
TeraCryption
Enterprise File Encryption System
File Security & Access Control
1. Does access to encrypted files depend solely on Windows, Active Directory, or an external IAM system?
No. TeraCryption applies its own user verification and file-access controls before allowing a user to decrypt an encrypted file. A Windows login, Active Directory account, or permission to access a server or cloud storage location does not by itself authorize TeraKey decryption.
An administrator can create TeraCryption user records manually or import users from Active Directory. Importing a user does not replace TeraCryption’s requirements for an approved TeraKey installation, verified login, two-factor authentication, and applicable company, Group, and file permissions.
TeraCryption therefore separates access to the infrastructure where files are stored from authorization to decrypt their contents.
2. How does an administrator authorize a user to use TeraKey?
Only a TeraCryption administrator can add users to the organization’s TeraCryption system. Users can be entered manually or imported from Active Directory.
When an administrator creates a user manually, TeraCryption generates a unique user ID, username, and temporary password. The administrator assigns the applicable security permissions and must explicitly authorize installation of the TeraKey application.
By default, the user is permitted to install TeraKey on one Windows computer. Installation on additional computers requires administrator approval. After the administrator saves the user record, TeraCryption emails the user the access information and installation instructions.
3. What verification takes place when TeraKey is installed?
The TeraKey application must be installed on the user’s computer to encrypt and decrypt files.
During installation, the user enters the assigned username and temporary password. The installation process contacts TeraCryption to validate those credentials and confirm that installation has been authorized.
This establishes an association between the approved TeraKey installation, the registered user, and that computer. Downloading the application alone does not establish permission to use TeraKey or decrypt company files.
4. Can another TeraCryption user log in to the same TeraKey installation using their own credentials?
No. The TeraKey installation is associated with the user whose credentials were verified during installation on that computer.
For example, if John installs TeraKey on his desktop computer, Mary cannot use that installation to access encrypted files by logging in with her own TeraCryption credentials.
If John wants to install TeraKey on an additional computer, such as his laptop, the administrator must approve that additional installation.
5. How are the user’s password and password-reset identity established?
After installation, the user logs in with the assigned credentials and replaces the temporary password with a secret user password. The password is stored encrypted in TeraCryption and cannot be read by the administrator.
The user also establishes a personal four-digit identification code. This code is required when requesting a new password and provides an additional identity check during the password-reset process.
These controls help separate administrator responsibility for creating and managing user records from knowledge of the user’s secret password.
6. How does two-factor authentication verify access?
After the user establishes a secret password, login requires an additional verification code sent to the user’s smartphone or email.
The user must enter a valid code to complete login. Invalid verification codes are subject to a limited number of attempts.
Successful authentication does not by itself grant access to every encrypted file. The user must also have the applicable company, Group, and file permissions.
7. Who can decrypt a TeraCryption-protected file?
Only an authenticated and authorized TeraCryption user with the applicable company, Group, and file permissions can decrypt and access a protected file.
Possession of the encrypted file alone does not provide access. A user who receives, copies, or otherwise obtains a TeraCryption-protected file cannot decrypt it unless that user has been specifically authorized through the TeraCryption security environment.
This allows protection to remain associated with the file wherever the protected file is stored, copied, or shared.
8. How does TeraCryption control access to protected files?
TeraCryption controls access to protected files through authenticated users, company authorization, security Groups, and file-level permissions.
Users are assigned to Groups according to the information they are authorized to access. Protected files associated with a Group can be decrypted only by authorized members of that Group. TeraCryption Enterprise adds File Ownership control, allowing a file owner to select which authorized members of the Group are permitted to decrypt individual files they own.
Access control therefore remains tied to the protected file itself, rather than depending solely on the folder, server, network, or cloud location where the file is stored. This allows organizations to maintain control over confidential information even when protected files are copied, moved, shared, or stored in different locations.
9. How does File Ownership give the file owner control over protected information?
TeraCryption Enterprise includes File Ownership control, allowing the owner of a protected file to maintain control over who is authorized to access and share that file.
The file owner can select which authorized members of the Group are permitted to decrypt the protected file and can change those permissions when required. Access can also be revoked when it is no longer required.
This provides organizations with an additional level of file-level control, allowing responsibility for confidential information to remain with the people who own and manage it while preserving organizational administrative oversight.
