Cryptio Gateway
Every statement encrypted before it leaves your building. Cryptio Gateway sits between your reporting system and your mail provider, locks each PDF with AES-256, and delivers the password through a separate channel. It runs entirely on your own server.
How it works
Your reporting system keeps sending statements exactly as it does today. The only change: it hands them to Cryptio Gateway instead of straight to your mail provider.
Receive
The gateway accepts each statement email from your reporting system, only from the machines and senders you allow.
Encrypt
Every PDF attachment is locked with AES-256. A PDF that cannot be protected is held back - never sent unprotected.
Send
The protected statement goes out through your own mail provider over a verified, encrypted connection.
Deliver the password
By SMS, by staff hand-over, or not at all when you use a memorable pattern the member already knows.
Built for statement runs
Everything an institution needs to send protected statements with confidence
Automatic PDF encryption
Every PDF attachment is protected before the email leaves your organisation.
- AES-256, the standard PDF password protection any PDF reader opens
- Several statements in one email, each protected
- Damaged or already-locked PDFs are held for review, never sent unprotected
- Email without a PDF can be held or passed through - your choice
Password delivery
The password travels separately from the statement.
- SMS through Arkesel, Hubtel, Twilio or your own provider
- Staff hand-over from the Manager, with every reveal recorded
- Memorable patterns (SSNIT-style or your own) with nothing to send
- Member phone numbers from your member list or your reporting system
Works with your mail provider
Keep the email service you already use.
- Microsoft 365 (including modern OAuth sign-in) and Google Workspace
- Zoho, SendGrid, Mailgun, Brevo, Amazon SES and on-premises Exchange
- Encrypted connections only, with certificate checks
- Automatic retries if your provider or internet connection is unavailable
Tamper-evident audit trail
A complete, verifiable record of every statement.
- Received, encrypted, sent and password delivered - with times
- Each entry is chained to the last, so any edit or deletion is detected
- Checked continuously, with an alert if anything is altered
- Export for auditors and regulators
Protected at every stage
Security in the gateway itself, not just the PDFs.
- Statements and passwords waiting in the queue are encrypted on disk
- Keys protected by Windows for your server alone
- Unprotected copies erased as soon as the protected one is sent
- Only your approved machines and senders can submit mail
Monitoring and alerts
Know about a problem before a member does.
- Live dashboard with the statement pipeline, charts and health
- Alerts by email, SMS, webhook or the Windows Event Log
- Every problem has a specific error code and the fix
- Runs as a Windows service that restarts itself
Backup and recovery
Rebuild the gateway on a new server if you ever need to.
- One encrypted backup file with settings, data and keys
- Scheduled backups, keeping as many as you choose
- Restore onto new hardware with a single command
Simple to run
A Windows program your IT team installs and manages.
- Guided settings in the Cryptio Gateway Manager
- Test your mail and SMS settings before going live
- Local support from the Cryptio team
Passwords your members can actually use
You choose the password style - including the pattern members already know from SSNIT statements.
Random
k7PqX2mZr9TbW4sNStrongest. Sent by SMS or handed over by staff.
Digits only
4821937506Easier to type on a phone. Sent by SMS or hand-over.
SSNIT style
GODF19850522First four letters of the first name + date of birth. Nothing to send.
Your own pattern
{FIRST_NAME:4}{DOB:DDMMYYYY}Built from member details you hold, previewed before you save.
Memorable passwords are convenient, and anyone who knows a member's details used in the pattern can open that statement. The choice is yours; the gateway shows the trade-off and records the style used for every statement.
Why on your own server
Built for Ghana's regulatory environment, where customer data increasingly has to stay at home.
Your data stays in Ghana
The Bank of Ghana's 2026 Cyber and Information Security Directive keeps critical customer data within Ghana and restricts external cloud to non-sensitive functions. Unprotected statements never leave your server.
Nothing for us to see
Cryptio Systems has no access to your statements, passwords or audit log. What reaches Microsoft 365 or Google is already encrypted.
Evidence of safeguards
The Data Protection Act, 2012 (Act 843) requires appropriate security for personal data. Encryption plus a tamper-evident record of every statement is evidence you can show.
Cryptio Gateway is designed to support these requirements; your compliance team remains responsible for how they apply to your organisation.
Who it's for
Any organisation that emails personal documents in volume
Pension trustees & fund managers
Benefit and contribution statements to members, many of them retirees, with passwords they can manage.
Banks, microfinance & fintechs
Account and loan statements, with customer data kept in Ghana as the Bank of Ghana directive expects.
Insurers
Policy schedules, renewal notices and claim letters to policyholders.
Laboratories & hospitals
Test results and reports - among the most sensitive personal data there is.
Payroll & HR services
Payslips and tax documents for whole workforces, every month.
Schools & public sector
Results, bills and assessments sent to parents and citizens.
Pricing
An annual subscription per server, based on how many statements you send each month, plus a one-time setup. Pilots are available for new clients. Tell us about your statement runs and we'll send a quote.
Frequently asked questions
Do we need to change our reporting software?
No. Your reporting software keeps sending statements by email; you point its outgoing mail setting at Cryptio Gateway instead of your mail provider.
What do our members need?
Nothing new - any PDF reader on a phone or computer opens the statement with its password.
Is this a cloud service?
No. Cryptio Gateway runs on a Windows server in your own organisation. Cryptio Systems never sees your statements, passwords or records. The gateway contacts our licence server only to confirm your subscription.
What happens if our internet connection goes down?
Statements wait safely in the encrypted queue and go out automatically when the connection returns. Nothing is lost.
What if a statement cannot be protected?
It is held back and shown to your staff with the reason and what to do - it is never sent unprotected.
How long does it take to set up?
We install and configure it with your IT team, test it on your own statements, and run a pilot before you go live.
Talk to us about Cryptio Gateway
Tell us a little about how you send statements today. We'll arrange a demo on your own statements and explain what a pilot would involve.