Retyc for Enterprises - SMEs and Large Companies
Secure transfer and datarooms for SMEs, startups, and large companies. Protect your intellectual property and collaborate with complete confidentiality.
Use cases
Your professional use cases
Retyc Transfer for exchanges with outside partners, Retyc Collaborate for datarooms on sensitive projects, Retyc Box to receive documents and applications. Three products covering your internal and external exchanges, without changing how your teams work.
Secure collaboration across teams
Share strategic documents, roadmaps and technical specifications between teams spread across several sites. Every access is attributed to a person and logged.
Sharing with external partners
With Retyc Transfer, send contracts, NDAs, proposals and specs to your clients, suppliers or partners. Automatic expiry and instant revocation.
Intellectual property protection
Protect your pitch decks, patents and R&D work. Encryption relies on hybrid keys, designed so that anything intercepted today stays unreadable tomorrow.

Security
Security you steer from the admin panel
End-to-end encryption protects the contents, that much is settled. What sets enterprise use apart are the rules deciding who may receive what, and for how long.
Automatic end-to-end encryption
Your files are encrypted on the workstation before anything is sent. Nothing for your teams to configure, and on the server side the API rejects any encryption key that is not hybrid.
Rules attached to your labels
Classify your transfers and datarooms by label, then attach a rule to each label: members only, a list of allowed domains, a cap on how long a transfer stays available. The label stays visible to everyone who sees the transfer, recipients included.
Blocked domains where it counts
Your list of forbidden domains applies when a transfer is created and when someone is invited into a dataroom alike. Members of your own organisation are never blocked.
An exportable audit log
Views, downloads and changes are timestamped and tied to their author. You set how long those events are kept, and you pull the log out as CSV.

Features
Features that fit your organisation
What an organisation actually uses: a transfer when something must be sent, a dataroom when it must last, a drop address when something must be received.
Sign in through your corporate SSO
Your teams sign in with the directory you already run: Microsoft Entra ID, Google Workspace, Okta, or any other OIDC or SAML provider. It is bound to your domain names, and the second factor can be enforced at your provider.
Secure document intake
With Retyc Box, hand a drop address to a partner, a client or a candidate. They send their files with no account to create, and you are notified on arrival.
Five roles for a dataroom
Owner, administrator, editor, contributor or viewer. Each person gets their role on the dataroom, and the contributor is the one who drops their own files without being able to touch anyone else's.
Custom branding and domain
Enterprise options: match the interface to your colours and use your own domain, for a consistent brand experience.

Sovereignty
Your data stays under European law
When a client asks where their files end up, you can tell them plainly, without having to name an American or Chinese hyperscaler.
Hosting and authentication in Europe
Storage and the authentication server both run at Scaleway, in Europe, on a host certified ISO 27001 and HDS. A short chain, one your procurement team can look into.
No dependency on hyperscalers
None of the large American or Chinese providers takes part in the processing chain. We control every link of the technical stack.
What we cannot do
Even under a legal order, all we can hand over is encrypted blocks. Decryption keys never pass through our servers, so there is nothing readable to hand over.
A compliance file that holds up
The DPA, the subprocessor list and the technical white paper are public. Your clients' security teams find their answers there without going through a sales call.

Reversibility
Getting your data out does not depend on us
Reversibility is usually a contract clause nobody tests until the day they have to leave. Here it is a single command: our open-source command-line client pulls all of your data onto your own disk.
Everything comes out, in one command
Our command-line client writes a self-contained folder to your disk: your organisation and its members, the blocked domains, and every dataroom with its decrypted files, its metadata and its activity log. One command, one folder, nothing to reassemble.
The key that opens the export is yours
The export needs the private key of your service account, of which we only ever hold the public half. So we can neither produce that export on your behalf, nor stop you from producing it.
Open-source client, open formats
The client is published under the MIT licence, so your teams can check what it does. What comes out is a plain tree of folders and files, readable in ten years without needing Retyc.
A stated scope
Transfers are not covered by the export, as the admin API exposes no way to download them. And a dataroom the key cannot open is recorded in the export manifest rather than quietly left out.

Scalability
Grow without re-signing or migrating
Changing plan is a billing setting, not a project. Nothing moves on the data side.
Start right away
Create your account and get to grips with the platform in a few minutes, with no commitment.
Upgrade without migration
Move from Solo to Business or Enterprise in one click. Your datarooms and permissions are exactly where you left them, only the invoice changes.
Transparent pricing
The price depends on the number of members and on storage, and both figures are shown on the pricing page. No line item appears along the way.
Dedicated Enterprise support
The Enterprise plan opens a dedicated support channel, contractual service commitments and help connecting your own tools.

Let's talk about your organisation
One demo is enough to see how Retyc fits into your exchanges, what your administrators control, and through which door your data comes back out.
Frequently asked questions
Retyc in the enterprise, in a few answers.
Day-to-day use happens in the browser, with nothing to install. For technical teams, an open-source command-line client and an MCP server let you automate transfers and dataroom management.
Yes. Authentication runs on Keycloak, which federates with Microsoft Entra ID, Google Workspace, Okta or any other OIDC or SAML identity provider. The provider is bound to one of your domain names, and you can enforce the second factor there. We set the connection up with you at deployment time, after which the configuration stays visible in your organisation settings.
Every user gets a role on the dataroom, from plain viewer to owner, and you can change it or take it away whenever you want. Every action stays recorded in the audit log, role changes included.
Yes. You can keep a list of blocked domains, applied both when a transfer is created and when someone is invited into a dataroom. Organisation labels go further: to each label you attach a rule limiting recipients to members or to a list of allowed domains, and capping how long a transfer stays available.
A single command from our open-source client pulls everything onto your disk: the organisation, its members, the blocked domains and every dataroom with its decrypted files and its log. You need the private key of your service account, the one we have only ever held the public half of. Two limits we would rather state up front: transfers are not covered (the admin API exposes no way to download them), and a dataroom the key cannot open is flagged in the manifest rather than silently skipped.
That is what the service account is for. Once enabled, it appears as a recipient of every new transfer and as a read-only member of every new dataroom, which lets you reopen those spaces without their creator. Its private key is generated on your side and never reaches us: keep it in your secret manager, because we cannot regenerate it.
The items that come up most often are public and you can attach them directly: the technical white paper describes the architecture and the cryptographic primitives, the subprocessor list names the host (Scaleway, in Europe), and the DPA covers the contractual side. On the CLOUD Act question: we hold no key, so an order could only reach encrypted blocks.
Yes, the Enterprise plan lets you match the interface to your colours and use your own domain, for a brand experience your partners recognise.