Internxt
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Valencia-based open-source zero-knowledge encrypted cloud (Internxt, 2020), post-quantum crypto, lifetime plans, 1 GB free, 1M+ users.
Internxt is a European service hosted in Spain, with at most minor, transient US exposure under the CLOUD Act. It is listed under File sharing.
Assessment notes
Internxt Universal Technologies S.L. (Valencia, Spain; VAT B98936354) is a founder-controlled zero-knowledge encrypted cloud-storage product founded in 2020 by Fran Villalba Segarra: fully open-source code on GitHub, post-quantum cryptography (Kyber-512) in addition to AES-256 / TLS 1.3, ISO/IEC 27001:2022 certified, independently audited by Securitum (2024), HIPAA-aligned, with a public DPA at internxt.com/DPA.pdf; the cap table is no longer bootstrapped — a EUR 3.3M round closed in July 2025 brought in outside investors, but all of them are European (Prosegur Tech Ventures and Angels Capital in Spain, Andorra Telecom in Andorra, plus Extension Fund and Kevlar Fund), so there is no US-VC or US-PE presence and the EU-owned classification stands; the distributed-node infrastructure is global rather than EU-only but zero-knowledge encryption means plaintext customer data never leaves the device; EU-owned with public DPA and open-source clients, with only a minor CLOUD Act flag reflecting the multi-region node distribution.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: Yes
-
Third-party certification: Yes
Jump to
About Internxt
Internxt is a Valencia-based zero-knowledge encrypted cloud-storage product operated by Internxt Universal Technologies S.L. (VAT B98936354), founded in 2020 by Fran Villalba Segarra (CEO), currently with a team of approximately 30 and more than 1 million active users. The product covers Drive, Send (file transfer), VPN, Antivirus, Cleaner, Mail, and Meet across a single privacy-focused account, positioning itself as a European Mega / Tresorit / Proton Drive challenger with two structural differentiators: fully open-source code (publicly auditable on GitHub) and post-quantum cryptography (Kyber-512 alongside AES-256 at rest and TLS 1.3 in transit). Internxt was the first cloud-storage vendor to ship post-quantum protection across consumer tiers, and the codebase has been independently audited by Securitum (2024).
For an EU-sovereignty audit Internxt stands out for two reasons. First, ownership: the company was bootstrapped until July 2025, when a €3.3M capital increase led by Prosegur Tech Ventures (ES) brought outside investors in, with Angels Capital (ES), the state-owned Andorra Telecom (AD), Extension Fund and Kevlar Fund participating, alongside a €1.4M CDTI grant. No US investor is named in any source, so the EU-owned classification holds, but the individual stakes are not public and the company can no longer be described as founder-controlled. Second, compliance: ISO/IEC 27001:2022 certified, HIPAA-aligned, GDPR-compliant, Spanish DPO via Egida (legal@egida.es), terms last updated January 2026. The infrastructure side is a distributed-node architecture with servers in multiple countries rather than a single EU-locked region, a choice driven by encryption philosophy: because every file is encrypted on the device before upload and the encryption keys never leave the user, plaintext customer content cannot be read by any node operator anywhere in the world. This makes the multi-region distribution a minor CLOUD Act flag rather than material (the threat model assumes the encryption stands).
Pricing in EUR is a hybrid of subscription and lifetime, and the billing mechanism is unusual enough to spell out. Internxt sells annual and lifetime plans only, with no month-to-month option, and an annual plan is a twelve-month commitment charged monthly rather than one payment up front. The low headline rate on the site is an 80 percent discount on the first month alone, not a first-year promotion: Essential 1 TB is €1.99 for the first month and €9.99 per month for the remaining eleven, Premium €3.99 then €19.99, Ultimate €1.99 then €29.99. 1 GB encrypted is free; lifetime plans are a signature offering: one-time payment for permanent access up to 5 TB per plan, stackable across multiple plans with the same email up to 100 TB total. 30-day money-back guarantee. Best fit: privacy-first individuals and SMBs that want a Spanish-founded open-source alternative to Dropbox / iCloud / Google Drive with the option to escape subscriptions via lifetime plans, post-quantum protection, and verifiable code.
Sub-processor map · none disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Internxt
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Switzerland · €10/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Switzerland · €4/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€10/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€4/mo |