Controlled decryption bound to identity, device, and policy.
Sensitive files stay encrypted at rest and in transit. A Companion Agent, identity-provider authentication, enrolled device keys, optional endpoint posture, short-lived leases, and a Key Broker govern when plaintext is released - never with a universal master key.
- Per-document envelope encryption
- No bulk-decrypt endpoint, no master key
- Short-lived, device-bound rendering leases
Enterprise
Zero-trust access control
What Enterprise does
Envelope encryption
Random per-document DEKs wrapped under customer-controlled KEKs.
Device keys
Hardware-backed, non-exportable keys in TPM or Secure Enclave.
Key Broker
Narrow, single-document unwrap grants - never bulk decryption.
Identity integrations
Microsoft Entra, Login.gov, PIV/CAC, OIDC, SAML, and Okta.
Companion Agent
Local policy enforcement, leases, heartbeats, and signed telemetry.
Endpoint posture
Normalized signals from CrowdStrike, Defender, SentinelOne, and Jamf.
The future of trusted documents
Bring cryptographic verification, verifiable provenance, and zero-trust access control to every document your organization creates and receives.