HomeUse casesThird-party risk
Third-party risk

When the file leaves, your control shouldn’t.

Vendors, contractors, and partners need your data to do their jobs. The moment you send it, most security tools stop working. Confidencial embeds protection directly into the file, so you stay in control of what you shared, wherever it ends up.

CONFIDENCIALSELECTIVE ENCRYPTION ACTIVE
Vendor Due Diligence Package
DD-2026-0042 · Shared with Meridian Advisors · Confidential
DocumentDue diligence package
Shared withMeridian Advisors (vendor)
Pricing structure🔒 ENCRYPTED FIELD
Client references🔒 ENCRYPTED FIELD
Margin model🔒 ENCRYPTED FIELD
Access windowExpires in 30 days · revocable
3 fields encryptedLast open: unmanaged device
60%
of data breaches involve a third party, such as vendor, supplier, or contractor
IBM Cost of a Data Breach, 2024
$4.91M
average cost of a third party data breach in 2025
IBM Cost of a Data Breach, 2024
54%
of organizations experienced a third-party data breach in the past 12 months
Ponemon Institute, 2023
267
median days to identify and contain a breach involving a third party
IBM Cost of a Data Breach, 2025
The third-party lifecycle

Every file you share is a file you no longer control.

Vendors and partners need your data to do their jobs. From the moment a file leaves, it lives on systems you don’t run, gets copied, and sometimes passed along again, and you stay accountable for all of it. It doesn’t have to be that way.

Package
Assemble the file
Share
Send to a vendor
In use
They open & work
Stored
Saved to their systems
Breach
Their environment is hit
Without
UNENCRYPTED
Pricing & IP sit in a plain file
OPEN HANDOFF
Emailed or dropped in a portal
FULL READ
Vendor opens every field
UNMANAGED COPY
On a device you can’t see
YOUR LIABILITY
Their breach, your exposure
With Confidencial
FIELD-LEVEL
Encrypt only the sensitive parts
NO VIEWER
Opens natively in Word & PDF
FULL AUDIT TRAIL
Every open logged, by whom
REVOCABLE
Kill access when the deal ends
CIPHERTEXT ONLY
Attacker gets nothing readable
Exposure point: your data is readable hereControlled: Confidencial holds the lineAuditable & revocableyou keep the keys

Five phases. One encryption layer. The keys never leave your environment.

How it works

Five steps from shared and exposed to shared and controlled

From discovery to post-share governance. No new workflow for your vendors. No viewer required on their end.

01  Discover

Find what you’re sharing before it goes

Confidencial scans the files and repositories feeding your external workflows, such as SharePoint, OneDrive, Google Drive, S3, contract systems. Classifiers surface sensitive content before it reaches a vendor.

02  Protect

Encrypt sensitive fields before the file leaves

Selective encryption targets specific fields inside a document. The vendor sees the contract terms, not the pricing model. The file opens normally in any app; the sensitive content stays controlled wherever it travels.

03  Exchange

Send, request, and collect with governance built in

Confidencial’s Exchange workflows replace ad hoc email and upload portals. Send files with embedded access controls, request documents through a governed intake channel, which means every exchange tracked from open to close.

04  Revoke

End access the moment the engagement ends

When a vendor relationship closes or a risk signal fires, encrypted fields lock across every device that ever accessed the document. No file recall, no deletion verification, no endpoint agent on the vendor’s side.

05  Audit

Prove what was accessed, when, and by whom

Every interaction generates a cryptographic record, which fields, which identity, which device, which time. For HIPAA, ISO 27001, EO 14117, and vendor risk reviews, that’s field-level evidence delivery logs can’t match.

See it in action

Share it. Still control it.

One vendor package, two outcomes. Shared as-is, a breach in their environment hands an attacker everything. Shared with Confidencial, the same file is ciphertext to anyone you didn’t authorize, and every open is logged. Flip between them.

Third-Party Risk Demo
Vendor_Package_Q3.pdf PLAIN
Client Name
Harborview Capital LLC
Engagement Value
$4,200,000
Deal Structure
Leveraged Buyout — Confidential
Contact / Signatory
D. Nakamura, Managing Director
Target Entity
Meridian Group Holdings
Internal Ref
PRJ-2024-0847 / Tier 1
Breach scenario
📤
File sent to Apex Consulting
Forwarded via email, no access controls
09:14
⚠️
Apex environment breached
Attacker gains access to vendor file store
11:02
🔓
Full document contents exposed
Client name, deal value, signatories — all readable
11:03
☠️
Confidential deal data is in attacker hands.
You sent the file. You lost control the moment it left.
Why existing tools fall short

Perimeter security stops at the perimeter.

Secure email gateways, file transfer tools, and vendor portals protect the channel. The moment the file arrives at its destination, the protection ends. Confidencial protects what’s inside the file which is the only thing that matters once it’s left your network.

