SecureFile for Government
Agency files that stay protected anywhere.
Case files, tax records and reports live on desktops, shared drives, email and USB drives. SecureFile encrypts each file and carries the access policy with it, so a lost laptop or forwarded attachment doesn't become a breach.
Click Caseworker / Lost laptop to switch views
SecureFile for government capabilities
-
Encryption that travels
Files stay encrypted on any device, drive or inbox.
-
Need-to-know access
Control who can open, edit, print and share.
-
Audit for oversight
Every open, share and denial on record.
-
Find what you have
Discover and classify CUI, PII and FTI in files.
Protects files across the tools agencies already use
- Windows
- macOS
- File servers
- SharePoint
- OneDrive
- Teams
- Outlook
- Box
- USB
Where agency data actually lives
Not in a database. In files, everywhere.
Most agency work happens in documents: intake forms, spreadsheets, scanned IDs and exported reports saved to desktops and shared drives. Each copy is sensitive data outside any system's control.
-
High risk
Desktops & laptops
Working copies of case files, saved locally and taken into the field.
Desktop\Case Files\Intake_Thompson.pdf -
Medium risk
Shared network drives
Years of department folders with permissions no one has reviewed.
\\agency-fs01\Benefits\2015-2026\ -
High risk
Email attachments
Reports sent to other agencies, contractors and the wrong recipient.
RE: Q3 payments (attached).xlsx -
High risk
USB & removable media
Files moved between air-gapped systems, courts and field offices.
E:\transfer\1099_extract_2026.pdf -
Medium risk
Scans & images
Scanned IDs, signed forms and evidence photos full of PII.
Scans\Scanned_ID_Nguyen.jpg -
Medium risk
Cloud & collaboration
SharePoint, OneDrive and Teams shares that spread beyond the team.
Teams › Eligibility › Files
The problem
Folder permissions stop at the folder.
Network permissions protect the shared drive. They don't protect the copy on a laptop, the attachment in someone's inbox or the file on a USB drive. SecureFile protects the file itself.
| When an agency file is... | Folder permissions alone | With SecureFile |
|---|---|---|
| On a lost or stolen laptop | Readable by whoever has it | Encrypted; access can be revoked remotely |
| Emailed to the wrong recipient | Breach notification process begins | Won't open outside authorized identities |
| Shared with a contractor | Copy is out of the agency's control | View-only, expires when the contract ends |
| Copied to a USB drive | Readable on any machine | Unreadable without authorization |
| Exfiltrated by ransomware | Citizen data published or sold | Stolen files stay encrypted |
-
On a lost or stolen laptop
- Folder permissions alone
- Readable by whoever has it
- With SecureFile
- Encrypted; access can be revoked remotely
-
Emailed to the wrong recipient
- Folder permissions alone
- Breach notification process begins
- With SecureFile
- Won't open outside authorized identities
-
Shared with a contractor
- Folder permissions alone
- Copy is out of the agency's control
- With SecureFile
- View-only, expires when the contract ends
-
Copied to a USB drive
- Folder permissions alone
- Readable on any machine
- With SecureFile
- Unreadable without authorization
-
Exfiltrated by ransomware
- Folder permissions alone
- Citizen data published or sold
- With SecureFile
- Stolen files stay encrypted
Need-to-know, per file
Same case file. Different rights for every role.
Policies travel inside the file, so the same rules apply on a desktop, in SharePoint or after the file is emailed.
-
Who can do what with Intake_Thompson_CF-30917.pdf Intake_Thompson_CF-30917.pdf Open Edit Print Share Copy to USB Assigned caseworker Owns the case Yes Yes Yes Within agency No Supervisor Case review Yes Yes Yes Yes No Records officer Retention & PIA requests Yes No Watermarked No No Partner agency Data sharing agreement Until 12/31 No No No No Contractor Modernization project No No No No No -
File catalog, retention & legal holds
Know every sensitive file the agency holds, who owns it and how long it must be kept, so records schedules and public information requests are easier to manage.
Sensitive file catalog File Class Owner Retention Intake_Thompson_CF-30917.pdf CUI HHS 7 years Investigation_memo_0412.docx CUI-LE OIG Legal hold 1099_extract_2026.pdf FTI Revenue Per IRS 1075 -
Audit trail for oversight
Every open, print, share and denied attempt, ready for inspectors general, auditors and incident response.
File access log User Action File Where a.perez Opened Intake_Thompson.pdf Laptop d.parker Viewed Q3_benefits.xlsx Email unknown Open denied Intake_Thompson.pdf Outside agency
Compliance alignment
Federal file controls, built into every document.
SecureFile helps agencies apply NIST, CJIS and IRS safeguards to the documents where sensitive data actually lives.
Control references are to NIST SP 800-53 Rev. 5. SecureDB supports compliance and authorization programs. It does not by itself make a system compliant or authorized.
-
Access enforcement
Only authorized identities can open each file, wherever it is.
NIST 800-53 AC-3 -
Information flow control
Limit sharing, printing and copying by role and destination.
NIST 800-53 AC-4 -
Audit events
Opens, shares, prints and denials recorded per file.
NIST 800-53 AU-2 -
Media protection
Files on USB and removable media stay encrypted.
NIST 800-53 MP-5 -
Protection at rest
CUI, PII and FTI encrypted on desktops, servers and the cloud.
NIST 800-53 SC-28
Texas public sector
Buy OnData through Texas contracts.
Texas agencies, counties, cities and school districts can purchase OnData through state contracts, which can simplify procurement.
FAQ
Questions from agency teams.
Have another question? Talk to our public sector team →
Do employees have to change how they work with files?
No. Authorized staff open, edit and save files in the same applications they use today. Protection is applied automatically by policy.
What happens if a laptop is lost or stolen?
The files on it stay encrypted. You can revoke access remotely, and any attempt to open them is denied and logged.
Can we share files with other agencies and contractors safely?
Yes. Policies can allow view-only access, block printing or copying, and end access when an agreement or contract ends.
How do protected files work with public information requests?
Authorized records staff can open, review and release files as usual, and the audit trail shows who accessed what during the request.
Can SecureFile find sensitive files we don't know about?
Yes. Discovery scans desktops, file servers and cloud storage to find and classify files holding CUI, PII and FTI.