Best European endpoint protection

A BI platform reads everything: revenue, endpoint protection, customer records, churn. These European alternatives to Power BI and Tableau cover dashboards, planning and embedded analytics, and each of them can be deployed so that the underlying data never leaves European infrastructure.

How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect the order tools appear in. It never buys a listing: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect the order in which tools appear; it never affects whether a tool is listed. Editorial policy

13 European Endpoint Protection Tools

ESET

Detection built in Bratislava since 1992

#1 of 13 in this category
Slovakia
Top independent scores Low false positives Published pricing

Bitdefender

Top-tier detection with managed response

#2 of 13 in this category
Romania
Managed detection MSP channel EU processing

TEHTRIS

French detection and response with ANSSI-qualified parts

#3 of 13 in this category
France
ANSSI qualified Endpoint to container FR processing

CrowdSec

Open-source server protection with shared threat signals

#4 of 13 in this category
France
Open source Community feed For servers

G DATA

Written and processed entirely in Germany since 1985

#5 of 13 in this category
Germany
No-backdoor guarantee DE processing Since 1985

WithSecure

Co-monitored detection through European partners

#6 of 13 in this category
Finland
Co-monitoring Partner channel Since 1988

Hornetsecurity

Microsoft 365 security where the compromise starts

#7 of 13 in this category
Germany
Email security M365 backup ISO 27001

Stormshield

ANSSI-qualified French EDR from an Airbus Defence and Space subsidiary, built for sovereignty-grade buyers

#8 of 13 in this category
France Enterprise pricing on request
ANSSI CSPN qualification and CCN-LINCE (Spain) approvalSignatureless behavioural detectionDevice control to reduce attack surface

DriveLock

German endpoint platform combining device control, application whitelisting, encryption and antivirus in one console

#9 of 13 in this category
Germany Per endpoint, quoted
Device and application control alongside antivirusISO 27001 / ISO 9001, TeleTrusT "made in Germany" sealAzure hosting in European data centres

IKARUS Security Software

Austrian antivirus vendor detecting malware from Vienna since 1986, OPSWAT Platinum and VB100 certified

#10 of 13 in this category
Austria Per seat, quoted through sales
Cloud-managed anti.virus for endpoints and serversOPSWAT Platinum and Virus Bulletin VB100Also offers mail security and mobile device management

Heimdal

Danish platform bundling next-gen antivirus, EDR, patch management, DNS security and PAM in one console

#11 of 13 in this category
Denmark Per endpoint, quoted
Next-gen antivirus, EDR and managed XDRPatch management and DNS security includedEU storage region selectable (Netherlands or Germany)

Arcabit

Polish antivirus vendor since 2004, VB100 certified, with a RoundKick EDR module for larger networks

#12 of 13 in this category
Poland Enterprise pricing on request
Endpoint, Small Office and Server protection tiersRoundKick EDR moduleVirus Bulletin VB100 certified

SentryBay

British Armored Client stops keylogging and screen capture on BYOD and VDI endpoints no agent can reach

#13 of 13 in this category
United Kingdom Enterprise pricing on request
Blocks keylogging, screen capture and DLL injectionBuilt for unmanaged, BYOD and VDI/DaaS endpointsComplements rather than replaces anti-malware

Key takeaways

  • ESET ranks #1 among the European endpoint protection vendors in this directory. It has been detecting malware from Bratislava since 1992, its engine is consistently near the top of independent AV-Comparatives and AV-TEST results, and it is one of the few in this market that publishes business pricing.
  • Europe is unusually strong here. Anti-malware is one of the few software categories where the European vendors are not the alternative but the originals: ESET in Slovakia, Bitdefender in Romania and G DATA in Germany all predate most of the American names they now get compared with.
  • An endpoint agent is the most privileged software you install. It runs as root or SYSTEM on every machine, updates itself automatically, and reports home continuously. Where the company writing it is established is not a compliance detail; it is the whole trust model.
  • CrowdSec is a different shape from the rest and worth understanding on its own terms: open source, community-sourced threat intelligence, and aimed at servers and infrastructure rather than laptops.

European endpoint protection is anti-malware and endpoint detection and response software from a vendor established in Europe — and the establishment question bites harder here than anywhere else in this directory, because an endpoint agent runs with the highest privileges on every machine you own and sends telemetry about all of them to whoever wrote it.

