CRYHOD 3 year license - Full-disk encryption for laptops and workstations - NATO & EU Restricted certified

SKU
CYWW-YSP36-P10
More Information
SKU CYWW-YSP36-P10
Manufacturer CRYHOD
CRYHOD – European software-based encryption with two-factor authentication - NATO & EU Restricted certified

Laptop lost or stolen? Without a smart card, nobody gets past the boot screen. CRYHOD encrypts the entire disk with AES 256 and asks for identification before the system even starts up. No token, no access, no data breach.

Specifications


Pre-Boot Authentication + Full Disk AES 256 bits Encryption for all partitions
Two-factor authentication: smart card or USB token with PIN code, via any PKCS#11 crypto processor and common PKI
Also for USB sticks, external drives and virtual machines
Invisible to the user: on-the-fly encryption with Single Sign On
Central management via ONEPX: roll out policies, monitor compliance
Windows 11 and Windows Server, BIOS and EFI


Certifications


Netherlands: certified by the NLNCSA  for Departementaal Vertrouwelijk (RESTRICTED)
NATO Restricted: NIAPC, green status
EU Restricted: second evaluation by the BSI (Germany)
Common Criteria EAL3+ (ANSSI-CC-2022/35)
ANSSI Qualification Standard:  Diffusion Restreinte, valid until 2028
ENS Alta: (CCN, Spain)


Our advice

Encryption protects the disk, not the key. A password can be observed or shared; a smart card cannot. That is why you should always deploy CRYHOD with two-factor authentication in the pre-boot. This is also the configuration on which the government qualifications are based. We can supply the token and reader solutions as an addition, such as NEOWAVE Badgeo QSCD smart cards and a contact smart card reader.

ONEPX management console: see which laptops are really encrypted

Ask an administrator how many laptops are encrypted right now and there is a short silence. Then a script, an export, an assumption. Until a laptop is left behind on a train and someone wants proof within 24 hours that the drive was locked. "Probably" is not an answer, it is a reportable data breach. ONEPX, the web console for CRYHOD, ends the guesswork: every workstation enrols itself, you set your policy once per department or project, and a live compliance score shows who is protected and who is not. Connect it to Active Directory or LDAP and you are running the same afternoon.

Who it is for


Dutch government: approved for information up to Departementaal Vertrouwelijk
Defence: demonstrable compliance up to NATO Restricted and EU Restricted
Defence and aerospace suppliers: designs protected while travelling
GDPR and NIS2: a lost encrypted laptop is usually not a reportable data breach
Every mobile workplace: encrypt and forget


Why European

France uses it to encrypt its ministries. Developed in Europe, evaluated by European authorities, no foreign access.