| Fortify-DLP-Classify | Discovery, risk baseline, vulnerability scanning and reporting on Windows, Linux and macOS |
|---|---|
| Fortify-DLP-Enforce | Everything in Classify, plus dynamic file encryption, compliance profiles and channel whitelisting |
| Platform | Actifile, deployed to Windows, Linux and macOS endpoints and operated by Fortify 24x7 |
| Discovery | Personally identifiable information and cardholder data located across endpoints and servers |
| Risk baseline | A measured starting position for data breach exposure rather than an estimate |
| Vulnerability scanning | Scanning with trend reporting so the direction of travel is visible over time |
| Reporting | Data breach risk report with a per-device breakdown of insecure data |
| Encryption | Dynamic encryption and decryption of files in place, transparent to the person using them |
| Compliance profiles | Multiple profiles so different regimes can be applied to different parts of the estate |
| Channel control | Application and channel whitelisting governing which routes secured data may travel |
| Billing unit | Per device, per month |
Double extortion changed what a backup protects you from
For most of the last decade, a good restore point ended the conversation. It largely does not any more. Operators now copy data out before encrypting anything, so the second demand does not care whether you recovered. It is about publication: customer records, payroll, medical detail, card data, the contract terms you agreed with a client who would be unhappy to see them.
Backup is no defence against that, and it was never designed to be. What reduces the second demand is holding less exposed material, and holding what remains in a form that is worthless when copied.
Nobody knows where their sensitive data is. Including you.
This is not an accusation, it is an observation from every assessment we have run. Cardholder data sits in a spreadsheet somebody built for a reconciliation in 2019. Personal records live in an export from a system that was decommissioned. Copies propagate into downloads folders, shared drives, and the laptop of the person who was covering that month.
Fortify-DLP-Classify is Actifile, and it locates that material. Personally identifiable information and cardholder data are discovered across Windows, Linux and macOS, producing a data breach risk report with a per-device breakdown of insecure material, alongside vulnerability scanning with trend reporting. The output is a baseline: a real figure for your exposure, on a specific date, that you can move.
Deletion is usually the cheapest control on that list. A substantial share of what discovery surfaces is material nobody needed to keep, and removing it costs nothing per month.
Encryption in place, and the channels data may travel
Fortify-DLP-Enforce is the same Actifile agent with its enforcement half switched on. It carries everything in the discovery line and adds the controls that change the outcome of a copy. Files are encrypted and decrypted dynamically, so the person working on a document sees a document, while the same file lifted off the machine by someone without the entitlement is unreadable rather than merely inconvenient.
Application and channel whitelisting governs which routes secured data is permitted to travel. This is the difference between knowing that a spreadsheet of customer records exists and controlling whether it can be attached, uploaded, or written to a USB stick at all. Multiple compliance profiles let a regulated part of the business run stricter rules than the rest without imposing them on everyone.
The report your insurer, auditor and largest client will all ask for
Three separate audiences ask the same question in different words: what sensitive data do you hold, where, and what protects it. Answering with a policy document is noticeably weaker than answering with a scan.
The risk report and its trend line do double duty. Internally it directs effort at the machines that actually carry the exposure. Externally it is evidence of a measured position rather than an assertion, which is generally what separates a smooth renewal from a long one.
Buy discovery first, even if you intend to buy both
Encryption applied before you know what exists is a policy written against a guess. Discovery routinely finds that the sensitive material is concentrated on a small number of machines, which changes both the scope you enforce on and the number of devices you are paying for.
Run discovery, read the baseline, then decide. Some businesses move the whole estate to the enforcement line, some enforce on a department, and some find the honest answer is to delete a great deal and enforce on very little.
Where this stops
This is prevention and measurement, not forensics. Discovery tells you what sensitive data is present on a device today. It does not establish whether data has already been taken, by whom, or when, and it is not a substitute for an investigation where exfiltration is suspected.
These lines support a compliance programme rather than constituting one. No product makes an organisation compliant with any regime on its own, and any breach notification decision remains a legal question for your counsel rather than a technical one for us.