PROTECT Glossary
A quick reference for PROTECT-specific terms.
Activity Log
A log that records events generated by agents, users, and protection operations.
Agent
The GuardWare PROTECT software installed on an endpoint. It enforces protection policies, encrypts files, and manages access to protected data.
Application
A program that PROTECT is allowed to trust. Approved applications can open, edit, save, encrypt, and decrypt protected files.
Audit Log
A record of activities performed within PROTECT, including policy changes, encryption events, and user actions.
Authorised Website
A website configured in PROTECT where protected files can be uploaded and downloaded seamlessly through the browser extension.
Automatic Protection
A feature that encrypts files automatically when they match configured protection criteria.
Avoid Folders
Directories excluded from automatic encryption. Files in these folders stay unencrypted unless a protected subfolder overrides the rule.
Browser Extension
The GuardWare PROTECT extension installed in Chromium-based browsers that automatically decrypts files during upload and re-encrypts them during download.
Classification
The process of identifying and categorising files based on their sensitivity or content. It also refers to the sensitivity label applied to a file.
Data-Centric Security (DCS)
A security approach that protects the data itself rather than relying only on network, endpoint, or perimeter controls.
Data Type
A collection of detection rules used to identify sensitive information within files. Data Types can contain Sensitive Words, Regular Expressions, and Filename Expressions.
Decrypt
The process of removing encryption from a protected file so authorised users can access its contents.
Detours
A setting that stops protected Office files from being automatically saved or synced to OneDrive or SharePoint while they are being edited.
Encrypt
The process of applying PROTECT encryption to a file to prevent unauthorised access.
Encryption Policy
A rule that determines when and how files are automatically protected.
Endpoint
A device such as a workstation, laptop, or server where the PROTECT Agent is installed.
GuardWare Management Console
The web-based administration interface used to configure PROTECT settings, policies, users, devices, applications, websites, and keys.
Immediate Data Disposal
The ability to revoke access to protected files, making them inaccessible even if copies exist elsewhere.
In-Use Encryption
Encryption that remains active while a file is being viewed or edited, ensuring continuous protection.
Key Revocation
The process of invalidating encryption keys, preventing access to protected files.
MIP
Short for Microsoft Purview Information Protection. PROTECT can use MIP for Office files, or combine MIP with PROTECT for layered protection.
Offline key lifespan
The time a user can open protected files without reconnecting to the PROTECT server. When the period expires, the device must reconnect to refresh access.
Persistent Encryption
Encryption that stays with the file wherever it is stored, shared, or transferred.
Policy Assignment
The process of applying a protection policy to users, groups, endpoints, or Data Types.
Protected File
A file that has been encrypted by PROTECT and is subject to access controls.
PROTECT Device
An endpoint running the PROTECT Agent. Devices appear in the console for monitoring and remote actions.
PROTECT Usage Profile
A view that shows the Security Groups and user policy that apply to a user. It helps explain which PROTECT actions the user can access.
Remove Protection
The action of permanently removing PROTECT encryption from a file.
Restrict Circulation
A control that prevents other users from expanding file access by adding more Security Groups. It keeps control with the original owner.
Right-click menu
The main end-user entry point for PROTECT in Windows Explorer. Users can add protection, remove protection, change protection, and apply sharing controls from there.
Rule
A configurable condition used by PROTECT to determine when an action such as encryption should occur.
Security Group
A group of users assigned permissions to access, decrypt, or manage protected files.
Seamless Download
A feature that automatically re-encrypts files downloaded from authorised websites.
Seamless Upload
A feature that automatically decrypts protected files when they are uploaded to authorised websites.
Sensitive Word
A keyword or phrase used by PROTECT to identify sensitive content within files.
User Policy
A policy applied to users or groups that determines their protection and access settings. It controls what appears in the client and in the right-click menu.
Last updated

