Dispatch · 5 July 2026

mailbox.org and the certified route out of Google Workspace

mailbox.org backs its EU-hosting claim with ISO 27001 and BSI C5 audits. Here's what's verified, what's self-declared, before you leave Workspace.

Most encrypted-email marketing pages promise privacy. mailbox.org’s page for businesses leaving Google Workspace leads with something narrower and more checkable: ISO 27001 certification, a BSI C5 Type 2 attestation from Germany’s federal information security agency, the BSI IT Security Label, and a TÜV-certified data protection officer. FindInEurope’s dossier marks all four as verified, which puts mailbox.org in a different category from most of its privacy-first competitors. This is not a claim to take on faith; it is a set of external audits a buyer’s own compliance team can check.

BSI C5 in particular is a familiar bar for German public-sector and regulated-industry buyers. It is the audit standard Germany’s federal cybersecurity office built specifically to assess cloud providers, and a Type 2 attestation means the audit covered a period of actual operation, beyond the design review on paper that a Type 1 attestation would cover. For a team migrating off Google Workspace under a compliance mandate, that is a more concrete checkbox than a general privacy promise.

The corporate facts behind the service are equally traceable. mailbox.org is operated by Heinlein Hosting GmbH, registered in Berlin under HRB 220010 B at the Amtsgericht Charlottenburg, a fact verified against the register itself. The company is a wholly owned subsidiary of Heinlein Support GmbH, also based in Berlin, with no non-EU parent disclosed anywhere in the public filings. That ownership claim is marked claimed rather than verified: the imprint confirms where the company is registered, not who ultimately controls it, so the distinction stands even though both facts point to the same page.

Legal footing is more straightforward. mailbox.org operates under German law and is subject to GDPR along with German data-protection regulation, a status verified against its published privacy policy. Where the data physically lives is a separate question: the company states that customer data stays exclusively in two independent Berlin data centres, a specific and plausible claim, but one that comes from mailbox.org’s own data-protection page rather than from an outside inspection, so it is marked claimed.

On the technical side, mailbox.org sticks to protocols a business can actually migrate with: standard IMAP, SMTP, CalDAV, and CardDAV, S/MIME and PGP support for encrypted mail, and data export for portability. Because CalDAV and CardDAV sit alongside IMAP and SMTP, calendar and contacts move with the mailbox, the two pieces of a Workspace migration that a plain email switch usually leaves stranded. That verified entry matters for anyone worried about getting stuck once they leave Workspace; the standard-protocol approach is the opposite of a walled garden. The one remaining self-declared item is environmental: renewable electricity for the Berlin data centres and office, stated by the company, not independently audited.

Put together, mailbox.org’s record divides along a line worth remembering when comparing it to other Workspace alternatives. Company identity, legal jurisdiction, protocol openness, and the security certifications sit on register- or audit-grade evidence. Ownership detail, data-centre exclusivity, and environmental practice rest on the company’s own statements. Both halves are useful for a migration decision, but only one half is independently checkable today. The full dossier at /listings/mailbox-org/ lists every source behind these ratings, alongside the current score.

Services in this dispatch

# Service HQ Governing law Score FIE-SEAL Visit
01 mailbox.org Privacy-focused email and groupware from Berlin, ISO 27001 and BSI C5 certified. Alternative to Gmail · Google Workspace DE German law; subject to GDPR and German data-protection regulation
91 Partial Jurisdiction 100 Independence 78
SEAL-1 Dossier →