Mailfence
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Belgian secure email + calendar + docs (ContactOffice, est. 1999); browser-side PGP, donates 15% to EFF + EDRi.
Mailfence is an EU-owned service hosted in Belgium, with no identified CLOUD Act exposure. It is listed under Private email.
Assessment notes
Mailfence is operated by ContactOffice Group (Belgium, founded 1999): 25+ years operational, European data centres, OpenPGP end-to-end encryption in-browser, no ads / no trackers / no backdoors, donates 15% of Ultra-tier revenue to EFF + EDRi; under Belgian / EU jurisdiction with strong privacy laws, EU-owned, no CLOUD Act exposure; no formal ISO 27001 attestation surfaced on the public site, and a public DPA URL is available.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
End-to-end encryption: NoIntegrated OpenPGP end-to-end encryption available, but opt-in — mail is not zero-access by default.
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Mailfence
Mailfence (operated by ContactOffice Group, Belgium, founded 1999) is one of the longest-running European secure-email services: OpenPGP end-to-end encryption done in-browser, integrated calendar, docs, contact groups, no ads, no trackers, no government backdoors, EU jurisdiction (Belgium). Pricing tiers from Free (500MB) to Ultra ($225/mo billed monthly for 60GB). Notable ethical commitment: 15% of Ultra-tier revenue donated to the Electronic Frontier Foundation and European Digital Rights. Available in 12 languages; iOS, Android, and PWA apps. No formal ISO 27001 attestation was surfaced on the public site.
Sub-processor map · none disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Mailfence
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €3/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: No Sub-processors: Yes Open source: No -
-
Germany · €1/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: No Public DPA: Not assessed Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: No
Sub-processors: Yes
Open source: No
|
€3/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: No
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
|
€1/mo |