Most data protection stops working the moment a file leaves the place that was protecting it. A firewall doesn’t travel with a document. Neither does a folder permission, or a DLP rule sitting at the edge of your network. Once a file is downloaded, emailed, or shared with someone outside the company, whatever was protecting it stays behind. What happens next comes down to trust.

Policy-based data protection starts from a different premise. Instead of protecting the place a file lives, it protects the file itself. Every protected file carries its own policy wherever it goes, and that policy, not the network it’s sitting on or the platform it was shared through, is what actually decides who can open it and what they’re allowed to do once they have.

In practice, that policy comes down to four questions. They’re the same four questions whether the file is a set of financial statements, a patient record, or a contract headed to outside counsel: who can access it, what they can do with it, when, and from where.

Who can access it

Access can be limited to specific named people or organizations, not just “anyone with the link.” That matters because links get forwarded. A policy tied to identity holds even if the file ends up somewhere it was never supposed to.

What they can do with it

Access isn’t all-or-nothing. A file can be set to full access for one person and read-only for another, with printing, downloading, and editing controlled individually. Someone can be allowed to view a document without being able to save a copy of it.

When it can be accessed

Access can be time-limited: set to expire on a specific date, or opened only within a defined window. A file shared for a two-week diligence period doesn’t need to stay open forever just because nobody remembered to close it out.

Where it can be accessed from

Access can be restricted by location, down to the country or region. A file that should only be opened from inside the US can simply refuse to open from anywhere else, regardless of who’s asking.

Those four controls are what “policy-based” actually means in practice. What makes them worth building a security strategy around is what happens after the file is shared.

Protection doesn’t end at “send”

Most security decisions get made once — at the firewall, at the point of sharing — and then the file is on its own. Policy-based protection keeps that decision live. The policy on a file can be tightened, loosened, or revoked entirely at any time, including long after it’s already reached someone outside the organization. A file shared six months ago for a deal that fell through doesn’t have to stay open just because nobody thought to close the loop.

Full visibility, including the failed attempts

Every access attempt is visible to whoever owns the file, successful or not, inside the network or outside it. That includes the attempts that didn’t work: someone trying to open a file after their access was revoked, or from a location the policy doesn’t allow. Most tools only show you what happened. This shows you what was tried.

Enabling business instead of blocking it

This is where policy-based protection breaks from the two approaches most companies already have in place. Microsoft Purview protects data while it stays inside a defined environment. DLP tools try to stop sensitive data from leaving in the first place. Both start from the same assumption: the safest thing to do with sensitive information is keep it contained.

Policy-based protection starts from a different one. Sensitive information has to leave the building. That’s simply how deals get financed, how patients get referred, how contracts get negotiated. So the question isn’t how to stop that. It’s how to make sure the protection leaves with it.

How Keyavi does this

SafeSuite applies this kind of protection directly to files. It’s the core product for teams sharing sensitive documents as a regular part of the job. SafeSuite Lite does the same thing from inside Outlook or Gmail, encrypting and policy-protecting an email’s body and attachments without anyone leaving their inbox.

Four questions, one file, protection that travels with it wherever it goes and stays yours to control long after you’ve hit send. That’s the idea everything else on this site builds from.


See how SafeSuite fits into your process.

See it in action and get your specific questions answered.

Book a Demo
Back to Resources