European endpoint protection compared

European endpoint protection tools compared on position, country, entry price and best use
PositionToolEstablishedEntry priceBest for
#1 ESET Slovakia Per seat per year, published for business tiers Any organisation that wants proven detection with a console a normal IT team can run
#2 Bitdefender Romania Per seat per year, published Companies wanting top-tier detection with strong managed and MSP options
#3 TEHTRIS France Enterprise pricing on request European organisations with real security maturity and sovereignty requirements
#4 CrowdSec France Free and open source / paid plans for the threat feed Teams protecting internet-facing servers who want shared threat intelligence without a licence
#5 G DATA Germany Per seat per year, published German organisations that want detection built and processed entirely in Germany
#6 WithSecure Finland Per seat, quoted through partners Mid-sized and larger European organisations buying through a partner
#7 Hornetsecurity Germany Per seat per month, quoted Microsoft 365 tenants where the real risk arrives by email
#8 Stormshield France Enterprise pricing on request French and EU public-sector buyers needing sovereignty guarantees
#9 DriveLock Germany Per endpoint, quoted German mid-market wanting device control and antivirus in one console
#10 IKARUS Security Software Austria Per seat, quoted through sales Austrian and DACH organisations wanting a long-established AV engine
#11 Heimdal Denmark Per endpoint, quoted Teams wanting endpoint, patch and DNS security in one platform
#12 Arcabit Poland Enterprise pricing on request Polish organisations wanting a domestic alternative to Kaspersky
#13 SentryBay United Kingdom Enterprise pricing on request Protecting BYOD, VDI and unmanaged endpoints from keylogging

Every European endpoint protection tool reviewed

#1 ESET

Bratislava, Slovakia Founded 1992 Per seat per year, published for business tiers Free 30-day trial

Best for: Any organisation that wants proven detection with a console a normal IT team can run

  • Operating company. ESET, spol. s r.o.
  • Jurisdiction. EU (Slovakia)
  • Where the data sits. European Union
  • Independent checks. ISO 27001
  • Source code. Closed source
  • Replaces. CrowdStrike, SentinelOne, Norton, Microsoft Defender for Business

ESET, spol. s r.o. has been writing detection software in Bratislava since 1992, which makes it older than most of the American vendors it now competes with and older than the category as a marketing term.

The engine is the reason to take it seriously: it sits at or near the top of AV-Comparatives and AV-TEST year after year, with a consistently low false-positive rate, which matters more in practice than a headline detection percentage because false positives are what makes an IT team switch the product off.

What makes it the pick here rather than merely a good option is the combination of that engine with a product a normal team can actually operate.

The console is manageable without a security specialist, the agent is light enough that people do not notice it, business pricing is published rather than quoted, and there is a real EDR tier for organisations that grow into needing one. The limits are the ones that come with breadth: it is not the deepest threat-hunting platform on this list, and a large enterprise with its own security operations centre will find TEHTRIS or WithSecure aimed more precisely at them.

What ESET does well

  • Consistently near the top of independent AV-Comparatives and AV-TEST results
  • Low false-positive rate, which is what keeps it switched on
  • Published business pricing rather than a quote
  • Light agent and a console a general IT team can run
  • Slovak company, EU processing, building detection since 1992

Where ESET falls short

  • Not the deepest threat-hunting platform here
  • EDR tier is priced separately from the base protection
  • Aimed at broad usability rather than at a mature security team

Standout feature. Thirty years of engine, not thirty months: the detection has been tested publicly and independently for longer than most competitors have existed.

#2 Bitdefender

Bucharest, Romania Founded 2001 Per seat per year, published Free trial

Best for: Companies wanting top-tier detection with strong managed and MSP options

  • Operating company. S.C. Bitdefender S.R.L. (J40/20427/2005)
  • Jurisdiction. EU (Romania)
  • Where the data sits. European Union
  • Independent checks. ISO 27001
  • Source code. Closed source
  • Replaces. CrowdStrike, SentinelOne, Norton

S.C. Bitdefender S.R.L. in Bucharest is the other European vendor that consistently tops independent testing, and on raw detection there is very little between it and ESET. Where it differs is the shape of the business around the product: a large managed detection and response offering, a deep MSP channel, and a habit of licensing its engine to other security vendors, which is why Bitdefender technology turns up inside products that do not carry its name.

