Echoworx Release Turns Encryption Into Audit Evidence

A spacious Madrid coworking area with plants and long desks. An African American man stands with a laptop while colleagues move in blur, capturing dynamic, collaborative office atmosphere.

DORA enforcement is live. NIS2 obligations are tightening. GDPR penalties keep climbing. For security managers at regulated institutions, the mandate is blunt: “encrypted” is no longer a checkbox — it is a control you must prove, message by message, under audit.

The Echoworx July release lands on that pressure point. It sharpens auditability, hardens cryptographic defaults, and cuts the manual key work that drains your team. Here is what matters most.

Audit Visibility, Straight Into Your SIEM

The headline for security teams is the new Audit API endpoint for Web Portal message events. It streams the events auditors ask about — notifications, reads, attachment downloads, replies, and antivirus activity — directly into your SIEM.

That turns secure communication from a blind spot into a reviewable trail. Recipient interaction becomes documented, timestamped, and retrievable — exactly the continuous control DORA and NIS2 now expect.

Stronger Crypto Defaults Without the Rework

The July release makes S/MIME and PGP key size configurable at the profile level — 2048, 3072, or 4096-bit RSA. The default moves from 2048 to 3072-bit, aligning your baseline with modern guidance without a manual re-key project.

For architects planning post-quantum readiness, this is one less legacy default to defend at your next review.

Less Manual Key Management, Less Risk

Several enhancements attack the operational drag that makes PGP and S/MIME painful to govern at scale:

  • Dynamic Recipient Key LDAP Lookups discover PGP keys at a standard URI on the recipient domain — cutting manual key exchange.
  • Separate S/MIME and PGP LDAP Lookups let you enable external key server discovery independently, matching policy to protocol.
  • PGP Sender-Only Signing bounces messages back when no valid signing key exists, closing a silent gap in signing assurance.
  • Self-Service PGP Decryption lets users route legacy endpoint-encrypted messages through the gateway for decryption — no help-desk ticket required.

Each one reduces IT burden while tightening the control surface. Governance and efficiency move together, not against each other.

Tighter Control Over the Recipient Experience

Three portal upgrades give you sharper containment:

  • Reply-All Controls strip unrecognized domains from replies, keeping sensitive threads inside approved boundaries.
  • Secure Portal Message Forwarding permits controlled forwarding only to allowed domains.
  • Per-Recipient Notification Controls let registered recipients manage reminders — reducing noise without weakening the audit record.

Why It Lands Now

Echoworx remains the trusted encryption partner for the world’s most regulated institutions — global banks, financial institutions, and highly regulated institutions across critical infrastructure sectors cannot afford to get this wrong. The July 2026 release reflects that focus: auditable by design, sovereign by architecture, and efficient by default.

Book a gap assessment with an Echoworx encryption expert to walk through what’s relevant to your setup.