you need free-tier IMAP Bridge, fully self-hosted FOSS mail on your own servers, or Workspace-class collaboration depth—consider Tuta, Posteo, or Mailfence among EU peers, or stay on Google/Microsoft if suite lock-in wins.

Key capabilities

Bodies and attachments are encrypted so Proton states it lacks keys to read stored mail. Proton-to-Proton traffic is end-to-end encrypted automatically; external recipients need password-protected messages or PGP/WKD for comparable content protection. Subject lines are not fully E2EE under OpenPGP header rules.

Paid plans that include Mail can run Bridge locally to connect Outlook, Thunderbird, or Apple Mail over IMAP/SMTP while encrypting and decrypting on the device. Free accounts use official web/mobile/desktop apps instead of Bridge.

Paid and business tiers support custom domains, extra addresses, catch-all and groups, hide-my-email aliases, and org admin for seats, storage, and retention policies. Suits teams leaving Google/Microsoft who still need branded addresses.

Web, mobile, and desktop clients are published on GitHub with third-party audit reports linked from Proton’s open-source page. The hosted mail backend is not offered as self-hosted FOSS—audit client trust, not full server reproducibility.

Built-in tracker protection, phishing heuristics, link confirmation, SPF/DKIM/DMARC for custom domains, hardware-key 2FA, and optional Proton Sentinel monitoring for high-risk accounts. Complements encryption with everyday abuse defenses.

At a glance

HQ
Plan-les-Ouates (Geneva), Switzerland
Legal entity
Proton AG (CHE-354.686.492); Proton Foundation supervision
Hosting model
Proton-owned hardware in Switzerland (vendor claim)
Self-host
No (SaaS); clients open source
Commercial model
Freemium + paid consumer and business seats
Bridge
Paid plans that include Mail

Best fit when

  • Teams that need default end-to-end / zero-access encryption without running their own mail stack
  • Orgs that want Swiss legal venue and documented resistance to direct foreign data demands
  • Businesses migrating branded domains off Gmail/Outlook with Easy Switch and Bridge for desktop holdouts
  • Security-conscious professionals who value open-source clients, published audits, and hardware-key 2FA
  • Buyers who need a public DPA plus vendor-claimed ISO 27001 / SOC 2 Type II for questionnaires

Poor fit when

  • Fully self-hosted requirements (Proton Mail is SaaS; clients are open source, not a full on-prem mail server)
  • Desktop IMAP on free accounts only—Bridge needs a paid plan that includes Mail
  • Workflows that depend on unencrypted-looking mail to external parties who will not use password links or PGP
  • Teams that primarily need full Microsoft 365 / Google Workspace collaboration depth rather than encrypted mail first

Consider instead when

  • When: You want German E2EE email with a different crypto product surface and may not need Proton’s full ecosystem

    Consider: Tuta

    Compare desktop interoperability and business admin maturity side by side.

  • When: You want ad-free European mail with strong transport privacy but do not require zero-access E2EE for all stored content

    Consider: Posteo

    Different threat model: Posteo is privacy-forward without Proton’s zero-access default.

  • When: You need OpenPGP-centric mail with classic collaboration extras under Belgian operation

    Consider: Mailfence

    Weigh automatic Proton-to-Proton E2EE UX versus Mailfence’s model.

  • When: Collaboration suite depth and ecosystem lock-in outweigh encryption defaults

    Consider: Google Workspace or Microsoft 365

    Accept US-provider jurisdiction and scanning/processing models as tradeoffs.

Jurisdiction & ownership

Legal entity
Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland (EU representative: Proton Europe sàrl, Luxembourg)
Governing law
Swiss law (Terms; Geneva courts for business/non-US consumer disputes as stated in Terms)
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
Primary mail storage on Proton-owned servers in Switzerland (vendor security pages). Not marketed as AWS/GCP/Azure inbox hosting. Public privacy policy lists US-group processors for support and payments (Zendesk; Chargebee, Stripe, PayPal) and group support processing in North Macedonia and Taiwan; HubSpot noted for business sales inquiries.

