A Fortify 24x7 brand. Pilotage across the security stack, and your own people stay on the helm.Chart roomSpeak to a duty engineer
Independence IT Group
Chart 07 / Data cargo control

You cannot govern a cargo nobody has weighed.

Every company at this size is sitting on regulated records it could not currently point to. An extract somebody pulled for a board paper, a share that came across with an acquisition, a folder of documents promised as temporary three years ago. Discovery comes first for an unremarkable reason: policy written over records nobody can find governs precisely nothing.

ActifileDiscovery firstEncryption on the way out
2 lines drawn here / every rate live from billing
Lines on this chart2
PlatformActifile
Billed onDevice
Sequence of workWeigh, score, then enforce

Weigh it, score it, and only then rule on it

The discovery code reads endpoints and shares hunting regulated and proprietary records, then attaches a figure to whatever sits on each individual machine. Having a figure is what lets remediation be sequenced, and sequencing is the whole difference between an effort that ends and a report that gets forwarded. A laptop holding forty thousand records and a laptop holding eleven are unlike problems, and pretending otherwise is how this work stalls.

Enforcement makes sense afterward, once the shape is visible. Encrypt whatever has to remain in place, shift whatever should never have arrived, and rule on the routes by which the remainder may travel.

Policy written over records nobody can find governs precisely nothing.

How records actually leave a company

Departure is rarely cinematic. Records leave as an attachment, through a sync client somebody signed into privately, onto a stick before a flight, or by way of an application nobody ever thought of as a route out. Enforcement rules on those routes application by application, and encrypts files so that a copy which does travel is worth considerably less on arrival than it appears.

Understand this station as a control and never as a certificate. It generates the evidence an assessor will ask you for. It does not establish what your obligations are, and we will not let it be read that way.

Codes drawn on this chart

Line sheets and rates

Figures underneath arrive directly out of billing. Whatever gets logged waits in the logbook while you keep reading.

Fortify-DLP-ClassifyLine sheet

Sensitive Data Discovery

Actifile, reading endpoints and file shares

Discovery of regulated and proprietary records across the company, scored per machine, so that remediation arrives with a sequence attached instead of as an open ended list.

  • Reads endpoints and shares looking for personal, financial, and proprietary records.
  • Puts an exposure figure against each machine, floating the worst of them upward.
  • Output an assessor can accept as evidence, not a summary written for a meeting.
Piloted onActifile discovery
SoundsFiles across endpoints and shares, tested against regulated patterns
Logged forWhat turned up, on which machine, and which way the figure is moving
Handed toYour team, while Fortify 24x7 engineers work the findings
Charted byDevice, monthly
Soundingper device
taken each month, always up front
QTY
Fortify-DLP-EnforceLine sheet

Encryption and Channel Control

Actifile, ruling on the ways records depart

Encryption over the records that have to stay where they are, plus a ruling on which applications and which channels the remainder is allowed to move through.

  • Encryption that stays invisible, so entitled colleagues carry on working.
  • A ruling per application, over the routes records genuinely depart by.
  • Compliance profiles matched to whichever framework your assessor works to.
Piloted onActifile enforcement
SoundsMatched files on the move, by application and by channel
Logged forEncryption state, and every attempt at a route out
Handed toFortify 24x7 engineers, against a policy you signed off
Charted byDevice, monthly
Soundingper device
taken each month, always up front
QTY
Honest scope

Where this chart runs out of water

No station in this catalog attracts more overselling than this one. These are the boundaries we hold ourselves to.

  • Discovery reads what it is able to open. Records inside formats it cannot parse, or held on systems that were never enrolled, are absent from the figure. Read the number as a floor and never as a total.
  • It has no opinion about your legal obligations. Locating regulated records and evidencing their handling is the job. Working out which rules bind your particular business belongs to counsel and to whoever audits you.
  • Somebody entitled to the file can still walk away with it. Where a colleague may legitimately open a document, that colleague may also keep a copy. Leaver process and periodic access review carry that weight. Software does not.
  • Encryption defends a file and not a judgement. Where a document is encrypted and then shared quite legitimately by a person who should have thought harder, it has been shared. Every technical control ends where authority starts.
  • Classifying your business is not our work. Deciding what your company treats as sensitive, and drafting the policy that follows, sits with your team. Running the tooling that enforces that answer is where we come in.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - Independence IT Group is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.