Tresorit
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Swiss-Post-owned (state-anchored) E2E encrypted enterprise cloud storage (Tresorit AG, Zurich), Swiss + EU DC options, ISO 27001.
Tresorit offers EU hosting in Ireland, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under File sharing.
Assessment notes
Tresorit AG (Zurich, Pfingstweidstrasse 60b; CHE-349.825.210) is the enterprise-grade zero-knowledge end-to-end-encrypted cloud-storage product founded in 2011 by István Lám and Szilveszter Szebeni in Hungary and majority-acquired by Swiss Post (the Swiss state-owned postal operator) in 2021; Swiss Post remains the majority shareholder, and the about page describes Tresorit as part of Swiss Post's digital business services, so the company sits under Swiss state-anchored ownership (a stronger reading that Swiss Post is now the sole shareholder is not confirmable from a primary source, and 2021 coverage has the founders retaining a minority); ISO/IEC 27001:2022 certified by TÜV Rheinland, GDPR + HIPAA + ITAR + FINRA + CCPA + CJIS + DORA + NIS2 + TISAX coverage, customer-selectable Swiss or EU data residency, contracts under Swiss law / Swiss Federal Act on Data Protection. The verified sub-processor list (2026-06) shows Tresorit's primary hosting is Microsoft Azure (a US-owned hyperscaler), which raises CLOUD Act exposure to material on a structural reading; in practice the zero-knowledge end-to-end encryption means Azure stores only ciphertext and Tresorit holds no keys, so compelled disclosure yields no readable content. State-anchored Swiss (Swiss Post) ownership, ISO/IEC 27001:2022 certified by TÜV Rheinland; since the May 2026 audit the Data Processing Addendum is published at a public, login-free URL linked from tresorit.com/legal, closing the documentation gap that previously capped this listing.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 15 · 13 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Tresorit
Tresorit is the enterprise zero-knowledge end-to-end-encrypted cloud-storage product operated by Tresorit AG at Pfingstweidstrasse 60b, 8005 Zurich, Switzerland (CHE-349.825.210), with offices also in Budapest, Hungary and Munich, Germany. Founded in 2011 by Hungarian engineers István Lám and Szilveszter Szebeni, the company built its reputation around mathematically-provable client-side encryption: every file, file name, and metadata is encrypted on the user device before upload, so neither Tresorit nor any data-centre operator can access plaintext customer content. The company serves 11,000+ organisations with 4.9 / 4.5 G2 / Capterra ratings.
For an EU-sovereignty audit Tresorit's ownership story is unusually strong. In July 2021 Swiss Post (the Swiss state-owned postal and digital-services operator) acquired a majority stake, and the about page now describes Tresorit as part of Swiss Post's digital business services under the Swiss Post Digital name. Majority ownership is confirmed; a stronger claim that Swiss Post is now the sole shareholder could not be confirmed against a primary source, and 2021 coverage has the founders retaining a minority. This pushes the directory's other (Switzerland) classification into the highest end of that tier: Swiss jurisdiction with state-owned parent is structurally as close to "sovereign" as a vendor can credibly claim. The compliance footprint matches: ISO/IEC 27001:2022 certified by TÜV Rheinland (covering sales, development, maintenance, and support of E2E-encrypted cloud services), plus alignment with GDPR, HIPAA, ITAR, FINRA, CCPA, CJIS, DORA, NIS2, and TISAX, an unusually broad regulated-industry coverage including US healthcare (HIPAA), US defence-export controls (ITAR), US financial markets (FINRA), and US criminal-justice systems (CJIS) for the rare global customers who need that combination on top of a Swiss-jurisdiction base. Customer-selectable Swiss or EU data residency, contracts under Swiss law and the Swiss Federal Act on Data Protection.
Pricing in EUR: the personal ladder was renamed during 2026 and is now Personal Lite (50 GB), Personal Essential (1 TB) and Personal Pro (4 TB), with a monthly or yearly toggle advertising 20 percent off annual billing. The older Personal Plus tier no longer exists, and the amounts now render client-side, so the pricing page is the figure to budget against. Business plans start in the €14-30/user/month range across SecureCloud and Engage tiers; Enterprise is negotiated. Best fit: regulated enterprises (legal, financial-services, healthcare, defence), Swiss public-sector buyers, journalists and NGOs, and any organisation needing a Dropbox / Box / OneDrive replacement with mathematically-provable zero-knowledge encryption from a state-anchored Swiss vendor. Together with Proton Drive, Tresorit forms the directory's Swiss-encrypted file-sharing dual-pick; Proton wins on consumer / freemium and ecosystem breadth (Mail/VPN/Pass/Calendar/Docs), Tresorit wins on enterprise compliance breadth and the unique Swiss-Post state-owned governance.
Sub-processor map · 15
-
Amazon Simple Email Service (SES) USUnited States
Transactional and notification emails (data in Ireland/EU)
-
DocuSign USUnited States
Electronic signatures for agreements
-
Google reCAPTCHA USUnited States
Fraud and misuse prevention during checkout
-
Microsoft Azure USUnited States
Primary hosting (E2E-encrypted content stored in Ireland/EU) and application performance monitoring
-
Pardot (Salesforce) USUnited States
Marketing campaigns for customers and subscribed visitors
-
PayPal USUnited States
Online payments
-
Productboard USUnited States
Customer feedback management
-
Salesforce USUnited States
Customer relationship management (data in Ireland/EU)
-
SendGrid (Twilio) USUnited States
Transactional and notification emails
-
Stripe USUnited States
Payment processing
-
Twilio USUnited States
Two-factor authentication (voice and SMS)
-
Zendesk USUnited States
Customer support tools
-
Zuora USUnited States
Subscription billing, invoicing and management
-
Tresorit GmbH EUGermany
Affiliate sub-processor delivering Tresorit services
-
Tresorit Kft. EUHungary
Affiliate sub-processor delivering Tresorit services
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Simple Email Service (SES) | United States | Transactional and notification emails (data in Ireland/EU) | US |
| DocuSign | United States | Electronic signatures for agreements | US |
| Google reCAPTCHA | United States | Fraud and misuse prevention during checkout | US |
| Microsoft Azure | United States | Primary hosting (E2E-encrypted content stored in Ireland/EU) and application performance monitoring | US |
| Pardot (Salesforce) | United States | Marketing campaigns for customers and subscribed visitors | US |
| PayPal | United States | Online payments | US |
| Productboard | United States | Customer feedback management | US |
| Salesforce | United States | Customer relationship management (data in Ireland/EU) | US |
| SendGrid (Twilio) | United States | Transactional and notification emails | US |
| Stripe | United States | Payment processing | US |
| Twilio | United States | Two-factor authentication (voice and SMS) | US |
| Zendesk | United States | Customer support tools | US |
| Zuora | United States | Subscription billing, invoicing and management | US |
| Tresorit GmbH | Germany | Affiliate sub-processor delivering Tresorit services | EU |
| Tresorit Kft. | Hungary | Affiliate sub-processor delivering Tresorit services | EU |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of Tresorit
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Switzerland · €4/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
-
Spain · €10/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: Yes -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€4/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
|
€10/mo |