Software without US sub-processors
EU and privacy-first SaaS verified to run with no US sub-processors in the data path — compared on ownership, hosting region, CLOUD Act exposure and sub-processor chain.
Software listed here is verified to operate with no US sub-processors in the data path: an EU/EEA/Switzerland operator, no US parent, and no US-incorporated processor in the chain. That combination — not server location alone — is what keeps data outside US CLOUD Act reach, because jurisdiction follows ownership and processor incorporation, not where the servers sit.
Software without US sub-processors, as listed on this page, means the operating company is incorporated in the EU, EEA or Switzerland, holds no US parent in its ownership chain, and routes no data through a US-incorporated processor at any point in the stack. That is a chain of three facts — operator incorporation, ultimate ownership and the full sub-processor list — and all three must hold. A product that is EU-hosted but owned by a US parent, or EU-owned but relying on a US-incorporated CDN or managed-database layer, does not clear the bar.
This hub spans all categories in the directory and is benchmarked on the same criteria used across every listing: hosting region, ownership signal, CLOUD Act exposure and the sub-processor chain. Every entry is sourced to the vendor's public sub-processor documentation and re-verified quarterly, so the list reflects current chains rather than a one-time assessment.
The CLOUD Act extends US government reach to data held by any company subject to US jurisdiction, regardless of where the servers physically sit. This is the mechanism that makes a US hyperscaler's "EU region" an incomplete answer to the sovereignty question: the operator's jurisdiction does not change when the data moves to a Frankfurt data centre. The same logic applies one level down. A vendor that is itself EU-incorporated can still re-introduce exposure through its sub-processors — a US-incorporated transactional email service, an analytics layer hosted on a US cloud, or a managed database run by a US subsidiary. Each of those processors is separately reachable under the CLOUD Act.
This is why the directory records ownership and sub-processors as separate, evidenced signals rather than deriving one from the other. A clean ownership chain with a single overlooked US processor is still an exposure. Both must be clear for the "no US sub-processors" flag to apply, and that combination is what this hub surfaces across every product category.
-
Tuta
Hannover-based end-to-end encrypted mail (formerly Tutanota); post-quantum crypto, own DE data centre, ISO 27001.
E2E Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 0 sub-procs Open ↗ -
kDrive (Infomaniak)
Swiss kDrive cloud (Infomaniak, Geneva, since 1994), own Swiss DCs, ISO 27001 + B Corp 2025, district-heating heat recycling.
Public DPA Sub-processors Open sourceEU-SOVEREIGNCH · 0 sub-procs Open ↗ -
Mailbox.org
Berlin-based private email + drive + meet + office bundle (Heinlein Support GmbH); ISO 27001 + BSI C5, €1/mo entry.
E2E Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 0 sub-procs Open ↗ -
Sylius
Polish open-source Symfony e-commerce framework (MIT); commercial Plus modules from €800/yr GMV-based.
Public DPA Sub-processors Open sourceEU-SOVEREIGN0 sub-procs Open ↗ -
MyCashflow
Finnish all-in-one e-commerce SaaS with own Helsinki hosting and 0% commission across plans.
Public DPA Sub-processors Open sourceEU-SOVEREIGNFI · 0 sub-procs Open ↗ -
Posteo
Berlin one-person-shop privacy email at €1/mo (Posteo e.K., since 2009); anonymous signup, BSI TR-03108 certified.
E2E Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 0 sub-procs Open ↗ -
Mailfence
Belgian secure email + calendar + docs (ContactOffice, est. 1999); browser-side PGP, donates 15% to EFF + EDRi.
E2E Public DPA Sub-processors Open sourceEU-SOVEREIGNBE · 0 sub-procs Open ↗ -
Nextcloud
German open-source content-collaboration platform (Nextcloud GmbH, Stuttgart, 2016); fully self-hostable + managed Nextcloud One hosted in DE.
Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 0 sub-procs Open ↗ -
Infomaniak Mail (kSuite)
Swiss email + groupware (Infomaniak Group SA, Geneva, since 1994), own Swiss DCs, ISO 27001 + B Corp 2025, free tier with @ik.me address.
E2E Public DPA Sub-processors Open sourceEU-SOVEREIGNCH · 0 sub-procs Open ↗ -
luckycloud
Berlin-based German zero-knowledge cloud (luckycloud GmbH, 2015), own DCs in Berlin/Nuremberg/Frankfurt, ISO 27001 BSI.
Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 0 sub-procs Open ↗ -
Filen
German zero-knowledge E2E cloud (Filen Cloud Dienste UG, Recklinghausen, 2021), Tier IV ISO 27001 DCs, no US data, open source apps.
Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 7 sub-procs · 5 US Open ↗ -
Kolab Now
Swiss open-source Kolab groupware SaaS (Apheleia IT AG, Bern; Kolab Systems since 2010, Kolab Now since 2013), board incl. FSF Europe founder Georg Greve.
E2E Public DPA Sub-processors Open sourceEU-SOVEREIGNCH · 0 sub-procs Open ↗ -
Koofr
Slovenian cloud storage (Koofr d.o.o., est. 2013), German ISO 27001 data centres, optional client-side encryption via Koofr Vault, 10 GB free.
Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 0 sub-procs Open ↗ -
Mailo
French family-owned email since 1998 (Mail Object; founders Voyat & Lenoir, reacquired from Lagardère 2007), French-hosted, Free tier €0 + Premium from €1/mo.
E2E Public DPA Sub-processors Open sourceEU-SOVEREIGNFR · 0 sub-procs Open ↗ -
Runbox
Norwegian private email since 1999 (Runbox Solutions AS), own NO data centre, 100% renewable hydro, PGP + 2FA + PFS, double carbon-negative.
E2E Public DPA Sub-processors Open sourceEU-SOVEREIGNNO · 0 sub-procs Open ↗ -
STRATO HiDrive
German cloud storage (STRATO GmbH, United Internet/IONOS group), two German data centres, ISO 27001 + Trusted Cloud, optional zero-knowledge E2E.
Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 0 sub-procs Open ↗ -
Soverin
Independent Dutch paid email (from €3.25/mo); ISO 27001 + NIS2 Ready, all data in Netherlands, full IMAP/SMTP/CalDAV/CardDAV compatibility.
E2E Public DPA Sub-processors Open sourceEU-SOVEREIGNNL · 0 sub-procs Open ↗ -
LeitzCloud (vBoxxCloud)
Dutch vBoxx-operated Leitz-branded business cloud, German DCs shared with ITZBund, ISO 27001 + ISO 9001 + ISAE 3402.
Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 0 sub-procs Open ↗ -
Jottacloud
Norwegian cloud storage & backup (Jotta Group AS, est. 2008), 100% Norway-hosted on renewable power, server-side AES-256, public DPA, no CLOUD Act reach.
Public DPA Sub-processors Open sourceEU-SOVEREIGNNO · 0 sub-procs Open ↗ -
AirVPN
Italian hacktivist-founded VPN (Perugia, 2010), no-logs, port forwarding — but no longer serves Italian residents (Piracy Shield).
Public DPA Sub-processors Open sourceEU-SOVEREIGN0 sub-procs Open ↗ -
Anytype
Berlin-based local-first peer-to-peer E2E-encrypted knowledge OS (Anytype, 2019); Any Source Available License; data lives on user device.
Public DPA Sub-processors Open sourceEU-SOVEREIGN0 sub-procs Open ↗ -
Aruba Cloud
Italian sovereign cloud (Aruba S.p.A.), 4 Italian DCs (Arezzo/Bergamo/Rome), ACN-qualified up to AI3/QC3 for public administration.
Public DPA Sub-processors Open sourceEU-SOVEREIGNIT · 0 sub-procs Open ↗ -
BookStack
UK solo-dev MIT-licensed self-hosted wiki + documentation platform (Dan Brown, 2015); no SaaS, no vendor counterparty risk.
