Proton
Swiss end-to-end encrypted Mail, VPN, Drive, Calendar, Pass and Wallet, owned by a Swiss non-profit foundation.
Profile last updated: · View sources
About Proton
Proton AG is a Swiss privacy company founded at CERN in 2014 and headquartered in Plan-les-Ouates, Geneva. The Proton suite -- Mail, VPN, Drive, Calendar, Pass, Wallet and the Lumo AI assistant -- is engineered so that Proton itself cannot read user content thanks to end-to-end encryption and a zero-access server architecture.
Proton is owned by the Proton Foundation (Fondation Proton), a Swiss non-profit foundation that became the primary shareholder on 17 June 2024. The foundation's binding purpose is to further the advancement of privacy, freedom and democracy, and it can block hostile takeovers of the company. Proton runs on its own bare-metal infrastructure in Switzerland with no Cloudflare, AWS or US hyperscaler in the user-facing request path. Public clients are open source under GPL-3.0 (with MIT/BSD-3-Clause cryptographic libraries) and are independently audited by Cure53 and Securitum.
Integrations
Demo video
Features
- End-to-end encryption across Mail, Drive, Pass, Calendar, VPN and Wallet
- Zero-access server architecture -- Proton cannot read user content
- Swiss jurisdiction with primary data centre in Zurich
- Owned by the Swiss non-profit Proton Foundation since June 2024
- Self-hosted on Proton-owned hardware -- no Cloudflare, AWS or US hyperscaler in the request path
- ISO/IEC 27001:2022 certified (since May 2024) and SOC 2 Type II attested (Schellman, July 2025)
- Independent annual code audits by Cure53 and Securitum (VPN no-logs review for four consecutive years)
- Open-source clients on the ProtonMail and protonpass GitHub organisations (GPL-3.0 + MIT/BSD-3-Clause crypto)
- PGP-compatible Mail with anonymous Send and Hide-My-Email aliases via SimpleLogin
- Proton Sentinel high-security program and hardware-key support in Proton Pass
- Native apps on Web, iOS, Android, macOS, Windows, Linux; Tor onion mirror at protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion
- SAML SSO and SCIM provisioning plus DPA and SCCs on Business plans
Sovereignty Scorecard
Procurement-grade signals on data sovereignty, ownership, and EU residency.
We score every European vendor against six sovereignty dimensions captured in the SHIELD acronym. Each card below maps to one letter — read them as a checklist when comparing providers.
The third parties that touch customer data — payment processors, KYC vendors, support chatbots, analytics.
Where the legal entity sits, who controls it, and which subsidiaries operate under the same group.
Where customer data is physically stored, who runs the hosting stack, which CDN sits in front.
Whether the vendor or its subprocessors fall under the US CLOUD Act or other extraterritorial reach.
Public terms, privacy policy, DPA, subprocessor list, impressum, and security or trust pages.
Independent audits and certifications (ISO 27001, BSI C5, TISAX, SOC 2) plus open-source transparency.
Foundation owned
Primary shareholder is the Proton Foundation (Fondation Proton), a Swiss non-profit foundation registered as CHE-418.863.304 at the same Plan-les-Ouates address as Proton AG. Foundation control was established on 17 June 2024; trustees today include Dr. Andy Yen, Sir Tim Berners-Lee, Prof. Carissa Véliz, Antonio Gambardella and Dingchao Lu. Remaining Proton AG shares are held by Proton employees, the Geneva innovation foundation FONGIT, and individual Proton users.
🇨🇭 Plan-les-Ouates, Switzerland
Proton AG
- Proton Europe sàrl — 🇱🇺 LuxembourgArticle 27 GDPR EU representative for Proton AG. Address: rue de Grünewald 94, L-1912 Luxembourg.
- Proton Financial AG — 🇨🇭 SwitzerlandOperates the Proton Wallet product line.
- ProtonLabs DOOEL Skopje — North MacedoniaEngineering and data-processing entity (Skopje, North Macedonia).
- ProtonLabs Taiwan Co., Ltd. — TaiwanEngineering and data-processing entity (Taipei, Taiwan).
- SimpleLogin — 🇫🇷 FranceHide-My-Email alias service; acquired April 2022. Founder Son Nguyen Kim joined Proton's leadership team.
Fixed region
All user content -- mail, files, calendar entries, password vaults, VPN session data -- is stored on Proton-owned hardware in Switzerland. Primary data centre is in Zurich. Region is not customer-configurable.
