Self-hosted
Fair 5.0 Easy 2.3 Secure 3.7
| Pillar | Criterion | Score | Evidence |
|---|---|---|---|
| Easy | Day-one UX Can non-technical staff use it without a project? | 2 | Admin UI exists; end users need a mail client story. Source |
| Easy | Operate Admin burden, updates, backups and language coverage. | 1 | Spam, DNS, TLS and upgrades are a specialist job. Source |
| Easy | Integrate SSO, mail/CalDAV, APIs and common NGO connectors. | 4 | IMAP, CalDAV, SOGo and LDAP/OIDC options. Source |
| Fair | Lock-in / exit Can you leave with your data in open formats, at known cost? | 5 | You hold the maildirs; IMAP export is native. Source |
| Fair | Sovereignty EU legal entity, EU hosting, and exposure to extra-EU lawful access? | 5 | Host wherever you choose, including EU. Source |
| Fair | Openness Open source or open standards? Are independent implementations possible? | 5 | Open source mail stack on standard protocols. Source |
| Secure | IT security Authentication, encryption, patch cadence and independent audit. | 4 | Security tracks how well you run it. Source |
| Secure | User security 2FA, roles, phishing resistance and safe defaults. | 3 | SOGo/2FA possible; phishing depends on user training. Source |
| Secure | Personal data GDPR fit: DPA, residency, sub-processors and Schrems II posture. | 4 | No SaaS processor if you host and log lawfully in the EU. Source |