If it's stolen, it should be useless. That's what PROTECT delivers.
Persistent encryption. Remote revocation. Complete audit trail. Data that cannot be read, cannot be ransomed, and cannot be published, wherever it goes.
- Controlling data even if it is stolen
- Supply chain data security
- Remote kill ability
- Persistent encryption
- Secure data in use, at rest and in transit (encryption in use)

Risk management for all businesses:








The question most security strategies fail to answer.
The principle behind most data security investment is containment, keeping sensitive data inside the boundary so it stays safe. In 2026, that boundary is a fiction. Data moves across supplier ecosystems, cloud platforms, personal devices, and partner networks as a matter of routine. Containment, as a primary strategy, has run its course.
The Hidden Risks of Unstructured Data Governance
Ownership disappears when projects finish and teams move on. Permissions drift silently through inherited groups and one-off exceptions. Classification is inconsistent, some labels, some policy, and a lot of human judgement. Unstructured data, documents, spreadsheets, designs, and email attachments carry the bulk of the risk and are the hardest to govern.
PROTECT applies a different principle entirely
The encryption is not a gate the file passes through. It is a property the file carries permanently, so that control stays with you, not with whoever ends up holding it. When every sensitive file is persistently encrypted by default, the question stops being "what happens if it's stolen?" and starts being irrelevant.
Encryption that stays on the file. Control that stays with you.
Persistent encryption
Protected files remain encrypted when stored anywhere, transferred by any method, and when in use by an authorised user or application.
Controlling data outside your secure environment.
When a protected file is accessed by an unauthorised party, through a breach, through exfiltration, through a compromised supply chain, they cannot read it. It cannot be used as leverage in a ransomware demand. It cannot be published to cause reputational damage. It is, in every meaningful sense, worthless to them.
Revoke access
The keys that unlock it are yours. And when you need to revoke access, you can do so remotely, immediately, without any physical interaction with the file or the device that holds it.
Controlling data even if it is stolen
A breach, an insider, a compromised supply chain. When a file leaves your environment through any of these, PROTECT ensures it cannot be read, cannot be published, and cannot be used as leverage. The encryption travels with the file. The keys stay with you. Stolen data becomes irrelevant.
Supply chain data security
Every file you share with a supplier, contractor, or tender panel remains under your authority after you send it. PROTECT gives you the ability to revoke access to any file, at any time, from anywhere, the moment the engagement ends, without touching the device that holds it. You control what you share. You control when it expires.

Encryption that travels with the file. Control that never leaves.
Persistent file encryption, AES 256 and RSA 2048
Applied at the file level, not the folder, not the drive, not the platform. The encryption does not pause when the file is opened, does not disappear when it is forwarded, and does not end when it reaches a third party. It stays, in storage, in transit, and in active use.
Remote key destruction
Revoke access to any file, at any time, from anywhere, by destroying the associated encryption key. Immediate effect, no physical access to the file or device required. Every file you have ever shared externally remains under your authority until you decide otherwise.
Transparent to authorised users
Format-preserving encryption means authorised users work with files exactly as they always have. No workflow disruption. No productivity overhead. The protection is invisible to the people who are meant to have access.
Unique key per file
Each protected file receives its own individual encryption key. This isolates risk, so a compromised key affects only one file, not the entire protected data estate.
Centralised key management
Full oversight of every protected file, who has access, when it was accessed, from where. Grant, restrict, and revoke access from a single console. All keys managed centrally by your security team via Microsoft Key Vault.
Eliminates ransomware leverage
Double extortion ransomware works because the attacker holds data that is readable and damaging. PROTECT removes that lever entirely. Exfiltrated data that is persistently encrypted has no publication value and cannot be used as leverage.
Complete audit trail
Every file access logged, who opened it, when, and from which device. Supports investigation, accountability, and regulatory compliance without needing to reconstruct a timeline after the fact.
Works with your existing stack
Compatible with any DMS, cloud application, or ERP out of the box. Offline, online, and hybrid environments supported. No rip-and-replace. No integration project. Supports files of all types, not limited to Office and PDF.
100%
of protected files remain encrypted when stored anywhere, transferred by any method, and when in active use by a user or application
AES 256 &
RSA 2048
the hybrid encryption combination at the core of PROTECT. Military-grade. Applied at the file level. Persistent across the entire file lifecycle.
Remote Kill
you can destroy access to any file, instantly, from anywhere. No physical access to the device required.
What a CISO gets from PROTECT.
The outcomes that matter when data leaves your environment.

A breach that doesn't become a crisis.
When a file is exfiltrated, through a breach, an insider, or a supply chain compromise, it cannot be read. It cannot be published. It cannot be used as leverage. The uncertainty that makes breaches expensive disappears.

Ransomware with nothing to threaten you with.
Stolen data is only dangerous if it can be read. PROTECT means exfiltrated files are cryptographically unreadable to anyone without your keys. The extortion model collapses, not because the attacker failed to get the files, but because the files are worthless to them.

Control over every file you've ever shared externally
Project delivery relies on a constant flow of documents across M365, SharePoint, Teams, file shares, and contractor ecosystems. Every handoff is a potential exposure point. Most controls were built for a world where the perimeter still existed.

The ability to operate without restriction
When a file is exfiltrated, through a breach, an insider, or a supply chain compromise, it cannot be read. It cannot be published. It cannot be used as leverage. The uncertainty that makes breaches expensive disappears.
The situations PROTECT was built for.

The breach that gets through
Even organisations with mature security postures experience breaches. Phishing succeeds, credentials are compromised, a zero-day is exploited. When that happens, the difference between a catastrophic event and a manageable one is whether the data that was taken can actually be read. With PROTECT, it cannot.

