Logo: Tuta

Tuta

German end-to-end encrypted email, calendar, and contacts from Tutao GmbH in Hanover—with post-quantum TutaCrypt, open-source clients, and freemium personal plus business plans.

Open source

Tuta (formerly Tutanota) is a German end-to-end encrypted email, calendar, and contacts service from Tutao GmbH in Hanover. Mailbox content is encrypted by default, including subjects, bodies, attachments, contacts, and calendar data, so only account holders and intended recipients can decrypt it on their devices.

It exists as a German alternative to IMAP hosts that store readable mail and bolt encryption on later. Between Tuta users, encryption is automatic. To non-Tuta addresses, senders can still run end-to-end encrypted threads with a shared password, without asking the recipient to install software.

The concrete differentiator is TutaCrypt, the hybrid post-quantum path for new accounts, plus open-source clients (GPLv3) and a deliberate refusal of IMAP/SMTP bridges and Google-dependent push. The commercial model is freemium personal accounts plus paid personal and business tiers.

Default mailbox E2EETutaCrypt post-quantumEU-operated (Germany)Open-source clientsDE data centers (claimed)No IMAP (by design)

Shortlist when you need default end-to-end encrypted mail, calendar, and contacts under German law with post-quantum TutaCrypt and official multi-platform apps. Skip when teams must keep Outlook/Thunderbird via IMAP or need a full M365/Workspace suite—consider Proton Mail (Bridge) or mailbox.org instead.

Key capabilities

Between Tuta users, messages encrypt automatically including subject lines, bodies, and attachments. External recipients can use a shared password for end-to-end threads without installing software. Contacts and calendars use the same zero-access model; only delivery metadata (addresses, timestamps) stays readable by design.

New accounts use TutaCrypt: Kyber-1024 KEM plus X25519 ECDH with AES-256, targeting harvest-now-decrypt-later risks. Protocol details are published; existing accounts migrate as key rotation rolls out. Tuta intentionally avoids PGP so subjects and non-mail features can stay encrypted and algorithms can be upgraded in-product.

Calendar events—including times, titles, locations, and attendees—are end-to-end encrypted. Reminders are pushed as encrypted payloads and fired locally so servers are not told when an event starts. Sharing stays encrypted; invites can go out via mail, optionally password-protected for externals.

Web, Android (Play and F-Droid), iOS, Windows, macOS, and Linux clients are published under GPLv3 on GitHub. Desktop builds are signed for verification. There is no IMAP/SMTP bridge: third-party mail apps cannot connect, which preserves encryption at rest but forces a client switch for Outlook/Thunderbird holdouts.

Paid business plans add custom domains, aliases, shared mailboxes, multi-admin roles, password/2FA resets, catch-all, templates, and optional branding/login on your own site. Vendor-stated uptime SLA and a GDPR order-processing agreement support B2B procurement—confirm current plan matrix on tuta.com.

At a glance

HQ
Hanover, Germany (Tutao GmbH)
Product
Encrypted email, calendar, contacts (SaaS)
Hosting
Own servers in ISO 27001 data centers in Germany (vendor claim)
Open source
Clients GPLv3 on GitHub; no productized self-host
Protocols
No IMAP/SMTP client access; official apps only
Crypto
TutaCrypt hybrid (Kyber-1024 + X25519 + AES-256) for new accounts
Commercial model
Freemium personal + paid personal/business (no ads)

Best fit when

  • Teams that will standardize on Tuta's official web/mobile/desktop clients for default zero-access email
  • Orgs prioritizing subject-line encryption, encrypted calendar, and post-quantum hybrid crypto under German jurisdiction
  • SMEs needing custom domains, aliases, shared mailboxes, and multi-admin controls without running their own mail servers
  • Journalists, NGOs, and privacy-led departments that value F-Droid builds, no Google Push dependency, and ad-free operation
  • Buyers who want open-source client auditability plus a freemium path for personal trial before business seats

Poor fit when

  • Hard requirement for IMAP/SMTP in Outlook, Thunderbird, Apple Mail, or third-party automation
  • On-prem / customer-operated mail server mandates (no productized self-host for the backend)
  • Workflows that depend on first-class PGP or S/MIME interoperability with external partners
  • Primary need is full Google Workspace or Microsoft 365 collaboration (Drive, Meet, deep Outlook) rather than encrypted mail first

Consider instead when

  • When: Users must keep desktop IMAP clients or need Bridge-style Outlook integration

    Consider: Proton Mail (Bridge on paid plans) or mailbox.org / Posteo / Soverin

    Those options trade Tuta's automatic subject E2EE model for standards-based access

  • When: You need a broader German digital workplace (Drive, Office, video) with optional PGP

    Consider: mailbox.org

    Stronger suite breadth; different default encryption depth than Tuta's full zero-access mailbox

