Skip to main content

BSI C5 certification for mailbox: Full compliance with BSI criteria for cloud security confirmed

Berlin, 7 January 2026 – Heinlein Hosting GmbH, the legal operator of mailbox, has received the BSI C5 Type 1 certificate from the German Federal Office for Information Security (BSI). This certificate from the independent testing agency confirms that mailbox fully complies with the BSI security criteria specifically for cloud services. Together with ISO/IEC 27001 certification and other awards, the certificate attests to the priority that the provider of the secure digital workplace attaches to email security, information security and data protection.

Trophy in recognition of excellent performance

BSI C5 certification: Seal of quality for data security

The certification confirms that mailbox meets the strict requirements of the Cloud Computing Compliance Criteria Catalogue (C5). This catalogue is a set of criteria developed specifically for cloud providers that raises the information security, availability and confidentiality of data to a tested and verifiable level. It was developed by the BSI on the basis of nationally and internationally established standards and publications in order to enable users in sensitive areas such as public authorities or the healthcare industry to gain transparency from providers regarding the fulfilment of cloud security criteria, thereby ensuring compliance with security and compliance requirements within the framework of risk management.

The BSI C5 certification is further confirmation of mailbox's expertise and pioneering position by independent testing bodies. ‘We are very proud of this certification. It is another clear signal to our customers that the safety of their data is subject to the strict tests and controls required for the German and European markets and sensitive applications,’ says Peer Heinlein, founder and CEO of the Heinlein Group, which includes the companies Heinlein Support, mailbox, OpenTalk and OpenCloud.

BSI C5 Type 1 Testat
ISO/IEC 27001:2022 Zertifikat

Criterion for provider selection with growing relevance

For more and more industries and public institutions, the BSI C5 certificate is becoming a relevant or even mandatory criterion when selecting their partners. ‘mailbox has been committed to data security for years. We are therefore particularly pleased that the certificate officially confirms this,’ says Peer Heinlein. ‘Our customers can rely on certified cloud security and the highest level of information security, as evidenced by our ISO 27001 certification and other awards.’

mailbox: ISO 27001 certified and awarded quality seals

mailbox protects its customers' data with state-of-the-art encryption, continuous monitoring and innovative security procedures. Data is stored exclusively on redundant German servers in 100% GDPR compliance. In addition to the BSI C5 certification, mailbox is also ISO/IEC27001 certified. ISO 27001 is the international standard for information security management systems (ISMS). It offers organisations a systematic approach to protecting their information. Specifically, this approach helps to identify, assess and control risks to the confidentiality, integrity and availability of information.

In addition, mailbox 2025 was awarded the ‘Software made in Germany’ and ‘Software hosted in Germany’ quality seals by the German Federal Association of IT SMEs (BITMi). In addition, mailbox has achieved gold status as part of the BSI's Email Security Year 2025. The Heinlein Group company has thus committed itself to the full implementation of state-of-the-art email security standards and has already successfully implemented them. Users of mailbox benefit from the provider's pioneering position and can rely on certified cloud and email security.

 

About mailbox

mailbox is the digital workplace for secure communication and provides digital sovereignty from Germany for the world. The mailbox Suite integrates email, calendar, contacts, office, video conferencing and drive in one intuitive solution, running exclusively from German data centres.

As a European provider, mailbox completely avoids advertising, tracking and data monetisation, serving businesses, public and educational institutions, resellers and private individuals with highest demands for data protection and digital independence.

mailbox is part of the Heinlein Group, which has been the expert in free and secure communication for over 30 years.

 

About Heinlein Group:

Heinlein Group, based in Berlin, stands for digital sovereignty, data protection and open source. It brings together the brands Heinlein Support, mailbox, OpenTalk and OpenCloud, which offer many years of expertise in open standards, personal consulting and innovative solutions for secure communication and independent IT infrastructure. Whether email services, video conferencing or file management – Heinlein Group's products are GDPR-compliant, flexible in use and technically state-of-the-art. Together with its hosting, consulting and Heinlein Academy divisions, Heinlein Group covers the entire spectrum for setting up and operating sovereign and resilient IT infrastructures.

For over 30 years, companies, public institutions, educational institutions and providers have placed their trust in the expertise of Heinlein Group. Its offerings create maximum control and transparency, strengthen digital independence and promote sustainable IT development.

More press releases

mailbox Logo

mailbox.org repositions itself: Germany's digitally sovereign workplace

Read more about mailbox.org repositions itself: Germany's digitally sovereign workplace
Trophy in recognition of excellent performance

mailbox.org achieves gold status in BSI Email Security Year 2025

Read more about mailbox.org achieves gold status in BSI Email Security Year 2025
Trophy in recognition of excellent performance

mailbox.org receives "Software made in Germany" and "Software hosted in Germany" seals

Read more about mailbox.org receives "Software made in Germany" and "Software hosted in Germany" seals
Support Image

mailbox Public Relations

Nina Gruber