The document you are worried about is on four machines already.
Sensitive material in a household does not sit in one repository. It is emailed to an attorney, forwarded to a business manager, opened on a laptop in a hotel, saved to a desktop for convenience during a negotiation and never removed. A scan of a passport made for one booking in 2019 is still in a downloads folder somewhere.
So the first honest step is not a policy. It is an inventory. You cannot make a decision about material you have not located, and every conversation we have had about this begins with somebody being surprised by where a copy turned out to be.
What the first tier establishes.
Both lines in this family are Actifile. Document Discovery is the first of them: it installs across Windows, macOS and Linux computers and looks at what is genuinely stored there. It picks out anything identifying a person, along with card data, and turns that into a baseline of risk: no abstract score, but a machine by machine account of which unprotected material is sitting where.
It also scans for vulnerabilities on those machines and reports the trend over time, which is the number that tells you whether an estate is being maintained or merely described. The output is a document a business manager or an attorney can read, and it is the basis of every sensible decision that follows: what to delete, what to move, what to encrypt, and which machine should not be holding any of it.
What the second tier adds.
Document Encryption is that same discovery with enforcement laid over it. Encryption and decryption happen on the fly, so material stays readable throughout ordinary work and turns opaque the moment it leaves that setting. A copied file is still a copied file. It is simply not a legible one.
It carries multiple compliance profiles, so the rule applied to medical paperwork can differ from the rule applied to a contract, and it adds application and channel allowlisting: which programs, and which routes out, are permitted to handle protected material at all. That is the control which addresses the ordinary failure, where somebody attaches the wrong document to the right message, or drags a folder into a personal cloud account to work on it at home.
Discovery first. Always.
We will not sell you enforcement on day one, and if you ask for it we will suggest otherwise. Encryption rules written before anybody knows where the material lives break legitimate work, and a control that breaks legitimate work is removed within a month by somebody who has a deadline.
Run discovery, read the baseline, decide what you actually care about, then enforce on that. Upgrading a machine from the first tier to the second is a line change on the next invoice and nothing more.
| Built on | Actifile, in discovery mode |
|---|---|
| Platforms | Windows, macOS and Linux |
| Discovery | Information that identifies a person, and card data, located machine by machine |
| Baseline | A measured starting point for how exposed the estate currently is |
| Vulnerabilities | Scanned, with the trend reported as it moves |
| Reporting | A machine by machine account, written to be read by people who are not technical |
| Billed | Monthly, for each computer |
| Built on | Actifile, with enforcement switched on |
|---|---|
| Includes | Everything in Document Discovery |
| Encryption | Files sealed and unsealed on the fly, throughout ordinary work |
| Profiles | Multiple compliance profiles, applied by material type |
| Channels | Application and channel allowlisting for protected material |
| Upgrade path | Interchangeable per machine, effective on the next invoice |
| Billed | Monthly, for each computer |
Where this family stops
These lines govern material on machines we manage. They do nothing about information about you that is already public or already in the hands of a data broker. That is real work and we do it, but it is scoped in conversation rather than sold here: see matters we discuss first.
Discovery is not a backup. A protected copy of the same material lives in Copies held elsewhere, and encryption at rest on a laptop is a configuration item under management.