For banks, insurers and regulated institutions

Cryptio Enterprise
Self-Hosted

Your organisation's encryption, running on your own network. Your administrators decide who can decrypt what - department by department - and nothing ever touches Cryptio's servers.

Deployed with your IT team, starting with a scoped pilot on your own infrastructure.

Your network

Cryptio Enterprise server
policy · key recovery · access control · audit
Finance
Claims
HR
Only the server checks your licence with Cryptio. Documents, keys and records stay inside.

What it is

Cryptio Enterprise normally runs against Cryptio's own service. The Self-Hosted edition puts that control on a machine inside your organisation instead. Your IT team installs the Cryptio Enterprise server like any other Windows program, your staff's Cryptio desktop apps connect to it, and your administrators manage policy, key recovery, department access and audit from there.

Capabilities

We're clear about what exists today and what is still on our roadmap.

Available nowOn the roadmap
Available now

Self-hosted server

Installs as a Windows service on a machine you choose, with encrypted connections across your network. Nothing depends on Cryptio's cloud.

Available now

Document management

A central, access-controlled repository for files and notes: upload, grant access by department, keep every earlier version, and browse by department and type. Documents are stored encrypted on your server.

Available now

Department access control

Documents are shared with departments; access is granted to each member's own key, with no shared department secret.

Available now

Revocable access

The server releases a document key only after checking current department membership. Remove someone from a department and their next attempt to open its documents is refused.

Available now

Encrypted internal memos

Share a Secure Note with one or more departments. It appears in their repository, protected by the same department access and revocation as files.

Available now

Staff enrolment

Each person's desktop is paired to the server with a one-time code from your administrator.

Available now

Central audit and live updates

One server-side audit trail for every department, and staff see new documents and access changes as they happen.

Available now

Server-held licence

Only the server checks the licence, with a seat count for your organisation. Staff machines never contact Cryptio.

Available now

Organisation-held key recovery

Recover a staff member's files with your organisation's own recovery key - generated and held by your administrators, never by Cryptio.

Available now

Encryption policy enforcement

Set minimum key sizes and allowed algorithms centrally, enforced on every desktop.

Available now

Tamper-evident audit logs

Each entry is chained to the last, so any edit or deletion is detected.

Available now

Command-line automation

Scripted, unattended encryption for batch jobs and integrations.

Available now

Strong encryption engine

AES-256-GCM, AES-256-CBC and ChaCha20-Poly1305, with RSA-2048/4096 for sharing. Documents are encrypted and decrypted on the desktop; the server never sees their contents.

On the roadmap

Active Directory / LDAP

Departments mapped to your existing user directory.

On the roadmap

Secure external drop

A way for auditors, regulators or claimants to submit files without installing Cryptio.

Why self-hosted

Data stays in Ghana

Documents, keys and records never leave your network - in line with the Bank of Ghana's 2026 directive on keeping critical customer data in the country.

One firewall exception

Only the server checks your licence with Cryptio. Staff machines never need to reach the internet for Cryptio.

Your keys, not ours

Organisation recovery keys are generated and held by your administrators. Cryptio Systems cannot decrypt your files.

Small blast radius

Access is granted to each person's own key - there is no shared department secret, so one lost laptop exposes only its owner's access.

Who it's for

Institutions with their own IT team and several departments

Insurers

Claims, underwriting and medical files, each visible only to the departments that handle them.

Banks & financial institutions

Credit files, board papers and customer records under the Bank of Ghana directive.

Regulators & public bodies

Sensitive investigations and correspondence, with a full record of who opened what.

Large employers

HR and payroll records, contracts and disciplinary files, with access removed when people move on.

How we work with you

1

Briefing & demo

We show a working deployment and learn how your departments handle sensitive documents.

2

Scoped pilot

We install on your network with one or two departments, and agree success criteria with you.

3

Security review

We support your security assessment and recommend an independent penetration test before rollout.

4

Rollout

Organisation-wide deployment, with support terms agreed for your IT team.

Pricing

Quoted per engagement, based on the number of staff who will use Cryptio. Tell us about your organisation and we'll prepare a proposal.

Frequently asked questions

Does anything go to Cryptio's servers?

Only the server's licence check. Documents, keys, department membership and audit records stay on your network.

What do we need to run it?

A Windows machine on your network with enough disk space for your documents and a backup plan for it. We help you size it during the pilot.

If we remove someone's access, is it immediate?

Yes, going forward: their next attempt to open a document is refused. No system can recall a copy someone already opened and saved before their access was removed, and we won't pretend otherwise.

Who supports it?

Your IT team handles day-to-day operation, as with any server you run. Cryptio Systems provides support on terms agreed for your engagement.

How is this different from the Cryptio Enterprise plan?

The same capabilities, but running on your own network instead of Cryptio's service - plus department access control, revocable access and central audit for larger organisations.

Can we use our existing user accounts?

Active Directory / LDAP integration is on our roadmap and is prioritised with pilot clients who need it.

Request a briefing

Tell us about your organisation and how sensitive documents move between departments. We'll arrange a briefing and demo with your team.

Or email us directly at support@getcryptio.com