Payslips, contracts and patient letters leave by email every day. They should not leave readable — EncryptTitan encrypts Microsoft 365 and Google mail by subject keyword, Outlook plug-in or DLP rule, and outside recipients read it in a branded portal once they authenticate.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers EncryptTitan — TitanHQ’s email encryption product. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Sensitive mail is encrypted on the way out, and outside recipients sign in to a portal to read it.
What consolidation actually replaces, dimension by dimension.
| Dimension | Password-protected ZIPs | EncryptTitan |
|---|---|---|
| Sensitive attachments | Password-protected ZIPs, password in a second mail | Encrypted by keyword, plug-in or DLP rule |
| When staff forget | The message leaves in clear text | A DLP policy can encrypt it anyway |
| The recipient’s side | Install a tool or phone for the password | Authenticate in a portal with your branding |
| Proof of delivery | Call and ask whether it arrived | Sent-and-read traceability for admins |
| A wrong recipient | Nothing to do once it has gone | Recall the encrypted message |
| What it is NOT | — | File rights management, a documented India region, or a price list |
The cheapest test is a week with one team: set a subject keyword and one DLP rule, send to real clients, then read the traceability log.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A sender types the agreed keyword in the subject, which also covers attachments, or clicks the Outlook plug-in; a DLP policy can catch sensitive content when both are forgotten.
TitanHQ hosts the encryption service; its documentation shows SpamTitan being configured for EncryptTitan, so filtering and encryption can sit in one outbound path.
Recipients reach a portal carrying your branding, and the message decrypts only after they authenticate; TLS with host verification covers server-to-server delivery.
One console serves many tenants, with recall of sent messages and full traceability of what was sent and read, which suits an MSP running many small customers.
Triggers at the sender, a branded portal at the recipient — with TLS checks, recall and tracking in a multi-tenant console.
EncryptTitan encrypts outbound email by keyword, plug-in or DLP rule and delivers it through a branded portal.
Typing the agreed keyword in the subject encrypts the message and its attachments, with no new software for the sender to learn.
An Outlook plug-in gives senders an explicit encrypt option, for staff who would rather click than remember a keyword.
DLP-based policy encrypts messages whose content matches your rules, so sensitive mail is protected even when the sender does nothing.
Outside recipients open protected mail in a portal that carries the sender’s branding, which helps it look less like a phishing lure.
A recipient can decrypt and read the message only after authenticating, so a forwarded notification alone does not expose it.
TLS with host verification protects delivery to partner mail servers; TitanHQ specifies TLS 1.2 or higher for its HIPAA claim.
A sent encrypted message can be recalled, which matters when a payslip or contract goes to the wrong address.
Full traceability shows which encrypted messages were sent and which were read, ending most “did they get it?” calls.
Multi-tenancy lets an MSP run encryption for each customer separately from one place, beside the rest of the TitanHQ products.
TitanHQ’s EncryptTitan V2 demo from April 2025, the only EncryptTitan video on the official @CyberSentriq channel.
TitanHQ’s walkthrough of EncryptTitan V2, and the only EncryptTitan video on the official channel.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Senders can put a keyword in the subject line, which encrypts attachments as well, or press the Outlook plug-in. Behind both, a DLP-based policy encrypts matching content when staff forget. Every route ends at the same branded portal.
TitanHQ aims EncryptTitan at MSPs as well as businesses. It is multi-tenant, admins can recall sent messages and trace what was sent and read, and the MSP Partner Program adds round-the-clock priority support.
TitanHQ positions EncryptTitan directly against Office 365 Message Encryption, and it names Google mail as well as Microsoft 365. Check licences first: Microsoft 365 E3 already carries manual labels and Rights Management encryption.
No price, licence unit or rupee rate is published, and it is in none of TitanHQ’s bundles. No storage region is documented, Indian or otherwise. It encrypts messages, not files: a downloaded attachment carries no rights. One official video exists.
List the messages that carry personal, financial or health data, who sends them, and which outside parties receive them.
Decide which mail needs a DLP rule, which a subject keyword, and who gets the Outlook plug-in; write the keyword down.
Brand the portal, then send test mail to friendly clients on Gmail and Outlook to check sign-in and reading on their devices.
Turn on DLP policies for the content found in week 1, set TLS host verification for key partners, and read the traceability log.
Extend to every sender, review recalls and unread messages monthly, and get TitanHQ to state in writing where portal mail is held.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Payroll staff type the keyword in the subject and the payslip PDFs go out protected, with no separate step for attachments.”
“We look after a dozen clinics from one multi-tenant console, and the sent-and-read log ends most disputes about delivery.”
