Proton Mail cloud
Fair 3.0 Easy 4.0 Secure 5.0
| Pillar | Criterion | Score | Evidence |
|---|---|---|---|
| Easy | Day-one UX Can non-technical staff use it without a project? | 4 | Clean web and mobile apps; learning curve for E2EE labels. Source |
| Easy | Operate Admin burden, updates, backups and language coverage. | 5 | Proton operates everything; almost no local admin. Source |
| Easy | Integrate SSO, mail/CalDAV, APIs and common NGO connectors. | 3 | IMAP bridge is optional/paid; calendar and VPN in the same family. Source |
| Fair | Lock-in / exit Can you leave with your data in open formats, at known cost? | 3 | Export exists; some features stay inside Proton apps. Source |
| Fair | Sovereignty EU legal entity, EU hosting, and exposure to extra-EU lawful access? | 4 | Swiss company and hosting; outside the EU but strong privacy law. Source |
| Fair | Openness Open source or open standards? Are independent implementations possible? | 2 | Closed source clients and servers; open crypto protocols. Source |
| Secure | IT security Authentication, encryption, patch cadence and independent audit. | 5 | E2EE and a mature security programme. Source |
| Secure | User security 2FA, roles, phishing resistance and safe defaults. | 5 | 2FA and phishing-resistant defaults are first-class. Source |
| Secure | Personal data GDPR fit: DPA, residency, sub-processors and Schrems II posture. | 5 | Zero-access E2EE and a clear DPA; Swiss jurisdiction. Source |