HP Client Security Commercial Managed IT Software
6 
Layer Data protection  Description 
unauthorized access. Starting with new 2013 PCs, HP Drive 
Encryption is FIPS 140-2 L1 certified. 
•  With Drive Encryption, authentication (a password, smart card 
or fingerprint) is required before Windows will even start 
•  Encrypted drives removed from the system cannot be read by 
another PC without proper authorization 
•  HW encryption supported with Self-Encrypting Hard Drives 
(SEDs). 
•  HP Drive Encryption provided with new 2013 PCs is powered by 
WinMagic. 
1.  For enterprise level manageability, HP Drive Encryption is 
upgradeable to WinMagic SecureDoc Enterprise. HP offers 
licensing for HP and non-HP PCs. 
2.  For HP Drive Encryption on PCs released prior to 2013, 
DigitalPersona Pro Workgroup offers enterprise level 
manageability. 
  HP File Sanitizer 
5
(See HP File Sanitizer on page 21) 
You can permanently erase individual files, folders and personal 
information from the internal hard drive on your PC. Only supports 
traditional hard drives. 
  HP Trust Circles 
6 
(See HP Trust Circles on page 22) 
HP Trust Circles protects accidental data leakage by allowing only 
members of a Trust Circle to access specified documents. Assign 
folder(s) to each Trust Circles, and all files placed in those folders are 
encrypted so that only the contacts assigned to the Trust Circle can 
access them. 
•  When included, HP Trust Circles Standard supports creating up 
to 5 Trust Circles with up to 5 contacts per Trust Circle. 
  HP Disk Sanitizer External Edition  Software that will permanently destroy data on standard hard drives 
in preparation for system disposal or redeployment. 
A printable report is generated for this operation. 
  HP Privacy Manager 
7 
(End of Life)  Protect supported Microsoft Office® files and emails sent in Microsoft 
Outlook® by allowing only your selected Trusted Contacts to access 
the information. 
•  Creates a digital identity that is verified by authentication to 
help prevent supported Microsoft Office files from getting into 
the wrong hands by encrypting for selected trusted contacts 
only 
•  No longer offered with new HP Business PCs. 
Hardware-based  Common Criteria EAL4+ Certified 
TPM 
A Common Criteria certification Evaluation Assurance Level 4+ 
(EAL4+) Trusted Platform Module (TPM) provides hardware-based 
encryption keys and more secure storage. 
  Self-Encrypting Drives (SEDs)  Encrypts and decrypts data as it is being written to, or read from the 
drive. Users get faster encryption performance than that of 
software-based only encryption solutions. 
 Secure Erase 
8
  Permanently destroys data on your hard drive (HDD or SSD) in 
preparation for system redeployment or disposal. Once executed, the 
hard drive controller will completely rewrite all the data on the drive 
and cannot be recovered even with advanced data recovery tools. 
Meets NIST 800-88 Secure Erase guidelines. 
1.  Self-Encrypting Drives (SEDs) are not supported if the encryption is enabled. 
2.  Automatic DriveLock will work on another HP Business PC when the BIOS passwords are the same. Requires user set up. 
3.  For the use cases outlined in the DOD 5220.22-M Supplement. Not supported on HP Business Desktops. HP Business Desktops 
support HP Disk Sanitizer External Edition available from hp.com. 
4.  Requires Windows. Data is protected prior to Drive Encryption login. Turning the PC off or into hibernate logs out of Drive 
Encryption and prevents data access. 










