Security controls

Cloud Email Encryption Security Controls

The secure operation of an enterprise email encryption service depends on identity controls, cryptographic key management, policy consistency, system integration and useful audit records. The Echoworx platform documents capabilities across these areas; each deployment’s configuration and compliance responsibilities remain distinct.

Centralized administration and policy

Supported administration workflows can govern encryption delivery, signing policies and identity integration. Controls may be applied according to:

  • the sender;
  • the recipient’s domain;
  • message characteristics such as content or classification.

Tenant-aware key and certificate lookup

The supplied technical material describes per-tenant certificate segregation and configurable LDAP directory search controls. These guard against inappropriate certificate selection in supported workflows, for example picking up another tenant’s certificate or one from an unintended directory.

They are logical safeguards within the service and do not amount to physical isolation. See Directory and tenant controls.

Logging and auditability

Source material identifies logging of:

  • key generation;
  • certificate issuance;
  • policy triggers;
  • message delivery states.

Records like these can support operational review, incident investigation and the collection of evidence for audits. Logging alone does not establish compliance with GDPR, DORA, NIS2, PCI DSS or any other framework.

Platform and infrastructure assurance

The underlying platform is described by its vendor as a cloud-native deployment on Amazon Web Services. Information about the vendor’s own certifications, registrations and audit reports should be obtained from the vendor and checked for current scope and applicability.

No certification claims

A certification or attestation held by the platform vendor does not mean that Keystone Management Group LLC or CloudPGP holds it. CloudPGP makes no certification claims of its own on this website and does not display third-party certification marks.

Key governance

Key governance covers how keys enter the platform, how they are handled while in use and who controls them. The platform supports key import and documents a customer-managed-key capability (MYOK) associated with AWS KMS.

MYOK is a platform feature for managing certain keys. It is separate from the question of where individual PGP and S/MIME message private keys are held, which should be confirmed for each deployment. See Key custody and customer control.

Compliance responsibilities

Regulatory requirements depend on organizational use, configuration, contracts and governing law. This informational page does not certify an installation or replace a customer’s compliance assessment.

Discuss your security requirements

Contact us about controls, logging and key governance in your environment.

Contact us