Integrations

Email Encryption Integrations

The underlying Echoworx platform is designed to fit into existing enterprise mail systems using established messaging and identity standards. The configuration depends on the organization’s routing design, directories, identity provider and certificate requirements.

Mail platforms and gateways

Supported patterns documented in the source material use SMTP routing alongside the following systems:

Documented mail integration patterns
SystemIntegration pattern
Microsoft 365 SMTP routing of eligible messages to and from the encryption engine
Google Workspace SMTP routing of eligible messages to and from the encryption engine
Existing secure email gateways SMTP routing alongside the gateway, according to its rules

In each case the mail platform is configured with routing rules that pass eligible messages to the encryption engine over SMTP and accept processed messages back for delivery. These are transport-level integrations: no native add-in or application connector is claimed where only SMTP routing is documented.

LDAP directories and key lookups

PGP public keys and S/MIME recipient certificates can be discovered through compatible directory configurations. Administrators may control which directory sources the platform queries.

Directory choice is part of the security design: querying an untrusted or outdated directory could return the wrong key or certificate, so the list of directories to search should be deliberate and maintained.

Identity integration

The supplied material identifies two identity standards for supported authentication workflows, including centralized single sign-on and recipient portal access:

  • SAML, widely used for enterprise single sign-on;
  • OpenID Connect, an identity layer built on OAuth 2.0.

The exact experience depends on identity-provider setup and enabled options. See SSO and identity federation.

Certificate authority integration

The reference architectures show an API connecting the encryption engine to supported certificate issuers, including public CA examples and AWS Private CA. The precise CA workflow is integration-dependent.

For a walkthrough of both architectures, including the AWS Private CA workflow, see the Cloud S/MIME page.

Plan a technically sound integration

Before implementation, administrators should document:

  • mail flow, outbound and inbound;
  • gateway routing and the order in which rules apply;
  • LDAP directories and how far each one is trusted;
  • public-key exchange requirements with partners;
  • certificate policies and certificate authority integrations;
  • access methods for recipients who cannot use PGP or S/MIME.

This website does not provide an automated integration wizard. Integration is configured within the encryption service and the organization’s own mail and identity systems.

Talk through your integration

Contact us with details of your mail platform, gateways, directories and identity provider.

Contact us