Access control
Secure Email Authentication & Access Control
Encryption protects message content, while authentication helps determine who can access a secured message or document. Supported recipient access methods vary by delivery channel, organizational policy and the enabled features of the underlying Echoworx platform.
Secure recipient portal access
Depending on policy, recipients who retrieve messages through a secure portal may use:
- self-registration for a portal account;
- a passphrase set by the sender;
- a single-use PIN;
- multi-factor authentication;
- passkeys;
- an enterprise identity provider through single sign-on.
Accountless access is available for specific supported workflows only; it is not a universal feature.
Passwordless access and passkeys
Passkeys support device-based authentication. A recipient typically unlocks a passkey with a device PIN or a biometric check such as a fingerprint, and that check happens on the recipient’s own device.
Because each passkey is tied to the service it was created for, passkeys are designed to resist phishing. That protection depends on proper implementation and on the authentication workflow, and not every recipient device or browser supports passkeys.
Multi-factor and inclusive verification
Supported second-factor options described by Echoworx include:
- Authenticator-app TOTP: time-based one-time codes generated by an app on the recipient’s device;
- Text message: a one-time code sent by SMS;
- Automated voice call: a code read out by phone, useful when receiving text messages is impractical.
Offering several methods gives recipients more than one way to complete verification. The methods differ in strength: codes delivered by SMS or voice can be intercepted or redirected, and no one-time-code method is as resistant to phishing as a passkey. Whether a given set of factors meets a framework such as PCI DSS or NIST guidance depends on the specific use case.
SSO and identity federation
SAML and OpenID Connect can support integration with existing enterprise identity providers for compatible portal and administrative workflows. Compatibility depends on the identity provider’s support for these standards and on configuration; support for every identity provider is not implied.
Authentication establishes who someone is. Authorization decides what that person may access. An identity provider can authenticate a user, while the encryption service’s policies still decide which messages or functions that user can reach.
Reinforced account recovery
Supported account-recovery controls include additional verification for password resets by text message, voice call or TOTP.
Legacy knowledge-based recovery questions may also be available where required. They are weaker than modern multi-factor methods and passkeys, because answers can often be guessed or researched.
Encrypted document access
The platform covers protected PDF, Office document and ZIP attachment workflows. Depending on configuration, a recipient opens a protected file with:
- a password established by the sender;
- a generated verification code communicated separately;
- a password the recipient maintains for repeated exchanges.
Communicating a password or code out of band means sending it through a different channel from the document, such as a phone call or text message, so that intercepting the email alone is not enough to open the file.
Opening a protected attachment is different from opening a PGP or S/MIME encrypted message. The attachment is protected by a password-based mechanism that common document and archive software can open, whereas PGP and S/MIME rely on the recipient’s private key.
Administrative policies
Administrators can define which recipient and message-based authentication choices are available, so that enabled methods align with organizational policy. These settings are managed in the encryption service itself; this website does not provide access to the administration console.
Access questions
Do recipients need to register?
Not always. Recipients who use their own PGP or S/MIME keys read messages in their usual software. For portal delivery, policy decides whether recipients register, use a sender-set passphrase, enter a single-use PIN or sign in through an identity provider. Accountless access applies only to specific supported workflows.
Can recipients use a passkey?
Where passkeys are enabled and the recipient’s device and browser support them, yes. The recipient unlocks the passkey with a device PIN or biometric check on their own device.
How do voice verification and TOTP differ?
With TOTP, an authenticator app on the recipient’s device generates a short-lived code without needing a phone signal. With voice verification, an automated call reads a code to the recipient, which helps people who cannot easily receive text messages. Both are one-time-code methods and neither is as phishing-resistant as a passkey.
Can passwords be reset with multi-factor verification?
Yes. Supported recovery controls can require an additional verification step by text message, voice call or TOTP before a password is reset.
How are encrypted PDFs accessed?
The recipient opens the protected PDF with a password set by the sender, a verification code sent separately, or a password they maintain for repeated exchanges, depending on configuration. See Encrypted document access.
Plan recipient access
Contact us to discuss portal access, verification methods and identity integration.