Securely store, share, and manage your files with an advanced, easy-to-use, and highly customizable platform
CyberGrant protects every aspect of your digital security
Discover the modular solutions designed to protect your company from external and internal threats, as well as new challenges like AI.
Digital asset protection
Automatic classification
Cloud encryption
Email protection
Anti-phishing
Tailored cybersecurity for every business.
Scalable solutions compatible with legacy systems, designed for both SMEs and large enterprises requiring full control over data, access, and sharing.
Discover security features to protect your data, files, and endpoints
Securely store, share, and manage your files with an advanced, easy-to-use, and highly customizable platform
Control every credential like a file. Share, track, and revoke access instantly.
RemoteGrant protects your business from attacks and data loss by enabling employees to securely access workstations and files from anywhere.
Encrypt every email and keep control of attachments, even after sending.
AIGrant is your personal assistant - it understands your data, keeps it secure, and delivers exactly what you need.
Encrypts every file on SharePoint and OneDrive, in any format, leaving your libraries, permissions, and daily workflows untouched.
Ninety-eight percent of the Italian organizations we work with run SharePoint. Almost none of them have encrypted the files stored on it. The problem isn't negligence. It's a wrong assumption: that managing access permissions is the same as protecting the file. It isn't. This article explains the difference and what it takes to close the gap.
If you manage SharePoint for a mid-to-large organization, you've probably answered the same question dozens of times: "Are our SharePoint files secure?" The honest answer depends on what you mean by secure.
SharePoint protects access: who can enter, read, modify, download. It's a collaboration and document governance tool, and on that front it works well. The problem starts when you assume that protecting access is the same as protecting the file.
The moment a document leaves the SharePoint perimeter (as a download, an email attachment, a OneDrive sync, or a USB copy) the content is readable. Not because something failed: that's exactly how it's supposed to work. SharePoint did its job, which was to check who had permission to download. After that, the protection ends.
The 2026 Verizon Data Breach Investigations Report puts 62% of breaches down to a human element, with 48% involving a third party or vendor. In both cases, the access was usually legitimate: an employee taking files home, an external contractor syncing a project folder, a departing collaborator with documents already downloaded weeks earlier. SharePoint doesn't flag those scenarios because they aren't anomalies. They're normal operations.
This isn't a criticism of SharePoint. It's a description of what it wasn't designed to do.
Microsoft's answer to this gap is Microsoft Purview, bundled in E5. The answer is partial, and understanding where it stops is more useful than knowing where it starts.
Purview encrypts Office files: Word, Excel, PowerPoint, Outlook. For those formats, the protection works, with some caveats on external sharing covered below.
For everything else, the behavior changes. A JPEG uploaded to a Purview-protected SharePoint site becomes PJPEG. A TXT becomes PTXT. Opening those files requires Microsoft's proprietary viewer: Photoshop won't recognize them, Notepad won't open them, Adobe Reader won't work without a complex integration. Any organization working with design files, CAD drawings, PDFs, source code, or any non-Office format faces a hard choice: leave those files unprotected, or accept that users can no longer open them with their usual tools.
There's a second limitation, less visible but significant in many environments. A privileged Azure tenant administrator can open Purview-encrypted files. That's not a bug. It's Microsoft's trust model. In an organization where the Azure infrastructure is managed by an external service provider, or where you want to separate data custody from tenant administration, that becomes a real problem.
The third limitation is external sharing. Sending a Purview-protected file to a collaborator outside the company requires creating an account in the sender's Azure system. It's not impossible, but it adds an onboarding step that often slows down sharing or gets bypassed.
The CyberGrant Connector for SharePoint brings file-centric protection directly into the SharePoint and OneDrive environment. Files stay where they are: no migration, no library changes, no modifications to the permission policies the organization has spent years configuring.
The logic is the same we use for network shares with RemoteGrant: files are encrypted automatically on upload, according to rules defined at the site or folder level. The organization decides which areas to protect. The rest of the SharePoint environment stays unchanged.
In-browser opening. Encrypted files open directly from SharePoint in the browser, through FileGrant, using the Microsoft authentication already integrated. The user doesn't switch interfaces, doesn't authenticate to a separate system. They see the file, open it, edit it.
Local opening. Users who sync files through OneDrive open them locally with a double-click, the same way they always have. RemoteGrant intercepts the open request, decrypts in memory, and the document opens in the native application. No temporary copy is written to disk: when the file closes, no trace of the decrypted content remains locally.