Website: Proton-owned hardware in Switzerland (RIPE netblock 185.70.42.0/24, LIR CH-PROTONMAIL-20140915)
Application: Proton-owned data centre in Zurich, Switzerland
Email: Proton-owned mail clusters in Switzerland (MX terminators: mail.protonmail.ch / mailsec.protonmail.ch)
CDN: Self-hosted (no Cloudflare, Akamai, Fastly or other third-party CDN in the user-facing request path); static assets served from pmecdn.protonweb.com under Proton control
| Name | Country | Purpose |
|---|---|---|
| Stripe, Inc. | 🇺🇸 United States | Card payment processing |
| Chargebee, Inc. | 🇺🇸 United States | Subscription billing and revenue automation |
| PayPal | 🇺🇸 United States | Alternative payment processing (PayPal group entities in US and Singapore) |
| Zendesk, Inc. | 🇺🇸 United States | Customer support ticketing and live chat |
| Calendly | 🇺🇸 United States | Sales meeting scheduling for the business team |
ISO/IEC 27001:2022 — Information Security Management System covering all Proton services. Initial certification May 2024, three-year cycle with annual surveillance audits, accredited by ANAB.
SOC 2 Type II Trust Services Criteria attestation completed July 2025 by Schellman. Covers Mail, VPN, Calendar, Drive, Pass and Wallet.
Swiss Federal Act on Data Protection (revised 2023).
HIPAA-compliant offering for Business customers handling US-regulated PHI.
PCI DSS compliance via Stripe, Chargebee and PayPal payment processors. Proton appears on the processors' attestations rather than holding a direct certificate.
Pricing
€0
- 1 GB Mail + Drive storage
- End-to-end encryption across Mail, Drive, Pass, Calendar
- 1 free Proton VPN connection
- Free Proton Pass on all devices
€3.99
- 15 GB total storage
- 10 email addresses
- Custom domain support (1 domain)
- Unlimited folders, labels and filters
€9.99
- 500 GB storage across all services
- Proton VPN with Secure Core and 10 high-speed connections
- Proton Pass with unlimited shared vaults
- Up to 3 custom domains
- Sentinel high-security program
€12.99
- 1 TB per user across Mail, Drive and Pass
- DPA and SCCs available
- SAML SSO and SCIM provisioning
- Admin console with audit logs
- Priority business support
Videos
Official downloads
Questions & Answers
6 questions
Who owns Proton?
Proton AG is owned by the Proton Foundation (Fondation Proton), a Swiss non-profit foundation registered as CHE-418.863.304. The foundation became Proton AG's primary shareholder on 17 June 2024 and its binding purpose is, in its own words, 'to further the advancement of privacy, freedom, and democracy around the world.' The foundation can block hostile takeovers and Proton pledges 1% of net revenues to the foundation when conditions allow. Remaining shares are held by Proton employees, the Geneva innovation foundation FONGIT, and individual Proton users.
Where is my data stored and who has access?
All user content -- mail, files, calendar entries, password vaults, VPN session data -- is stored on Proton-owned hardware in Switzerland. Proton's primary data centre is in Zurich. End-to-end encryption with zero-access architecture means Proton itself cannot read the content of user data; only metadata such as account creation time and the IP address used at registration is retained, and that metadata can be omitted by paying in cash. Region is not customer-configurable; Switzerland is the only jurisdiction.
Is Proton subject to the US CLOUD Act?
Proton AG is Swiss-domiciled with no US subsidiary or US-headquartered parent -- the CLOUD Act does not reach Proton AG directly. However, several of Proton's commercial subprocessors are US-incorporated and handle limited operational data: Stripe, Chargebee and PayPal for payment processing; Zendesk for customer support; Calendly for sales meeting scheduling. None of these subprocessors have access to encrypted user content -- they only see the metadata necessary for their specific function. Article 271 of the Swiss Criminal Code additionally prohibits Proton from responding directly to foreign-authority requests that are not channelled through Swiss authorities.
Where does Proton publish its subprocessor list?
Proton's canonical subprocessor list lives in section 3.1 of the Privacy Policy at https://proton.me/legal/privacy -- the Data Processing Agreement explicitly references this section as the controlling document. There is no standalone subprocessor page (/legal/subprocessors returns 404). The currently named subprocessors are Stripe, Chargebee, PayPal, Zendesk and Calendly, all handling payment or support data only.
What certifications and audits has Proton completed?
Proton AG holds ISO/IEC 27001:2022 certification (initial certification May 2024, ANAB-accredited, three-year cycle with annual surveillance audits) and completed its first SOC 2 Type II attestation in July 2025, audited by Schellman. The compliance framework additionally covers GDPR, the revised Swiss FADP, HIPAA, CCPA, CJIS and PCI. Independent third-party code audits have been performed by Cure53 (most recent: Proton Pass, July 2023) and Securitum (most recent: Proton VPN no-logs audit, August 2025 -- the fourth consecutive annual review).
Are Proton apps open source?
Yes. All Proton client applications are open source on two GitHub organisations: github.com/ProtonMail (Mail, Drive, Calendar, Bridge, mobile clients, plus the gopenpgp cryptographic library) and github.com/protonpass (Pass and the standalone Authenticator). The main clients are licensed under GPL-3.0; the cryptographic libraries (gluon, go-proton-api, go-crypto, pmcrypto, gopenpgp) are MIT or BSD-3-Clause. All clients have undergone independent third-party audits.
Alternatives
Other European companies in the same category as Proton.
Quick facts
Sources & verification
Every fact on this page is backed by a primary or independent source. Most recent verification: May 12, 2026.