Public DPA Sub-processors Open sourceEU-BASED0 sub-procs Open ↗ -
centralstationCRM
Cologne-based German SMB CRM (42he GmbH), all-German hosting on Hetzner + Core-Backbone + Telekom, free tier for 3 users.
Public DPA Sub-processors Open sourceEU-SOVEREIGNDE · 3 sub-procs Open ↗
| Compare | Sovereignty | Cert. | Pricing | Signals | Open | ||
|---|---|---|---|---|---|---|---|
|
Hannover-based end-to-end encrypted mail (formerly Tutanota); post-quantum crypto, own DE data centre, ISO 27001.
|
HANNOVER · DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Freemium
€3 /mo
|
E2E
Public DPA
Sub-processors
Open source
|
→ | |
|
Swiss kDrive cloud (Infomaniak, Geneva, since 1994), own Swiss DCs, ISO 27001 + B Corp 2025, district-heating heat recycling.
|
GENEVA · CH
Switzerland
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Paid
€4 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Berlin-based private email + drive + meet + office bundle (Heinlein Support GmbH); ISO 27001 + BSI C5, €1/mo entry.
|
BERLIN · DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
C5
|
Paid
€1 /mo
|
E2E
Public DPA
Sub-processors
Open source
|
→ | |
|
Polish open-source Symfony e-commerce framework (MIT); commercial Plus modules from €800/yr GMV-based.
|
—
Poland
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— | Freemium |
Public DPA
Sub-processors
Open source
|
→ | |
|
Finnish all-in-one e-commerce SaaS with own Helsinki hosting and 0% commission across plans.
|
HELSINKI · FI
Finland
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Paid
€49 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Berlin one-person-shop privacy email at €1/mo (Posteo e.K., since 2009); anonymous signup, BSI TR-03108 certified.
|
BERLIN · DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Paid
€1 /mo
|
E2E
Public DPA
Sub-processors
Open source
|
→ | |
|
Belgian secure email + calendar + docs (ContactOffice, est. 1999); browser-side PGP, donates 15% to EFF + EDRi.
|
BRUSSELS · BE
Belgium
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Freemium
€3 /mo
|
E2E
Public DPA
Sub-processors
Open source
|
→ | |
|
German open-source content-collaboration platform (Nextcloud GmbH, Stuttgart, 2016); fully self-hostable + managed Nextcloud One hosted in DE.
|
STUTTGART · DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Freemium
€6 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Swiss email + groupware (Infomaniak Group SA, Geneva, since 1994), own Swiss DCs, ISO 27001 + B Corp 2025, free tier with @ik.me address.
|
GENEVA · CH
Switzerland
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
ISO9001
+2 more
|
Freemium
€6 /mo
|
E2E
Public DPA
Sub-processors
Open source
|
→ | |
|
Berlin-based German zero-knowledge cloud (luckycloud GmbH, 2015), own DCs in Berlin/Nuremberg/Frankfurt, ISO 27001 BSI.
|
BERLIN · DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Paid |
Public DPA
Sub-processors
Open source
|
→ | |
|
German zero-knowledge E2E cloud (Filen Cloud Dienste UG, Recklinghausen, 2021), Tier IV ISO 27001 DCs, no US data, open source apps.
|
DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Freemium
€2 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Swiss open-source Kolab groupware SaaS (Apheleia IT AG, Bern; Kolab Systems since 2010, Kolab Now since 2013), board incl. FSF Europe founder Georg Greve.
|
CH
Switzerland
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Paid
€5 /mo
|
E2E
Public DPA
Sub-processors
Open source
|
→ | |
|
Slovenian cloud storage (Koofr d.o.o., est. 2013), German ISO 27001 data centres, optional client-side encryption via Koofr Vault, 10 GB free.
|
DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Freemium
€1 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
French family-owned email since 1998 (Mail Object; founders Voyat & Lenoir, reacquired from Lagardère 2007), French-hosted, Free tier €0 + Premium from €1/mo.
