Selective encryption

Most tools encrypt the file. We encrypt inside it.

An engine that encrypts, redacts, or tokenizes individual fields, words, paragraphs, and pixels without breaking the file, format, or workflow. Protection travels with the data, everywhere it goes.

WordExcelPDFCSVImages
The three protection modes

One engine. Three ways to protect.

Different data, different risk profiles, different regulatory requirements. Selective protection applies the right mechanism to each sensitive entity, in the same document.

Mode 01

Selective encryption

Sensitive entities are encrypted in place using public keys. The document is readable; the sensitive content is not. Policy controls access, and different entity types can be encrypted with different key groups. Authorized users see plaintext. Everyone else sees ciphertext, including the AI model, the vendor’s server, and the attacker who exfiltrated the file.

ReversibleAccess-controlledPolicy-bound
Mode 02

Redaction

Sensitive entities are destroyed and it is irreversible. The document structure is preserved; formatting and surrounding content remain intact. The sensitive value is permanently gone. Used for court production, regulatory disclosure, and any scenario where permanent removal is the legal requirement rather than access-controlled visibility.

IrreversibleCourt-readyFormat-preserving
Mode 03

Reversible tokenization

Sensitive information is replaced with meaningful placeholders that preserve context while protecting the underlying data. The original values are stored in a database and recoverable by authorized users. Built specifically for passing documents to LLMs, RAG pipelines, and AI agents without exposing the underlying values. The model processes structure and context without ever seeing what it shouldn’t.

RecoverableAI-safecontext-preserving
Precision

Protection at every level of the document.

Other tools encrypt entire files or entire disks. Selective protection operates at the element level, leaving context intact for the people and systems that need it.

Field

SSN, account numbers, drug compounds, patient IDs, pricing

Word

Named entities, counterparty names, key personnel, specific terms

Phrase / Clause

Privileged legal analysis, deal terms, confidential findings

Region / Cell

Spreadsheet ranges, salary bands, financial tables, formula outputs

Pixel / Image region

Faces, signatures, ID documents, sensitive images within files

Works natively in
WordExcelPDFCSVImages
Native add-ins for Word and Excel. No special viewer required.
selective encryption

One document. Different keys.
Different people see different data.

The document looks identical to everyone. They just can't read what they're not cleared to see. Patented selective protection is applied at the word, cell, or field level, embedded directly in the file. No redacted copies. No duplicate versions. One document. One key per element.

Viewing as
Employment Agreement — Acme Corp
1 Mar 2025 · Rev 3 · Confidential
HR Manager

AI Agent receives context, never secrets. Salary and PII fields are encrypted before ingestion.

The blast radius

When protection travels with the data, risk drops.

The breach still happens. What the attacker leaves with is ciphertext. Every exfiltration, AI exposure, vendor compromise, and insider action becomes a contained, auditable, defensible event.

A file is exfiltrated from a breached serverNOTHING READABLE.
A sensitive document is forwarded to the wrong personTHEY SEE THE REDACTED VERSION.
Sensitive data enters an LLM or RAG pipelineTHE MODEL NEVER SEES IT.
A vendor’s environment is compromised after you share a fileYOUR DATA STAYS SEALED.
An insider downloads and walks out with classified documentsYOU KNOW WHO, WHAT, WHEN & can revoke.
A cloud misconfiguration exposes a bucket of sensitive filesTHE BUCKET IS FULL OF NOTHING valuable.
How it compares

Every other tool protects a location.

Coverage ends when data leaves the system being protected. Selective protection is the only approach where coverage follows the data, into any environment, any AI system, any third-party tool.

ToolWhat it coversWhere coverage endsWith Confidencial
Full-disk encryptionDevice at restDisk powers on. File copied off-device. No protection in transit, in use, in sharing, or in AI.Protection persists everywhere
DLPEgress monitoringThe monitored network boundary. Blind to approved SaaS flows, authorized sharing, and AI ingestion.Protection persists everywhere
DSPMPosture visibilityDiscovery and classification only. A map of the problem, not a fix. No cryptographic protection applied.Protection persists everywhere
Rights Management (IRM)File-level access policyNo field granularity. Vendor-ecosystem locked. Can't tokenize for AI pipelines.Protection persists everywhere
Traditional redactionVisual blockingRedaction errors are common and irreversible. No access-controlled mode. No AI-safe tokenization. No audit trail.Protection persists everywhere
ConfidencialThe data itselfDoesn't. Protection travels with the file through sharing, exfiltration, AI ingestion, and third-party systems. All three modes in the same engine.Always on
Business outcomes

The breach may happen, but the impact is contained.

Reduce risk, ease compliance, and unlock efficiencies.

1

Incident scoping time

Per-document cryptographic logs tell you exactly what was accessed and what wasn’t.

2

AI initiatives unblocked

Tokenization lets sensitive data flow into LLMs and RAG pipelines without exposing values. Security enables AI adoption instead of blocking it.

3

Demonstrable compliance

Cryptographic audit trails embedded in the file replace checkbox attestation for HIPAA, PCI DSS, GDPR, and AI regulations.

4

Quantum-resistant today

Hybrid KEM/DEM architecture. Migration path to CRYSTALS-Kyber without re-encrypting existing data. Protected through the quantum transition.

Why trust the math

Patented. DARPA-origin.
NIST-validated.

This technology came out of cryptographic research at the institution that built the internet. It's not an idea. It's a commercialization of a solved problem.

Origin

DARPA-funded R&D at SRI International

SRI built ARPANET. The selective encryption and selective sharing architecture behind Confidencial emerged from DARPA-funded research into secure multiparty computation and resilient distributed systems — the institution that anticipated this threat class before anyone else.

DARPA OriginSRI InternationalPatented
Cryptographic validation

NIST-approved algorithms. PQ-ready architecture.

Every cryptographic primitive is NIST-approved. Multi-layer AES + RSA + C11 format-preserving binding. Hybrid KEM/DEM architecture supports migration to CRYSTALS-Kyber without re-encrypting existing data. Data protected today is protected through the quantum transition.

NIST-ApprovedPQ-readyZero-knowledge
Enterprise certifications

Independently audited for enterprise deployment

SOC 2 Type II, ISO 27001:2022, HIPAA, PCI DSS SAQ-D, GDPR-aligned. Built for regulated industries where "we believe it was encrypted" is not an acceptable answer to a regulator or a plaintiff.

SOC 2 Type IIISO 27001:2022HIPAAPCI DSS
Government validation

AFWERX STTR Phase II recipient.

Assessed "Awardable" in the DoD CDAO Tradewinds Solutions Marketplace. AFWERX STTR Phase II contract for US Air Force sensitive document security. Environments where protection failure has national security consequences; this is the threat model the architecture was designed for.

DoD Tradewinds AwardableAFWERX STTR Phase IIData Solution of the Year - Legal 2026
See it on your documents

What does your most sensitive file look like when it's actually protected?

We'll show you selective encryption, redaction, and tokenization running on your file types, in your workflows, against your actual threat model.