A EUR 5 Million Round With an Unusual Pitch

xorlab, a Zurich-based email security company, has closed a EUR 5 million Series A+ round earmarked for expansion across the DACH region, Benelux, and the Nordics. The company sells threat detection for phishing, business email compromise, and account takeover, the everyday attacks that make email one of the most exploited channels into a corporate network.

Spicehaus Partners led the round as an existing investor, joined by continuing backers Grapha Holding, EquityPitcher Ventures, and ZKB Start-up Finance. The announcement landed on September 1, and five million euros is modest next to the sums late-stage security and AI startups routinely raise elsewhere in Europe. That the same set of investors chose to write another check, rather than a fresh syndicate resetting the valuation, reads as a vote of continuity rather than a rescue.

InvestorRole in the round
Spicehaus PartnersLead investor (existing)
Grapha HoldingContinuing investor
EquityPitcher VenturesContinuing investor
ZKB Start-up FinanceContinuing investor

The round matters less for its size than for what the money is funding: a wider push for a product built around one design decision most email security vendors don't offer as a genuine choice, letting the customer pick which jurisdiction its mail actually runs in. Email also remains one of the most common entry points for the incidents DORA and NIS2 were written to reduce, which is part of why a niche player scaling in this exact category is worth watching beyond its own balance sheet. A EUR 5 million round doesn't buy new technology so much as it buys sales capacity, local staff, and the compliance paperwork needed to sell into a new set of national regulators, unglamorous work that determines whether the pitch actually reaches procurement teams.

The Customer List Is the Real Signal

xorlab's existing customer list already reads like a checklist of regulated Europe: private bank Julius Baer, telecom operator Swisscom, wealth manager Vontobel, security and currency technology group Giesecke+Devrient, and the research organisation CERN. Together they span exactly the mix of sectors DORA, NIS2, and GDPR were each written to cover, financial services, critical infrastructure, and organisations holding data whose loss would be genuinely consequential.

None of these are speculative logos. A bank sits squarely inside DORA's scope. A telecom operator sits inside NIS2's. A firm like Giesecke+Devrient works in currency, identity, and security technology, where operational resilience and data control are already board-level concerns, and CERN runs sensitive international research communications that plenty of governments would rather not see routed through infrastructure they don't control. Regulators drafting DORA and NIS2 did not invent this concern from scratch; they wrote it because businesses like these were already worried about concentration risk in a small number of non-EU vendors, and that risk isn't abstract for any of these five, since a bank, a telecom operator, a security manufacturer, and a physics laboratory all depend on email working correctly and confidentially every single day.

The product is built to match that concern rather than argue it away: customers choose fully on-premises deployment with local processing and storage, a hybrid setup, or a cloud option, and in every one of those modes the data centres sit in the EU and the staff handling the service are based in Europe. That range of options matters because compliance teams increasingly need to document not just that data is encrypted, but which country's courts and intelligence services could theoretically compel access to it.

What Changed for an EU Compliance Buyer This Week

Before this week, an EU compliance team evaluating email security could reasonably treat vendor jurisdiction as a footnote below feature comparisons and price. A funded, customer-backed alternative built specifically around that footnote makes it harder to leave off the evaluation sheet. That shift matters even when the check size is small, because it changes what a vendor's sales team can credibly promise in a due-diligence questionnaire, and it hands smaller vendors a template for winning regulated customers on jurisdiction alone, not just on catching more phishing than the incumbent.

xorlab frames its pitch explicitly around DORA, NIS2, and GDPR compliance, and around cutting reliance on US-controlled infrastructure and security vendors, the framing the company and its backers call sovereign. Its chief executive put the underlying argument plainly: Europe needs its own cybersecurity champions, not European copies of US incumbents, a line that targets an anxiety many EU boards already carry, that critical infrastructure decisions made in Brussels or Berlin can still be shaped by decisions made in Washington.

None of this makes xorlab a guaranteed winner, and five million euros doesn't buy market dominance in a category with entrenched, well-funded incumbents. But it does confirm that jurisdiction has become a line item companies will actually pay to control, not just a compliance worry they note and move past, and for an industry built on convincing buyers that the next feature matters most, that's a genuinely different sales conversation.

Why We Do This

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.