Proton’s CTO: No company is going to jail for you

Summary of Proton’s CTO: No company is going to jail for you

by The Verge

1h 24mJuly 16, 2026

Overview of Proton’s CTO: No company is going to jail for you

In this Decoder episode, The Verge’s Nilay Patel speaks with Bart Butler, CTO of Proton, about how the company tries to make privacy a product guarantee rather than a marketing promise. The conversation focuses on Proton’s architecture, Swiss legal structure, foundation ownership, and direct-to-user business model as safeguards against data misuse. It also digs into the real-world limits of that model: legal demands from governments, the Stop Cop City data handoff, Europe’s surveillance and age-verification debates, and the challenge of using AI without undermining privacy.

What Proton Is Trying to Build

Proton presents itself as a privacy-first ecosystem of productivity and security tools, including:

  • Proton Mail
  • Proton VPN
  • Proton Drive
  • Proton Calendar
  • Proton Pass
  • Proton Meet
  • Lumo, its AI assistant

Bart Butler frames Proton’s real product as trust: users pay the company directly, and Proton’s architecture is designed so it cannot easily access, sell, or leak user data.

Core privacy principles

  • End-to-end encryption is the foundation wherever possible.
  • Proton’s business model is subscription-based, not ad-driven.
  • The company tries to align its incentives with users by making surveillance and data monetization technically and financially unattractive.
  • Trust is reinforced by:
    • technical design
    • corporate structure
    • jurisdictional choices

How Proton Is Structured to Resist Pressure

A major theme is that Proton is built with “defense in depth” against mission drift.

Organizational setup

  • Proton is a Swiss corporation with about 650 employees.
  • A Proton Foundation holds a controlling stake in Proton AG.
  • The foundation is intended to preserve the company’s privacy mission even if leadership changes.
  • Proton says this structure makes hostile acquisition or a values shift much harder.

How decisions get made

  • Proton is organized into product divisions and cross-functional support teams.
  • Mail and Calendar are grouped closely; Drive, Pass, VPN, and Lumo are separate divisions.
  • Butler says the company tries to avoid internal politics and keep management layers shallow.
  • Leadership encourages employees to challenge decisions and surface disagreements early.

The Tension Between Privacy and Growth

Butler emphasizes that Proton is not trying to be a tiny idealistic niche product. It wants to compete with big tech at scale.

Key idea

  • Proton cannot win by being “10x or 100x smaller” than major platforms.
  • Growth is part of the mission because privacy has to be “privacy by default” at mainstream scale.
  • The company wants products that are:
    • easy to use
    • feature-complete
    • secure
    • private without requiring technical expertise

He argues that Proton must compete in capitalism while preserving its values, not retreat from the market entirely.

Government Pressure, Jurisdiction, and the Stop Cop City Case

A major segment focuses on the limits of Proton’s protections when governments make legal demands.

Stop Cop City / Swiss request

  • Proton handed over payment data in a case tied to the Stop Cop City protest investigation.
  • That data went through Swiss authorities and ultimately to the FBI.
  • Butler argues Proton complied with a valid legal process under Swiss jurisdiction.

Proton’s position

  • The company says it cannot decide which government requests are legitimate.
  • It relies on:
    • Swiss law
    • mutual legal assistance processes
    • encryption that limits what Proton can actually hand over

“No company is going to jail for you”

Butler repeatedly stresses that:

  • companies are always subject to law
  • no company is above jurisdiction
  • privacy is about minimizing what can be compelled, not claiming immunity

Threats to Leave Switzerland or the EU

The episode also covers Proton’s warnings that it may leave countries or regions whose laws would undermine its privacy mission.

Switzerland

  • Proton has threatened to leave if Swiss law becomes incompatible with privacy guarantees.
  • Butler says the threat is serious, not rhetorical.

EU and “chat control”

  • Proton has also signaled it may leave EU countries if laws require message scanning or weaken encryption.
  • Butler calls mandatory scanning and backdoors dangerous because they create systems that can later be repurposed for mass surveillance.

Child Safety, Age Verification, and the Encryption Debate

This is one of the most substantial parts of the conversation.

Butler’s position

  • He acknowledges that child sexual abuse material (CSAM) is a real and serious problem.
  • But he argues that backdoors and blanket scanning are not acceptable solutions.
  • His core claim: you cannot build a backdoor that only the “good guys” can use.

Alternatives he points to

  • Zero-knowledge proofs for age verification
  • Privacy-preserving credentials
  • More targeted enforcement and abuse detection
  • Better resourcing in the physical world, not just digital surveillance

His warning

  • Systems built for age verification or content scanning can become tools for authoritarian abuse.
  • Once anonymity is weakened, the same infrastructure can be used to identify dissidents, journalists, or political opponents.

How Proton Handles Abuse Without Mass Scanning

Butler says Proton does not simply refuse to police abuse.

What Proton does

  • The company dedicates nearly 10% of total resources to anti-abuse work.
  • It uses internal signals to detect abusive behavior.
  • It can shut down accounts suspected of ransomware or other misuse.
  • He says Proton often identifies bad actors before legal requests arrive.

Important limitation

  • Proton still cannot inspect encrypted content in many cases.
  • The company relies on a mix of:
    • behavioral indicators
    • reports
    • account patterns
    • legal requests where applicable

AI, Lumo, and Data Sovereignty

The final section covers AI and how it changes Proton’s product strategy.

Proton’s AI approach

  • Lumo is Proton’s privacy-focused AI assistant.
  • It is built using open-source models, not proprietary frontier models trained in-house.
  • Proton runs inference itself and avoids handing data to third-party model providers when possible.

Why this matters

Butler sees AI as both:

  • a competitive necessity
  • a new privacy risk

He argues that Proton’s approach gives users control over when they choose to share data with an AI system, instead of defaulting to broad data collection.

His view of AI’s effect on software

  • AI has sped up coding and shifted bottlenecks elsewhere.
  • It is most useful in software because software is testable and rule-based.
  • He sees AI as a major productivity boost, but not a total reinvention of software engineering.

Main Takeaways

  • Proton’s core promise is privacy by design, not trust in leadership alone.
  • The company’s encryption, subscription model, and foundation structure are all meant to align incentives with users.
  • Proton accepts that it must still obey law and jurisdiction, but wants to minimize what any government can compel.
  • Butler strongly opposes mass surveillance, backdoors, and indiscriminate content scanning.
  • He believes child safety can be addressed with more privacy-preserving technical and policy approaches.
  • AI is being integrated in a way that tries to preserve user control, not erode it.

Bottom Line

The episode frames Proton as a case study in whether a privacy company can survive at scale without being absorbed by the incentives it opposes. Butler’s answer is that it can—but only if the product architecture, corporate governance, and business model all work together. The real tension, he argues, is not whether privacy matters, but whether modern regulation and AI-driven infrastructure will leave any room for it.