Enterprise email encryption

Cloud-Hosted PGP & S/MIME Encryption

Modernize email encryption with centralized key management, automated certificates, and policy-driven security.

Encryption infrastructure

Enterprise security. Without the infrastructure burden.

Manage PGP keys, S/MIME certificates, and encryption policies through a centralized cloud platform.

Organizations can connect existing email-routing infrastructure to a managed encryption engine while retaining established PGP and S/MIME communication workflows.

Two established standards

PGP and S/MIME, managed in the cloud

PGP and S/MIME provide different ways to secure and sign email. PGP relies on public and private key pairs and established public-key exchange workflows. S/MIME uses X.509 certificates and certificate authorities.

CloudPGP brings both technologies into an enterprise-oriented cloud workflow, so administrators can manage policy, directory lookups and supported key or certificate processes centrally rather than relying on each user’s email client or a separately maintained encryption server.

How processing works

Integrate with existing email systems

Email is routed through a cloud encryption service according to the organization’s configured mail rules. Recipient public keys or certificates may be located through supported directory services, and message encryption and signing behavior follows configured policies.

  1. Route: eligible messages are sent from existing mail systems to the encryption engine.
  2. Apply policy: rules decide whether a message is encrypted, signed or both, and with which standard.
  3. Find keys and deliver: recipient keys or certificates are looked up and the protected message is delivered.
  4. Handle replies: public-key handling supports protected replies and inbound decryption where configured.

When an intended recipient cannot receive a particular encrypted format, supported delivery alternatives, such as a secure web portal, validated TLS delivery or an encrypted document, can be used where configured. These alternatives have different security properties and are not equivalent to PGP or S/MIME message encryption.

Control and visibility

Centralized controls for cryptographic communications

Depending on platform configuration, administrators can manage certificate and key workflows, define message-handling rules and review logging associated with encryption processing.

Advanced integration options include certificate authority connectivity, directory controls and identity-provider integration. Which of them apply depends on the integrations enabled for a given deployment.

Discuss your encryption environment

Contact us about hosted PGP, S/MIME and supported migration or integration paths.

Contact us