ConstitutionComputing
Article V of VI

Papers and Effects

Sensitive records are never only where the policy says they are. Before you can defend them you have to find out where they actually went.

V
Schedule · Article V2 lines · charged monthly in advance
Data DiscoveryFortify-DLP-Classify · billed per device
Loading
Qty
Data Discovery and EncryptionFortify-DLP-Enforce · billed per device
Loading
Qty
Discovery and measurementFortify-DLP-Classify
PlatformActifile, on Windows, macOS, and Linux.
What it looks forPayment card data and personally identifiable records, wherever they have come to rest on the device rather than only where an inventory expects them.
BaselineAn initial measurement of how much regulated data the organization is actually holding, which is the number nobody has and everybody assumes is smaller.
Per-device reportingA breach risk report broken down machine by machine, so remediation has an order of priority instead of a vague sense of unease.
VulnerabilitiesScanned with trend reporting attached, so exposure reads as a direction of travel rather than one snapshot.
How it billsMonthly, against each device.
EnforcementFortify-DLP-Enforce
IncludesEverything in Fortify-DLP-Classify, unchanged.
EncryptionFiles are encrypted and decrypted on the fly, so the protection travels with the document instead of stopping at the folder it was found in.
Compliance profilesMultiple profiles, so the rules that apply to health records and the rules that apply to card data can differ within one estate.
ChannelsAllowlisting by application and by route, governing which programs may touch protected material and where it is permitted to go.
How it billsMonthly, against each device.
01The problem

The right to be secure in your papers and effects

The phrase is older than the computer and it describes the problem exactly. Every organization holds records that would harm real people if they escaped: names beside account numbers, medical details, identity documents, card data that was supposed to have been deleted after the transaction cleared.

Those records never stay where the policy put them. They are exported for a report, mailed to a colleague, copied to a desktop before a trip, and left in a folder called old by somebody who has since left. The organization is liable for all of it and can locate almost none of it.

02Discovery

Finding what is actually there, machine by machine

The agent examines the files on each device and identifies regulated data by what it is rather than by where it sits or what somebody labelled it. The first report is routinely uncomfortable: a spreadsheet of card numbers from a payment migration years ago, an unencrypted export of the entire customer table on a laptop, an onboarding folder holding scans of passports.

None of that is unusual and none of it is anybody's fault in particular. It is the ordinary sediment of a business doing business. It is also, precisely, what a breach notification is calculated from.

03Measurement

Turning exposure into a number a board can act on

Security arguments fail in budget meetings because they are made in adjectives. This line reports how many sensitive records exist, on which machines, and in what concentration, with trend reporting that shows whether the position is improving.

That does two things. It puts the remediation in priority order, because the six worst machines usually hold most of the exposure. And it converts an argument about risk appetite into an argument about a figure, which is the only kind of security argument that reliably gets funded.

04Enforcement

Protection that travels with the file

Measurement alone leaves you better informed and equally exposed. Fortify-DLP-Enforce adds dynamic encryption, applied to protected material so that it stays encrypted when it is copied, attached, or carried off on a device that later goes missing.

Multiple compliance profiles let one estate hold different rules for different categories of record, and application and channel allowlisting governs which programs and routes may handle protected data at all. The distinction between the two lines is the distinction between knowing and doing, and organizations under a genuine regulatory obligation should assume they need the second.

Custody

Regulators ask what you knew and when you knew it

After an incident the questions are not about your firewall. They are about which records were on that machine, how long they had been there, whether they were encrypted, and whether anybody had ever looked.

An organization that can answer those four questions from a report is in a materially different position from one that must reconstruct the answer under time pressure, with counsel present and a notification clock running. Discovery is worth buying for that reason alone, before any of the enforcement follows.

Where this Article stops

  • Discovery reaches devices carrying the agent. Records resting only in a cloud service, an application database, or an appliance nobody can install software on fall outside this line, and we say so rather than let the report imply otherwise.
  • Detection of regulated data is pattern-based and, like every such system, produces both false positives and misses. Treat the first report as a starting inventory to refine, not as a certified register.
  • Encryption protects the file. It does not prevent a person with legitimate access from reading what they are entitled to read, photographing the screen, or repeating it aloud.
  • None of this is backup. Encrypt a file, delete it, and it is still gone, unless Article VI is holding a copy.