Posteo
Verified“German to the core. An EU sovereignty benchmark.”
- Founded
- 2009
- Customers
- 500k+
- Staff
- 40+
- Data centres
- 3 (DE)
93 = midpoint of Control 94 & Data 91
Sovereignty Quadrant
Control β who owns & governs the company Β· Data β where your data lives. Every dot is a company β click to open it.
Every number below traces to 15 sourced facts across 4 independent sources, last verified 2026-06-12. 3 open questions hold confidence at 88% β they lower confidence, never the score.
Control β
Who legally and economically controls the company
Legal & Jurisdiction
95
Incorporated and run entirely in Germany as Posteo e.K. (registered sole trader) in Berlin, fully within EU/German jurisdiction and directly reachable by EU and German law. No foreign parent or holding structure exists.
Why 95? 4 sourced facts · click to expand
Legal form and registry
Posteo Legal Notice (Impressum) Β· as of 2026-06-12
Operates under German jurisdiction as a Berlin-based provider
Posteo About page Β· as of 2026-06-12
Control & Ownership
92
Privately and wholly owned by the two German founders, Patrik and Sabrina LΓΆhr. Voting control and economic upside both sit in Germany. Not listed on any exchange and explicitly free of outside investors, loans or debt. e.K. form means single registered proprietor with unlimited personal liability.
Why 92? 3 sourced facts · click to expand
Self-financed, no investors or debt
Posteo About page Β· as of 2026-06-12
No public listing; funded by subscriptions only
Posteo About page Β· as of 2026-06-12
Data β
Where your data lives and who can reach it
Data & Infrastructure
90
User data lives exclusively on servers in German data centres (Frankfurt, Bielefeld, Berlin) running open-source software on Posteo's own fully-encrypted hardware (LUKS/dm-crypt), with no US hyperscaler and therefore no CLOUD Act exposure. Posteo holds no IP addresses or personal data, confirmed by an audit from Germany's Federal Data Protection Commissioner. Marginal deduction because colocation facilities are third-party-operated buildings, not Posteo-owned real estate.
Why 90? 4 sourced facts · click to expand
Servers located only in German data centres
Posteo About page Β· as of 2026-06-12
Full-disk encryption with open-source software
Posteo Encryption page Β· as of 2026-06-12
Holds no IP addresses or personal user data
Posteo Transparency Report Β· as of 2026-06-12
100% renewable power for servers and offices
Posteo About page Β· as of 2026-06-12
Operations & People
93
Headquarters, leadership, and staff are all in Berlin; reporting and pricing are in EUR. A small but fully German-centered team of 40+ serves 500k+ customers. No offshore operations or foreign leadership.
Why 93? 4 sourced facts · click to expand
First German company to publish a transparency report
Posteo Transparency Report Β· as of 2026-06-12
Aligned to the EU Commission’s official Cloud Sovereignty Framework (SEAL, Jun 2026) β
What we don’t know
3 open questions β they lower confidence, never the score
- ?
Does Posteo own the physical buildings, or only the hardware colocated in third-party German data centres?
Public sources confirm German data centres and Posteo-controlled encrypted hardware but not facility ownership; pure ownership of real estate would push infra even higher.
- ?
Exact split of which data lives in Frankfurt vs Bielefeld vs Berlin and any redundancy across them.
Affects resilience assessment but not the sovereignty conclusion β all sites are in Germany.
- ?
Post-2021 telecom-surveillance (TKΓ) obligations and any standing IP-logging order following the long-running German court dispute.
Posteo states it holds no IP data; a renewed legal obligation could in theory change minimal retention, though its 'no data exists' position has held in its transparency reports.
EU Cloud Sovereignty Framework lens
SEAL was designed to assess cloud service providers; this is an analogous sovereignty mapping for an email provider, not a formal SEAL certification.
Strategic
Founder-owned German firm with no foreign dependency or investor pressure; mission explicitly EU-privacy and sustainability.
Legal & jurisdictional
Incorporated and operated solely in Germany (Posteo e.K., Berlin); fully within EU/GDPR reach, no foreign parent.
Data & AI
Data stored only in German data centres; no IP/personal data retained, confirmed by the Federal Data Protection Commissioner. No AI/training use of mail content.
Operational
HQ, leadership and 40+ staff in Berlin; EUR reporting; self-financed from subscriptions.
Supply chain
Open-source software stack and German colocation, but underlying server hardware components are inevitably non-EU-manufactured.
Technological
Exclusively open-source software, LUKS full-disk encryption, TLS/PFS, DANE/TLSA; no US hyperscaler involved.
Security & compliance
External Cure53 audit, German DPA audit of IP-handling, annual transparency reports since 2014, 2FA available.
Environmental sustainability
100% renewable power (Green Planet Energy) for servers and offices since founding; energy-efficient hardware policy.
EU alternatives
Berlin-based (Heinlein Support), German servers, GDPR-native paid email; comparable privacy-first peer with custom-domain support.
Hanover-based, German-hosted, end-to-end encrypted mailbox including subjects and contacts; stronger E2EE but proprietary client.
Strong privacy and E2EE but Swiss (EEA, not EU member); outside EU legal harmonisation though under strong data-protection law.
How the method works
Methodology v2 (provisional): the score is the midpoint of two axes β Control (who owns and governs the company) and Data (where your data lives and who can reach it). Each axis is scored only on verified evidence; unknowns reduce confidence, never the score. Every input below is sourced; the weights and judgments are open to challenge.
Spotted an error? Every claim is sourced β challenge it and we correct the record.
- 2026-06-12 β Initial golden profile, authored from primary sources (human + AI review).
Report Incorrect Data
Found an error in this company's profile? Help us improve our data by submitting a correction.
Verified 2026-06-12 Β· Human + AI joint review (sources independently checked) Β· Methodology