Solutions · Cloud encryption

Encrypt Microsoft 365 before your data leaves the building

A cloud encryption gateway sits between your people and the cloud. Documents, mail and fields are encrypted before they ever reach Microsoft, Google or AWS, and the keys stay with you. The provider stores ciphertext it cannot read, index or hand over. Your teams keep working in the same tools.

The problem: you cannot leave, and you cannot stay as you are

Most organisations cannot abandon Microsoft 365, Google Workspace or AWS overnight. The licences are signed, the workflows are built, and the people know the tools. At the same time, the legal ground has moved: a US provider remains subject to the CLOUD Act no matter which country the data centre stands in, and since Schrems II a European organisation has to be able to explain what actually protects the data, not merely where it sits.

That leaves a gap that contracts do not close. Data-processing agreements govern behaviour, not capability. As long as the provider holds readable data, the provider can be compelled to produce it. Encryption is the only measure that changes what is technically possible rather than what is contractually promised.


How it works

Together with our partner eperi we put a gateway in front of the cloud service. Nothing about the user's day changes.

Someone creates a document

Writing an email, saving a file, filling a field in a cloud application — the ordinary work, in the ordinary tool.

The gateway encrypts it instantly

Encryption happens before the data leaves your network. The keys are generated and held on your side, never by the cloud provider.

The provider stores ciphertext

What arrives in the cloud cannot be read, indexed, analysed, used for training or produced in response to a foreign order.

Your people work as before

Search, sorting and the familiar interface keep working, because the gateway decrypts on the way back for the people you have authorised.


What it replaces

This is the fastest of our four routes to sovereignty, because it changes the risk without changing the platform. It is often the first step, taken while a longer migration is still being planned.

No migration project

Your tenant, licences and workflows stay exactly where they are. Nothing has to be exported, remapped or retrained.

A technical answer, not a contractual one

Instead of relying on assurances about provider behaviour, you remove the provider's ability to read the data at all.

Room to decide later

Encryption today does not lock you in. When you do move workloads to sovereign infrastructure, the gateway comes with you.


Who this is for

Organisations under GDPR that stay on Microsoft 365

Where leaving is not realistic in this budget year but the risk assessment still has to hold up.

Regulated industries

Healthcare, finance, public bodies and research, where the question is not whether data is in the cloud but who could be made to read it.

Canadian organisations with US dependencies

Where PIPEDA obligations and a US-headquartered provider have to coexist in the same architecture.


Frequently asked questions

Does search still work if everything is encrypted?
Yes, for the people you authorise. The gateway decrypts on the way back, so search, sorting and previews behave as users expect. What changes is that the cloud provider can no longer index the plaintext for its own purposes.
Who holds the keys?
You do. Key generation and storage stay on your side of the gateway. This is the whole point: if the provider could obtain the keys, the provider could still be compelled to produce readable data.
Does this make Microsoft 365 GDPR-compliant?
It removes the specific risk that the provider can read or disclose your content, which is the hardest part of the assessment to argue away. Compliance is still an overall judgement about your processes; encryption changes the technical facts that judgement rests on.
What about the CLOUD Act?
The CLOUD Act reaches US providers regardless of where the data centre stands, including so-called sovereign cloud regions. A provider holding only ciphertext, with no access to the keys, has nothing readable to produce.
How long does a deployment take?
Considerably shorter than a migration, because nothing moves. The work is scoping which services and fields to cover, integrating the gateway, and testing the workflows your people actually use. We size it after looking at your tenant.
Can we combine this with sovereign hosting later?
Yes, and many do. Encryption protects what is in the hyperscaler today; sovereign hosting takes workloads out of it over time. The two are steps on the same path, not alternatives.
What happens if the gateway is unavailable?
It sits in the data path, so it is deployed for redundancy like any other component that must not be a single point of failure. Sizing and failover are part of the scoping conversation, not an afterthought.
Which services can be covered?
Microsoft 365, Google Workspace and AWS are the common ones, and the gateway can also cover fields inside cloud applications rather than whole documents. Which of your services are worth covering is the first question we work through.

Find out what this would look like on your tenant

Tell us which services you run and where the risk assessment hurts. We will tell you what a gateway would and would not solve — honestly, including the cases where a migration is the better answer.