Found an error? Report it
Profile content
- primary · about-pageproton.me/about
- primary · about-pageproton.me/about
- primary · blogproton.me/blog/proton-non-profit-foundationConfirms 2014 founding at CERN and foundation ownership transfer on 17 June 2024
- primary · otherproton.me/support/who-owns-protonmailConfirms shareholder structure
- primary · http-headersproton.me/pricing21 hreflang locales emitted by /pricing; de-duplicated to 19 ISO 639-1 codes
- primary · pricing-pageproton.me/pricing
- primary · otherproton.me/support/proton-plans
- primary · blogproton.me/blog/proton-business-updatesBusiness plan rebrand to Proton Business Suite
- primary · about-pageproton.me/about
- primary · security-pageproton.me/business/trust
- primary · http-headersproton.meonion-location response header confirms Tor mirror
- primary · termsproton.me/legal/termsConfirms Proton AG legal entity and Plan-les-Ouates HQ
- primary · privacy-policyproton.me/legal/privacySection 3.1 enumerates the five subprocessors
- primary · dpaproton.me/legal/dpaConfirms the privacy policy as the canonical subprocessor list
- primary · transparency-reportproton.me/legal/transparencyArticle 271 Swiss Criminal Code bar to direct foreign-authority compliance
- primary · otherproton.me/foundationFoundation purpose, trustees and revenue pledge
- primary · blogproton.me/blog/iso-27001-certificationISO 27001:2022 certification details
- primary · blogproton.me/blog/soc-2SOC 2 Type II completion in July 2025 by Schellman
- primary · otherproton.me/mail/bridgeProton Bridge documents the supported IMAP/SMTP clients
- primary · blogproton.me/blog/security
- primary · transparency-reportproton.me/legal/transparency
Sovereignty (SHIELD)
- primary · privacy-policyproton.me/legal/privacySection 3.1 names Stripe, Chargebee, PayPal, Zendesk and Calendly. No standalone /legal/subprocessors page (404).
- primary · termsproton.me/legal/termsAddress: Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva
- registry · otherwww.uid.admin.ch/Detail.aspxSwiss federal UID register entry for Proton AG (CHE-354.686.492; legal form 0106 Corporation; VAT active since 2016-01-01)
- primary · blogproton.me/blog/proton-non-profit-foundation
- primary · otherproton.me/foundation
- registry · otherwww.uid.admin.ch/Detail.aspxSwiss federal UID register entry for the Proton Foundation (Fondation Proton, CHE-418.863.304; legal form 0110 Foundation)
- primary · otherproton.me/support/who-owns-protonmailConfirms additional shareholders: Proton employees, FONGIT, individual users
- primary · privacy-policyproton.me/legal/privacyNames Proton Europe sàrl (LU), Proton Financial AG (CH), ProtonLabs DOOEL Skopje (MK) and ProtonLabs Taiwan Co., Ltd (TW)
- primary · blogproton.me/blog/proton-and-simplelogin-join-forcesSimpleLogin acquisition announcement, April 2022
- primary · otherproton.me/support/who-owns-protonmailPrimary data centre in Zurich, Switzerland
- primary · dns-recordsproton.medig proton.me -> 185.70.42.45 in netblock 185.70.42.0/24 registered to Proton AG via RIPE LIR CH-PROTONMAIL-20140915. NS records: ns1/ns2/ns3.proton.me. MX records: mail.protonmail.ch, mailsec.protonmail.ch.
- primary · http-headersproton.mecurl -I confirms no Cloudflare/Akamai/Fastly headers; direct TLS from Proton-owned IPs
- primary · transparency-reportproton.me/legal/transparencyArticle 271 Swiss Criminal Code prohibits direct foreign-authority compliance; Proton AG is Swiss-domiciled with no US subsidiary
- primary · privacy-policyproton.me/legal/privacyUS-incorporated subprocessors (Stripe, Chargebee, PayPal, Zendesk, Calendly) handle payment and support data only -- basis for partial-via-subprocessors rather than none
- primary · about-pageproton.me/aboutFooter enumerates terms, privacy, DPA, transparency and trust URLs
- primary · blogproton.me/blog/iso-27001-certificationISO 27001:2022 since May 2024, ANAB-accredited, three-year cycle
- primary · blogproton.me/blog/soc-2SOC 2 Type II completed July 2025 by Schellman
- primary · security-pageproton.me/business/trustTrust page lists ISO 27001, SOC 2, GDPR, Swiss FADP, HIPAA, CCPA, CJIS and PCI
- primary · blogproton.me/blog/security-auditMost recent Securitum VPN no-logs audit, August 2025 (fourth consecutive annual review)
- primary · blogproton.me/blog/pass-open-source-security-auditCure53 Proton Pass audit, July 2023
- primary · othergithub.com/ProtonMail184 repos; major clients under GPL-3.0; crypto libraries under MIT or BSD-3-Clause
- primary · othergithub.com/protonpassPass and Authenticator repos; verified domain ownership of proton.me