Open-Xchange AG
Germany · owned by Independent (Germany) · www.open-xchange.com · 11 vendors
Open-Xchange (OX) is a German software company and self-described world's leading independent email provider, offering open-source-based email and collaboration solutions for telcos, hosting providers, and the public sector via its flagship OX App Suite platform. The company also develops and maintains Dovecot Pro, a carrier-grade IMAP email server, and PowerDNS, a high-performance DNS solution for mission-critical networks. Hundreds of millions of users worldwide rely on OX-powered services daily.
Resilience scores
- Digital Sovereignty: 18
- Digital Resilience: 9
- Financial Resilience: 6
Disruption prediction
Open-Xchange AG has an estimated 11% probability of disruption in the next 6 months.
6 of Open-Xchange AG's 11 vendors monitored for disruptions.
Technology vendors
- Anthropic, PBC — Technology — United States
- HubSpot, Inc. — Technology — United States
- Mistral AI — Technology — France
- and 8 more
Services catalogue
7 services in catalogue across 4 categories; runs on 11 sub-vendors.
- Authenticated Bridge
- Cloud Solutions
- Collaboration Software
Insights
Last updated 2026-08-16 · revision 9
11 direct vendors, 216 subvendors
Direct vendors by controlling owner country (sample)
- France: 1
- Germany: 1
- Singapore: 1
Subvendors by controlling owner country (sample)
- Canada: 6
- Norway: 2
- Japan: 1
Migration Readiness: 10/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Open-Xchange AG exhibits exceptionally high migration readiness. Their internal tech stack is predominantly modern, cloud-native, and containerized, utilizing technologies such as Docker, Kubernetes, Helm, AWS, and GCP. This architecture is ideal for seamless migration to various cloud environments or for re-platforming, as it promotes portability and reduces dependency on legacy infrastructure. The company's deep expertise in managing complex regulatory environments, particularly GDPR and IT-Grundschutz (as evidenced by their public sector offerings and focus on data sovereignty), positions them well to navigate data residency and compliance requirements during any migration. Their experience with EU and US data centers further supports this. Financial stability, inferred from a history of strategic growth and mergers, suggests the capacity to fund significant migration initiatives. The 'Vendor Relationships' data, specifically 'Total Vendors: 0', is a critical factor for migration readiness. If taken literally, it implies an extremely low level of vendor lock-in, as there are no major external vendor contracts or proprietary technologies to untangle, which dramatically simplifies and accelerates any migration effort. Even if the 'Vendor HQ Countries' and 'Vendor Geographic Diversity' imply some indirect vendor involvement for '20 services', the overall open-source nature of their core products (Dovecot, PowerDNS) and their internal tech stack indicates a strong degree of control and flexibility, minimizing migration challenges typically associated with vendor dependencies. The company's ability to offer 'Telco Email Transition' services also demonstrates their internal capabilities and experience in large-scale platform migrations.
Compliance
8 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 is typically used for non-financial assurance engagements, including sustainability reporting, data privacy attestations, and controls reporting (similar to SOC 2 but under IAASB standards). Open-Xchange AG does not appear to be in a sector where ISAE 3000 reporting is mandated (e.g., financial services, listed companies). However, as a cloud service provider with enterprise customers, ISAE 3402 (a sub-standard for service organizations) could be relevant. Risk is Low because: (a) ISAE 3000/3402 is not a regulatory requirement for OX's industry; (b) ISO 27001 certification serves as the primary assurance mechanism; (c) no evidence of customer demand for ISAE 3000 reports has been found. The risk would increase if OX expands into financial services or regulated industries requiring ISAE 3402 reports.
Evidence: https://www.open-xchange.com/about-ox/why-open-xchange/ox-trust-center/?hsLang=en
Cyber Resilience Act (source) — Assessment Required
The EU Cyber Resilience Act (Regulation (EU) 2024/2847), which entered into force in December 2024 with phased compliance deadlines (reporting obligations from September 2026, full compliance by December 2027), directly applies to manufacturers of products with digital elements — including software products. Open-Xchange AG develops and distributes OX App Suite, Dovecot Pro, and PowerDNS, all of which are software products with digital elements. OX would likely be classified as a manufacturer under the CRA, with obligations including: security-by-design requirements, vulnerability handling, security update obligations, and conformity assessment. Risk is Medium because: (a) the CRA is new and compliance timelines are still being established; (b) OX's existing ISO 27001 certification and security practices (penetration testing, bug bounty, vulnerability disclosure) provide a strong foundation; (c) however, formal CRA conformity assessment has not been publicly disclosed; (d) non-compliance could result in market access restrictions within the EU.
Evidence: https://www.open-xchange.com/about-ox/why-open-xchange/ox-trust-center/?hsLang=en, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847
BDSG — Compliant
As a German-incorporated company, Open-Xchange AG is subject to the BDSG (Bundesdatenschutzgesetz), which supplements and implements GDPR at the national level in Germany. The BDSG includes additional requirements for employee data processing, works council involvement, and specific sectoral rules. Given OX's demonstrated GDPR compliance posture (TOMs, Privacy Policy, Ethics & Compliance channel), BDSG compliance is highly likely. Risk is Low as BDSG compliance is largely co-extensive with GDPR compliance for a company of OX's profile.
Evidence: https://www.open-xchange.com/ethics-compliance?hsLang=en, https://ox.io/privacy, https://www.open-xchange.com/about-ox/why-open-xchange/ox-trust-center/?hsLang=en
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Open-Xchange AG demonstrates moderate financial resilience derived largely from qualitative and structural factors rather than disclosed financial performance. The company benefits from a sticky, embedded customer base of large telcos, ISPs and hosting providers (IONOS, KPN, Swisscom, Rackspace, TalkTalk, Deutsche Telekom heritage) where email/DNS infrastructure switching costs are extremely high, producing recurring multi-year revenue. Its carrier-grade positioning and role in Europe's digital-sovereignty push (e.g., Schleswig-Holstein migration in 2024) provide a structural tailwind and diversified product mix across OX App Suite, Dovecot Pro, and PowerDNS. However, the resilience score is tempered by significant risks and limited transparency. Customer concentration is likely high, with a handful of large telcos/hosters dominating revenue. The company faces intense competition from hyperscalers (Google Workspace, Microsoft 365) and must monetize open-source products against free community editions. As a privately held AG backed by long-standing VC investors (eCAPITAL, Iris Capital), there is inherent exit/ownership-change risk, and the lack of published quantitative financials (revenue, EBIT, equity) makes credit and counterparty due diligence difficult. Historical press coverage placed revenues at €30–40M annually in the late 2010s, but current figures are unverified.
Key strengths: Sticky, embedded customer base with high switching costs among telcos/ISPs, Carrier-grade positioning serving large-scale service providers, European digital-sovereignty tailwind (public-sector demand for non-US alternatives), Diversified product mix across App Suite, Dovecot Pro, and PowerDNS, Experienced ownership and leadership (eCAPITAL, Iris Capital, ex-1&1 CEO Andreas Gauger), Recurring, multi-year revenue model from per-mailbox/per-user licensing
Risk factors: Customer concentration risk with a few large telcos/hosters (IONOS, Deutsche Telekom, KPN), Hyperscaler competition from Google Workspace and Microsoft 365, Open-source monetization challenge (free community editions of Dovecot, PowerDNS), Limited financial disclosure/transparency as a private AG, VC ownership creates potential exit/consolidation event risk, FX exposure from USD-denominated North American revenue
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.