Widespread cloud adoption and the explosion of device types used to access cloud services have intensified security and compliance risks. Employees and contractors can use personal cloud tools for work outside employer oversight, while business units can procure SaaS without adequate risk assessment. Mobile access from outside the organizational perimeter compounds exposure. Key concerns include where data is stored and processed, cloud provider staff access, lawful government demands for data access without customer permission, and the need to demonstrate GDPR-compliant use of personal data for agreed purposes.
To address these issues, the market has grouped overlapping capabilities under Cloud Access Security Brokers (CASBs), including storage encryption, rights management, data leakage prevention, and access brokers/gateways. A particularly sensitive area is office productivity and email platforms such as Office 365 and Google Workspace, which contain information spanning the entire organization; protecting them against leakage and unauthorized disclosure is essential. A core recommendation is customer-controlled encryption for data stored in cloud services.
Vaultive, a privately held US company founded in 2009, provides the Vaultive Cloud Data Security Platform (CDP): a stateless, network-layer encryption and data security proxy designed to be seamless for applications and transparent to end users. Initially focused on Exchange Online/Office 365 encryption, Vaultive has expanded to simplify SaaS integrations and add behavioral controls, content-based blocking/redaction, auditing, and alerting. For Office 365, Vaultive encrypts data in transit, at rest, and in use so it is never stored in the cloud as clear text; the proxy encrypts/decrypts messages in flow without storing them. It supports common protocols and mobile access, works with PGP and S/MIME, uses AES-256 with patented methods that preserve server-side functionality, and keeps keys customer-controlled (optionally in HSMs) with options for geography-specific key localization. Limitations include fewer predefined SaaS integrations and no discovery/access control for unsanctioned cloud apps.
See All Locations
See All Locations