  • When: Swiss jurisdiction and multi-product privacy suite (VPN, drive, pass) matter more than German HQ

    Consider: Proton Mail

    Compare Bridge, ecosystem lock-in, and published cert posture side by side

  • When: Belgian OpenPGP-centric suite with browser crypto and classic protocols is preferred

    Consider: Mailfence

    Different encryption UX (PGP-oriented) versus Tuta's automatic proprietary stack

Jurisdiction & ownership

Legal entity
Tutao GmbH (HRB 208014, Hanover)
Governing law
German law / GDPR
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Low
Hosting / residency
Vendor states mailbox data is stored end-to-end encrypted on Tutao-operated servers in ISO 27001-certified data centers in Germany. No AWS/GCP/Azure primary hosting named on official security/privacy pages. Privacy statement discloses payment processing via PayPal (Europe) and banks for card/SEPA; no comprehensive public subprocessor list found for ops tools.

No known US parent from imprint. CLOUD Act exposure assessed low for mailbox content given EU entity and DE hosting claims; residual third-country touch is mainly billing (PayPal Europe) and any unpublished processors—confirm in DPA annex. Indicative only, not legal advice.

  • Independent security / no-logs auditVendor claimed
  • ISO 27001Partial
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • HighNo IMAP/SMTP third-party clients

    Desktop and mobile holdouts cannot stay on Outlook/Thunderbird/Apple Mail. Plan full client migration or pick a standards-based alternative.

  • MediumWeaker protection to non-Tuta recipients

    Without a shared password, external mail is ordinary SMTP (TLS in transit). Only Tuta-to-Tuta and password-protected external threads are true E2EE.

  • MediumHosted service, not on-prem mail

    Open-source clients help inspectability, but mailboxes still depend on Tutao's German SaaS backend, uptime, and German legal process.

  • LowData-center ISO vs company ISMS

    ISO 27001 wording refers to data centers. Do not tick 'vendor ISO 27001 certified' on questionnaires without the actual Tutao certificate.

  • MediumLimited public subprocessor inventory

    Privacy policy covers payments (e.g. PayPal Europe) but lacks a detailed live subprocessor register. Request the DPA annex for DPIA completeness.

  • LowGerman court orders on accessible data

    Transparency reports show regular German requests. Stored E2EE content stays undecryptable by Tutao; real-time monitoring can expose newly arriving unencrypted SMTP mail. Align expectations with counsel.

Open questions for due diligence

  • Will Tutao provide a current signed AVV/DPA with a full subprocessor list (DNS, billing, support, CDN if any)?
  • Is there a current organizational ISO 27001 or SOC 2 report for Tutao GmbH, or only facility-level data-center certification?
  • What is the documented status of TutaCrypt key rotation for all legacy accounts in your tenant?
  • Are any US-group cloud services used for backups, DNS, or support tooling beyond payment processors named in the privacy statement?
  • For business rollout: migration tooling limits (EML/MBOX import on desktop) and dual-running period with legacy IMAP hosts?

Frequently Asked Questions

No. Tuta does not offer IMAP/SMTP access or a Bridge-style proxy, because those protocols would require delivering decryptable data to third-party clients. Official web, mobile, and desktop apps are the supported path. If IMAP is a hard requirement, evaluate Proton Mail Bridge, mailbox.org, Posteo, Soverin, or similar standards-based EU hosts instead.

Define a shared password for that contact once; subsequent messages in the conversation stay encrypted and open in a password-protected view. Without a password, mail can still be sent unencrypted over SMTP with TLS (MTA-STS, SPF, DKIM, DMARC supported). Unencrypted inbound/outbound mail is encrypted at rest on Tuta's servers after arrival but is not end-to-end with the external party.

Clients and substantial code are open source (GPLv3), and advanced users can build custom clients, but Tutao does not productize a supported self-hosted mailbox cluster. Procurement should treat Tuta as German-operated SaaS. If you must run the MTA and storage yourself, look at self-hosted stacks or hosts that ship full IMAP servers under your control.

End-to-end encrypted content (bodies, subjects, attachments, calendar details, contacts) is not readable by the operator under normal operation. Email addresses of senders and recipients, message dates, and account inventory data needed for the service remain available. Under valid German court orders, the company may release inventory/traffic data and encrypted content blobs, or—for real-time monitoring—plaintext of newly arriving unencrypted SMTP mail. See the published transparency report.

Tutao states that data is stored on its own servers in ISO 27001-certified data centers in Germany and that it provides a GDPR Order Processing Agreement (Auftragsverarbeitungsvertrag) for business customers. Confirm the signed DPA, any subprocessor annex, and SLA wording with sales before relying on questionnaire answers. Facility ISO certification is not the same as Tutao holding its own published ISO 27001 certificate.