HomeUse casesRegulatory submissions
Regulatory submissions

Hand it to the regulator, but keep the keys.

Compliance reports, audit responses, incident filings, full of PII, PHI, and IP, sent over email and portals you don’t run. Confidencial encrypts the data itself and keeps the keys in your environment, so every submission stays auditable and revocable, even after a regulator is breached.

CONFIDENCIALSELECTIVE ENCRYPTION ACTIVE
Audit Response — Exam 2026-114
SUB-2026-0114 · Submitted to OCC · Confidential
Filing typeAudit response · Exam 2026-114
RecipientOCC · Supervision Dept.
Customer PII🔒 ENCRYPTED FIELD
Risk assessment🔒 ENCRYPTED FIELD
Bank financials🔒 ENCRYPTED FIELD
Access window90 days · revocable anytime
3 fields encryptedAudit trail: every open logged
20 months
attackers held undetected access to a U.S. banking regulator's email before it was caught
OCC disclosure, 2025
150K+
supervisory messages exposed in that single regulator breach
OCC disclosure, 2025
30%
of breaches now involve a third party you don't control
Verizon DBIR, 2025
$9.8M
average breach cost in healthcare, which is the most-breached regulated sector
IBM Cost of a Data Breach, 2024
The submission lifecycle

Every submission is a transfer of control.

From the day you compile a filing to long after a regulator stores it, your most sensitive data sits in systems you don't run, and you stay accountable for all of it. It doesn't have to be that way.

Compile
Gather the filing
Submit
Send to the regulator
In review
They open & store it
Retained
Sits in their systems
Breach
Their breach, your liability
Without
UNENCRYPTED
PII, PHI, and IP sit in plain files
OPEN CHANNEL
Emailed or uploaded to a portal
NO VISIBILITY
You can't see who opens it
STORED FOREVER
Kept in their systems indefinitely
YOUR LIABILITY
Their breach becomes your exposure
With Confidencial
FIELD-LEVEL
Encrypt only the sensitive entities
TRAVELS PROTECTED
Encryption rides with the file
FULL AUDIT TRAIL
Every open & download logged
ACCESS EXPIRES
Time-boxed, revocable anytime
CIPHERTEXT ONLY
A breach yields nothing readable
Exposure point: your data is readable hereControlled: Confidencial holds the lineAuditable & revocable you keep the keys

Five phases. One encryption layer. The keys never leave your environment.

How it works

Five steps from filing to full custody

Runs inside your environment. No new portal for the regulator, no change to how your team files.

01  Connect

Connect your repositories

Confidencial runs in your environment and connects to SharePoint, OneDrive, S3, and network shares, wherever filings are assembled. Your keys never leave.

02  Classify

Find the regulated data

Built-in classifiers flag PII, PHI, financials, and IP across structured and unstructured files, so nothing regulated ever ships unprotected.

03  Protect

Encrypt at the field level

Selective encryption seals the sensitive entities and leaves the rest readable. The filing opens normally; the regulated content stays protected, before it ever leaves.

04  Share

Submit without losing control

Send through any channel, including email, portal, and secure transfer. Protection travels with the file; the regulator opens what they're authorized to, and nothing more.

05  Track

Prove it with a full audit trail

Every view, download, and unauthorized attempt is logged, internal teams and external recipients alike, giving you exam-ready evidence for ISO 27001, HIPAA, and EO 14117.

Why existing tools fall short

Your tools protect the trip. Not the destination.

Secure email encrypts the send. The portal is the agency's to defend. MFT logs the transfer. None protect the filing once it's sitting in a system you don't run. Confidencial does.

ScenarioSecure emailRegulator portalMFT & DLPConfidencial
The regulator is breached after you submitEncryption ends at delivery. Their stored copy is plaintext.Out of your hands the moment you upload.Protects the transfer, not the file at rest with them.Sensitive fields stay encrypted in their systems. Attackers get ciphertext.
A filing is forwarded or reused beyond its purposeNo control after the first open.~Portal access only; downloaded copies roam free.~May log the transfer. Can't follow the file.Access is policy-bound and revocable on every copy.
Prove who opened a filing, and when, for an examDelivery receipts at best.~Their portal logs — their system, not yours.~Transfer logs only. No document-level custody.Cryptographic trail — every view by identity, time, device.
Satisfy ISO 27001, HIPAA, and EO 14117 for external data~Encrypts transit, not the lifecycle.~Depends on the agency's controls, not yours.~Boundary controls only.Field-level encryption, audit trail, and keys you hold.

UEBA sees the pattern. DLP watches the upload. CASB logs the session. None of them protect the filing once it's sitting in someone else's system.

Common questions

Hard questions. Direct answers.

01

If the regulator's systems are breached after we submit, is our data exposed?

Not the protected content. Sensitive fields stay encrypted inside the file wherever it lives, including the regulator's storage. A breach of their systems hands an attacker ciphertext, not your customers' PII. The keys never left your environment.
02

Can we prove to an examiner exactly who accessed a submission?

Yes. Confidencial keeps a cryptographic audit trail of every view, download, and unauthorized attempt, internal and external, with identity, timestamp, and device. That's verifiable, field-level evidence for ISO 27001, HIPAA, SOC 2, and EO 14117, not just a delivery receipt.
03

How is this different from secure email or the agency's portal?

Those protect the trip, not the destination. Once a message is delivered or a file is uploaded, encryption ends and the copy lives in a system you don't run. Confidencial embeds protection in the data itself, so it stays encrypted, access-controlled, and revocable after submission, regardless of channel.
04

How do we satisfy ISO 27001, HIPAA, and EO 14117 for data we hand to a third party?

Confidencial encrypts regulated content at the field level, keeps the keys in your environment, and logs every access for the life of the file. That combination of persistent encryption, ownership of keys, and a complete audit trail is exactly the external-data-handling evidence those frameworks ask for, and it holds even after the file leaves your walls.
Case in point

Submitting the data shouldn't mean surrendering it.

Publicly reported · 2025
01 — What happened

Attackers held persistent access to a U.S. banking regulator's email system for more than 20 months, breaching over 100 accounts and exposing 150,000+ messages, including bank financials and supervisory documents. Major institutions suspended electronic communication with the agency.

02 — The gap

The data was encrypted in transit, and then simply stored. Once it landed in the regulator's systems, the submitting institutions had no control, no visibility, and no way to pull it back. Their breach became everyone's exposure.

"The information in the emails that were accessed is likely to result in demonstrable harm to public confidence."

— OCC official, letter to Congress, April 2025 (reported by Bloomberg)
20 months
attackers inside the regulator's email, undetected
150K+
supervisory messages exposed in the breach
0
control the submitting firms kept once data landed

Field-level encryption and a cryptographic audit trail don't depend on the recipient's security. Customer PII, risk assessments, financials, all encrypted at the object level, readable only by who you authorize, revocable the moment you choose, logged at every touch. With Confidencial, a breach of the regulator is a non-event for your data.

Before your next filing

The question isn't whether you can submit it. It's whether you still control it after you do.

Compliance reports. Audit responses. Incident filings. Which of those are readable right now in a system you don't run? Map your submission exposure in 20 minutes, most teams are surprised by what's still open.