Soverin
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Independent Dutch paid email (from €3.25/mo); ISO 27001 + NIS2 Ready, all data in Netherlands, full IMAP/SMTP/CalDAV/CardDAV compatibility.
Soverin is an EU-owned service hosted in the Netherlands, with no identified CLOUD Act exposure. It is listed under Private email.
Assessment notes
Soverin is operated by Soverin B.V. (Amsterdam NL, KvK 61552275, founded ~2014), an independent Dutch email provider with paid-only mailboxes (from €3.25/mo), all data hosted in the Netherlands under EU law, EU-owned, no US parent, no CLOUD Act exposure. Holds ISO 27001 / 14001 / 9001, NIS2 Ready Mark, full Internet.nl score, NEN 7510 in progress. Gaps: no publicly linked DPA, no public sub-processors list (privacy statement mentions one unnamed external first-line support partner); the service is TLS-encrypted, not end-to-end encrypted, a deliberate trade-off for full IMAP/SMTP/CalDAV/CardDAV compatibility with any client.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
End-to-end encryption: NoTLS in transit; no end-to-end encryption.
-
Public DPA: No
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Soverin
Soverin is operated by Soverin B.V. (Amsterdam, KvK 61552275) and has been running since around 2014 as an independent, self-funded Dutch email provider: no VC backing, no US parent. The service is paid-only (from €3.25/mo / €39/yr, with optional .nl domain at €13/yr); there is no free tier, which is consistent with the "no ads, no profiling, no third-party data" pitch. Mail, calendar and contacts are reachable via standard IMAP / SMTP / CalDAV / CardDAV with any client. Soverin deliberately does not implement end-to-end encryption in the Proton/Tuta sense, in exchange for that full protocol compatibility; data is encrypted in transit (TLS) and at rest on the storage layer, and per the privacy statement is processed only within the EU. Certifications held: ISO 27001, ISO 14001, ISO 9001, NIS2 Ready Mark, perfect Internet.nl score (DNS / email / web / IPv6); NEN 7510 (Dutch healthcare InfoSec) listed as in-progress. The privacy statement names one unnamed sub-processor (external first-line customer support, under DPA + ISO scope) but the document is not a publicly linked customer-facing DPA, the key remaining gap given the otherwise clean EU ownership, EU hosting, and multiple ISO certifications. Positioning is squarely against US free webmail (no CLOUD Act exposure); UI in English and Dutch.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Soverin
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
missingSub-processors list— missing
-
OpenTerms of Servicesoverin.com/about…
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €3/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: No Sub-processors: Yes Open source: No -
-
Germany · €1/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: No Public DPA: Not assessed Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: No
Sub-processors: Yes
Open source: No
|
€3/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: No
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
|
€1/mo |