For a company without security staff, the managed option is the genuinely interesting part, because it answers the question the rest of this category leaves open — who reads the alerts.

The trade-offs are worth knowing: the product range is wide enough to be confusing at first, some capabilities sit behind tiers that are not obvious from the pricing page, and the console has more in it than a small IT team will use. None of that touches the detection, which is excellent.

What Bitdefender does well

  • Detection scores at the very top of independent testing
  • Strong managed detection and response for companies without security staff
  • Deep MSP channel and published per-seat pricing
  • Romanian company, EU processing

Where Bitdefender falls short

  • Wide product range that takes work to navigate
  • Capabilities split across tiers in ways the pricing page does not make obvious
  • Console offers more than a small team needs

Standout feature. Someone else reads the alerts: the managed option answers the question that sinks most endpoint detection projects.

#3 TEHTRIS

Paris, France Founded 2010 Enterprise pricing on request Demo on request

Best for: European organisations with real security maturity and sovereignty requirements

  • Operating company. TEHTRI-Security SAS (RCS Paris 521 474 445)
  • Jurisdiction. EU (France)
  • Where the data sits. France
  • Independent checks. ANSSI-qualified components
  • Source code. Closed source
  • Replaces. CrowdStrike, SentinelOne, Palo Alto Cortex

TEHTRI-Security SAS in Paris built its platform for organisations where the sovereignty question is not a preference but a requirement — French public sector, defence-adjacent industry, critical infrastructure. It covers endpoints, servers, mobile and containers under one detection and response platform, with components qualified by ANSSI, the French national cybersecurity agency, and a stated position of not sending data outside France.

That focus explains both the appeal and the limits. For a European organisation that has to demonstrate where its security telemetry lives, this is a far shorter conversation than with any American vendor, and the platform is genuinely broad.

But it assumes you have people who can run a detection and response platform, pricing is quoted per engagement, and outside France the brand and the partner network are much thinner than ESET or Bitdefender. It is not a product to buy because it looked good in a comparison table.

What TEHTRIS does well

  • Detection and response across endpoints, servers, mobile and containers
  • ANSSI-qualified components and a clear French data position
  • Built for organisations with sovereignty requirements rather than preferences
  • French company, French processing

Where TEHTRIS falls short

  • Assumes a security team that can run it
  • Enterprise pricing on request
  • Thin partner network outside France

Standout feature. Sovereignty as a specification: ANSSI qualification is an external check on the claim rather than a marketing line about it.

#4 CrowdSec

Montrouge, France Founded 2020 Free and open source / paid plans for the threat feed Free

Best for: Teams protecting internet-facing servers who want shared threat intelligence without a licence

  • Operating company. CrowdSec SAS (RCS 880 140 496)
  • Jurisdiction. EU (France)
  • Where the data sits. European Union
  • Independent checks. Open source (MIT)
  • Source code. Open source
  • Replaces. Cloudflare bot management, Fail2ban at scale

CrowdSec SAS in Montrouge is the odd one in this category and belongs here anyway.

It is open source under MIT, it runs on servers rather than laptops, and it works by reading your logs, spotting attack behaviour, and blocking the addresses behind it — then sharing that signal with everyone else running CrowdSec, so an address hammering a server in Poland is blocked in Portugal before it arrives. Think of it as Fail2ban with a community behind it and a modern architecture.

It does not scan files, it does not protect laptops, and comparing it with ESET on malware detection is comparing two different jobs. What it does do is remove a whole class of noise from internet-facing infrastructure for nothing, with paid plans only for the enriched threat feed and enterprise features. The catch is the usual open-source one: you run it, you configure the scenarios, and the quality of what you get out depends on the attention you put in.

What CrowdSec does well

  • Free and open source under MIT, with paid tiers only for the enriched feed
  • Community threat intelligence: one attacker blocked everywhere at once
  • Built for servers and internet-facing services
  • French company, EU processing

Where CrowdSec falls short

  • Not endpoint anti-malware; it does not protect laptops
  • You run and tune it yourself
  • Young company compared with the rest of this list

Standout feature. The network effect turned defensive: every participant blocking an attacker makes the block faster for everyone else.

