Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Tresorit

VERIFIED
File sharing · Switzerland
Founded 2011 · tresorit.com ↗

Swiss-Post-owned (state-anchored) E2E encrypted enterprise cloud storage (Tresorit AG, Zurich), Swiss + EU DC options, ISO 27001.

Why this score?

Tresorit AG (Zurich, Pfingstweidstrasse 60b; CHE-349.825.210) is the enterprise-grade zero-knowledge end-to-end-encrypted cloud-storage product founded in 2011 by István Lám and Szilveszter Szebeni in Hungary and majority-acquired by Swiss Post (the Swiss state-owned postal operator) in 2021 — Swiss Post is now sole shareholder, putting the company under Swiss government / state-anchored ownership; ISO/IEC 27001:2022 certified by TÜV Rheinland, GDPR + HIPAA + ITAR + FINRA + CCPA + CJIS + DORA + NIS2 + TISAX coverage, customer-selectable Swiss or EU data residency, contracts under Swiss law / Swiss Federal Act on Data Protection — rated 4/5: an otherwise exceptional state-anchored Swiss profile with no CLOUD Act exposure, but the DPA is not publicly accessible — it requires a paid plan and Subscription Owner role (account-gated), and no standalone public DPA URL exists; the rubric reserves 5/5 for a publicly accessible DPA.

SCORE
4.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
JUMP TO
OVERVIEW

About Tresorit

Tresorit is the enterprise zero-knowledge end-to-end-encrypted cloud-storage product operated by **Tresorit AG** at Pfingstweidstrasse 60b, 8005 Zurich, Switzerland (CHE-349.825.210), with offices also in Budapest, Hungary and Munich, Germany. Founded in 2011 by Hungarian engineers István Lám and Szilveszter Szebeni, the company built its reputation around mathematically-provable client-side encryption — every file, file name, and metadata is encrypted on the user device before upload, so neither Tresorit nor any data-centre operator can access plaintext customer content. The company serves 11,000+ organisations with 4.9 / 4.5 G2 / Capterra ratings. For an EU-sovereignty audit Tresorit's ownership story is unusually strong. In July 2021 **Swiss Post** — the Swiss state-owned postal and digital-services operator — acquired a majority stake; as of 2026 Swiss Post is the **sole shareholder**, making Tresorit a fully Swiss-state-anchored entity. This pushes the directory's `other` (Switzerland) classification into the highest end of that tier: Swiss jurisdiction with state-owned parent is structurally as close to "sovereign" as a vendor can credibly claim. The compliance footprint matches: **ISO/IEC 27001:2022** certified by TÜV Rheinland (covering sales, development, maintenance, and support of E2E-encrypted cloud services), plus alignment with GDPR, HIPAA, ITAR, FINRA, CCPA, CJIS, **DORA**, **NIS2**, and **TISAX** — an unusually broad regulated-industry coverage including US healthcare (HIPAA), US defence-export controls (ITAR), US financial markets (FINRA), and US criminal-justice systems (CJIS) for the rare global customers who need that combination on top of a Swiss-jurisdiction base. Customer-selectable Swiss or EU data residency, contracts under Swiss law and the Swiss Federal Act on Data Protection. Pricing in EUR: a Personal Plus tier starts at approximately €10/month for ~1 TB; Business plans start in the €14-30/user/month range across SecureCloud and Engage tiers; Enterprise is negotiated. Best fit: regulated enterprises (legal, financial-services, healthcare, defence), Swiss public-sector buyers, journalists and NGOs, and any organisation needing a Dropbox / Box / OneDrive replacement with mathematically-provable zero-knowledge encryption from a state-anchored Swiss vendor. Together with Proton Drive, Tresorit forms the directory's two-pillar 5/5 Swiss-encrypted file-sharing shortlist; Proton wins on consumer / freemium and ecosystem breadth (Mail/VPN/Pass/Calendar/Docs), Tresorit wins on enterprise compliance breadth and the unique Swiss-Post state-owned governance.
SUB-PROCESSORS

Sub-processor map · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
from €10/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    support.tresorit.com/hc…
    Open ↗
  • Terms of Service
    tresorit.com/legal…
    Open ↗
ALTERNATIVES

Alternatives in this category