Cryptio Enterprise
Self-Hosted
Your organisation's encryption, running on your own network. Your administrators decide who can decrypt what - department by department - and nothing ever touches Cryptio's servers.
Deployed with your IT team, starting with a scoped pilot on your own infrastructure.
Your network
What it is
Cryptio Enterprise normally runs against Cryptio's own service. The Self-Hosted edition puts that control on a machine inside your organisation instead. Your IT team installs the Cryptio Enterprise server like any other Windows program, your staff's Cryptio desktop apps connect to it, and your administrators manage policy, key recovery, department access and audit from there.
Capabilities
We're clear about what exists today and what is still on our roadmap.
Self-hosted server
Installs as a Windows service on a machine you choose, with encrypted connections across your network. Nothing depends on Cryptio's cloud.
Document management
A central, access-controlled repository for files and notes: upload, grant access by department, keep every earlier version, and browse by department and type. Documents are stored encrypted on your server.
Department access control
Documents are shared with departments; access is granted to each member's own key, with no shared department secret.
Revocable access
The server releases a document key only after checking current department membership. Remove someone from a department and their next attempt to open its documents is refused.
Encrypted internal memos
Share a Secure Note with one or more departments. It appears in their repository, protected by the same department access and revocation as files.
Staff enrolment
Each person's desktop is paired to the server with a one-time code from your administrator.
Central audit and live updates
One server-side audit trail for every department, and staff see new documents and access changes as they happen.
Server-held licence
Only the server checks the licence, with a seat count for your organisation. Staff machines never contact Cryptio.
Organisation-held key recovery
Recover a staff member's files with your organisation's own recovery key - generated and held by your administrators, never by Cryptio.
Encryption policy enforcement
Set minimum key sizes and allowed algorithms centrally, enforced on every desktop.
Tamper-evident audit logs
Each entry is chained to the last, so any edit or deletion is detected.
Command-line automation
Scripted, unattended encryption for batch jobs and integrations.
Strong encryption engine
AES-256-GCM, AES-256-CBC and ChaCha20-Poly1305, with RSA-2048/4096 for sharing. Documents are encrypted and decrypted on the desktop; the server never sees their contents.
Active Directory / LDAP
Departments mapped to your existing user directory.
Secure external drop
A way for auditors, regulators or claimants to submit files without installing Cryptio.
Why self-hosted
Data stays in Ghana
Documents, keys and records never leave your network - in line with the Bank of Ghana's 2026 directive on keeping critical customer data in the country.
One firewall exception
Only the server checks your licence with Cryptio. Staff machines never need to reach the internet for Cryptio.
Your keys, not ours
Organisation recovery keys are generated and held by your administrators. Cryptio Systems cannot decrypt your files.
Small blast radius
Access is granted to each person's own key - there is no shared department secret, so one lost laptop exposes only its owner's access.
Who it's for
Institutions with their own IT team and several departments
Insurers
Claims, underwriting and medical files, each visible only to the departments that handle them.
Banks & financial institutions
Credit files, board papers and customer records under the Bank of Ghana directive.
Regulators & public bodies
Sensitive investigations and correspondence, with a full record of who opened what.
Large employers
HR and payroll records, contracts and disciplinary files, with access removed when people move on.
How we work with you
Briefing & demo
We show a working deployment and learn how your departments handle sensitive documents.
Scoped pilot
We install on your network with one or two departments, and agree success criteria with you.
Security review
We support your security assessment and recommend an independent penetration test before rollout.
Rollout
Organisation-wide deployment, with support terms agreed for your IT team.
Pricing
Quoted per engagement, based on the number of staff who will use Cryptio. Tell us about your organisation and we'll prepare a proposal.
Frequently asked questions
Does anything go to Cryptio's servers?
Only the server's licence check. Documents, keys, department membership and audit records stay on your network.
What do we need to run it?
A Windows machine on your network with enough disk space for your documents and a backup plan for it. We help you size it during the pilot.
If we remove someone's access, is it immediate?
Yes, going forward: their next attempt to open a document is refused. No system can recall a copy someone already opened and saved before their access was removed, and we won't pretend otherwise.
Who supports it?
Your IT team handles day-to-day operation, as with any server you run. Cryptio Systems provides support on terms agreed for your engagement.
How is this different from the Cryptio Enterprise plan?
The same capabilities, but running on your own network instead of Cryptio's service - plus department access control, revocable access and central audit for larger organisations.
Can we use our existing user accounts?
Active Directory / LDAP integration is on our roadmap and is prioritised with pilot clients who need it.
Request a briefing
Tell us about your organisation and how sensitive documents move between departments. We'll arrange a briefing and demo with your team.