SecureFile for Government

Agency files that stay protected anywhere.

Case files, tax records and reports live on desktops, shared drives, email and USB drives. SecureFile encrypts each file and carries the access policy with it, so a lost laptop or forwarded attachment doesn't become a breach.

View files as
C:\Users\aperez\Documents\Case Files

Opened by a.perez@hhs.state.gov · assigned caseworker

Opened by unknown user · device outside agency

Policy: cui-case-files

  • Intake_Thompson_CF-30917.pdf CUI · Case file
  • Q3_benefit_payments.xlsx PII · Finance
  • Investigation_memo_0412.docx CUI · Law enforcement
  • Scanned_ID_Nguyen.jpg PII · Identity document
  • 1099_extract_2026.pdf FTI · Tax

Intake_Thompson_CF-30917.pdf

CUI

Benefits Intake — Case CF-30917

Applicant: R. Thompson

SSN: 512-55-3390 · DOB: 1979-04-22

Household income: $31,200 / yr

Address: 1408 E. 12th St, Austin TX

Notes: Home visit scheduled 9/12…

Decrypted for authorized user · access logged

Encrypted file contents:U2FsdGVkX1+Vq8mFeD2hJ4kTn9Lc3xWp7RsY0bQe5ZaG1fHuN6vKjM2oPi8tCr4dXw9sLy3EnB7gAq0zIh5RfT2uVc6Jm1Ko8Pd==

Access denied · attempt logged · owner notified

5 of 5 files encrypted on this device

1-click remote revoke

1 denied attempt 0 blocked attempts

Click Caseworker / Lost laptop to switch views

SecureFile for government capabilities

  • Encryption that travels

    Files stay encrypted on any device, drive or inbox.

  • Need-to-know access

    Control who can open, edit, print and share.

  • Audit for oversight

    Every open, share and denial on record.

  • Find what you have

    Discover and classify CUI, PII and FTI in files.

Protects files across the tools agencies already use

Where agency data actually lives

Not in a database. In files, everywhere.

Most agency work happens in documents: intake forms, spreadsheets, scanned IDs and exported reports saved to desktops and shared drives. Each copy is sensitive data outside any system's control.

  • High risk

    Desktops & laptops

    Working copies of case files, saved locally and taken into the field.

    Desktop\Case Files\Intake_Thompson.pdf
  • Medium risk

    Shared network drives

    Years of department folders with permissions no one has reviewed.

    \\agency-fs01\Benefits\2015-2026\
  • High risk

    Email attachments

    Reports sent to other agencies, contractors and the wrong recipient.

    RE: Q3 payments (attached).xlsx
  • High risk

    USB & removable media

    Files moved between air-gapped systems, courts and field offices.

    E:\transfer\1099_extract_2026.pdf
  • Medium risk

    Scans & images

    Scanned IDs, signed forms and evidence photos full of PII.

    Scans\Scanned_ID_Nguyen.jpg
  • Medium risk

    Cloud & collaboration

    SharePoint, OneDrive and Teams shares that spread beyond the team.

    Teams › Eligibility › Files

The problem

Folder permissions stop at the folder.

Network permissions protect the shared drive. They don't protect the copy on a laptop, the attachment in someone's inbox or the file on a USB drive. SecureFile protects the file itself.

What happens to an agency file with folder permissions alone and with SecureFile
When an agency file is... Folder permissions alone With SecureFile
On a lost or stolen laptop Readable by whoever has it Encrypted; access can be revoked remotely
Emailed to the wrong recipient Breach notification process begins Won't open outside authorized identities
Shared with a contractor Copy is out of the agency's control View-only, expires when the contract ends
Copied to a USB drive Readable on any machine Unreadable without authorization
Exfiltrated by ransomware Citizen data published or sold Stolen files stay encrypted
  • On a lost or stolen laptop

    Folder permissions alone
    Readable by whoever has it
    With SecureFile
    Encrypted; access can be revoked remotely
  • Emailed to the wrong recipient