Supplier with good intentions & poor controls
Revoke access to any file, at any time, from anywhere, by destroying the associated encryption key. Immediate effect, no physical access to the file or device required. Every file you have ever shared externally remains under your authority until you decide otherwise.

The insider who decides to leave
A departing employee who copies sensitive files to a personal drive. A disgruntled contractor who exports a client database before their engagement ends. These are regular occurrences that standard DLP tools detect after the fact, if at all. PROTECT means you can revoke access to every file they took, immediately, remotely, with no physical interaction with the device.

The ransomware demand that has no leverage
Double extortion ransomware works because the attacker holds something you need. Persistent encryption changes that equation entirely. If every sensitive file is encrypted with keys only you control, exfiltrated data cannot be read, cannot be published meaningfully, and cannot be used as leverage. The ransomware business model depends on your data having value to someone else. PROTECT removes that value.
All-in-One Data Protection
That Never Sleeps
GuardWare combines data discovery, continuous monitoring, and persistent file encryption into a single powerful platform—keeping your data secure even while it’s in use.
Discover and classify sensitive data across your systems.
Monitor file activity in real time for complete visibility.
Keep files encrypted even during active use.
Maintain control over your data—no matter where it goes.
Secure by design.
Compatible by default.
PROTECT is designed to deploy into your existing environment without disruption. No rip-and-replace. No lengthy integration project. It works with the systems you already run and adds a layer of protection those systems were never built to provide.

For the organisations where IP is the asset.
Persistent encryption for CAD files, engineering specifications, and design IP

Securing Proprietary CAD and Engineering Assets
In industries where a single set of design files represents years of investment and competitive advantage, the risk of IP exfiltration during bids, tenders, or project delivery is existential. PROTECT Design extends the same persistent encryption and remote revocation capability to proprietary CAD and engineering file formats that standard protection tools cannot reach.

Secure CAD Collaboration Without Losing Control
Now you can share CAD files with suppliers, contractors, and tender panels and remain in control of every file across its entire lifecycle, from initial draft to decommission. Even if a file is stolen, it cannot be opened without your authorisation.
Real-Time Visibility for Confident Compliance










"The uncertainty that makes breaches expensive isn't just about where data lived, it's about what happened to it between then and now. INSIGHT exists because the question 'what has your data been doing today?' deserves a real-time answer, not a retrospective one. Monitoring shouldn't exist to catch people out. It should exist to protect people from the consequences of mistakes they didn't know they were making."

Rizwan Mahmood
Co-Founder & CEO, GuardWare
"The part that makes breaches expensive isn't the intrusion. It's the uncertainty afterwards, what data was taken, who has it now, and whether it can still be read. PROTECT removes the uncertainty. Even if it's stolen, it's useless."

Rizwan Mahmood
Co-Founder & CEO, GuardWare
"We now have complete visibility of data across our assets. In the very first week of monitoring we detected and prevented two data dumps to USB drives by staff."

Bobby Stojceski
Chief Security Officer, Penske Australia & New Zealand
The only vendor delivering data discovery, continuous monitoring, and persistent file encryption in a single integrated platform.
PROTECT is the final layer, data that leaves your environment is worthless to anyone without your keys.
Data-Centric Security suite designed as one operational sequence:
Find and classify
Full monitoring across all channels including M365
Persistent file encryption
Together, the suite gives you control end to end.
Find and classify
Map sensitive data across all repositories, including M365. Know what you have, where it lives, and what needs to be tightened first.
Full monitoring across all channels
Extends visibility beyond M365 to endpoints, cloud platforms, AI tools, USB activity, web traffic, and home environments. The complete picture, across every channel where data moves.
Encrypt and control
Persistent file encryption so sensitive files remain protected even when they leave your environment, with remote key revocation for every file, including files already shared externally.
Common Questions
How is PROTECT different from standard encryption tools?
Most encryption technologies protect data at rest or in transit, but the protection ends the moment a file is opened. PROTECT applies persistent encryption that stays with the file in active use, so a file that is forwarded, copied, or exfiltrated remains encrypted and unreadable by anyone without your keys.
Can we revoke access to a file that has already been shared externally?
Yes. Remote key destruction allows you to revoke access to any protected file at any time, from anywhere, by destroying the associated encryption key. Immediate effect, no physical access to the file or device required. This applies to files already shared with third parties, contractors, and suppliers.
Does PROTECT disrupt how our people work?
No. Format-preserving encryption means authorised users work with files exactly as they always have. The protection is invisible to people who are meant to have access, with no workflow changes and no productivity overhead.
What file types does PROTECT support?
PROTECT supports files of all types, not limited to Office and PDF. Custom wrapper technology enables persistent encryption for non-standard file formats, including CAD files and engineering specifications via PROTECT Design.
Does it work in offline environments?
Yes. PROTECT is designed for the reality of how organisations operate, including scenarios where files are accessed offline, in air-gapped environments, or across hybrid infrastructure. Protection does not depend on network connectivity.
What evidence does PROTECT produce for audit and compliance?
Every file access is logged, who opened it, when, and from which device. This creates a complete audit trail that supports internal governance, regulatory response, and compliance with the Australian Privacy Act, ISO 27001, DISP, CMMC 2.0, ACSC ISM, and other relevant frameworks.
Persistent encryption doesn't just protect your data. It removes the limits on how you use it.
Share with suppliers. Respond to tenders. Engage contractors. Because wherever the data goes, the control stays with you, and if it’s stolen, it’s useless.


