Two lines, and the order matters. The first goes through your machines and reports what confidential material is genuinely sitting on them, usually to some discomfort. The second encrypts what counts and bounds the routes it can travel by. Reversing that order buys an ugly month.
Nobody plans to leave an exchange verification packet loose in a downloads folder. It happens because somebody had to send it once, at speed, a year and a half ago. The same goes for the exported list of counterparty details, the scan of a passport, and the screenshot taken to help a colleague which then simply stayed put.
This first line goes through whatever you aim it at and reports what is present, whereabouts, and in what quantity. Each device gets a score so remediation can begin at the worst one rather than whichever came to mind. It genuinely only reports, and we would far rather you saw the list before anything got encrypted.
Encryption here attaches to the document itself instead of to whichever folder it started out in, which is the difference between protection that survives being copied and protection that does not. Something carried off on a memory stick or dropped into a personal cloud stays unreadable, so exfiltration becomes an irritation rather than a disclosure.
Route limits are the other half. Removable media, personal sync clients and unapproved applications can each be bounded by policy. Nobody is trying to make work impossible. The aim is to narrow the accidental exit until using it has to be a conscious act.
Billing supplies every figure below while the page loads. An entry holds its place while you go on reading.
A catalogue has to exist before a policy can. This line reads the machines you point it at and reports back what confidential material is sitting on them, whereabouts, and in what quantity, which tends to be a less comfortable read than anybody expects.
| Deposited on | Whichever workstations or servers you aim it at, one unit apiece |
|---|---|
| Seals | Nothing yet, and deliberately so; this line writes the catalogue |
| Held at | Findings and file locations recorded within the Actifile tenant |
| Sealed by | Actifile |
| Witnessed by | Fortify 24x7 engineers walking the report through with you line by line |
Encryption bound to whatever material matters, with limits placed on how it is permitted to travel. A document carried off on a memory stick or dropped into somebody's personal cloud stays unreadable, which turns a theft into an inconvenience.
| Deposited on | The same devices, once you know what is genuinely sitting on them |
|---|---|
| Seals | Material leaving by an unapproved route, and the legibility of anything taken |
| Held at | Keys and policy within the Actifile tenant, with files staying put |
| Sealed by | Actifile |
| Witnessed by | Fortify 24x7 engineers shaping policy and handling every exception |
Data protection covers material at rest on machines under your management. It is no general answer to secrecy, and some things it deliberately leaves alone.
Heads up: card statements show FORTIFY 24X7 - Cryptinest is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.