Compliance reports, audit responses, incident filings, full of PII, PHI, and IP, sent over email and portals you don’t run. Confidencial encrypts the data itself and keeps the keys in your environment, so every submission stays auditable and revocable, even after a regulator is breached.
From the day you compile a filing to long after a regulator stores it, your most sensitive data sits in systems you don't run, and you stay accountable for all of it. It doesn't have to be that way.
Five phases. One encryption layer. The keys never leave your environment.
Runs inside your environment. No new portal for the regulator, no change to how your team files.
Confidencial runs in your environment and connects to SharePoint, OneDrive, S3, and network shares, wherever filings are assembled. Your keys never leave.
Built-in classifiers flag PII, PHI, financials, and IP across structured and unstructured files, so nothing regulated ever ships unprotected.
Selective encryption seals the sensitive entities and leaves the rest readable. The filing opens normally; the regulated content stays protected, before it ever leaves.
Send through any channel, including email, portal, and secure transfer. Protection travels with the file; the regulator opens what they're authorized to, and nothing more.
Every view, download, and unauthorized attempt is logged, internal teams and external recipients alike, giving you exam-ready evidence for ISO 27001, HIPAA, and EO 14117.
Secure email encrypts the send. The portal is the agency's to defend. MFT logs the transfer. None protect the filing once it's sitting in a system you don't run. Confidencial does.
| Scenario | Secure email | Regulator portal | MFT & DLP | Confidencial |
|---|---|---|---|---|
| The regulator is breached after you submit | ✕Encryption ends at delivery. Their stored copy is plaintext. | ✕Out of your hands the moment you upload. | ✕Protects the transfer, not the file at rest with them. | ✓Sensitive fields stay encrypted in their systems. Attackers get ciphertext. |
| A filing is forwarded or reused beyond its purpose | ✕No control after the first open. | ~Portal access only; downloaded copies roam free. | ~May log the transfer. Can't follow the file. | ✓Access is policy-bound and revocable on every copy. |
| Prove who opened a filing, and when, for an exam | ✕Delivery receipts at best. | ~Their portal logs — their system, not yours. | ~Transfer logs only. No document-level custody. | ✓Cryptographic trail — every view by identity, time, device. |
| Satisfy ISO 27001, HIPAA, and EO 14117 for external data | ~Encrypts transit, not the lifecycle. | ~Depends on the agency's controls, not yours. | ~Boundary controls only. | ✓Field-level encryption, audit trail, and keys you hold. |
UEBA sees the pattern. DLP watches the upload. CASB logs the session. None of them protect the filing once it's sitting in someone else's system.
Attackers held persistent access to a U.S. banking regulator's email system for more than 20 months, breaching over 100 accounts and exposing 150,000+ messages, including bank financials and supervisory documents. Major institutions suspended electronic communication with the agency.
The data was encrypted in transit, and then simply stored. Once it landed in the regulator's systems, the submitting institutions had no control, no visibility, and no way to pull it back. Their breach became everyone's exposure.
"The information in the emails that were accessed is likely to result in demonstrable harm to public confidence."
— OCC official, letter to Congress, April 2025 (reported by Bloomberg)Field-level encryption and a cryptographic audit trail don't depend on the recipient's security. Customer PII, risk assessments, financials, all encrypted at the object level, readable only by who you authorize, revocable the moment you choose, logged at every touch. With Confidencial, a breach of the regulator is a non-event for your data.
Compliance reports. Audit responses. Incident filings. Which of those are readable right now in a system you don't run? Map your submission exposure in 20 minutes, most teams are surprised by what's still open.