#5 G DATA

Bochum, Germany Founded 1985 Per seat per year, published Free 30-day trial

Best for: German organisations that want detection built and processed entirely in Germany

  • Operating company. G DATA CyberDefense AG
  • Jurisdiction. EU (Germany)
  • Where the data sits. Germany
  • Independent checks. No-backdoor guarantee, German TeleTrusT seal
  • Source code. Closed source
  • Replaces. CrowdStrike, Norton, Microsoft Defender for Business

G DATA CyberDefense AG has been in Bochum since 1985 and claims, with a reasonable case, to have shipped one of the first anti-virus products at all. Everything about the company is built around a German position: development in Germany, data processing in Germany, and a published no-backdoor guarantee alongside the German TeleTrusT "IT Security made in Germany" seal, which is an external commitment rather than a slogan.

For a German public body or a Mittelstand company with procurement rules that ask where software is written and where the telemetry goes, that combination is the whole argument, and it is a strong one.

Elsewhere the case is narrower: detection is good but not consistently at the ESET and Bitdefender level in independent testing, the interface is functional rather than modern, and the international partner network is smaller. Bought for the right reason it is an excellent fit; bought on a feature comparison it will look middling.

What G DATA does well

  • Developed and processed entirely in Germany
  • Published no-backdoor guarantee and TeleTrusT seal
  • Independent since 1985, one of the oldest vendors in the field
  • Published per-seat pricing and a 30-day trial

Where G DATA falls short

  • Detection scores solid but below ESET and Bitdefender in recent testing
  • Interface is functional rather than modern
  • Smaller partner network outside German-speaking markets

Standout feature. A written no-backdoor guarantee: a commitment almost nobody else in this market is willing to put in writing.

#6 WithSecure

Helsinki, Finland Founded 1988 Per seat, quoted through partners Trial on request

Best for: Mid-sized and larger European organisations buying through a partner

  • Operating company. WithSecure Corporation (Business ID 0705579-2)
  • Jurisdiction. EU (Finland)
  • Where the data sits. European Union
  • Independent checks. ISO 27001
  • Source code. Closed source
  • Replaces. CrowdStrike, SentinelOne, Sophos

WithSecure Corporation in Helsinki is the business half of what used to be F-Secure, separated in 2022 so the consumer and corporate sides could go their own ways. It sells almost entirely through partners and managed service providers, with endpoint protection, EDR and co-monitored detection where WithSecure analysts watch alongside your team — which is a sensible middle ground between running detection yourself and handing it over completely.

The partner-led model is the thing to plan around. It means the quality of what you get depends substantially on which partner you buy through, pricing is quoted rather than published, and a small company buying direct is not really the target. For a mid-sized European organisation that already works with an IT partner, it is a strong and unusually mature option from a company that has been doing this since 1988.

What WithSecure does well

  • Co-monitored detection: their analysts alongside your team
  • Long track record, established 1988, Finnish company
  • Mature partner and managed-service channel across Europe
  • EU processing

Where WithSecure falls short

  • Sold through partners, so your experience depends on which one
  • Quoted pricing rather than published
  • Not aimed at small companies buying direct

Standout feature. Co-monitoring rather than all-or-nothing: their analysts watch with you instead of instead of you.

#7 Hornetsecurity

Hanover, Germany Founded 2007 Per seat per month, quoted Free trial

Best for: Microsoft 365 tenants where the real risk arrives by email

  • Operating company. Hornetsecurity GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. European Union
  • Independent checks. ISO 27001
  • Source code. Closed source
  • Replaces. Proofpoint, Mimecast, Microsoft Defender for Office

Hornetsecurity GmbH in Hanover comes at endpoint security from the direction most compromises actually take: the inbox. The product set is built around Microsoft 365 — email filtering, advanced threat protection, backup for mailboxes and SharePoint, security awareness training and permission management — rather than around an agent on the laptop.

Listing it here needs the caveat stated plainly: it is not an endpoint anti-malware suite and will not replace ESET or Bitdefender on your machines.

It sits in front of them, and for many organisations it prevents more incidents than the endpoint agent ever will, because phishing and business email compromise do not arrive as files to be scanned. Pricing is quoted per seat through partners, and the whole proposition assumes you are on Microsoft 365, which makes it either a perfect fit or irrelevant.