    Folder permissions alone
    Breach notification process begins
    With SecureFile
    Won't open outside authorized identities
  • Shared with a contractor

    Folder permissions alone
    Copy is out of the agency's control
    With SecureFile
    View-only, expires when the contract ends
  • Copied to a USB drive

    Folder permissions alone
    Readable on any machine
    With SecureFile
    Unreadable without authorization
  • Exfiltrated by ransomware

    Folder permissions alone
    Citizen data published or sold
    With SecureFile
    Stolen files stay encrypted

Need-to-know, per file

Same case file. Different rights for every role.

Policies travel inside the file, so the same rules apply on a desktop, in SharePoint or after the file is emailed.

  • Who can do what with Intake_Thompson_CF-30917.pdf
    Intake_Thompson_CF-30917.pdf Open Edit Print Share Copy to USB
    Assigned caseworker Owns the case Yes Yes Yes Within agency No
    Supervisor Case review Yes Yes Yes Yes No
    Records officer Retention & PIA requests Yes No Watermarked No No
    Partner agency Data sharing agreement Until 12/31 No No No No
    Contractor Modernization project No No No No No
  • File catalog, retention & legal holds

    Know every sensitive file the agency holds, who owns it and how long it must be kept, so records schedules and public information requests are easier to manage.

    Sensitive file catalog
    File Class Owner Retention
    Intake_Thompson_CF-30917.pdf CUI HHS 7 years
    Investigation_memo_0412.docx CUI-LE OIG Legal hold
    1099_extract_2026.pdf FTI Revenue Per IRS 1075
  • Audit trail for oversight

    Every open, print, share and denied attempt, ready for inspectors general, auditors and incident response.

    File access log
    User Action File Where
    a.perez Opened Intake_Thompson.pdf Laptop
    d.parker Viewed Q3_benefits.xlsx Email
    unknown Open denied Intake_Thompson.pdf Outside agency

Compliance alignment

Federal file controls, built into every document.

SecureFile helps agencies apply NIST, CJIS and IRS safeguards to the documents where sensitive data actually lives.

  • NIST SP 800-53
  • NIST SP 800-171
  • CJIS Security Policy
  • IRS Pub 1075
  • State records laws

Control references are to NIST SP 800-53 Rev. 5. SecureDB supports compliance and authorization programs. It does not by itself make a system compliant or authorized.

  • Access enforcement

    Only authorized identities can open each file, wherever it is.

    NIST 800-53 AC-3
  • Information flow control

    Limit sharing, printing and copying by role and destination.

    NIST 800-53 AC-4
  • Audit events

    Opens, shares, prints and denials recorded per file.

    NIST 800-53 AU-2
  • Media protection

    Files on USB and removable media stay encrypted.

    NIST 800-53 MP-5
  • Protection at rest

    CUI, PII and FTI encrypted on desktops, servers and the cloud.

    NIST 800-53 SC-28

Texas public sector

Buy OnData through Texas contracts.

Texas agencies, counties, cities and school districts can purchase OnData through state contracts, which can simplify procurement.

  • Texas contracts
  • ITSAC
View contracts →

FAQ

Questions from agency teams.

Have another question? Talk to our public sector team →

Do employees have to change how they work with files?

No. Authorized staff open, edit and save files in the same applications they use today. Protection is applied automatically by policy.

What happens if a laptop is lost or stolen?

The files on it stay encrypted. You can revoke access remotely, and any attempt to open them is denied and logged.

Can we share files with other agencies and contractors safely?

Yes. Policies can allow view-only access, block printing or copying, and end access when an agreement or contract ends.

How do protected files work with public information requests?

Authorized records staff can open, review and release files as usual, and the audit trail shows who accessed what during the request.

Can SecureFile find sensitive files we don't know about?

Yes. Discovery scans desktops, file servers and cloud storage to find and classify files holding CUI, PII and FTI.

More for government

Protect citizen data everywhere it lives.