A Fortify 24x7 brand. Security operations for North American business, staffed every day of the calendar.Client sign inContact
CyberDefense
Home / Catalog / Data loss prevention
Family 05 / Data loss prevention

Find it first. Then price it. Then protect it.

Continuous discovery of regulated data across the endpoints holding it, exposure quantified for the people who approve budgets, and transparent encryption on the files that warrant it.

Platform underneathActifile Endpoint discovery, risk quantification, and enforcement.
Lines in this familyTwo
Counted byDevice
Recommended orderDiscovery first, enforcement afterwards
01Problem

Almost every organization is wrong about where its data sits.

Ask where the regulated data lives and you will be told the finance system, the practice management platform, the CRM. Then somebody runs a discovery scan and turns up card numbers in a spreadsheet on a laptop, patient identifiers in an export made in 2019, and a folder of scanned documents on a share that has had no owner since a reorganization.

You cannot protect a population you have not measured, and you certainly cannot report on it to a regulator or an insurer. This family begins with finding it, which is why it is sold as two lines and not one.

The platform underneath

Actifile: discover, quantify, then enforce.

Actifile runs an agent on the endpoint and continuously identifies sensitive data at rest and in motion: personally identifiable information, payment card data, and whichever regulated categories attach to your industry. Discovery is ongoing rather than an annual project, because the exposure shifts every time somebody exports a report.

  • A baseline you can put in front of somebody. The output is a data breach risk report broken down device by device, showing where insecure data is sitting. It turns an argument about policy into a list of machines, and a list of machines is a conversation that can be finished.
  • Exposure stated as a number. Risk is quantified rather than described, which is what makes the case for remediation land with the people holding the budget. Treat the figure as a way of ranking the work, not as an insurance valuation.
  • Vulnerability scanning with trend reporting. Exposure tracked over time, so you can see whether last quarter's effort actually moved anything.
  • Transparent encryption on the enforcement line. Files are encrypted and decrypted in place for authorized people and applications. Anyone doing legitimate work notices nothing at all; a copy lifted out of that context is unreadable.
  • Compliance profiles and channel control. Several profiles for the regimes that apply to you, with allowlisting over which applications and channels may open protected data in the first place.
02Operation

Run discovery first. We mean it.

We ask customers to run the discovery line for a while before switching on enforcement, and we would give the same advice if we sold neither. Encryption policy written before you know where the data is produces two results: files that should have been protected and were not, and a business process that breaks on a Monday for reasons nobody can trace back.

Discovery establishes where the data is and who handles it. Enforcement then lands on a known population, with the applications and channels that legitimately need access already accounted for. The sequence costs a few weeks and saves a good deal more than that.

The lines in this family

Two lines / prices fetched live
Fortify-DLP-Classify

Data Discovery

per device
LoadingrateQTY
FunctionData discovery and risk baselining
FindsPersonally identifiable information and payment card data
PlatformsWindows / Linux / macOS
ReportingData breach risk report, broken down device by device
ScanningVulnerability scanning with trend reporting
QuantificationExposure expressed as a monetary risk figure
Counted byOne device / monthly

Start here. This is the line that tells you whether you need the next one, and on how many machines.

Fortify-DLP-Enforce

Data Encryption and Control

per device
LoadingrateQTY
FunctionEverything in the discovery line, and enforcement on top
EncryptionDynamic encryption and decryption of files in place
ComplianceMultiple compliance profiles
Channel controlApplication and channel allowlisting over protected data
PlatformsWindows / Linux / macOS
Counted byOne device / monthly

The enforcement tier, and a superset of the discovery line, so a device carrying this does not need that one as well.

Where this stops, plainly

Discovery sees the machines running the agent and the storage those machines can reach. Data existing only inside a SaaS platform you have not connected is outside its view entirely. If your sensitive population lives mostly in a cloud application, say so before buying and we will tell you honestly whether this is the right control to spend on.

Encryption protects a file. It does not correct a decision. An authorized person who chooses to send a document to the wrong recipient was authorized the whole way through, and no data protection product on the market resolves that. Channel controls narrow it. They do not close it.

And the risk figure is a prioritization instrument. It is an estimate derived from the data found and the regime applied. It is genuinely useful for deciding what to fix first. It is not a valuation, and we will not hand it to you as one.

FORTIFY 24X7

Heads up: card statements show FORTIFY 24X7 - CyberDefense is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.