What Hornetsecurity does well

  • Aimed at where compromise actually starts, which is email
  • Backup, awareness training and permission management alongside filtering
  • German company, EU processing, ISO 27001
  • Deep Microsoft 365 integration

Where Hornetsecurity falls short

  • Not endpoint anti-malware; it complements rather than replaces it
  • Only relevant if you run Microsoft 365
  • Quoted pricing through partners

Standout feature. It guards the door the attackers use: for most organisations the inbox compromises more machines than the machines do.

#8 Stormshield

Issy-les-Moulineaux, France Enterprise pricing on request

Best for: French and EU public-sector buyers needing sovereignty guarantees

  • Operating company. Stormshield
  • Jurisdiction. EU (France)
  • Where the data sits. Mostly the EEA, with international transfers under EU standard contractual clauses
  • Independent checks. ANSSI CSPN, CCN-LINCE (Spain), Cybersecurity Made in Europe label
  • Source code. Closed source
  • Replaces. CrowdStrike, SentinelOne, Palo Alto Cortex

Stormshield Endpoint Security Evolution is built by a company that already belongs to this directory's most demanding audience: Stormshield is a wholly-owned subsidiary of Airbus Defence and Space Cyber Programmes, and its endpoint agent holds a CSPN qualification from ANSSI, the French national cybersecurity agency, plus a Producto Cualificado approval from Spain's CCN-LINCE.

Those are external checks TEHTRIS's ANSSI-qualified components share but that ESET, Bitdefender and G DATA do not publish, which makes Stormshield the second sovereignty-grade option in this category, aimed at the same French public-sector and critical-infrastructure buyers TEHTRIS serves.

Where SES Evolution differs from TEHTRIS is emphasis: signatureless behavioural detection, device control and an agent architecture hardened against direct attacks on itself, rather than a platform reaching into mobile and containers.

Stormshield's own privacy notice says data is processed mostly within the EEA, with standard contractual clauses covering the rest. Pricing is quoted rather than published, there is no trial listed, and — like TEHTRIS — the partner network thins out fast outside France; a buyer without a sovereignty requirement will find ESET or Bitdefender easier to simply buy and run.

What Stormshield does well

  • ANSSI CSPN qualification and CCN-LINCE (Spain) approval
  • Signatureless behavioural detection built to survive attacks on the agent itself
  • Backed by Airbus Defence and Space
  • Device control included to reduce the attack surface
  • Data processing mostly within the EEA

Where Stormshield falls short

  • Quoted pricing only, no published price list
  • No trial listed
  • Thin partner network outside France, like TEHTRIS

Standout feature. A second sovereignty-grade option next to TEHTRIS: ANSSI's CSPN and Spain's CCN-LINCE have both signed off on the same agent.

#9 DriveLock

Munich, Germany Per endpoint, quoted Free trial available

Best for: German mid-market wanting device control and antivirus in one console

  • Operating company. DriveLock SE
  • Jurisdiction. EU (Germany)
  • Where the data sits. European Union (Microsoft Azure EU data centres)
  • Independent checks. ISO 27001, ISO 9001, TeleTrusT "IT Security made in Germany / made in EU"
  • Source code. Closed source
  • Replaces. CrowdStrike, Microsoft Defender for Endpoint, Ivanti Device Control

DriveLock SE in Munich sells a broader platform than a pure antivirus vendor: device control, application whitelisting, vulnerability management, BitLocker and disk encryption management, and Microsoft Defender orchestration sit alongside its own protection engine in one console. That breadth is the pitch for a company that currently runs device control, encryption management and antivirus as three separate products from three separate vendors, each with its own console and its own renewal date.

The company carries ISO 27001 and ISO 9001 certification and the TeleTrusT "IT Security made in Germany" and "made in EU" seals — the same category of external commitment G DATA makes with its no-backdoor guarantee, applied to a wider product.

Its cloud platform runs on Microsoft Azure with data centres in Europe, and a free trial is available, though standard pricing is quoted rather than published. The trade-off is configuration: application whitelisting and device control policies take real setup work, and a company that only wants antivirus is buying more platform than it needs.