Every format, no exceptions. JPEG with Photoshop, PDF with the corporate reader, PSD, AutoCAD, source code: the Connector encrypts any format and preserves the original extension. An encrypted JPEG stays JPEG. A developer who wants to open a text file with Notepad can. A designer who wants to open a PSD with Photoshop can. The content is protected; the workflow isn't.
Inline editing and library save. Opening, editing, and saving an encrypted document requires no extra steps. Changes are written directly to the SharePoint library, in the updated and still-encrypted version. No decrypt-edit-re-encrypt-re-upload cycle. You open, edit, save.
External sharing without Azure accounts. From SharePoint, a right-click lets you share an encrypted file with an external collaborator through FileGrant. The recipient gets the document with all protections active: screenshot blocking, copy-paste blocking, post-sharing revocation. No Azure account needed.
Protection from the Azure admin. Data segregation from the infrastructure is an architectural property, not a configurable policy. The Azure admin cannot open files protected by the Connector, even with full tenant privileges. Data custody and infrastructure administration stay separate.
The first shift is in how you think about managed service providers. If your Azure tenant is managed by a third party, sensitive content protection no longer depends on trusting that provider. The files are encrypted: even someone with full administrative access to the tenant cannot open them.
The second concerns unauthorized devices. Today, a user who syncs SharePoint to personal OneDrive takes company files outside the controlled perimeter. With the Connector, that file syncs normally but won't open on an unrecognized device. The content is unusable without the right context.
The third is workflow. With Purview, anyone who wants to modify a non-Office file has to manually unprotect it before opening it in the native application, then re-protect it when done. With the Connector, that cycle doesn't exist. Open, edit, save. Protection doesn't interrupt work.
The Connector's encryption uses CRYSTALS-Kyber, the post-quantum standard defined by NIST in FIPS 203 (ML-KEM), published August 2024. It's the same standard we use across the entire FileGrant suite.
Why this matters for SharePoint. Files stolen today in encrypted form can be decrypted once a sufficiently powerful quantum computer becomes available. That's the "harvest now, decrypt later" logic: someone collects the data now and waits. For files with long-term value (multi-year contracts, intellectual property, clinical records) the threat horizon isn't distant. It's already relevant when choosing the encryption you adopt today.
Microsoft Purview does not offer post-quantum encryption.
For a deeper look at the file-centric protection model underlying this architecture: Traditional DLP is obsolete: the limits exposed by NIS2. For the technical perspective on the post-quantum transition: How to prepare for the post-quantum future.
For full technical specifications of the Connector: CyberGrant Connector for SharePoint.
If you want to see it in action, you can request a demo.
Encryption is automatic. Rules are defined at the SharePoint site or folder level, and every file uploaded to a protected area is encrypted with CRYSTALS-Kyber (NIST FIPS 203) without any user action. Existing SharePoint permission policies stay unchanged; only the level of content protection changes. No document migration or library restructuring is required.
Yes, across every format. A JPEG opens with Photoshop, a PDF with the corporate reader, an AutoCAD file with its native software, a text file with Notepad. The Connector never changes file extensions. Editing happens directly in the browser or locally through RemoteGrant: changes save back to the SharePoint library with no extra decryption or re-upload steps.
Microsoft Purview encrypts Office files (Word, Excel, PowerPoint). For other formats, it changes the extension (JPEG becomes PJPEG) and requires a proprietary viewer. The Connector CyberGrant encrypts all formats without changing extensions. Purview offers no post-quantum encryption; the Connector uses CRYSTALS-Kyber (NIST FIPS 203). Purview requires creating an Azure account for external sharing; FileGrant needs only a right-click from SharePoint. A Purview-protected file is accessible to the Azure admin; a Connector-protected file is not.
No. Exclusion of the Azure tenant administrator is an architectural property of the Connector, not a configurable policy. Even with full privileged access to the tenant, the admin cannot open or export protected files. This allows organizations to separate data custody from infrastructure administration, a requirement increasingly relevant when the tenant is managed by an external provider.
From SharePoint, right-clicking an encrypted file starts the sharing flow through FileGrant. The recipient receives the document with all protections active: screenshot blocking, copy-paste blocking, post-sharing revocation. No Azure account is required for the recipient. Access to the document can be revoked at any time after sharing.
No. Files remain in existing SharePoint libraries. No structural changes, no permission redefinitions, no user retraining. The organization decides which sites or folders to protect; from that point, newly uploaded files in those areas are encrypted automatically. Everything else in the SharePoint environment stays unchanged.
The file syncs normally through OneDrive but will not open on an unauthorized device. The encryption makes the content unusable without a device recognized as authorized by the organization. This applies to personal laptops used for remote work as well.