MailStore

Germany · www.mailstore.com · 10 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 10 sub-vendors.

Insights

Last updated 2026-08-03 · revision 8

10 direct vendors, 178 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

MailStore exhibits a medium-to-high migration readiness. A key strength is its strategic commitment to modernization, highlighted by the launch of MailStore Cloud as a cloud-native SaaS solution and the ongoing migration to the Microsoft Graph API. This demonstrates an active transition towards modern, flexible architectures. The company's financial stability, backed by OpenText, provides ample resources to fund future migration and modernization initiatives. MailStore also benefits from a strong foundation in regulatory compliance, having successfully navigated complex EU data protection and archiving laws (GDPR, GoBD, HGB/AO, BDSG), which are critical considerations for any data migration. The on-premises MailStore Server product offers inherent flexibility for customers with strict data localization needs, as data residency is controlled by the customer. However, several factors temper the readiness score. The continued reliance on a significant on-premises legacy product (MailStore Server) means a portion of its customer base is not yet cloud-native. Furthermore, the stringent data residency requirement for MailStore Cloud, hosted exclusively in Frankfurt, Germany, imposes a significant constraint on potential migrations to other cloud regions or providers outside of Germany. While MailStore Cloud is 'provided and hosted by OpenText', this implies a degree of internal vendor lock-in to the parent company's infrastructure, which could complicate migration to *external* cloud providers. The 'Total Vendors: 0' data point is contradictory, but assuming the 'Vendor HQ Countries' (United States, Denmark, United Kingdom) indicate some vendor relationships, there is moderate geographic diversity. The unknown vendor lock-in risk is a factor that could impact future migration flexibility. Overall, while MailStore is actively modernizing, the legacy footprint and specific data residency constraints present challenges for broad, unconstrained migration.

Compliance

9 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

MailStore is headquartered in Germany (EU), making GDPR directly and unambiguously applicable. The company processes personal data of employees, customers, and partners globally. As a software vendor whose products are specifically marketed for GDPR compliance, MailStore has strong commercial incentives to maintain its own GDPR compliance. The company has obtained an independent GDPR audit certificate for its MailStore Cloud product and explicitly markets GDPR certification as a product feature. Risk is rated Medium rather than Low because: (1) MailStore is a subsidiary of OpenText (Canada/USA), creating cross-border data transfer obligations under GDPR Chapter V (SCCs or adequacy decisions required); (2) the company processes email data on behalf of 100,000+ corporate customers globally, creating significant data processor obligations; (3) German DPA (LDI NRW, covering North Rhine-Westphalia where Viersen is located) is an active enforcement authority. Risk is not High because the company has demonstrated proactive compliance posture with independent audits and certifications.

Evidence: https://www.mailstore.com/en/products/mailstore-cloud/, https://www.mailstore.com/en/imprint/, https://www.mailstore.com/en/company/, https://www.opentext.com/about/privacy, https://www.mailstore.com/en/legal/legal-gcc/

ISAE 3000 (source) — Assessment Required

ISAE 3000 is an international assurance standard used for non-financial assurance engagements, including privacy and sustainability reporting. It is the international equivalent framework underlying SOC 2 and similar assurance reports. For MailStore, ISAE 3000 could be relevant in the context of: (1) third-party assurance over GDPR compliance claims; (2) assurance over the IDW PS 880 (GoBD) certification, which is a German auditing standard that may incorporate ISAE 3000 principles; (3) customer-facing assurance reports. The risk is Low because ISAE 3000 is not a direct regulatory requirement for MailStore, and the company's existing certifications (GDPR audit, IDW PS 880, ISO data center) provide alternative assurance mechanisms. The absence of an ISAE 3000 report is not a compliance gap per se.

Evidence: https://www.mailstore.com/en/products/mailstore-cloud/, https://www.mailstore.com/en/products/mailstore-server/

GoBD — Compliant

GoBD compliance is a core commercial requirement for MailStore's German market and is explicitly certified. MailStore Cloud holds IDW PS 880 certification, which is the German auditing standard confirming compliance with GoBD (the German tax authority's principles for electronic bookkeeping and document retention). This certification is a key differentiator for MailStore in the DACH market and is prominently displayed on the product page. Risk is Low because: (1) certification is confirmed and publicly disclosed; (2) GoBD compliance is a core product feature and business requirement; (3) the certification is maintained and updated with product versions.

Evidence: https://www.mailstore.com/en/products/mailstore-cloud/, https://www.mailstore.com/en/products/mailstore-server/

Financials

Three-year financials

Financial Resilience Score: 7/10

MailStore Software GmbH is a wholly-owned subsidiary of OpenText Corporation (NASDAQ/TSX: OTEX), a large listed Canadian information-management software group with multi-billion USD revenues (~US$5.77B in FY2024) and consistent operating profitability. This parent backing provides substantial balance-sheet and liquidity resilience far beyond that of a standalone SMB software vendor. The business itself benefits from sticky, compliance-driven demand (GDPR, GoBD, HGB, AO requirements for email retention), a large installed base of over 100,000 corporate customers across more than 100 countries, and recurring maintenance/renewal revenue streams. The diversified reseller and MSP channel (~30 distributors, ~2,000 resellers, ~1,000 service providers) reduces customer concentration risk. However, standalone financials are not publicly disclosed, limiting external credit assessment. Structural headwinds include Microsoft 365's native archiving (Purview) increasingly bundling functionality that MailStore historically monetized, dependence on Microsoft APIs (with EWS discontinuation forcing Graph API migration by October 2026), and MailStore's status as a small entity within a large group whose strategic priorities could shift. The 2025 launch of MailStore Cloud represents a strategic pivot to SaaS aligned with market trends but carries execution risk.

Key strengths: Wholly-owned subsidiary of large listed parent OpenText (multi-billion USD revenues), Sticky, compliance-driven demand from GDPR, GoBD, HGB, AO regulations, Large installed base of >100,000 corporate customers in >100 countries, Recurring licence and maintenance renewal economics, Diversified channel: ~30 distributors, ~2,000 resellers, ~1,000 service providers, 'Made in Germany' positioning with GDPR/IDW PS 880 certifications, Strategic pivot to cloud with MailStore Cloud launch in 2025

Risk factors: Microsoft 365 native archiving (Purview) bundling threatens standalone product relevance, Dependence on Microsoft APIs; EWS discontinuation Oct 2026 forces Graph API migration, Small entity within large OpenText group; strategic priority not guaranteed, FX exposure: EUR cost base vs USD/GBP/multi-currency revenue, Limited public financial transparency (abbreviated GmbH filings only), Transition risk from perpetual-licence to cloud subscription model

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report