Kapalya Solutions for the Public Sector

Encryption Management Platform

Kapalya empowers businesses and their employees to securely store sensitive files at-rest and in-transit across multiple platforms through a user-friendly desktop and mobile application. This ubiquitous encryption solution protects all your corporate data by seamlessly encrypting files on end-points (computers/mobile devices), corporate servers and public cloud providers. With Kapalya, users have the ability to share encrypted files across multiple cloud platforms.

  • End-Point Security

    The Encryption Management Platform creates a secure vault on user endpoints where:

    • A data classification engine scans the endpoint for sensitive files and prompts users to encrypt
    • All data within the vault is encrypted
    • Each file and folder is assigned a unique encryption key
    • No additional disk or storage space is taken up on the endpoint

  • Public-Cloud Security

    The problem with using the encryption offered by public cloud vendors:

    • Vendors will encrypt files at-rest on their cloud, however, files sitting on a user’s endpoint are left un-encrypted and vulnerable to attacks.
    • The cloud provider won’t protect your files on endpoints or private clouds
    • Most cloud providers control the encryption keys, making data visible to their cloud administrators.

    Some cloud providers allow customers to bring and manage their own keys. However, integrating with a cloud provider’s key management system requires programming which could result in time consuming efforts and if not configured properly, could expose the customer’s data.

    The Encryption Management Platform is cloud agnostic and uses client-side encryption so files and folders are encrypted before leaving the endpoint. While in-transit, files are double encrypted as they move through an SSL tunnel. Since the user controls the keys, your files are protected from eavesdropping by any third-party, including your cloud storage provider.

  • Private Cloud

    Kapalya creates a secure vault for each user on your private cloud as well, to allow file and folder protection within your network.

    • Your internal corporate administrators do not have privileges to view end-user data.
    • User’s credentials are not tied to the enterprise’s active directory

  • Encryption Key Management

    Key management done differently:

    • One unique key for each file and folder
    • Keys are served in real-time
    • Keys are never stored on endpoints, public clouds or private clouds
    • Once a function is complete, the keys are destroyed
    • This approach allows for encrypted file sharing within and outside your network
    • When file sharing, only the unique key for that file is shared, not the keys to all your files

  • Data Classification

    Kapalya’s data classification engine scans 250+ file types for social security numbers, credit card numbers, state I.D.s and driver's’ license numbers. The engine is customizable to identify the sensitive data your organization handles.

    If confidential data is found sitting on endpoints, the platform will prompt users with a list of files, and options to preview, encrypt or delete.

    The frequency of scans can be on-demand or programmed to run at certain times or intervals and can be configured based on business needs.