You cannot protect what you cannot find.
Ask a business where its customer card numbers, employee social security numbers, or patient records live, and the honest answer is usually a shrug and a gesture at the file server. The records are also in mail attachments, in a spreadsheet on somebody's desktop, and in a folder from a project that finished in 2019.
That matters because the cost of a breach is calculated from the records exposed, not from the machines involved. If you do not know what you hold, you cannot size the risk, and you certainly cannot tell a regulator.
Find it, then price it.
The discovery line reads the machines and shares you nominate and picks out regulated record types across the file formats businesses genuinely use. Then it does something unusually practical: it puts a monetary figure on the exposure it found.
That number is what turns an abstract worry into a decision. It is also a number an insurer or a board will follow, which is more than can be said of a list of file paths.
Encrypt in place, watch the exits.
The enforcement line encrypts the files it found, in place, and does it invisibly. Approved staff open documents exactly as before and will not notice anything has changed. A copy that leaves through an unapproved route is unreadable to whoever receives it.
The exits themselves are governed too: removable drives, webmail, messaging applications, and cloud uploads can each be blocked or permitted, by file type and data category rather than by one blunt rule that stops people working.
Scanning takes time, and policy takes thought.
The first scan is the slow one, because it reads everything in scope. Machines with very large stores can take a while, and we schedule that so it does not land in the middle of your working day.
Channel policy also needs a conversation. Blocking every removable drive on day one is easy and usually wrong, because somebody legitimately needs one. We would rather spend an hour writing sensible rules than have you turn the control off in week two.
Lines on this rung
2 lines · rates per unit, per monthSensitive Data Discovery
Start by finding out what you actually hold. It reads the machines and shares you nominate, spots regulated data such as card numbers, social security numbers, and health records, and attaches a figure to the exposure.
- Scans local drives, mapped shares, and connected cloud storage.
- Recognises regulated record types across common file formats.
- Reports where the data sits, and who has been touching it.
- Produces a monetary exposure figure for the records found.
| Platform | Actifile agent |
|---|---|
| Scans | Local drives, mapped shares, connected cloud storage |
| Recognises | Card, social security, financial, and health record patterns |
| Output | Inventory by location plus a quantified exposure figure |
| Change | Nothing is blocked or encrypted at this tier |
| Priced by | Device, monthly |
monthly, taken in advance QTY
Encryption and Channel Control
Once you know where the sensitive files are, this encrypts them in place and controls the exits. Approved staff open files exactly as before. A copy that leaves through an unapproved channel is unreadable to whoever receives it.
- Encryption is applied in place and is invisible to approved users.
- Copies to removable media, webmail, or messaging apps can be blocked or encrypted.
- Policy is per file type and per data category, not one blunt rule.
- Includes everything in the discovery tier.
| Platform | Actifile agent |
|---|---|
| Encryption | Applied in place, transparent to approved users |
| Channels | Removable media, webmail, messaging, and cloud upload |
| Policy | By file type and data category |
| Includes | Discovery and quantification |
| Priced by | Device, monthly |
monthly, taken in advance QTY
Where this rung stops
This rung covers regulated records on the devices and shares you enrol. Its boundaries are worth stating before you rely on it.
- It scans what you point it at. Records held in a system nobody mentioned, or on a colleague's personal machine, are not in the inventory.
- The exposure figure is an estimate based on record counts and published cost models. It is a planning number, not a valuation you should present as fact.
- Encryption protects a copy that leaves. It does not stop an authorised person reading what they are authorised to read, and it is not a defence against a member of staff acting dishonestly within their own access.
- None of this is a compliance certificate. It produces the evidence a compliance programme runs on; the programme itself stays yours.
- A live break in is worked by the operations team through support, not by adding a subscription line. Say what you are seeing and we will tell you what happens next.
One more thing, stated where you can see it before you buy. Everything on this page is protective coverage bought in advance. It is not an emergency incident response retainer, and it does not put a responder on your site tomorrow because you subscribed today. An engagement of that kind is arranged directly with the Fortify 24x7 operations team. If something is under way as you read this, the quickest route to us is support@cyberthreat.help, or a case raised from your client portal.