ScenarioSecure email / MFTVendor portalDRMConfidencial
Vendor downloads file and saves to unmanaged storageProtects transit only. No visibility or control post-delivery.~Controls access to the portal. Can’t control the downloaded copy.~Restricts some actions. Requires proprietary viewer; breaks most workflows.Encryption travels with the file. Sensitive fields remain controlled on any device.
Contractor retains files after engagement endsDelivery is complete. No mechanism to revoke a file already received.Portal access revoked. Downloaded copy is permanent.~Some revocation capability. Depends on viewer enforcement; often bypassable.Encrypted fields lock instantly on revocation. No viewer required. No endpoint agent.
Partner’s environment is breached; attacker accesses shared filesNo protection once file is in partner’s environment.Controls apply to your portal, not files in their systems.~Viewer-based controls; attackers bypass with screenshots or viewer exploits.Sensitive fields stay encrypted. Attacker gets ciphertext, not readable content.
Prove file-level access control in regulatory examinationDelivery logs only. Cannot prove what was accessed or by whom.~Portal access logs. No document-level chain of custody post-download.~Usage logs if viewer is enforced. Incomplete for field-level audit requirements.Cryptographic audit trail: field-level access by identity, timestamp, and device.

Secure email secures the channel. Vendor portals control access to the portal. DRM restricts what the viewer can do. None of them protect the data once it’s in someone else’s hands. Confidencial is the only layer that travels with the file.

Common questions

Hard questions. Direct answers.

01

Does the vendor need to install anything to open a protected file?

No. Protected files open natively in Word, Google Docs, Adobe Acrobat, and the apps your vendors already use, which means no proprietary viewer, no plugin, and no friction for the recipient. Encrypted fields appear locked to anyone without authorization; the rest of the document works exactly as expected.
02

What happens if our vendor's environment is breached after we've shared files with them?

The attacker gets whatever the vendor's environment contained. For files protected with Confidencial, that's ciphertext for every encrypted field, including pricing, client records, formulation data, and regulated PII. The content is computationally inaccessible without the decryption keys, which never leave your environment. The breach happened in their environment; the data inside your files was not compromised.
03

We work with hundreds of vendors. Can this scale without becoming an operational burden?

Yes. Protection policies apply at the file or folder level, not vendor by vendor. Configure a policy once, for a document type, a data classification, or a vendor tier, and it applies automatically to every matching file. Revocation is equally broad: one policy change locks the relevant fields across every vendor who ever received a matching file.
04

Our compliance team needs to prove file-level access control for HIPAA, ISO 27001, and EO 14117. Can Confidencial support that?

Directly. Confidencial generates a cryptographic audit trail, which includes field-level access records with identity, timestamp, device, and action, for every protected file. For HIPAA business associate agreements, it's the documentation that proves PHI was governed throughout its lifecycle, including after it left your environment. For ISO 27001 and EO 14117, it satisfies the file-level governance and traceability requirements folder-level logs and delivery receipts can't meet.
05

Can we restrict what vendors can do with a file — forwarding, printing, downloading?

Usage controls, such as read-only, no-print, no-forward, expiration, can be configured per file, per recipient tier, or per document classification, and apply regardless of which application the vendor uses to open the file. Unlike DRM that depends on a proprietary viewer, Confidencial's controls operate at the data layer and require no software on the recipient's end.
06

What's the difference between this and just using a vendor portal?

A vendor portal controls access to the portal. The moment a vendor downloads a file, the portal's controls end. Confidencial's controls travel with the file, onto the vendor's device, into their local folders, across their internal systems if they share it further. The portal is a delivery mechanism; Confidencial governs the data inside the file after delivery.
Case in point

What happens when the transfer tool fails but the data doesn't.

Publicly reported · MOVEit, 2023
01 — What happened

A zero-day in Progress Software’s MOVEit file-transfer platform. Every organization using MOVEit to exchange files with vendors, agencies, and partners had their transfers exposed not from any misconfiguration, but because the tool itself was the attack surface.

02 — The gap

MOVEit secured the transit. Once a transfer was intercepted, the contents were fully readable with no second layer at the data level. Organizations had no visibility into what was taken, no way to revoke access to already-transferred files, and no way to contain the exposure after the fact.

“When the channel fails, everything inside it is readable.”

2,600+
organizations affected — agencies, banks, healthcare
77M+
individuals exposed via third-party transfers
$0
field-level protection — the tool was the only control

When the channel fails, everything inside it is readable. With Confidencial, the sensitive fields stay encrypted independently of the transfer mechanism, so when MOVEit fails, the attacker gets ciphertext, the exposure stops at the tool, and not your data.

Know what you’ve shared

Which files you’ve sent to vendors are fully readable on systems you don’t control?

Clinical data sent to a CDMO. Pricing models shared with a consultant. Client records in a partner’s inbox. Most organizations can’t answer that question. The Data Exposure Assessment maps it in 20 minutes.