Our team attended the AI & Security Channel Hub yesterday, October 8, 2026, an event organized by Computer Gross for its partners. Throughout the day, we met with more than 50 partners and had the opportunity to discuss the security challenges businesses face every day. It was a day filled with conversations, practical questions, and the exchange of ideas and experiences.
Four areas drew more questions than the rest, and the questions were technical: not what it does, but how far it goes. They sound like four separate problems. They are one problem, seen from four points on the network: the document moves, and the protection stays where it was.
An IT lead asking how to protect a SharePoint library and one asking how to keep a contract out of a public AI assistant are not talking about the same technology. They are describing the same moment: the point where the document leaves the place where it was safe and stays readable.
The market data points the same way. The Verizon Data Breach Investigations Report 2026 records a 60% rise in one year in breaches involving third parties, which now account for 48% of the total. These are not broken perimeters. They are files that followed an ordinary path to somewhere the company does not control.
FileGrant, the file-centric platform from CyberGrant, starts here: the document is encrypted when it is created, not when it tries to leave. Authorized users keep opening it the way they always did. To everyone else, and to any system that tries to read it without authorization, it stays an unreadable file.
This drew the most questions, almost always with the same constraint attached: their customers cannot move anything. Fair enough. Nobody reorganizes a Microsoft 365 tenant to add a layer of security.
CyberGrant Connector is the FileGrant extension that works inside the existing libraries: documents stay where they are, users keep signing in with their Microsoft credentials, and every uploaded file is encrypted with quantum-safe CRYSTALS-Kyber, the NIST FIPS 203 (ML-KEM) standard published in August 2024. The encryption is zero-knowledge, so not even tenant administrators can read the documents.
These are the two points partners pushed hardest on. Connector also encrypts non-Office files, the CAD drawings, signed PDFs, images and application exports that Microsoft Purview sensitivity labels leave exposed. And encrypted files stay unreadable to Copilot when it indexes the library. The ToolShell case showed what happens without that cover: the servers were patched, the archives were readable anyway.
Connector does not replace SharePoint, OneDrive or Purview. It sits alongside them and covers what is missing there. We wrote about how it works in detail and why we released it.
The second area was internal shared folders and laptops. That is where documents sit longest, and where classification, when it exists at all, was done by hand years ago.
RemoteGrant is CyberGrant's second product and covers endpoints and remote access: transparent encryption on local files, access rules, removable media control, secured RDP connections. Users open the encrypted document from their own workstation with no extra steps. Away from that authorized workstation, the file does not open.
Nobody asked us this a year ago. Today it almost always arrives in the same form: not "how do you block ChatGPT", but "how do you keep a customer's document from ending up in there without anyone noticing".
And nobody does notice. An employee pasting a contract into a public assistant breaks no network rule, raises no alert and leaves no trace in the logs. Shadow AI is not malicious behavior. It is the shortest path to finishing a piece of work.
FileGrant's anti-AI scraping protection acts on the file rather than on the behavior: if an encrypted document is uploaded to a public AI, the model cannot read its content. And for the legitimate need underneath, querying your own documents in plain language, AIGrant, the private on-premise AI extension from CyberGrant, brings that capability inside the company: an enterprise RAG that answers on internal documents without those documents leaving.
The fourth area usually came with an objection already formed: it has been tried, and the recipients complained. That is why email encryption gets adopted and then quietly dropped.
EmailGrant is the FileGrant extension for email: it encrypts the message, tracks who opens it, allows access to be revoked after sending, and applies the same rules to attachments as to files in the platform, with expiration dates and an access log. The recipient installs nothing. We wrote about it starting from what happens after you hit send.
Facing four needs, the temptation is to buy four tools. It is also the fastest way to end up with four consoles, four classification policies and no continuity when the document moves between channels: from the SharePoint library to an attachment, from the attachment to a consultant's local folder.
The alternative is to move the protection one level down, from the channel to the document. The file is encrypted and classified once, and each channel adds its own surface without reopening the question. It is the principle we repeated in every conversation at the stand, and it is worth repeating here: the file can change channel, its protection stays with it.
Thanks to Computer Gross for organizing the event, and to the partners who stopped by with precise questions. By the end of the day, what drew the most comment was less any single capability than the range one platform manages to cover.
Yes. CyberGrant Connector works inside existing SharePoint and OneDrive libraries: documents stay where they are, users keep signing in with Microsoft credentials, and quantum-safe encryption is applied automatically to uploaded files. No migration is required and Microsoft 365 is not replaced.
Purview classifies and labels content inside the Microsoft ecosystem. Connector adds zero-knowledge file-centric encryption that also covers non-Office files such as CAD drawings, signed PDFs, images and application exports, and makes documents unreadable to tenant administrators and to Microsoft Copilot. Connector sits alongside Purview rather than replacing it.
Yes. Connector, AIGrant and EmailGrant are extensions of FileGrant, the file-centric platform from CyberGrant: each extends the same protection to a new channel, respectively SharePoint and OneDrive, private AI, and email. RemoteGrant is a separate product, covering endpoints and remote access.
No. FileGrant's anti-AI scraping protection acts on the file itself: if an encrypted document is uploaded to a public AI assistant, the model cannot read its content. The authorized user continues to open it normally from their own workstation.
RemoteGrant applies transparent encryption to local files, along with per-workstation access rules, removable media control and secured RDP connections. The document stays openable from authorized workstations and unreadable anywhere else, even if the copy is moved.
Quantum-safe describes algorithms designed to resist attacks from a future quantum computer. CyberGrant uses CRYSTALS-Kyber, standardized by NIST as FIPS 203 (ML-KEM) in August 2024. It answers the "harvest now, decrypt later" problem: data stolen today and stored until it can be decrypted, a concrete risk for information with multi-year value such as patents, designs and contracts.
Legacy DLP polices the exits: email, endpoints, uploads. It works while the data stays inside the perimeter and the channel is controlled. Once an authorized user legitimately shares a document, the control ends there. File-centric protection puts security inside the file, so it still applies after sharing, with the option to revoke access.