Skip to main content

Organization security

The Dashboard > Organization > Security tab gathers the security settings that apply to the whole organization. Restricted to Owners and Admins.

Blocked domains

You can forbid sending files to certain email domains. As soon as a domain is listed, recipients from that domain are rejected, for every send from every member.

Blocked domains

Click Add domains and paste your list of domains (one per line). The list can be changed at any time.

tip

To restrict recipients to a whitelist of domains rather than blocking some, use labels with the Domain whitelist mode.

Organization master key

The master key is a recovery key automatically added to every new transfer and every new dataroom created by the members of the organization. Whoever holds the matching private key can decrypt those files later, even without the sender's involvement: an employee leaving, a lost passphrase, a legal duty to hand data over.

info

The master key is a plan option. If it is not available in your organization, contact the sales team.

Enable the master key

Two possibilities at activation time:

  • Generate a key: Retyc generates a key pair in your browser. The private key is shown only once and is never stored by Retyc: download it and keep it outside Retyc, in a safe place (password vault, HSM, offline storage).
  • Import a public key: you provide the public key of a post-quantum hybrid age pair (age1pq1… format) generated outside Retyc, for instance with the age tool (version 1.3.0 minimum). The private key never leaves your infrastructure.
The master private key is your sole responsibility

Retyc only keeps the public part of the master key. If you lose the private key, the data it protects can no longer be recovered through it.

What the master key covers

  • It applies to transfers and datarooms created after its activation. Earlier objects are not retroactively re-encrypted, except datarooms whose membership changes: the master key is attached on that occasion.
  • It does not affect end-to-end encryption in any way: it acts as an additional recipient, just like a regular one.

Dataroom history retention

Every dataroom keeps an activity feed: events (uploads, downloads, invitations...) and chat messages. This setting defines how long that history is kept for all the datarooms of the organization, between 2 and 365 days (30 days by default).

Dataroom history retention

Events and messages older than the chosen duration are permanently deleted, with no recovery possible. To keep a record beyond that, export the log of a dataroom as CSV (see Member management).