Compliance

Email Security Compliance for Regulated Industries

Regulators now expect encrypted email to be auditable, governed and kept under jurisdictional control. CloudPGP helps you meet those expectations with policy-based PGP and S/MIME encryption, regional data centers and independently audited platform controls.

CloudPGP runs on the Echoworx encryption platform. The certifications, data centers and platform safeguards described on this page are those of Echoworx and apply to the platform on which CloudPGP operates.

Compliance drives email encryption

Frameworks such as DORA, NIS2, GDPR and KRITIS have made the security of business communications a board-level responsibility. Encryption on its own is no longer enough: organizations must be able to show how messages are protected, who can access them, where the data is processed and how keys are governed, including for exchanges that cross borders.

General-purpose email platforms rarely provide that level of evidence. A dedicated encryption service gives compliance, security and audit teams a single point of control and a consistent record.

Regulations CloudPGP helps you meet

CloudPGP provides encryption, access-control and audit capabilities that help you meet the communication-security requirements of these frameworks:

Regulatory frameworks and how CloudPGP helps
FrameworkScopeHow CloudPGP helps
DORA ICT risk management and digital operational resilience for financial entities in the EU Policy-controlled encryption with audit records, on a regionally redundant platform
NIS2 Cybersecurity risk-management measures for essential and important entities in the EU Encryption and cryptography policies, access control and logging for email communications
GDPR Protection of personal data of individuals in the EU Encryption as a technical measure for personal data sent by email, with data centers in the EU and the UK
KRITIS Germany’s security requirements for operators of critical infrastructure Strong encryption and audit records, with data centers in Germany
PCI DSS Security of payment card data for organizations that store, process or transmit it Encryption for cardholder data in email, on a platform validated at PCI DSS Level 1 for encrypted mail and secure portal
HIPAA Protection of electronic protected health information (ePHI) in the United States Encryption, access control and audit records for ePHI sent by email

Scroll sideways to see the whole table.

No product makes an organization compliant on its own. Whether these measures are sufficient depends on your sector, risk assessment, configuration and contracts, such as a business associate agreement under HIPAA.

Data sovereignty and residency

Where encrypted email is processed and stored is a governance decision. The Echoworx platform runs secure, high-performance data centers in five regions:

  • United States
  • Canada
  • United Kingdom
  • Ireland
  • Germany

This regional footprint keeps data close to where organizations and their customers operate, and supports data-residency and cross-border transfer obligations under GDPR and national rules.

  • Facilities engineered for security and redundancy.
  • SOC 2, PCI DSS and ISO certifications covering physical, system and operational security.
  • Strict access controls with continuous review.

Auditability and governance

Regulators and auditors expect evidence, not assurances. CloudPGP applies encryption through centrally managed policies and records key events, including key generation, certificate issuance, policy triggers and message delivery status.

These records support internal review, incident investigation and audit evidence. See Security Controls for the administration, tenant and logging controls in detail.

Cryptographic standards

Strong encryption is the starting point. The platform relies on established, widely reviewed standards:

  • RSA 2048-bit asymmetric encryption;
  • AES-256 symmetric encryption;
  • SHA-2 hashing for message integrity;
  • ANSI X.509 certificates and the S/MIME email protocols.

Hardware-backed key protection

The Echoworx platform integrates with AWS Key Management Service (AWS KMS), which uses tamper-resistant hardware security modules (HSMs) validated to FIPS 140-3 Level 3. Keys for secure portal, PGP and S/MIME processing are kept in protected HSM memory and are never exposed outside it.

This hardware-backed approach keeps cryptographic material governed at all times and underpins customer key-control options such as Manage Your Own Key (MYOK). See Key Management.

Preparing for post-quantum cryptography

Future quantum computers threaten today’s public-key algorithms, so preparation has to start now. Echoworx is rolling out hybrid post-quantum cryptography based on NIST-recommended algorithms. The rollout covers:

  • quantum-safe algorithms for S/MIME, PGP and TLS, ahead of broad industry adoption;
  • AES keys managed in AWS KMS to strengthen secure portal and PDF messages;
  • hybrid post-quantum TLS protecting calls to the AWS KMS API.

Defense in layers

Resilience comes from architecture. The Echoworx platform is built in protected layers:

  • Layered network zones, with public access limited to the outermost zone.
  • Front-end services isolated from operational components and from the most sensitive assets, such as private keys and hashed credentials.
  • Multiple firewalls enforcing strict policies across every segment.
  • Intrusion detection with real-time alerts for immediate response.

Operational resilience

For regulated institutions, resilience has to be demonstrable. The platform provides:

  • Full regional redundancy, with data replicated in real time for disaster recovery.
  • Business-continuity and disaster-recovery plans tested at least once a year.
  • Continuous governance through documented policies, annual risk assessments and external audits.
  • Personnel controls, including background checks, confidentiality agreements and role-based training.

Independent platform assurance

Independent verification matters as much as the controls themselves. The Echoworx platform on which CloudPGP operates holds the following certifications and accreditations:

Echoworx platform certifications and accreditations
CertificationWhat it confirms
SOC 2 An annual independent audit of processes, controls and systems for privacy, confidentiality, availability and integrity
PCI DSS Level 1 The highest level of payment account data security, for encrypted mail and secure portal
AWS Qualified Software Successful completion of the AWS Foundational Technical Review against the AWS Well-Architected Framework
FSQS Registered Vetted supplier status for financial services in the UK, Ireland and Northern Europe
OpenID Connect certification (Relying Party) A certified OpenID Connect relying-party implementation, held by fewer than 30 organizations worldwide
About these certifications

These certifications and accreditations are held by Echoworx for its platform. They are not certifications of Keystone Management Group LLC or of CloudPGP as a company, and they do not certify your own deployment or compliance.

Compliance questions

Does using CloudPGP make my organization compliant?

No product makes an organization compliant on its own. CloudPGP provides encryption, access-control, audit and data-residency capabilities that help you meet the communication-security requirements of frameworks such as DORA, NIS2, GDPR, KRITIS, PCI DSS and HIPAA. Your obligations depend on your sector, risk assessment, configuration and contracts.

Where is encrypted email processed?

The Echoworx platform that CloudPGP runs on operates data centers in the United States, Canada, the United Kingdom, Ireland and Germany. This regional footprint helps keep data close to where your organization operates and supports data-residency requirements.

Who holds the certifications listed on this page?

Echoworx holds the SOC 2, PCI DSS Level 1, AWS Qualified Software, FSQS and OpenID Connect certifications for its platform. They are not certifications of CloudPGP or Keystone Management Group LLC.

How are encryption keys protected?

Keys are protected with AWS Key Management Service, which relies on hardware security modules validated to FIPS 140-3 Level 3. See Key Management for key handling and custody options.

Is the platform preparing for post-quantum threats?

Yes. Echoworx is rolling out hybrid post-quantum cryptography based on NIST-recommended algorithms for S/MIME, PGP and TLS.

Bring your compliance questions

Our team can walk your stakeholders through the platform’s certifications, cryptographic standards, data-residency controls and resilience architecture.

Contact us