Specifications
Introduction 
| 9 
Users can work without interruption. With the exception of the initial logon to access 
protected data, Endpoint Encryption for Files and Folders provides complete 
transparent security. 
How Endpoint Encryption for Files and Folders Works 
The Endpoint Encryption for Files and Folders client encrypts folders and files 
according to policies determined by Endpoint Encryption Administrators. These policies 
are delivered by the Endpoint Encryption Server. The Endpoint Encryption for Files and 
Folders client acts like a filter between the application creating or editing the files and 
the storage media, e.g. the hard disk. 
Whenever a file is written to the storage media the Endpoint Encryption for Files and 
Folders filter executes the assigned encryption policies and encrypts the data, if 
applicable. Later, when an application reads the file, the encryption filter automatically 
decrypts the file reading it into the computer memory. Remember, the source file is 
always encrypted on disk. 
The encryption/decryption process happens automatically and is fully transparent to 
the user. The user does not notice any difference between working with encrypted and 
plaintext files; the user’s working procedures are not (and must not be) disturbed. 
When a file is encrypted, it is encrypted at its original location on the disk. Hence, no 
copies or other special files are created when encrypting a file. The original file 
remains encrypted at all times, only the parts read into the memory are decrypted 
when an application reads the file. 
When the application closes the file, the memory is wiped and the original file is still 
encrypted on disk. No decrypted traces of the file remain in the RAM. 
Endpoint Encryption for Files and Folders can encrypt files and folders on all formatted 
local drives, e.g. FAT and NTFS and network drives - e.g. NTFS and SAN with Unix 
servers. Also, Endpoint Encryption for Files and Folders supports encryption of files 
and folders within terminal server environments such as Microsoft® Terminal 
Server™. 
Encrypted folders and files are always visible to the user. The user can search and 
recognize files and folders as before encryption. A small padlock icon can be optionally 
attached to the file or folder icon, marking it as encrypted. 
With Endpoint Encryption for Files and Folders, it is easy to encrypt files and folders. 
Encryption can be enforced either by an organizational policy or by the user right-
clicking folders and files. 










