
TeraCryption
Enterprise File Encryption System
File Verification & Business Continuity
1. How can an organization verify that TeraCryption is protecting files correctly?
TeraCryption’s security behavior can be directly observed and tested by the customer rather than accepted solely from technical descriptions. During implementation or a Proof of Concept (POC), organizations can encrypt and decrypt files, confirm authorized access, verify that unauthorized users cannot decrypt protected information, test access revocation, and observe what happens when encrypted files are copied or moved. This allows organizations to evaluate TeraCryption through observable and repeatable security behavior in their own working environment, without requiring disclosure of TeraCryption’s proprietary cryptographic implementation.
2. How does TeraCryption verify that encryption operations are functioning correctly?
TeraCryption components perform periodic self-diagnostics and operational verification designed to reduce the possibility of an encryption operation stopping without detection. For example, TeraKey verifies that an encrypted file can be successfully decrypted as part of the protection process. If verification is not successful, the system can repeat the encryption and verification process before the protected file replaces the previous version. These automated checks provide an additional level of operational assurance that protected files remain usable by properly authorized users.
3. What happens to protected files if Internet connectivity is interrupted?
Existing TeraCryption-protected files remain encrypted and protected if Internet connectivity is interrupted. Loss of Internet service does not remove the encryption or expose the protected information. In a SaaS deployment, Internet connectivity is required for authentication and permission verification. Therefore, new encryption and decryption operations may pause until connectivity is restored. Organizations requiring greater operational independence can use redundant Internet connections with automatic failover or an on-premises deployment, depending on their business-continuity requirements.
4. Can authorized personnel access critical files during an extended Internet outage?
Yes. Organizations that require emergency offline recovery can use the optional TeraKey Decryptor — Emergency Offline Recovery, a company-specific recovery device designed for authorized administrators. It provides a controlled method for decrypting critical protected files during an extended Internet or service interruption when normal online authorization is unavailable. The emergency recovery device is not a Master Encryption Key and does not generate encryption keys. Because it provides exceptional recovery capability, it must be physically secured and restricted to specifically authorized personnel.
5. How does TeraCryption support backup, recovery, and business continuity?
TeraCryption is designed so that encrypted business files remain under the customer’s custody rather than being uploaded to TeraCryption for storage, encryption, or decryption. For organizations using TK-SERVER, TeraBackup can provide additional recovery capability by maintaining protected backup information that can assist in recreating the TeraCryption server environment following a serious failure or deletion. Database backups can also be encrypted and uploaded to supported cloud storage. TeraBackup is designed to supplement—not replace—an organization’s existing backup and disaster-recovery procedures, providing an additional layer of protection and recovery for the TeraCryption environment.
6. Can TeraCryption detect if an encrypted file has been tampered with?
Yes. When TeraBackup is deployed, TeraCryption provides an additional layer of protection designed to detect unauthorized modification of TeraKey-encrypted files before those files are accepted into the protected cloud backup. When a protected file on TK-SERVER changes, TeraBackup verifies that the file is a valid TeraKey-encrypted file before uploading it to replace the corresponding copy in cloud storage. If an encrypted file has been altered or tampered with and fails this verification, TeraBackup does not upload the altered file as the new backup copy. Instead, the suspect file is moved to quarantine, while the previously stored protected copy remains available for recovery. This provides an important additional layer of defense. Even if an unauthorized person obtains sufficient server privileges to reach and modify encrypted files stored on TK-SERVER, a tampered file that fails TeraBackup verification will not replace the previously protected cloud backup copy. This capability detects modification of an already TeraKey-encrypted file. It should not be confused with detecting corruption that existed in the original document before encryption. TeraKey can encrypt an already-corrupted source file because it does not determine whether the internal contents of an application file are logically valid.