What DriveLock does well

  • Device control, application whitelisting, encryption and antivirus in one console
  • ISO 27001 and ISO 9001 certified
  • TeleTrusT "made in Germany" and "made in EU" seals
  • Free trial available
  • Azure hosting in European data centres

Where DriveLock falls short

  • Quoted pricing, not published
  • Application and device control policies need real configuration work
  • More platform than a buyer who wants only antivirus needs

Standout feature. One console for device control, encryption and antivirus: DriveLock replaces three separate vendor relationships with one German one.

#10 IKARUS Security Software

Vienna, Austria Founded 1986 Per seat, quoted through sales Trial available on request

Best for: Austrian and DACH organisations wanting a long-established AV engine

  • Operating company. IKARUS Security Software GmbH
  • Jurisdiction. EU (Austria)
  • Independent checks. OPSWAT Platinum, Virus Bulletin VB100, Cyber Trust Austria label
  • Source code. Closed source
  • Replaces. CrowdStrike, Norton, Microsoft Defender for Business

IKARUS Security Software GmbH has been writing detection in Austria since 1986, with its first product, IKARUS virus.utilities, shipping in 1988 — a longer unbroken history than every other vendor in this category except G DATA. IKARUS anti.virus, the cloud-managed business product, blocks malicious downloads, isolates threats automatically and denies external connections from infected files, managed through a portal that handles device management, licensing and configuration profiles.

The independent signal worth weighing is OPSWAT Platinum certification and a Virus Bulletin VB100 award, plus the Austrian "Cyber Trust Austria" label — external checks on a vendor that does not publish AV-Comparatives or AV-TEST results as consistently as ESET or Bitdefender do.

Pricing is quoted through sales rather than published, and a trial has to be requested by phone or email rather than started from the site. For an Austrian or wider DACH buyer who wants a genuinely independent, long-running AV vendor rather than a reseller of someone else's engine, that is a reasonable trade.

What IKARUS Security Software does well

  • Detecting malware from Austria since 1986
  • OPSWAT Platinum certified and Virus Bulletin VB100 award
  • Cyber Trust Austria label
  • Cloud-managed portal for devices, licensing and configuration
  • Also offers mail security and mobile device management

Where IKARUS Security Software falls short

  • No published pricing; quoted through sales
  • Trial requested by phone or email, not self-serve
  • Independent test results published less consistently than ESET or Bitdefender

Standout feature. Detection work traced back to 1986: IKARUS is the second-longest-running vendor in this category, behind only G DATA.

#11 Heimdal

Copenhagen, Denmark Founded 2014 Per endpoint, quoted Free trial available

Best for: Teams wanting endpoint, patch and DNS security in one platform

  • Operating company. Heimdal Security A/S
  • Jurisdiction. EU (Denmark)
  • Where the data sits. Customer-selectable data centre: EU (Netherlands or Germany), UK, US or UAE
  • Source code. Closed source
  • Replaces. CrowdStrike, SentinelOne, Microsoft Defender for Endpoint

Heimdal Security A/S in Copenhagen sells one of the widest platforms in this category: next-generation antivirus, endpoint detection and response, patch management, DNS security, ransomware encryption protection, privileged access management and managed XDR all sit under one Heimdal console rather than across separate tools. For a team that currently patches with one product, filters DNS with another and runs antivirus with a third, consolidating onto Heimdal removes two vendor relationships rather than adding one.

The point to weigh before buying is where the data actually sits.

Heimdal's own privacy policy lets a customer choose the storage region per product, and the European options are Microsoft Azure in the Netherlands or Amazon Web Services in Germany — but the same choice list includes the UK, the United States and the UAE.

That is a materially weaker default than ESET's or Bitdefender's straightforward EU processing, and a buyer choosing Heimdal for European jurisdiction reasons has to actively select the European region rather than assume it. A free trial is available; standard pricing is quoted rather than published.

What Heimdal does well

  • Antivirus, EDR, patch management, DNS security and PAM in one platform
  • Free trial available
  • Can choose an EU storage region (Netherlands or Germany)
  • Managed XDR option for teams without a security operations centre
  • Danish company, founded in 2014

Where Heimdal falls short

  • EU hosting is a choice, not the default — UK, US and UAE regions are offered too
  • Quoted pricing, not published
  • Broad platform means less depth than a specialist in any one module

Standout feature. A wide platform with a catch: Heimdal is Danish, but its data-region picker also offers the US and the UAE, so EU residency has to be chosen deliberately.