|
FR
France
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Freemium
€1 /mo
|
E2E
Public DPA
Sub-processors
Open source
|
→ | |
|
Norwegian private email since 1999 (Runbox Solutions AS), own NO data centre, 100% renewable hydro, PGP + 2FA + PFS, double carbon-negative.
|
NO
Norway
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Paid
€2 /mo
|
E2E
Public DPA
Sub-processors
Open source
|
→ | |
|
German cloud storage (STRATO GmbH, United Internet/IONOS group), two German data centres, ISO 27001 + Trusted Cloud, optional zero-knowledge E2E.
|
DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Paid
€6 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Independent Dutch paid email (from €3.25/mo); ISO 27001 + NIS2 Ready, all data in Netherlands, full IMAP/SMTP/CalDAV/CardDAV compatibility.
|
NL
Netherlands
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Paid
€3 /mo
|
E2E
Public DPA
Sub-processors
Open source
|
→ | |
|
Dutch vBoxx-operated Leitz-branded business cloud, German DCs shared with ITZBund, ISO 27001 + ISO 9001 + ISAE 3402.
|
DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Paid |
Public DPA
Sub-processors
Open source
|
→ | |
|
Norwegian cloud storage & backup (Jotta Group AS, est. 2008), 100% Norway-hosted on renewable power, server-side AES-256, public DPA, no CLOUD Act reach.
|
NO
Norway
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Freemium
€7 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Italian hacktivist-founded VPN (Perugia, 2010), no-logs, port forwarding — but no longer serves Italian residents (Piracy Shield).
|
—
Italy
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Paid
€7 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Berlin-based local-first peer-to-peer E2E-encrypted knowledge OS (Anytype, 2019); Any Source Available License; data lives on user device.
|
BERLIN
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— | Freemium |
Public DPA
Sub-processors
Open source
|
→ | |
|
Italian sovereign cloud (Aruba S.p.A.), 4 Italian DCs (Arezzo/Bergamo/Rome), ACN-qualified up to AI3/QC3 for public administration.
|
AREZZO · IT
Italy
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
ISO/IEC 27017
+1 more
|
Paid
€1 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
UK solo-dev MIT-licensed self-hosted wiki + documentation platform (Dan Brown, 2015); no SaaS, no vendor counterparty risk.
|
—
United Kingdom
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Free
€0 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Cologne-based German SMB CRM (42he GmbH), all-German hosting on Hetzner + Core-Backbone + Telekom, free tier for 3 users.
|
DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Freemium
€24 /mo
|
Public DPA
Sub-processors
Open source
|
→ |
Start by narrowing to your category using the filters above — the "no US sub-processors" bar applies equally to password managers, cloud storage, email and analytics, but the sub-processor risk varies by product type. For each shortlisted product, open the profile and read the sub-processor chain against your own transfer-impact assessment: the layers where US processors most often re-enter an otherwise clean stack are transactional email, CDN and DNS, product analytics, and managed databases.
For regulated buyers — financial services, healthcare, public sector — any US-incorporated processor is typically a veto regardless of contractual safeguards, because the CLOUD Act operates independently of contractual terms. For solo founders and small teams, the binding constraint is more often price and developer experience; look for EU-owned products with a short, verifiable sub-processor list rather than spending disproportionate effort on formal transfer-impact assessments. For enterprise procurement, combine this hub with the certification filters (BSI C5, SecNumCloud, EUCS) to build a shortlist that satisfies both the jurisdictional and the security-audit requirements. Use the sort and filter controls on the listing above to match by category, hosting country or compliance score.
Frequently asked questions
What does 'without US sub-processors' mean here?
Why do US sub-processors matter even with EU hosting?
How is this different from a category page?
Does 'no US sub-processors' guarantee GDPR compliance?
How often is this re-verified?
How we verified every listing here.
For each product we read the public DPA, sub-processors document, hosting region declaration, certifications, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.