---
title: "DataXray and Virtru: protection that travels with files"
description: "DataXray classifies files by content and Virtru encrypts them with attribute-based access control that stays with each file, running in a U.S. federal enclave."
url: "https://www.dataxray.io/partners/virtru/"
language: "en-US"
---

1. [Home](https://www.dataxray.io/)
2. [partners](https://www.dataxray.io/partners/)
3. Virtru

Partners

# Persistent protection for every classified file

DataXray classifies files by what they contain and passes those labels directly to Virtru. Virtru converts each file to Trusted Data Format, applying encryption and attribute-based access control that stays with the file wherever it travels. When policies or sensitive terms change, DataXray re-classifies and Virtru re-encrypts. The integration is running today inside a closed, air-gapped U.S. federal enclave.

[Book a demo](https://www.dataxray.io/demo/)

## Why classification and encryption belong together

Encryption is only as good as the decision about what to encrypt. Protect everything and files become unusable; protect by folder or file name and sensitive content slips through. DataXray decides from the content of each file, and Virtru enforces that decision with protection that stays with the file after it leaves your environment, so control does not end at the network boundary.

## What the integration delivers

The integration turns DataXray classifications into Virtru protection policies. Files are protected according to what they contain, stay under your control after they leave your environment, and have their protection updated when the rules change.

- **Turn classifications into protection policies**

  DataXray's labels map directly to Virtru policy.
- **Keep control after files leave**

  Access can be revoked or updated at any time, wherever the file has gone.
- **Protect current files and legacy backlogs**

  consistently, in the same workflow.
- **Reassess and update protection**

  when policies or sensitive terms change.

## How it works

DataXray discovers and classifies; Virtru encrypts and enforces. The flow is continuous: files are classified against your own sensitivity rules, protected by Virtru on that basis, and reassessed when the rules change. A dry run lets teams test encryption and decryption behavior before changes reach the wider estate.

- **Discover and classify**

  DataXray reads files at hundreds of thousands of words per second and classifies them with layered classifiers, including large language models, at 98.7% classification accuracy (measured on document-level PII/PCI detection in text-based English files).
- **Encrypt and protect**

  Virtru converts each file to Trusted Data Format (TDF), applying encryption and embedding an attribute-based access control (ABAC) policy based on its classification. Each file carries its own access rules.
- **Adapt to policy changes**

  When policies or sensitive terms change, DataXray re-crawls the sources and identifies the affected files, and Virtru re-encrypts them with updated attributes.
- **Protect legacy data**

  Large backlogs of existing files can be encrypted in a single workflow, after a dry run confirms the behavior.

## Built for federal and coalition environments

The integration is designed for environments where controlled information must stay protected across organizational boundaries. It supports requirements including CMMC Level 2, NIST SP 800-171, CUI handling, HIPAA and GDPR. Virtru's Data Security Platform is FedRAMP Moderate authorized and uses FIPS 140-2 validated cryptography.

## Operational in a closed environment today

The integration is running with a U.S. federal government client inside a closed, air-gapped enclave. DataXray scans SharePoint, Dell Isilon and shared drives across the environment, classifies files against the client's own sensitivity rules, and maps verified attributes to OpenTDF policy. Virtru encrypts at scale, with every file receiving cryptographic protection tied to its content. Continuous monitoring, re-classification and re-encryption run under active Zero Trust implementation requirements.

## Enterprise-ready deployment

DataXray runs inside your environment and your data never leaves it. It is agentless and containerized, operational in hours, and deploys on-premises, air-gapped, hybrid or in the cloud, with 55+ native connectors to datasource types plus a universal connector where no native one exists. Authority to Operate has been achieved on three networks in the U.S. Department of War.

## Where it fits

Encryption hand-off is one of the actions DataXray takes on a classified file, alongside retention labels, redaction and access decisions. The same classifications can also drive Microsoft Purview MIP labels and Thales controls. See [Integrations](https://www.dataxray.io/integrations/), the [Platform](https://www.dataxray.io/platform/) overview, [Security](https://www.dataxray.io/security/), or all [partners](https://www.dataxray.io/partners/).

## Frequently asked questions

### What does DataXray send to Virtru?

Classification labels and verified attributes for each file, which Virtru maps to encryption and attribute-based access control policy.

### What happens when a policy changes?

DataXray re-crawls the sources, identifies the files affected by the change, and Virtru re-encrypts them with updated attributes.

### Can it protect files we already have?

Yes. Large backlogs of existing files can be encrypted in a single workflow, and a dry run lets you test encryption and decryption first.

### Does it work in air-gapped environments?

Yes. The integration is running today inside a closed, air-gapped U.S. federal enclave.

### What is Trusted Data Format?

TDF is an open format, implemented by OpenTDF, that wraps a file with its encryption and access policy, so the protection travels with the file.

## See what is actually in your files. Thirty minutes, your sample data

[Book a demo](https://www.dataxray.io/demo/)

[Read the docs](https://docs.ohalo.co/)
