
TeraCryption
Enterprise File Encryption System
TeraCryption Architecture Overview
TeraCryption is a flexible enterprise file encryption architecture designed to protect sensitive documents while preserving normal business workflows.
TeraCryption architecture is designed to secure files through file-level encryption, centralized access control, and Automatic Key Management™. It protects files stored on servers or cloud platforms while ensuring that only authorized users with applicable permissions can decrypt and access sensitive information.
The system operates by encrypting each file individually and controlling access through secure authentication, allowing organizations to maintain strong data protection without relying on traditional shared drive permissions or exposing unencrypted data.
This architecture supports modern file security systems used to protect business-critical data.
1. Core Architecture Principles
TeraCryption is built on four core principles:
-
Encrypt before storage.
-
Automatic Key Management™ – no user-managed file-encryption keys.
-
Flexible storage hubs (server or cloud).
-
Centralized identity and sharing control
Learn more about TeraCryption's File Encryption Architecture, including unique one-time cryptographic material and Automatic Key Management™.
This approach ensures that encrypted files remain protected regardless of where they are stored.
The architectural foundation of the TeraCryption Enterprise File Encryption System evolved from secure communications technologies and patented bidirectional messaging systems originally developed for healthcare and enterprise environments.
The architecture supports Enterprise File Protection Infrastructure across distributed enterprise environments and cloud-based operational workflows.
2. Before Storage
TeraKey encrypts files on the user’s workstation before they are saved to:
-
A local file server
-
A network-attached storage (NAS) device (when mapped or accessible in the user’s file explorer)
-
A private cloud storage account (Google Drive, OneDrive, Amazon S3)
Encrypted files remain unreadable on the storage hub. Only authorized users with the applicable identity, Group, and file-access permissions can decrypt them.
This “encrypt-first” model allows file protection and decryption authorization to remain under TeraCryption control rather than depending solely on storage-provider access controls.
3. Flexible Storage Architecture
One of the key differentiators of TeraCryption is its ability to use either:
-
A local server as the encrypted storage hub
or
-
A cloud storage service to store encrypted files, functioning as a centralized storage hub
This flexibility allows organizations to:
-
Maintain full control using on-premise infrastructure
-
Operate in hybrid environments
-
Use cloud storage without exposing document content
The encryption model remains consistent across all deployment types.
4. Identity-Based Access Control
Access to encrypted files is controlled through:
-
User identity.
-
Group membership.
-
Applicable Group and file-level permissions.
The administrator uses TeraMail to:
-
Add and manage users.
-
Create Groups and assign authorized users.
-
Manage applicable user and Group permissions.
Users can be:
-
Added manually.
or
-
Imported from local Active Directory for large enterprise environments.
This ensures scalability for organizations with hundreds or thousands of users.
5. Encrypted File Sharing and Access Control
TeraKey enables encrypted file sharing through Group-based permissions.
With TeraCryption Standard, the administrator creates Groups and assigns users to them. Users can encrypt files to Groups to which they are assigned, and only authorized members of the corresponding Group can decrypt files encrypted to that Group.
TeraCryption Enterprise adds File Ownership control. The administrator can assign File Ownership rights to selected users. A file owner can then select which authorized members of their Group are permitted to decrypt individual files they own and can change those permissions as sharing requirements change.
This separates Group administration from individual file control:
-
The administrator controls Group membership and assigns File Ownership rights;
-
The file owner controls which authorized Group members can decrypt the individual files they own.
Encrypted files remain encrypted while access and sharing permissions are controlled.
6. Designed for Enterprise Deployment Plans
TeraCryption architecture supports multiple deployment configurations aligned with TeraCryption Plans:
Plan 1 – Individual User Encryption
Encrypted files are stored on the user’s workstation and can be securely shared with other authorized TeraKey users within a Group via network sharing, TeraMail, or email.
Plan 2 – Cloud Hub Architecture
TeraLink connects TeraKey to a configured cloud storage service that functions as a centralized hub for encrypted files. Shared Group folders automatically appear in Windows Explorer for each authorized user, enabling centralized encrypted file sharing.
Plan 3 – Local Server Hub Architecture
TeraLink connects TeraKey to a local server that functions as a centralized hub for encrypted files. Shared Group folders automatically appear in Windows Explorer for each authorized user, maintaining centralized control within the organization’s on-premise infrastructure.
Plan 4 – Server + Encrypted Mirror Backup
TeraBackup extends Plan 3 by automatically maintaining an encrypted cloud mirror of server-based encrypted Group folders to support recovery operations after ransomware or other disruption.
This flexible architecture allows organizations to select the configuration that aligns with their security policies, infrastructure preferences, and operational requirements.
7. Performance and Workflow Preservation
Because encryption and decryption occur at the user’s workstation:
-
Users work directly with authorized files through their normal Windows workflow.
-
No manual encryption steps are required.
-
Existing business workflows can be preserved.
-
Applications, including CAD tools and office software, can operate through their normal file workflows.
Security is integrated into the workflow rather than imposed on it.
8. Enterprise-Ready Security Architecture
TeraCryption architecture is designed to support:
-
Organizational security and compliance requirements.
-
Intellectual property protection.
-
Secure file sharing across departments.
-
Secure remote and local work environments.
These capabilities allow organizations to apply file-level security controls across departments, users, and storage environments.
9. Related Components
-
TeraKey – File encryption and decryption integrated with Windows Explorer
-
TeraMail – User, Group, and system administration
-
TeraLink – Connection between authorized TeraKey users and configured server or cloud storage hubs
-
TeraBackup – Encrypted cloud mirror for backup and recovery operations
Each component performs a specific function within the broader TeraCryption file encryption system architecture.
10. Architecture, Deployment and Security Considerations
The following considerations help understand how TeraCryption is deployed and positioned within an organization.
