FileGuard overview
Why FileGuard labels a file on the station, and how that label works with GenGuard, VisionX, Vault, and HostGuard.
FileGuard overview
FileGuard is a Trustity Control Platform module. It runs in the same TAO agent as VisionX, GenGuard, Vault, and HostGuard. The file is never uploaded to Trustity, and it is not written into the portal database.
That is the point of the module. A scanner in the cloud has to receive the file before it can say anything about it. FileGuard reads on the station, remembers a fingerprint, and the label is what travels. GenGuard then uses that label at the browser. VisionX still watches the screen. Vault still holds credentials and encrypted vault files. HostGuard still watches sign-ins. None of those jobs require a second copy of the document.
One entitlement and one organization policy:
| Capability | What it does | Status |
|---|---|---|
| Classification | An operator sets a label and, optionally, who may open the file. TAO recognizes that file on every entitled station. | Available |
| Discovery | The station reads documents in the user's folders, and on Windows it also reads pictures and scanned PDFs. Findings come back as labels to review, not as file contents. | Available |
| Browser enforcement | GenGuard asks the station before a paste, drop, or file picker hands the file to the page. | Available |
| Ransomware protection* | Stops a process that is encrypting protected files. | First quarter of 2027 |
* Ransomware protection is scheduled for the first quarter of 2027. Classification, discovery, and browser enforcement are available now.
What the portal stores
- The label, the file fingerprint, and the path the station reported
- The category of a finding, such as a card number or a keyword
- A short masked excerpt, only after an operator asks for one, and only for 15 minutes
The excerpt is withheld when the station cannot prove the secret is gone from that passage.
Where it is enforced
GenGuard in Chrome and Edge holds the file until TAO answers. That covers text files, Word, Excel, PowerPoint, PDF, and common images. A file that already has a label is blocked even when the page never shows its text.
On the workstation, GenGuard inside TAO continues to gate clipboard text, keyword files, and configured app contexts. Classification of an image or PDF is enforced in the browser. The full split is in FileGuard with the rest of the platform.
Turn it on
- Confirm the organization is entitled for FileGuard.
- Open Security Policies and enable the FileGuard policy. It applies to the whole organization.
- Let stations check in. An older agent keeps working; discovery and classified-file checks start after that station is on a TAO build that includes FileGuard.