“Our DLP rule catches account numbers when people skip the Outlook button, which was the hole in our old manual process.”
“Clients trust a portal with our logo on it more than a generic one; fewer of them reported the first message as phishing.”
“After a merger we had staff on Google mail and on Microsoft 365, and one encryption service covered both sets of senders.”
“With no price list and no stated data location, our budget sign-off and residency review both took longer than planned.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email encryption market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only; sold standalone, outside TitanHQ’s bundles.
The grid nobody publishes — how easily outside recipients can read protected mail vs how much control remains after it is delivered.
Portal after sign-in; recall and read tracking.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against OpenText Core Email Encryption, Microsoft Purview, Proofpoint Essentials, Symantec Email Security.cloud and Seclore EDRM — on triggers, recipients, control after delivery, price and India.
| Dimension | EncryptTitan | OpenText Core Email Encryption | Microsoft Purview (Message Encryption) | Proofpoint Essentials | Symantec Email Security.cloud | Seclore ARMOR EDRM |
|---|---|---|---|---|---|---|
| What it is | Portal email encryption | Zix-heritage encryption | Built into Microsoft 365 | A package feature | Filter with PGP add-on | File rights, not mail |
| Deployment | TitanHQ-hosted | Hosted, beside filter | Inside your tenant | MX or cloud API | MX cut-over | SaaS or self-hosted |
| Mail platforms | Microsoft 365 + Google | Google not named | Microsoft 365 only | Any host via MX | Any MX-routed host | Any app, via the file |
| Encryption trigger | Keyword, plug-in, DLP | DLP rules, no button | Label or rule | Not on TechBag’s page | Policy-driven | Needs a trigger |
| Recipient experience | Branded portal sign-in | TLS, S/MIME or portal | One-time passcode | Not documented here | TLS or PGP | No software needed |
| Control after delivery | Recall + read tracking | Message-level | Travels; partial revoke | Not documented | Transit protection | Revoke after sharing |
| Pricing model | Quote, no unit shown | Per user, by term | Basics in E3 | Per user, by package | Per user, via partners | Per user, in rupees |
| Published entry price | Not published | Not published | $12/user/month add-on | $2–5.86/user/month | Not published | Not published |
| Included vs add-on | In no bundle | Separate product | Auto-labels need E5 | Advanced and Pro only | PGP is extra | Classification apart |
| Admin and MSP use | Multi-tenant for MSPs | Secure Cloud portal | Per-tenant policies | Partner-run Essentials | Self-serve TLS setup | See who opened it |
| India data region | Not documented | Not listed | ADR covers India | Mumbai data centre | No Indian region | India-built vendor |
| Support | 24h priority for MSPs | Sold with support | Via your M365 contract | Partner first | Through partners | Support in India |
| Lock-in and exit | Rules to rebuild | Policies to rebuild | Microsoft-centred | Re-point MX to exit | Reroute to leave | Files need the vendor |
| Best fit | MSP-run small clients | Encryption-heavy MSPs | Microsoft E3/E5 estates | Essentials buyers | PGP partner exchange | Files that leave |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no email encryption guide yet, so EncryptTitan sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (staff who send sensitive email; staff-hour cost). Estimates model time lost to password-protected attachments, separate password messages, resends and recipient queries at an assumed 1.5 hours per sender a year, with 70% of it removed by triggered encryption and a portal. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: TitanHQ prints no price or licence unit for EncryptTitan, its pricing page offers no rupee currency, and the product sits outside all five TitanHQ bundles. TitanHQ’s FAQ says it offers free trials. TechBag maps your senders and triggers first, then gets the quote in INR with GST.
Best for policy-triggered mail encryption
Best for a broader rollout
Best for TitanHQ email estates
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is all your mail on Microsoft 365 or Google Workspace, the two platforms TitanHQ names, or is another host involved?
Which senders will use the subject keyword, which the Outlook plug-in, and what does the DLP policy catch on its own?
Which content patterns, such as account numbers or health records, should force encryption without a sender’s action?
Who receives your encrypted mail most often, and have a few of them tested the portal sign-in on their own devices?
Where does TitanHQ store messages held in the portal, and for how long? No EncryptTitan region is published.
Do you already hold Microsoft 365 E3 or E5, whose Message Encryption and labels may overlap with what you buy?
Do you need control after an attachment is saved? If so, EncryptTitan alone will not do it; look at rights management.
What is the licence unit and term, and does the quote cover all tenants? Ask for INR with GST and the support terms.
Map which mail must leave encrypted and who receives it, or let a TechBag advisor scope a pilot with your outside recipients on the branded portal.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.