10. How do users work with encrypted files without accessing the underlying storage directly?
Users work with encrypted files through normal Windows Explorer operations. They do not need to open the TK-SERVER storage folder on the server or sign in directly to the connected Google Drive, Microsoft OneDrive, or Amazon S3 storage to perform their work.
For accurate encrypted-file tracking, the organization must restrict users’ direct access to these storage locations. Copying, moving, modifying, and deleting files must take place through the TeraCryption workflow rather than through direct access to the storage.
This arrangement allows users to work through familiar Explorer operations while enabling TeraCryption to record the file operations performed through its controlled workflow.
11. What does encrypted-file tracking show, and where does it apply?
TeraCryption includes encrypted-file tracking that records which user accessed, modified, moved, or deleted an encrypted file in the Share Group folders. It also allows the administrator to review when a file was decrypted and whether it was subsequently re-encrypted.
Accurate tracking of files stored in the TK-SERVER folder on the server or in connected cloud storage requires users’ direct access to that storage to be restricted, so users perform file operations through the TeraCryption workflow in Windows Explorer. On a user’s computer, local file-history tracking applies to files stored in the My TeraKey folder.
If the log shows that a file was decrypted without a subsequent re-encryption event, the administrator can follow up with the responsible user. The user remains responsible for the security of the decrypted copy.
12. Can a TeraCryption administrator override a file owner’s sharing permissions or transfer ownership without approval?
No. In TeraCryption Enterprise, an administrator cannot add themselves to a file’s sharing permissions or change the owner’s permissions to obtain access.
When ownership must be transferred—for example, when a file owner retires—the administrator can request the transfer. TeraCryption sends an SMS approval request to the designated company executive registered with the TeraCryption service. The transfer requires that executive’s approval.
The administrator cannot change the approving executive’s registered email address or phone number. This separates administration of users and Groups from approval of a change in file ownership.
13. Can IT or server administrators decrypt protected files simply because they have administrative privileges?
No. Windows, server, network, or storage administrative privileges do not by themselves authorize decryption of a TeraCryption-protected file.
An administrator may have extensive control over the infrastructure where an encrypted file is stored—including the ability to view, copy, move, back up, or restore the file—but those infrastructure privileges do not automatically grant permission to decrypt its protected contents.
Decryption requires the administrator to be an authenticated and authorized TeraCryption user with the applicable company, Group, and file permissions, just like any other user. This allows organizations to separate responsibility for managing IT infrastructure from authorization to access confidential information.
Users perform their normal file operations through the TeraCryption workflow in Windows Explorer; direct access to the underlying storage must be restricted to maintain accurate encrypted-file tracking.
14. Can access to a protected file be revoked after it has been shared?
Yes. Access to a TeraCryption-protected file can be revoked even after the file has been shared or copied to another location. Because authorization is controlled by TeraCryption rather than by possession of the encrypted file, removing a user's applicable access permission prevents that user from subsequently decrypting the protected file.
The organization can therefore revoke applicable access without having to retrieve every previously distributed copy of the protected file.
With TeraCryption Enterprise, a file owner can also change which authorized members of the Group are permitted to decrypt an individual file they own.
15. What happens to protected files when an employee leaves the organization?
When an employee leaves the organization, the employee’s TeraCryption access can be revoked, preventing that user from subsequently decrypting protected company files.
This protection applies even if the former employee previously copied protected files to another folder, computer, storage device, or other location. Possession of the encrypted file does not by itself provide authorization to decrypt it.
The protected files remain available to other properly authorized users, allowing the organization to maintain continuity of access to its information while removing the departing employee’s ability to access it.
16. What happens if a TeraCryption-protected file is copied or moved to another location?
The file remains encrypted and protected when it is copied or moved to another folder, computer, server, storage device, or supported cloud environment.
Copying or moving the file does not remove TeraCryption protection or grant access to someone who possesses the copy. An authenticated and authorized TeraCryption user with the applicable company, Group, and file permissions is still required to decrypt and access the protected information.
This allows security to travel with the protected file rather than depend solely on the location where the file is stored.
Continued encryption and file-history tracking are separate: an encrypted copy remains encrypted, while accurate tracking depends on the controlled workflow and storage locations described above.
