Interested in a personalized demonstration? Book a Meeting
Latest Innovations from Echoworx
Staying secure isn’t a one-time achievement, it’s a commitment. With every update, we listen to the evolving needs of security leaders worldwide especially those driving GDPR, NIS 2, KRITIS, and DORA compliance. Explore how the latest solutions from Echoworx keep your team steps ahead, protected and prepared.

November 2025 Update
This update is not about adding more complexity; it is about surgically removing the obstacles that slow your organization down and introduce risk. We have listened to our global partner and engineered solutions for the real-world challenges you face every day.
Uncompromising Security, Unprecedented Simplicity
We have focused on enhancing usability where it matters most, removing barriers for your users and administrators without compromising security.
- New Document Encryption Delivery: Consider the problem of sending a secure document to a non-technical recipient under a tight deadline. The traditional registration process is a bottleneck. Our new verification code method for Document Encryption eliminates this completely. The sender securely communicates an on-the-fly code to the recipient—over the phone, for example. The recipient uses this code to instantly access the secure PDF or encrypted attachments. No registration, no passwords, no delays. It is robust security that works at the speed of human interaction.
- Centralized Certificate Configuration: Finding and configuring certificate-based encryption settings should be intuitive, not a treasure hunt. We have moved the S/MIME and PGP delivery method options to the forefront of the Web Portal. This simple change creates a more efficient workflow, allowing users to easily configure their preferred encryption method from a single, central page.
Streamlined Administration and Absolute Control
We are placing more power and control directly into the hands of your administrators, allowing you to align our platform with your precise corporate security policies.
- Self-Serve OpenID Identity Provider Settings: Managing administrator access across multiple platforms creates password fatigue and security gaps. You can now directly configure Single-Sign-On (SSO) for administrators through our self-serve OpenID settings. This allows you to integrate with your existing corporate Identity Provider, centralizing access control and enforcing your own security standards.
- Granular LDAP Server Control: Not all directories are created equal. Enterprise Administrators can now enable or disable specific LDAP directories within their profiles. This gives you precise control over which servers are searched for recipient certificates, optimizing the process and tailoring it to your exact infrastructure.
The End of Certificate Chaos
Certificate management has become one of the most persistent headaches in enterprise security. These updates are designed to bring order, ownership, and proactive control to your encryption infrastructure.
- Per-Customer Certificate Segregation: Sharing a global directory of public keys is like sharing a toothbrush—it is unhygienic and introduces unnecessary risk. We have re-architected our system to segregate S/MIME and PGP certificates on a per-tenant basis. This gives you complete ownership of your public keys, eliminating the conflicts and “wrong key” errors that halt critical communications. You manage your certificates, and only your certificates.
- Automatic Renewal of Expiring S/MIME Keys: Reacting to an expired certificate is already too late. We are moving security from reactive to proactive. For customers using DigiCert or SwissSign, you can now enable the automatic regeneration of employee certificates before they expire. This ensures a continuously valid certificate is always available, preventing service interruptions and last-minute emergencies.
- Expanded Inbound Signature Verification: Trust, but verify. Our signature verification capabilities now support opaque-signed S/MIME messages, in addition to clear-signed ones. The system delivers a comprehensive verification report, giving you a stronger, more complete security posture against inbound threats.
These are not just features. They are answers to the problems that keep you up at night. They represent a smarter, more efficient, and more secure way to operate.
September 2025 Update
This release is a direct result of our partnership with leading global enterprises. These updates focus on practical, impactful solutions to real-world operational challenges.
Usability and UI
- Improved 2-Step Verification: Enhanced page navigation for SMS and Authenticator App verification prevents common errors, ensuring a smoother, more intuitive authentication process for all users.
- New Rich Text Engine: The Web Portal's compose and reply editor now features a modern rich text engine with new font options and a clipboard, empowering users to create professional communications more efficiently.
- Authenticator App Display Name: A new dedicated enterprise property allows for customized display names in authenticator apps, improving clarity and brand consistency.
S/MIME and PGP
- New Signature Verification Options: Gain granular control over inbound signed messages with four verification criteria: Message Unaltered, Message Signed by Sender, Valid Signer Certificate, and Trusted Signer Certificate.
- Inbound Signature Stripping: You can now automatically strip signatures from inbound messages before delivery, reducing confusion for internal staff and minimizing potential security risks.
- Enhanced eFail Protection: To further protect against vulnerabilities, the system now strips HTML from inbound decrypted S/MIME and PGP messages by default.
- Expanded LDAP Search: It is now possible to search third-party LDAPs that do not use a Base DN, streamlining certificate and key management.
- Intermediate CA Certificate Support: For customers auto-generating S/MIME keys with Echoworx using SwissSign or DigiCert, intermediate Certificate Authority (CA) certificates are now stored in the user’s ID alongside end-user (leaf) certificates. This enables Echoworx to include intermediate certs in outbound S/MIME signatures.
May 2025 Update
Automated S/MIME certificate generation, enhanced LDAP integrations, advanced PGP management, and improved sender verification for better email authenticity.
S/MIME Enhancements
- CA Integration: Now, enterprises can automatically generate S/MIME certificates on demand from a trusted Certificate Authority. This replaces manual workflows for outbound message signing, reducing admin time and ensuring constant certificate availability.
- LDAP Publishing: X.509 public certificates are now published to the Echoworx Global LDAP Directory for streamlined management.
- Improved Credential Logic: Auto-generated S/MIME credentials now use the SENDER MIME header for better handling of group mailboxes and forwarded messages.
- Retry Mechanism for Certificates: Echoworx will retry certificate requests during temporary service outages to ensure smooth operations.
- Enhanced Security: Uploaded or generated S/MIME private keys are restricted to mapped profile domains.
- Expanded Directory Searches: Additional third-party public LDAPs are now searched for X.509 certificates.
PGP Enhancements
- Signed-Only Messages: Digitally sign outbound messages using PGP without encryption, configurable via policy settings.
- Key Harvesting: Echoworx now saves encryption-valid public keys from inbound PGP messages for future use, with full audit reporting.
- Domain-Restricted Keys: Uploaded or generated PGP private keys are now securely restricted to mapped profile domains.
- Expanded Directory Searches: Additional third-party public LDAPs are now searched for PGP keys.
New User-Focused Improvements
- Sender Verification: Verify DKIM and SPF on messages routed to Echoworx for encryption to enhance email authenticity.
November 2024 Update
Addresses core challenges like ensuring compliance, improving operational efficiency, and maintaining complete control over your sensitive communications.
Manage Your Own Key (MYOK)
Gain full control over your encryption keys with the new MYOK tool, allowing you to securely store and manage keys directly on AWS servers.
Expanded Two-Step Verification
Now offering OAuth and passwordless login options using Passkeys to strengthen identity-first security and meet evolving multi-factor authentication requirements.
Enhanced Certificate Management
Simplify encryption workflows with improved S/MIME and PGP certificate management, ensuring secure communication for industries handling sensitive data.
Discover the story behind these updates and the key drivers shaping them →
Security Assurance & Certification Programs




