A Fortify 24x7 brand. Security engineering for the companies that build things.Client sign inTalk to an engineer
EagleTech Innovations
Sheet 05 / Data protection

You cannot protect a file nobody has found yet.

Ask a founder where the sensitive material lives and you get a confident answer about the repository and the shared drive. The scan finds it in a downloads folder from last spring, in an export somebody made for a board deck, and in a copy on the laptop of a person who left in June. Discovery comes first because everything else depends on it.

ActifileDiscovery and scoringEncryption
2 lines / discover first / enforce second
Lines on this sheet2
PlatformActifile
Rate basisDevice
SequenceDiscover, then enforce

Discovery gives remediation an order

A scan that returns ten thousand findings and no ranking is a way of feeling busy. Actifile scores what it finds, weighting the type of data and how exposed it currently is, which converts a wall of results into a short list you can actually work through this quarter.

For a product company the interesting hits are rarely the ones you expected. Design exports outside the design system, credential files in a project folder, customer records in a spreadsheet a salesperson built in 2024, and archives of a repository that were never meant to survive the migration.

Enforcement bought without discovery is a set of rules aimed at a map you do not have.

Then govern the routes out

Once you know where the material is, the second line puts controls on it: encryption at rest wherever the material justifies it and limits on the channels data can leave by. That is a policy conversation more than a software one, and we work it with you rather than shipping a default that blocks your team on a Monday and gets switched off by Wednesday.

Sequencing matters. Enforcement bought without discovery is a set of rules aimed at a map you do not have.

Lines on this sheet

Specifications and rates

Prices below are pulled straight out of billing. Anything you add sits in your basket while you carry on reading.

Fortify-DLP-ClassifySpecification

Sensitive Data Discovery

Actifile, finding and ranking what matters

Scans the endpoints and shares you point it at, identifies regulated and proprietary material, and puts a score on the exposure so remediation has an order rather than a mood.

  • Finds regulated data and proprietary material across devices and shares.
  • Scores exposure per device, which is what turns findings into a work queue.
  • Repeats on a schedule, because the answer changes every time somebody exports something.
PlatformActifile
ScopeEndpoints and the file shares you nominate
OutputInventory of sensitive data with per device exposure scoring
CadenceContinuous, with scheduled reporting
SequenceBuy this before enforcement
Rate basisDevice, monthly
Fetchingper device
billed monthly, up front
QTY
Fortify-DLP-EnforceSpecification

Encryption and Channel Control

Actifile, governing the exits

The control half. Encryption applied wherever the material justifies it, and limits on the channels data may leave through, tuned with you rather than shipped as a default that gets disabled in week two.

  • Encryption at rest across whatever discovery flagged as worth protecting.
  • Controls on the routes data leaves by, set against your real workflows.
  • Policy written jointly, so the first exception does not become a ticket war.
PlatformActifile
ControlsEncryption at rest and channel restriction
TuningPolicy authored with your team before it is enforced
PrerequisiteDiscovery, on the same devices
Best fitMachines holding design files, source archives, customer records
Rate basisDevice, monthly
Fetchingper device
billed monthly, up front
QTY
Honest scope

Where this sheet stops

Data protection is often sold as though it removes the possibility of leakage. It does not, and a vendor who says otherwise has not run one of these programs.

  • A determined authorized person can still take it. Somebody who is supposed to read a document can photograph the screen. These lines raise the effort and create a record; they do not make theft impossible.
  • Discovery only sees what you point it at. Devices and shares in scope get scanned. A personal cloud account or a machine outside management is not covered and will not appear in the inventory.
  • Classification is very good, not perfect. Expect to tune it. Some proprietary formats need a rule written for them, and the first pass will surface both misses and false positives.
  • This is not a compliance certification. The inventory and controls support an audit. They are not themselves an attestation, and no line here signs a framework off on your behalf.
  • Encryption does not survive a deliberate export by a permitted user. If policy allows a route, data can travel it. Deciding which routes to allow is the actual work, and it belongs to you with our help.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - EagleTech Innovations is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.