Securely store, share, and manage your files with an advanced, easy-to-use, and highly customizable platform
CyberGrant protects every aspect of your digital security
Discover the modular solutions designed to protect your company from external and internal threats, as well as new challenges like AI.
Digital asset protection
Automatic classification
Cloud encryption
Email protection
Anti-phishing
Tailored cybersecurity for every business.
Scalable solutions compatible with legacy systems, designed for both SMEs and large enterprises requiring full control over data, access, and sharing.
Discover security features to protect your data, files, and endpoints
Securely store, share, and manage your files with an advanced, easy-to-use, and highly customizable platform
Control every credential like a file. Share, track, and revoke access instantly.
RemoteGrant protects your business from attacks and data loss by enabling employees to securely access workstations and files from anywhere.
Encrypt every email and keep control of attachments, even after sending.
AIGrant is your personal assistant - it understands your data, keeps it secure, and delivers exactly what you need.
Encrypts every file on SharePoint and OneDrive, in any format, leaving your libraries, permissions, and daily workflows untouched.
Screen capture is a data exfiltration channel that most security tools leave ungoverned. During video calls, screen sharing, and online collaboration, a confidential document can be captured with a simple screenshot or recording. The perimeter model does not intercept these cases, because nothing about them looks like an attack: they are legitimate operations performed in the wrong place.
A screenshot taken during a call leaves no trace in the firewall logs. It raises no alert. It crosses no channel a perimeter defense knows how to read. And yet, in that one action, a confidential document has just left the company.
Any document visible in a video call, a screen share, or an online workspace can be captured with a screenshot, a screen recording, or a photo taken with a phone. The perimeter model does not catch it. What it sees is a legitimate operation performed in the wrong place, by someone who is authorized to open the file.
Perimeter defenses look for intrusions and exit channels: a suspicious upload, a USB stick, an attachment headed to an external domain. A screenshot fits none of these categories. It happens on the screen of someone who has permission to open the document, inside an authorized session. The file passes through no inspectable gateway.
In its 2026 report on cybersecurity in the frontier AI era, ENISA urges security architectures to adopt an "assume-breached" posture, treating every environment as potentially already compromised, with defenses that reach beyond the perimeter. Screen capture is the clearest example of that logic. The exposure does not come from outside. It comes from a legitimate use of the document, from within.
Anyone who designs security knows it: the hardest blind spot to close is the one that coincides with a permitted operation. For more on the shift from perimeter to data, see Beyond the perimeter: file-centric DLP.
Microsoft Teams Premium introduced screen capture prevention. The limit is coverage. On Windows desktop a screenshot returns a black rectangle around the meeting window; on iOS and Android capture is blocked; but on macOS desktop, web browsers, and virtual desktops participants join in audio-only mode, and the feature requires a Premium license for the meeting organizer (Microsoft documentation).
Google Meet added watermarking in October 2024. The watermark overlays the participant's identity to discourage leaks, but it does not stop a screenshot, and image-editing software can remove it (Google Workspace Updates).
Both tools share the same architectural limit: they protect the session, the screen-sharing stream, not the document. Once the file is downloaded or opened outside the platform, it is vulnerable again. The control stays tied to the collaboration tool, not to the asset you want to protect.
This is the logic of file-centric DLP, or DLP 2.0. Protection lives inside the file and follows it wherever it goes: on the PC, in the cloud, at a third party, on a non-corporate device. The document is encrypted the moment it is created, not secured after the fact. From that point on the policies travel with it and take priority over the actions of whoever opens it.
For anyone designing the security architecture, the gain is measurable in dependencies removed: protection no longer depends on the meeting platform in use, on the recipient's operating system, or on the number of licenses purchased. It follows the data. Cases like the ones described in Booking, Eataly, Trenitalia: why stolen data was readable show what happens when this protection is missing and the content stays readable once it leaves.
Effective anti-capture protection is built in layers, each one acting on the document rather than on the session. Here is how it comes together.
Capture blocking protects what is on the screen. Encryption protects the file as it travels or is downloaded. These are two different layers of the same problem, and the second one looks far into the future.
A confidential document intercepted today is not only worth something today. Whoever obtains it can store it and wait, following the "harvest now, decrypt later" logic: archive the encrypted files now, decrypt them once a quantum computer is available. This is why file-centric protection relies on quantum-safe encryption. CyberGrant uses the CRYSTALS-Kyber algorithm, recognized by NIST as a post-quantum standard (FIPS 203, ML-KEM, August 2024). A file exfiltrated as a file stays unreadable without authorization, today and against future computing power.
CyberGrant applies this approach with FileGrant. Screenshot blocking during video calls and screen sharing runs through the proprietary viewer, which detects and stops capture tools, recorders, and unauthorized screen-sharing software regardless of the video-conferencing platform. Alongside it work dynamic watermarking, anti-AI scraping that prevents public generative AI systems from extracting the content, quantum-safe CRYSTALS-Kyber encryption, instant revocation with programmable expiry, and a complete audit trail. Document classification is handled by the private AI in AIGrant, which assigns security tags by reading the content.
FileGrant sits alongside the systems you already run. It coexists with Microsoft 365, SharePoint, and OneDrive and adds the missing protection to files already in place, without changing your workflows. It does not replace the collaboration platform. It adds the vault the platform was missing.
Want to see screen-capture blocking on a scenario like yours? Request a personalized demo.
Software blocking stops captures made with digital tools: system screenshots, screen recorders, screen-sharing utilities. No system can stop a photo taken with a phone against the screen. For that case, dynamic watermarking adds traceability, because the copy carries the identifying data of whoever produced it. The combination of software blocking and watermarking covers both scenarios.
Yes. With the file-centric approach, protection stays active after the file is sent. Access can be revoked at any time, and the document becomes unreadable for anyone no longer authorized. You can also set automatic expiry dates that close access on a chosen date, even while the recipient is viewing the file.
Meet watermarking overlays the meeting participant's identity to discourage and trace leaks, but it does not prevent capture. File-level blocking acts on the document itself: it stops the screenshot at the application level and stays with the file even outside the call, when it is downloaded or opened elsewhere.
Yes. A file-centric solution sits alongside Microsoft 365, SharePoint, and OneDrive and adds screenshot protection, persistent encryption, and post-sharing revocation to files already in place, without changing existing workflows.
Capture blocking protects what is on the screen. Quantum-safe encryption protects the file as it travels or is downloaded. A confidential document intercepted today can be stored while attackers wait for quantum computers, following the "harvest now, decrypt later" logic. The CRYSTALS-Kyber algorithm, a NIST FIPS 203 standard from August 2024, keeps the file unreadable without authorization, even against that future computing power.
Article 32 of the GDPR requires technical measures appropriate to the risk, including encryption, access control, and traceability of operations. Encryption, RBAC, and an audit trail meet this requirement and also support the traceability obligations set out by NIS2 and DORA for sensitive data.