For the complete documentation index, see llms.txt. This page is also available as Markdown.

PROTECT Glossary

A quick reference for PROTECT-specific terms.

Term
Definition

Activity Log

A log that records events generated by agents, users, and protection operations.

Agent

The GuardWare PROTECT software installed on an endpoint. It enforces protection policies, encrypts files, and manages access to protected data.

Application

A program that PROTECT is allowed to trust. Approved applications can open, edit, save, encrypt, and decrypt protected files.

Audit Log

A record of activities performed within PROTECT, including policy changes, encryption events, and user actions.

Authorised Website

A website configured in PROTECT where protected files can be uploaded and downloaded seamlessly through the browser extension.

Automatic Protection

A feature that encrypts files automatically when they match configured protection criteria.

Avoid Folders

Directories excluded from automatic encryption. Files in these folders stay unencrypted unless a protected subfolder overrides the rule.

Browser Extension

The GuardWare PROTECT extension installed in Chromium-based browsers that automatically decrypts files during upload and re-encrypts them during download.

Classification

The process of identifying and categorising files based on their sensitivity or content. It also refers to the sensitivity label applied to a file.

Data-Centric Security (DCS)

A security approach that protects the data itself rather than relying only on network, endpoint, or perimeter controls.

Data Type

A collection of detection rules used to identify sensitive information within files. Data Types can contain Sensitive Words, Regular Expressions, and Filename Expressions.

Decrypt

The process of removing encryption from a protected file so authorised users can access its contents.

Detours

A setting that stops protected Office files from being automatically saved or synced to OneDrive or SharePoint while they are being edited.

Encrypt

The process of applying PROTECT encryption to a file to prevent unauthorised access.

Encryption Policy

A rule that determines when and how files are automatically protected.

Endpoint

A device such as a workstation, laptop, or server where the PROTECT Agent is installed.

GuardWare Management Console

The web-based administration interface used to configure PROTECT settings, policies, users, devices, applications, websites, and keys.

Immediate Data Disposal

The ability to revoke access to protected files, making them inaccessible even if copies exist elsewhere.

In-Use Encryption

Encryption that remains active while a file is being viewed or edited, ensuring continuous protection.

Key Revocation

The process of invalidating encryption keys, preventing access to protected files.

MIP

Short for Microsoft Purview Information Protection. PROTECT can use MIP for Office files, or combine MIP with PROTECT for layered protection.

Offline key lifespan

The time a user can open protected files without reconnecting to the PROTECT server. When the period expires, the device must reconnect to refresh access.

Persistent Encryption

Encryption that stays with the file wherever it is stored, shared, or transferred.

Policy Assignment

The process of applying a protection policy to users, groups, endpoints, or Data Types.

Protected File

A file that has been encrypted by PROTECT and is subject to access controls.

PROTECT Device

An endpoint running the PROTECT Agent. Devices appear in the console for monitoring and remote actions.

PROTECT Usage Profile

A view that shows the Security Groups and user policy that apply to a user. It helps explain which PROTECT actions the user can access.

Remove Protection

The action of permanently removing PROTECT encryption from a file.

Restrict Circulation

A control that prevents other users from expanding file access by adding more Security Groups. It keeps control with the original owner.

Right-click menu

The main end-user entry point for PROTECT in Windows Explorer. Users can add protection, remove protection, change protection, and apply sharing controls from there.

Rule

A configurable condition used by PROTECT to determine when an action such as encryption should occur.

Security Group

A group of users assigned permissions to access, decrypt, or manage protected files.

Seamless Download

A feature that automatically re-encrypts files downloaded from authorised websites.

Seamless Upload

A feature that automatically decrypts protected files when they are uploaded to authorised websites.

Sensitive Word

A keyword or phrase used by PROTECT to identify sensitive content within files.

User Policy

A policy applied to users or groups that determines their protection and access settings. It controls what appears in the client and in the right-click menu.

Last updated