TrellixData Security

    Data Encryption

    FIPS 140-2 encryption with the recovery options that keep the help desk sane.

    When a device is lost or stolen, encryption is what turns a breach into a non-event — but only if you can prove the device was encrypted and the login experience did not drive users to work around it. Trellix Data Encryption protects 24 million devices worldwide with FIPS 140-2 validated cryptography, seamless login, and reporting that confirms encryption status for compliance. Faltrox deploys and manages it from one console.

    Overview

    What Data Encryption is

    Trellix Data Encryption protects data and devices from unauthorised access with FIPS 140-2 validated cryptography, protecting 24 million devices worldwide. When a device is lost or stolen, encryption is what turns a breach into a non-event — but only if you can prove the device was encrypted and the login experience did not drive users to work around it.

    It covers full-disk encryption for laptops and desktops, centralised management of native BitLocker and FileVault, and file and removable-media protection so data leaving on a USB stick or by email stays encrypted. Reporting confirms encryption status inside and outside your network, so a lost-device disclosure decision is made from evidence rather than assumption. Faltrox deploys and manages it from one console, with the self-service recovery options that keep encryption from becoming a help-desk queue.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Laptops & Desktops

    Full-disk encryption defends Windows and macOS endpoints from brute-force attacks on lost hardware.

    02

    Removable Media

    File & Removable Media Protection ensures data copied to USB or removable media is encrypted.

    03

    Email Attachments

    Data emailed out of the organisation is encrypted, covering a path endpoint DLP alone can miss.

    04

    BitLocker & FileVault

    Centrally manages native OS encryption — keys, PINs, and status — across Windows and macOS.

    05

    Lost & Stolen Devices

    Reporting proves encryption status of a device even after it leaves your network.

    06

    Regulated Data

    A FIPS 140-2 validated module meets the encryption standards for HIPAA, PCI-DSS, and GDPR.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Encrypt

      Deploy full-disk encryption, native BitLocker/FileVault management, or file and removable-media protection — individually or combined.

    2. 02

      Authenticate

      Multi-factor, passwordless authentication and Active Directory integration give a seamless login without weakening protection.

    3. 03

      Enforce

      Encryption policy is applied by user role and content classification and administered centrally from one console.

    4. 04

      Report

      Out-of-the-box reporting confirms the encryption status of every device for compliance and lost-device decisions.

    5. 05

      Recover

      Self-service recovery — security questions, challenge and response, and a mobile app — lets users regain access without a ticket.

    Capabilities

    Key capabilities

    Drive Encryption

    Full disk encryption defends laptops and desktops from brute-force attacks, with multi-factor passwordless authentication, multiple accounts per device, and Active Directory integration.

    Native Drive Encryption

    Centralises management of Microsoft BitLocker and Apple FileVault — collecting and managing keys, enabling PIN features, and auto-detecting Windows or macOS — so you govern native encryption from one place.

    File & Removable Media Protection

    Ensures data removed from a device or emailed is properly encrypted, restricts access by user role, and covers the removable-media path that endpoint DLP alone can miss.

    Compliance Reporting

    Out-of-the-box reporting confirms the encryption status of devices inside and outside your network, so a lost-device disclosure decision is made from evidence, not assumption.

    Self-Service Recovery

    Security questions, challenge and response, a mobile application, and in-house tools let users recover access themselves, keeping encryption from becoming a help-desk queue.

    FIPS 140-2 Validated

    A FIPS 140-2 validated cryptographic module meets the standards required for HIPAA, PCI-DSS, and GDPR, so the encryption itself is not a point of audit contention.

    Enterprise Visibility

    Up-to-date status on devices and file transfers across the enterprise, so encryption coverage is a live number rather than an annual survey.

    Unified Management

    Centrally manage users and groups and administer all encryption policy in one console — on-premises or SaaS — with Active Directory integration.

    Specifications

    Technical detail

    Products
    Drive Encryption, Native Drive Encryption (BitLocker/FileVault), File & Removable Media Protection
    Platforms
    Windows and macOS
    Cryptography
    FIPS 140-2 validated module
    Compliance
    HIPAA, PCI-DSS, GDPR
    Delivery
    Single console, on-premises or SaaS; Active Directory integration
    Scale
    24 million devices protected worldwide

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Data Encryption for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01We already use BitLocker and FileVault — why add this?

    Native Drive Encryption manages exactly those. The value is centralised key management, PIN enforcement, and estate-wide compliance reporting across both Windows and macOS from one console — the governance layer BitLocker and FileVault do not provide on their own.

    02What happens when a user forgets their password?

    Self-service recovery — security questions, challenge and response, a mobile app, and in-house tools — lets most users recover without a ticket. This matters because painful recovery is the reason encryption gets disabled in practice.

    03Can we prove a lost laptop was encrypted?

    Yes, and that is often the whole point. Out-of-the-box reporting confirms the encryption status of a device even after it leaves your network, which is frequently what determines whether a lost device is a reportable breach.

    04Does the FIPS validation matter for us?

    If you are subject to HIPAA, PCI-DSS, or GDPR, a FIPS 140-2 validated module removes the encryption algorithm itself as a point of audit dispute. For regulated industries this is a requirement, not a nicety.

    05How does this relate to Trellix DLP?

    DLP decides what data can move and where; encryption protects the data at rest and in transit when it does. They are bundled in the Data Security Endpoint Protection Suite precisely because the two controls cover each other’s gaps.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us