No known US parent; operating company is Swiss with Foundation supervision. Zero-access encryption limits disclosure of message bodies even under Swiss process. Account metadata and support/payment data remain accessible paths. US SaaS subprocessors raise indicative CLOUD Act exposure above a pure no-US-vendor baseline despite Swiss HQ. Indicative only—not legal advice.

  • Independent security / client auditsVendor claimed
  • ISO 27001Vendor claimed
  • SOC 2 / SOC 3Vendor claimed
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumWeaker defaults outside Proton

    Mail to Gmail/Outlook/others is not E2EE unless password-protected or PGP/WKD is used. Subject lines are not fully E2EE. Train users or you only protect the Proton-stored copy.

  • MediumUS support and payment processors

    Zendesk, Chargebee, Stripe, and PayPal appear in the public processor list. They should not see zero-access message bodies, but support content and billing data can touch US-group services—document this in DPIAs.

  • LowBridge requires paid Mail

    Desktop IMAP/SMTP via Bridge is not available on free accounts. Budget seats for users who refuse the official apps.

  • MediumHosted service, not self-hosted FOSS mail

    Open-source clients improve inspectability but you still depend on Proton’s operated backend, uptime, and Swiss legal process. Unsuitable if policy mandates customer-operated mail servers.

  • LowSwiss legal orders on accessible data

    Transparency reports show thousands of yearly legal orders for Mail with many complied. Bodies stay encrypted; recovery emails, IPs (when retained for abuse), and similar metadata may still be in scope. Align expectations with counsel.

Open questions for due diligence

  • What exact data-center sites and any non-Swiss regions apply to your tenant’s mailbox replicas today?
  • Will Proton provide the full SOC 2 Type II report under NDA and confirm ISO 27001 certificate scope/expiry for your questionnaire?
  • For business orgs: which users will be private vs non-private, and how will admin recovery work with zero-access constraints?
  • Which external partners must receive E2EE content, and will they accept password-protected messages or PGP?

Frequently Asked Questions

Proton-to-Proton messages are end-to-end encrypted by default. Messages to external providers use TLS in transit and are then stored under zero-access encryption in your Proton inbox, but the recipient’s provider can read the message unless you use password-protected email or interoperable PGP/WKD. Plan external collaboration workflows around those tools if content confidentiality outside Proton matters.

Yes on paid plans that include Mail, via Proton Mail Bridge, which runs locally and exposes IMAP/SMTP to desktop clients while handling encryption on the device. Free plans use Proton’s own apps. Confirm OS support and Bridge licensing against your seat plan before committing a desktop-heavy rollout.

Proton describes company-owned server hardware in Switzerland for mail infrastructure (secured facilities, encrypted disks). The public privacy policy separately lists processors such as Zendesk (support/live chat), Chargebee/Stripe/PayPal (payments), group support entities in North Macedonia and Taiwan, and related tools. Message plaintext is designed to stay zero-access; support tickets and billing data follow those processor paths under SCCs where transfers apply.

Yes: a public Data Processing Agreement applies when Proton processes personal data as a processor under the terms (Swiss governing law, Geneva jurisdiction). The Trust Center and blog claim ISO 27001 (audit completion announced for May 2024) and SOC 2 Type II (attestation announced July 2025). Download current certificates and confirm scope for your procurement file—do not treat marketing pages as the cert itself.

Proton AG is a Swiss company; privacy docs state it only discloses limited accessible user data under binding Swiss legal process, and Article 271 constraints limit direct foreign assistance. Transparency reports show many Swiss legal orders yearly for Mail—typically account/metadata class data Proton can access, not decrypted bodies. Foreign authorities generally need Swiss mutual legal assistance. This is not legal advice; map it to your counsel’s threat model.