Control File Access
1. How can you control who can open individual sensitive files in a shared drive or cloud storage?
TeraCryption provides encrypted file-level access control by organizing protected files according to authorized Groups. Each protected file is encrypted and can be opened only by an authenticated and authorized user who has permission to decrypt that file.
TeraLink creates and connects the corresponding storage folders for the Groups established through the TeraMail administrative console. TeraKey then presents each authorized user with the Group folders and protected files they are permitted to access through Windows File Explorer.
Access to storage should not determine access to sensitive information.
define authorization → authenticate → decrypt → revoke
2. Does access to a Group folder mean that every user should be able to open every sensitive file inside it?
No. TeraCryption separates access to a Group from permission to decrypt an individual protected file.
Users may belong to the same authorized Group because they need access to common business information, but individual sensitive files within that Group may require more restricted access. The owner of a protected file can control which authorized members of the Group are permitted to decrypt it.
This allows organizations to maintain a common Group working environment while applying more precise access control to sensitive files that should only be available to selected users.
join Group → select authorized users → decrypt permitted files → change sharing
3. Can IT administrators manage the storage environment without being able to decrypt confidential files?
Yes. TeraCryption separates administration of the storage environment from authorization to decrypt protected files.
IT administrators may need broad administrative access to servers, Active Directory, cloud storage, backups and other infrastructure without having a business need to read confidential information stored by HR, Payroll, Finance, Legal or executive Groups.
TeraCryption protects the information at the file level. Having administrative access to the underlying storage location does not by itself provide authorization to decrypt a protected file. Only users authorized within the TeraCryption security environment can decrypt the files they are permitted to access.
This allows the organization to maintain the administrative access required to operate its infrastructure while keeping access to sensitive information limited to the people who are authorized to read it.
administer storage → protect files → verify authorization → prevent unauthorized decryption
4. How does TeraCryption verify a user before allowing access to protected files?
When two-factor authentication (2FA) is enabled for the organization, each user enters their individual TeraKey username and secret password on the login screen. After the username and password are verified by the system, a verification code is sent to the user by email or SMS, according to the user’s selected method. The user must enter the code on a separate verification screen to complete the authentication process and access TeraKey.
2FA verifies the user’s identity for access to TeraKey. Separately, the TeraCryption administrator controls Group access and encryption permissions that determine which protected information the authenticated user is authorized to access.
This separation verifies who the user is independently from determining which protected files the user is authorized to decrypt.
enter username & password → verify 2FA code → access TeraKey
5. What happens when a user should no longer have access to protected files?
TeraCryption allows an organization to change or revoke a user’s access without decrypting and redistributing the protected files.
When an employee changes responsibilities, moves to another department or no longer requires access to certain information, the organization can change the user’s authorization or Group membership. If the user is disabled, access to the TeraCryption environment can also be terminated.
The protected files remain encrypted in their storage location. A user who is no longer authorized cannot decrypt them simply because the files are still present on a server, in cloud storage or because the user was previously authorized to access them.
This allows file protection to change as responsibilities change, without requiring users to manage, replace or redistribute encryption keys.
change authorization → remove Group access → prevent decryption → keep files encrypted
6. Can a user obtain an encryption key and use it to decrypt a protected file?
No. TeraCryption does not provide users with encryption keys to store, retrieve or enter for decryption. Each protected file is encrypted using unique one-time cryptographic material that is not reused to encrypt another file.
A user who has access to an encrypted file does not gain access to an encryption key that can be retrieved and used to decrypt it. Decryption is performed only through the TeraCryption security environment after the user’s authorization has been verified.
This eliminates user exposure to stored or reusable encryption keys while maintaining file-level protection and controlled access to sensitive information.
access encrypted file → no key to retrieve → verify authorization → decrypt if authorized