#12 Arcabit

Warsaw, Poland Founded 2004 Enterprise pricing on request

Best for: Polish organisations wanting a domestic alternative to Kaspersky

  • Operating company. Arcabit Sp. z o.o.
  • Jurisdiction. EU (Poland)
  • Independent checks. Virus Bulletin VB100
  • Source code. Closed source
  • Replaces. Kaspersky, Norton, McAfee

Arcabit Sp. z o.o. has been building antivirus software in Warsaw since 2004, and it is the only Polish vendor in this category. Its business range covers Endpoint Security for larger networks, a lighter Small Office Security tier, server protection, and a RoundKick EDR module for detection and response — a full enough spread that Arcabit pitches itself at large corporate and business networks, not only small offices.

The independent check on the detection engine is Virus Bulletin's VB100 award, the same signal ESET, Bitdefender and IKARUS carry. What Arcabit does not publish is pricing or a self-serve trial; both routes go through a contact form, and its presence outside Poland is thin. For a Polish organisation that wants to replace Kaspersky specifically, or simply prefers a domestic vendor with central management for many installations, Arcabit is a plausible and under-documented choice rather than a well-marketed one.

What Arcabit does well

  • Building antivirus in Warsaw since 2004
  • Virus Bulletin VB100 certified
  • RoundKick EDR module for detection and response
  • Central management console for large networks
  • Polish company and support

Where Arcabit falls short

  • No published pricing or self-serve trial
  • Thin presence outside Poland
  • Smaller company with less independent test coverage than ESET or Bitdefender

Standout feature. The only Polish vendor in this category: a direct domestic alternative for organisations moving off Kaspersky.

#13 SentryBay

London, United Kingdom Founded 2007 Enterprise pricing on request

Best for: Protecting BYOD, VDI and unmanaged endpoints from keylogging

  • Operating company. SentryBay Limited
  • Jurisdiction. United Kingdom (adequacy decision, outside the EEA)
  • Source code. Closed source
  • Replaces. CrowdStrike, SentinelOne, Citrix App Protection

SentryBay Limited, in London since 2007, solves a different problem than every other tool in this category: its Armored Client does not scan for malware or hunt for behavioural anomalies, it stops keylogging, screen capture and DLL injection on endpoints nobody manages — a contractor's laptop, a BYOD phone, or a VDI or DaaS session where installing a full EDR agent is not possible or not allowed.

Its own positioning is blunt about the difference: while EDR and XDR attempt to detect the threat, Armored Client is built to just stop the data loss.

That makes it a companion to the rest of this list rather than competition for ESET or Bitdefender: a company still needs anti-malware on the machines it controls, and Armored Client covers the sessions and devices it does not.

SentryBay Limited is registered in London and majority-owned by its own UK holding company, so the British jurisdiction question has a clean answer here — it sits outside the EEA under the UK's adequacy decision. Pricing and trial availability are not published; a demo has to be requested.

What SentryBay does well

  • Protects unmanaged, BYOD and VDI endpoints that cannot run a full agent
  • Blocks keylogging, screen capture and DLL injection specifically
  • Lightweight, targeted only at chosen corporate applications
  • British company, transparently and independently owned
  • Works alongside existing EDR rather than replacing it

Where SentryBay falls short

  • Not anti-malware; does not replace ESET, Bitdefender or the others here
  • United Kingdom, outside the EEA, dependent on the adequacy decision
  • No published pricing or trial

Standout feature. It protects the sessions nobody can put an agent on: SentryBay is the only tool here built for BYOD and VDI rather than managed machines.

Are you protecting laptops or servers?

The category name covers two jobs that need different products. Protecting employee laptops means anti-malware, device control, disk encryption management and a console that a small IT team can run. Protecting internet-facing servers means blocking scanners, brute force and known-bad addresses before they reach an application.

ESET, Bitdefender, G DATA and WithSecure are laptop-and-server endpoint suites in the classical sense. TEHTRIS goes further into detection and response across a whole estate. CrowdSec is the server-side one, and comparing it with the others on malware detection misses what it is for. Hornetsecurity, meanwhile, is strongest around email, which is where most endpoint compromises actually start.

