Persistent protection for every classified file
DataXray classifies files by what they contain and passes those labels directly to Virtru. Virtru converts each file to Trusted Data Format, applying encryption and attribute-based access control that stays with the file wherever it travels. When policies or sensitive terms change, DataXray re-classifies and Virtru re-encrypts. The integration is running today inside a closed, air-gapped U.S. federal enclave.
Why classification and encryption belong together
Encryption is only as good as the decision about what to encrypt. Protect everything and files become unusable; protect by folder or file name and sensitive content slips through. DataXray decides from the content of each file, and Virtru enforces that decision with protection that stays with the file after it leaves your environment, so control does not end at the network boundary.
What the integration delivers
The integration turns DataXray classifications into Virtru protection policies. Files are protected according to what they contain, stay under your control after they leave your environment, and have their protection updated when the rules change.
- Turn classifications into protection policiesDataXray's labels map directly to Virtru policy.
- Keep control after files leaveAccess can be revoked or updated at any time, wherever the file has gone.
- Protect current files and legacy backlogsconsistently, in the same workflow.
- Reassess and update protectionwhen policies or sensitive terms change.
How it works
DataXray discovers and classifies; Virtru encrypts and enforces. The flow is continuous: files are classified against your own sensitivity rules, protected by Virtru on that basis, and reassessed when the rules change. A dry run lets teams test encryption and decryption behavior before changes reach the wider estate.
- Discover and classifyDataXray reads files at hundreds of thousands of words per second and classifies them with layered classifiers, including large language models, at 98.7% classification accuracy (measured on document-level PII/PCI detection in text-based English files).
- Encrypt and protectVirtru converts each file to Trusted Data Format (TDF), applying encryption and embedding an attribute-based access control (ABAC) policy based on its classification. Each file carries its own access rules.
- Adapt to policy changesWhen policies or sensitive terms change, DataXray re-crawls the sources and identifies the affected files, and Virtru re-encrypts them with updated attributes.
- Protect legacy dataLarge backlogs of existing files can be encrypted in a single workflow, after a dry run confirms the behavior.
Built for federal and coalition environments
The integration is designed for environments where controlled information must stay protected across organizational boundaries. It supports requirements including CMMC Level 2, NIST SP 800-171, CUI handling, HIPAA and GDPR. Virtru's Data Security Platform is FedRAMP Moderate authorized and uses FIPS 140-2 validated cryptography.
Operational in a closed environment today
The integration is running with a U.S. federal government client inside a closed, air-gapped enclave. DataXray scans SharePoint, Dell Isilon and shared drives across the environment, classifies files against the client's own sensitivity rules, and maps verified attributes to OpenTDF policy. Virtru encrypts at scale, with every file receiving cryptographic protection tied to its content. Continuous monitoring, re-classification and re-encryption run under active Zero Trust implementation requirements.
Enterprise-ready deployment
DataXray runs inside your environment and your data never leaves it. It is agentless and containerized, operational in hours, and deploys on-premises, air-gapped, hybrid or in the cloud, with 55+ native connectors to datasource types plus a universal connector where no native one exists. Authority to Operate has been achieved on three networks in the U.S. Department of War.
Where it fits
Encryption hand-off is one of the actions DataXray takes on a classified file, alongside retention labels, redaction and access decisions. The same classifications can also drive Microsoft Purview MIP labels and Thales controls. See Integrations, the Platform overview, Security, or all partners.
Frequently asked questions
What does DataXray send to Virtru?
Classification labels and verified attributes for each file, which Virtru maps to encryption and attribute-based access control policy.
What happens when a policy changes?
DataXray re-crawls the sources, identifies the files affected by the change, and Virtru re-encrypts them with updated attributes.
Can it protect files we already have?
Yes. Large backlogs of existing files can be encrypted in a single workflow, and a dry run lets you test encryption and decryption first.
Does it work in air-gapped environments?
Yes. The integration is running today inside a closed, air-gapped U.S. federal enclave.
What is Trusted Data Format?
TDF is an open format, implemented by OpenTDF, that wraps a file with its encryption and access policy, so the protection travels with the file.