Mozilla Foundation

United States · www.thunderbird.net · 24 vendors

The Mozilla Foundation is an American nonprofit organization that supports and collectively leads the open-source Mozilla project. It is dedicated to safeguarding the internet as an open, accessible global resource, promoting digital rights, user privacy, and supporting innovators building trustworthy technology. The Foundation operates key infrastructure and controls Mozilla trademarks and copyrights, including those for products like the Thunderbird email client through its subsidiary MZLA Technologies Corporation.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 24 sub-vendors.

Insights

Last updated 2026-03-12 · revision 1

24 direct vendors, 324 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Mozilla Foundation (Thunderbird) shows a solid foundation for migration readiness, scoring 65. The company's internal tech stack includes modern cloud-native enablers such as inferred use of GCP/AWS, Docker for containerization, and Kubernetes for orchestration. The adoption of modern languages like Kotlin, Swift, Rust, JavaScript/TypeScript, and protocols like JMAP, along with a commitment to open standards (CalDAV, IMAP/SMTP/POP3), facilitates potential migration efforts. The open-source nature of Thunderbird's core product significantly reduces proprietary lock-in. While 'Total Vendors' is listed as 0, the existence of 'Total Services: 32' with 'Vendor Geographic Diversity: 5 unique countries' suggests a degree of vendor flexibility, assuming these services are provided by external entities. However, several critical factors remain unknown, impacting the readiness score. There is no data on financial stability, which is crucial for funding a large-scale migration. Regulatory environment and data residency requirements are also unspecified, which can introduce significant complexity and cost to migration planning. Furthermore, while modern elements are present, the core Thunderbird Desktop application, built on Gecko/XULRunner, might represent a more monolithic architecture that could require substantial refactoring for a full microservices or serverless migration. The 'Vendor Lock-in Risk' is unknown, which could pose challenges for the 'Thunderbird Pro' cloud services.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

GDPR applies to any organization processing personal data of EU/EEA residents. Mozilla Foundation/MZLA Technologies Corporation operates globally and likely processes personal data from EU users through Thunderbird downloads, user support, donations, and telemetry. While the risk of major fines exists (up to 4% of annual turnover), Mozilla has historically shown commitment to privacy and data protection. The medium risk reflects uncertainty about current compliance status and the need for formal assessment.

Evidence: https://www.thunderbird.net/, https://blog.thunderbird.net/2020/01/thunderbirds-new-home/

SOC 2 (source) — Assessment Required

SOC2 is relevant for service organizations that store, process, or transmit customer data. Mozilla Foundation/MZLA Technologies Corporation provides software services and likely processes user data through downloads, support systems, and donation processing. While not legally required, SOC2 compliance would demonstrate commitment to security and privacy controls. The medium risk reflects the potential reputational and business impact of not having SOC2 attestation, especially for enterprise users.

Evidence: https://www.thunderbird.net/, https://www.thunderbird.net/en-US/contact

ISO 27001 (source) — Assessment Required

ISO 27001 is an international standard for information security management systems. For a technology organization like Mozilla Foundation/MZLA Technologies Corporation that develops software used globally and handles user data, ISO 27001 certification would demonstrate systematic approach to information security. The medium risk reflects the importance of information security in software development and the potential reputational benefits of certification, though it's not legally mandated.

Evidence: https://www.thunderbird.net/en-US/about, https://www.thunderbird.net/en-US/contact

Financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report