top of page

Control File Access

How can you control who can open individual sensitive files in a shared drive or cloud storage?

TeraCryption provides encrypted file-level access control by organizing protected files according to authorized Groups. Each protected file is encrypted and can be opened only by an authenticated user who has permission to decrypt it.

TeraLink creates and connects the corresponding storage folders for the Groups established through the TeraMail administrative console. TeraKey then presents each authorized user with the Group folders and protected files they are permitted to access through Windows File Explorer.

Access to storage should not determine access to sensitive information.

authorize → authenticate → access → revoke.

Does access to a Group folder mean that every user should be able to open every sensitive file inside it?

No. TeraCryption separates access to a Group from permission to decrypt an individual protected file.

Users may belong to the same authorized Group because they need access to common business information, but individual sensitive files within that Group may require more restricted access. The owner of a protected file can control which authorized members of the Group are permitted to decrypt it.

This allows organizations to maintain a common Group working environment while applying more precise access control to sensitive files that should only be available to selected users.

Can IT administrators manage the storage environment without being able to decrypt confidential files?

Yes. TeraCryption separates administration of the storage environment from authorization to decrypt protected files.

IT administrators may need broad administrative access to servers, Active Directory, cloud storage, backups and other infrastructure without having a business need to read confidential information stored by HR, Payroll, Finance, Legal or executive Groups.

TeraCryption protects the information at the file level. Having administrative access to the underlying storage location does not by itself provide authorization to decrypt a protected file. Only users authorized within the TeraCryption security environment can decrypt the files they are permitted to access.

This allows the organization to maintain the administrative access required to operate its infrastructure while keeping access to sensitive information limited to the people who are authorized to read it.

How does TeraCryption verify a user before allowing access to protected files?

Each user must log in to TeraKey with their individual username and private password before accessing protected files. Optional two-factor authentication can provide an additional identity verification step through the user’s registered phone or email.

Authentication alone does not provide access to every protected file. TeraCryption also verifies that the authenticated user is authorized for the corresponding Group and has permission to decrypt the individual file.

This combination of user authentication and file-level authorization helps ensure that access to a computer, Windows account or storage location alone is not sufficient to decrypt protected information.

What happens when a user should no longer have access to protected files?

TeraCryption allows an organization to change or revoke a user’s access without decrypting and redistributing the protected files.

When an employee changes responsibilities, moves to another department or no longer requires access to certain information, the organization can change the user’s authorization or Group membership. If the user is disabled, access to the TeraCryption environment can also be terminated.

The protected files remain encrypted in their storage location. A user who is no longer authorized cannot decrypt them simply because the files are still present on a server, in cloud storage or were previously accessible to that user.

This allows file protection to change as responsibilities change, without requiring users to manage, replace or redistribute encryption keys.

TM logo 300 x 300 transparent_edited

Enterprise File Encryption System

    TeraCryption provides enterprise file security and encryption solutions internationally, with established sales, operations and support in North America and expanding sales activities in international markets, including Europe and the Caribbean.

    North America Locations

    TeraCryption USA

    401 Park Ave S, 

    New York, NY.

    USA

    Tel: 212-921-5222
    Toll Free: 1-800-387- 4237

    • Linkedin

    TeraCryption Canada

    20 Valleywood Drive,

    Markham, Ontario,

    Canada

    Tel: 905-475-5557

    Toll Free: 1-800-387- 4237

    TeraCryption Mexico

    Comunicaciones Elite S.A. de C.V.

    Atenas, Col. Conjunto Europa

    Irapuato, Guanajuato,

    Mexico

              462-152-4294 Manager

              462-627-7007​ Sales

              rgproactivo@gmail.com

              comsel7@gmail.com

              www.comsel.mx

    WhatsApp
    Email
    Internet

    © 2026 Canamex Communications Corporation
    © 2026 TeraCryption Corporation

    TeraCryption is the enterprise file security division of Canamex Communications Corporation

     

    All rights reserved. Information, products, software, operational description, and specifications are subject to change without notice. All information is provided on an “AS IS” basis without warranties. TeraCryption, the TeraCryption logo, and other TeraCryption trademarks are the property of Canamex Communications Corporation.  All other trademarks are the property of their respective owners.

    Contact us at TeraCryption

    bottom of page
    google-site-verification: google43d31fc921668958.html