Solutions / CyGate®

CyGate®

Protect the document, not just the folder

Your organization's documents stay encrypted at all times, including while someone is working on them. They only open for the authorized person, on the authorized computer, and stop being available once the session is closed.

If someone copies those files, what they take away is ciphertext. That is the difference between protecting access and protecting the document.

Control ends where the folder ends

File server permissions protect the folder, not the document. The moment someone with legitimate access copies a contract to a USB stick, attaches it to a personal email or syncs it to their own cloud, the file leaves the perimeter and all the protection stays behind.

The outcome is familiar: the organization finds out about the leak when the document is already outside, with no record of who took it and no way to revoke it. And when a ransomware incident arrives, that same unprotected file is exactly what the attacker copies before encrypting, so they can later demand a second payment for not publishing it.

Permanent protection, normal work

CyGate® keeps all corporate documentation encrypted with AES-256 without changing the way anyone works. People keep using Word, Excel and Acrobat as always, on an ordinary Windows drive.

There is no portal to upload files to, no manual encrypt and decrypt step, and no new way of working to teach. Protection no longer depends on each person remembering to apply it.

What it solves

The document that leaves the company

Taking a protected document outside the authorized environment is not something a user can do by oversight or shortcut. The restriction is enforced by the operating system itself, not by a policy that can be switched off.

Revoking access for real

Withdrawing a permission takes effect immediately and reaches the copies already in circulation: with no valid authorization, the file does not open anywhere. Access can also be limited to the computer that was registered.

Handing over to a third party without losing the trail

Controlled delivery to internal and external recipients requires explicit permission, asks for a reason, is audited and expires. Nothing leaves without a record.

Knowing what happened and when

Every open, export and delivery is logged with user, computer and time. The web console brings together the activity and the status of each protected folder.

Deploying without operational risk

CyGate® does not touch the Windows kernel. That keeps it out of the class of failure that has left entire fleets unable to boot after a faulty update.

No levers, no extortion

A data hostage situation charges for two separate things: giving your files back, and not publishing them. They are two independent levers, which is why disabling only one rarely avoids the payment. Those with impeccable backups still pay to keep their contracts from being leaked. Those who do not fear disclosure still pay to avoid being shut down.

CyGate® disables both.

Lever 1 · "I publish your information"

The threat is exfiltration prior to encryption, which works even if you restore without paying. What the attacker took was already encrypted and they have nothing to open it with: there is nothing to publish and nothing to sell. There is no confidentiality breach to notify either, because the GDPR expressly treats encryption as grounds for not communicating with data subjects, and several US state laws provide the same safe harbor.

Lever 2 · "I give your files back"

The threat is destructive encryption, which halts operations until someone pays or restores. The defense is the backup, and this is where CyGate® changes its economics: the copy is born protected, so it can be kept on inexpensive storage or in the cloud without that storage having to be trusted. And CyGate® recognizes an attack underway on the documents in time to stop the backup rotation, before the last good copy is lost.

What can be read by whoever takes the data

With both levers removed, no reason to pay is left. The work of restoring remains, which costs operating time and which no technology eliminates, but there is no longer a transaction to negotiate.

What the attacker takesCan they read it?
The documents on the file serverNo
A full backupNo
The system databaseNo
The entire server, with privilegesNo, with key custody on a physical device

Backup, keys and scope

A backup you do not have to protect separately

Protecting a conventional backup forces you to encrypt the repository and safeguard one more key. With CyGate® the copy is already born protected, so the backup stops being an asset to watch over and becomes an inert file. A misplaced backup medium is not an incident.

Master key custody

The master key is the only unrecoverable part of the system. CyGate® supports its custody on an external cryptographic device, split among several holders, so that no single person can reconstruct it and no individual loss destroys it.

How far it goes

CyGate® protects the organization's documents and the information that lives in them, which is what an attacker monetizes. It does not replace protection for the rest of the estate: endpoints, the directory and virtualization need their own controls. What CyGate® guarantees is that, whatever happens in that layer, your documents are not negotiable.

Capabilities

Permanent protection

AES-256 across all documentation, including while it is being worked on.

Friction-free work

The usual applications, on an ordinary Windows drive. Nothing new to learn.

Central control

Web console for users, folders, permissions, deliveries and auditing.

Straightforward deployment

Standalone server and agent installer, without touching the system kernel.

Quantum-safe and crypto-agile

The documentation CyGate® protects is encrypted with AES-256, which NIST considers resistant to the quantum computer. What your documents hold today stays protected after Q-Day.

And like every Cyte encryption product, CyGate® comes with crypto-agility by default: the algorithm, the key size and the mode of operation are configuration parameters. Migrating to the NIST post-quantum standards is deployed without rewriting the application or stopping operations.

Protection that travels with the document

Crypto-Vault® Ultra moves files securely from one point to another. CyGate® protects the file while it lives on the file server and while someone works with it, which is precisely the stretch where a document spends most of its useful life.

CyGate® closes the distance between having a confidentiality policy and being able to prove it during an incident, which is when it gets tested.

Support and professional assistance

Contact a specialist or schedule a demo of CyGate®.

The Cyte team