Who reads your telemetry, and under whose law?

Every EDR product ships behaviour data off the machine: process trees, file hashes, sometimes file contents. That is how detection works and it is not something to avoid, but it does mean a continuous outbound feed describing what your staff do all day.

The question worth asking is not whether the vendor is GDPR compliant — everyone says yes — but which legal entity receives that feed, in which country it is processed, and which government can compel access to it. For a European vendor established in the EU, the answer is short. That is the entire argument for this category, and it is why we record where each company is established rather than only where it hosts.

Can you actually run the console with the team you have?

Endpoint detection generates alerts, and alerts need someone to read them. A product that surfaces sophisticated detections is worth nothing to a company where nobody has time to triage a queue, and this is the most common way security spend is wasted.

ESET, Bitdefender and G DATA are built to be run by a general IT team or a managed service provider. TEHTRIS and WithSecure assume more security maturity, or a partner supplying it. Before comparing detection rates, decide honestly who will look at the console on a Tuesday afternoon, and buy for that person.

How we selected and ranked these 13 tools

Every tool on this page is in the European Purpose directory, which means the operating company is established in Europe and we have verified that from the company register or the vendor's own legal notice rather than from a marketing page. Tools headquartered outside Europe are not eligible, however good they are.

  1. Feature verification (weight: 40%). We check each capability against the vendor's own documentation and product pages, and record what the tool does rather than what the category is assumed to include.
  2. Ease of adoption (weight: 30%). Integrations, published API access, trial availability and how much configuration stands between signing and a usable result.
  3. Value and transparency (weight: 30%). Published pricing counts in a vendor's favour; quote-only pricing is recorded as quote-only rather than estimated. We weigh what a buyer gets for the entry price, not the headline feature count.
  4. Editorial review. Three people touch every page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's documentation. The three weights above decide the order; a position is a ranking against the other European tools in this category, not an absolute score.

Vendor-reported outcomes — ROI figures, margin uplift, time saved — are labelled as vendor claims wherever they appear on this page. We have not audited them, and neither has anyone else who quotes them. Read our full editorial process for how pages are re-verified.

Frequently asked questions

ESET holds #1 among the European endpoint protection vendors in this directory. It has been building detection from Bratislava since 1992, scores consistently well in independent AV-Comparatives and AV-TEST testing, and publishes business pricing rather than routing everything through sales. Bitdefender from Romania is the closest alternative and tests just as well.

Yes. TEHTRIS in France is the closest in ambition, offering detection and response across endpoints, servers and mobile from a French company with ANSSI-qualified components. ESET, Bitdefender and WithSecure all offer EDR tiers as well, generally at lower cost and aimed at organisations without a dedicated security operations team.

In this category the question is slightly backwards. ESET, Bitdefender and G DATA have been near the top of independent AV-Comparatives and AV-TEST results for years, and all three predate most of the American names they are compared with. Anti-malware is one of the few software categories where Europe never lost the lead.

Antivirus blocks known-bad files. EDR — endpoint detection and response — records what processes do, spots suspicious behaviour that no signature covers, and lets you investigate and roll back. EDR produces alerts that someone has to read, so it is only worth buying if you have that someone, whether in-house or through a managed provider.

G DATA and TEHTRIS process within their own countries, and so do Stormshield, IKARUS and Arcabit; DriveLock hosts its cloud platform on Microsoft Azure in Europe.

ESET, Bitdefender, WithSecure, CrowdSec and Hornetsecurity process within the European Union, and Heimdal lets you pick an EU storage region but also lists the UK, the US and the UAE as options.

Twelve of these thirteen vendors are established in the EU; SentryBay is British, covered by the UK's adequacy decision rather than by EU membership, which for an agent running with full privileges on every machine you own is the point of the category rather than a detail of it.

No. CrowdSec is open-source software that protects servers and internet-facing services by detecting attack behaviour in logs and blocking the addresses behind it, sharing signals across a community of users. It does not scan files on laptops, and it is complementary to the endpoint suites in this list rather than an alternative to them.

Not on this list?

If you build a European endpoint protection tool that belongs here, tell us about it. Every suggestion is checked against the same criteria as the tools above: European ownership and hosting, a real product, and pricing we can verify. A listing is editorial, and we say so on this page where placement is paid.

Suggest your tool