Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Mailbox.org

VERIFIED
Private email · Germany
Founded 2014 · mailbox.org ↗

Berlin-based private email + drive + meet + office bundle (Heinlein Support GmbH); ISO 27001 + BSI C5, €1/mo entry.

Why this score?

Mailbox.org is operated by Heinlein Support GmbH (Berlin, founded 2014) on own German data centres, holds ISO/IEC 27001:2022 + BSI C5 Type 1 (rare full BSI-standard certification for an SMB email vendor), GDPR-compliant, PGP-supported, 100% renewable energy; entry tier €1/mo; full 5/5 with no CLOUD Act exposure.

SCORE
5.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About Mailbox.org

**Mailbox.org** (operated by **Heinlein Support GmbH**, Berlin) is a procurement-grade German private-email-plus-productivity suite — **Mail + Drive + Meet + Office** in a single bundled offering — entry tier from **€1/mo** (Light), business plans from €1/user/mo. The compliance posture is rare: **ISO/IEC 27001:2022 + BSI C5 Type 1** (Bundesamt für Sicherheit in der Informationstechnik Type-1 Cloud Computing Compliance certification, the BSI's standard for trusted cloud services in Germany), plus full **PGP** support for end-to-end-encrypted mail. Servers in own German data centres on 100% renewable energy. Slogan "Ihre Daten. Ihre Kontrolle." For DACH compliance buyers this is one of the cleanest picks across the entire directory.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
C5
ACTIVE
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
from €1/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

DPA accessibility is not scored for this listing. Self-hosted or local software, vendors that are not data processors, and products carrying a SecNumCloud, EUCS or BSI C5 certification are not assessed on DPA accessibility — see How we score.
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — not assessed
    n/a
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    mailbox.org/en…
    Open ↗
ALTERNATIVES

Alternatives in this category