Navigation

Get in touch
Logo
News

Encryption / File & folder encryption

Confidential files are not for everyone.

u.trust LAN Crypt protects confidential files where your teams work with them. We offer the solution for regular business use as well as for projects with special approval requirements. Whether you have a few employees, multiple sites or an international organization, OTOKO® plans protection domains, roles and keys, handles the rollout and provides maintenance and Level 1-3 support as the exclusive EMEA distributor.

Services in detail
a laptop computer sitting on top of a wooden table — illustrative image
File & folder encryption

Analysis, integration and documented handover

Utimaco / OTOKO®

Encryption from the product to ongoing operation.

Exclusive EMEA distributor for DiskEncrypt and u.trust LAN Crypt. Your partner for custom adaptations, installation, commissioning, maintenance and Level 1-3 support.

File and folder encryption

u.trust LAN Crypt

Protect confidential files in a targeted way and control access through a planned role and key model. OTOKO® supplies u.trust LAN Crypt and integrates the solution into your file storage, workflows and administration.

For small businesses, midsize companies and enterprises: standard deployment and separate editions for classified information. We align licensing, user scope and support with your organization.

Approved edition: version 13.0.x · VS-NfD
Vendor
Utimaco IS GmbH
BSI approval
BSI-VSA-10966 · up to VS-NfD
Approved on
11/15/2025
Valid until
11/15/2028
Entry as of
11/15/2025

This entry names VS-NfD. No EU or NATO approval is shown here for this version.

These details apply to the versions named and their respective deployment and operating conditions. Customer-specific modifications and changes are reviewed for their effect on the scope of approval before implementation. BSI list of approved products.

Your brief for OTOKO®

File & folder encryption: what we take on for you.

The work packages are derived from your current situation. Your team knows the agreed scope, the required involvement and the results that should be available at handover.

Standard or approved edition

We determine protection needs, the number of users and the operational requirements. You receive a suitable selection for regular business use or a separately reviewed, approved edition. Product, version and included services are specified in detail in the quote.

Your result

A transparent proposal covering configuration, rollout and ongoing support.

Map protection domains and collaboration

Which documents belong together, who needs to read them and how do project members change? Together, we translate these workflows into protection domains and policies. Existing file shares and applications are factored in, so that encryption follows your actual work processes.

Your result

A data and role model with documented protection domains.

Plan key management and recovery

Keys require designated owners and a process for joiners, leavers, deputies and emergencies. Administration and business-side data access are deliberately kept separate. A recovery concept is agreed with the authorized parties and tested in practice.

Your result

A key and recovery concept with defined approvals.

Test the rollout with real applications

A pilot tests opening, editing, saving and the intended exchange of files. Business applications, synchronization and backup are examined for how well they work together with the selected solution. The rollout follows only after these results have been evaluated.

Your result

A pilot report and an agreed rollout plan.

Implement VS-NfD with LAN Crypt 13.0.x

We plan deployment of the version approved under BSI-VSA-10966 based on your data pathways and protection domains. Installation, configuration and customer-specific adaptations are assessed against the approved deployment conditions. The agreed commissioning and handover into maintenance and support follow afterward.

Your result

A documented setup with a verified approval reference and structured support.

Planning & implementation

File & folder encryption in everyday project work.

Protecting business data, even without a classified information security requirement

Personnel files, development documents, quotes and customer data already deserve protection in normal business operations. Your company does not need to handle government contracts or process classified information for this. Together, we determine which files are encrypted, who needs access on the business side and how deputies can be arranged. The standard solution is aligned with these workflows; an approved edition is added when your specific protection needs require it.

From a defined folder to a company-wide role model

A small business can start with a protected storage area for management and HR. In midsize companies, for example, separate project teams, multiple sites and external collaboration come into play. For enterprise structures, we additionally plan delegated administration, systematic permission changes and clearly assigned key responsibilities. The selection takes into account client versions, existing storage locations, application compatibility and how authorized people continue working even after a device change.

Encryption and file permissions serve different purposes

A file share first governs who may access data through a specific access path. File and folder encryption adds to this protection: access to the content additionally depends on the keys required. What matters is which data pathways the chosen solution actually covers. Together, we look at local storage, shared directories, copy operations and exchange with partners. This shows where confidential content is processed and where different or additional protection is needed.

The application perspective remains important here. Authorized people still need to be able to edit files; at that moment, plaintext can exist. Encryption therefore does not automatically prevent data loss through an already authorized or compromised user. Endpoint protection, sensible roles and secure exchange procedures remain part of the overall setup. In the pilot, we examine the intended workflows and document their limits. This gives your team a clear statement of what is protected and what responsibility remains elsewhere.

Enforcing key control in daily operations

Choosing a method does not yet resolve the organizational questions. Who is allowed to add new members to a project? What happens when someone leaves? How is data made accessible if an authorized key is not available? These questions are answered before the rollout. An agreed role model prevents broad access rights from arising merely out of convenience. Recovery is given named owners and a documented approval path that matches the protection requirements of your information.

Backup and recovery must also fit together with the key concept. Data can technically exist and still remain unusable if the associated keys are missing. Conversely, a recovery procedure must not bypass the intended access restrictions unnoticed. That is why backup scope, key availability and recovery are tested together. The handover explains these procedures to administrators and business owners. Changes to protection domains or products are then evaluated against the same setup.

Rolling out and supporting LAN Crypt for VS-NfD

u.trust LAN Crypt version 13.0.x from Utimaco IS GmbH is approved under BSI-VSA-10966 up to VS-NfD. The approval, issued on November 15, 2025, is valid until November 15, 2028; the entry is current as of November 15, 2025. We translate the requirements of your file storage into a specific setup and check platform, configuration and operating procedures against the associated documentation. For this version, we do not state an EU or NATO approval: this approval entry names only VS-NfD. Requirements for NATO RESTRICTED are therefore assessed separately and not derived from the national approval.

Even in a military project, product approval, system operation and personnel access are considered separately. Ü3 denotes a security clearance for people, not an encryption level. Required clearances and access authorizations must be clarified before deployment for the specific personnel involved. This does not mean that the worldwide OTOKO® team as a whole is cleared for classified information. For initial discussions, we use an unclassified description; confidential project documents are only exchanged through agreed, permitted channels.

From EMEA distribution to Level 1-3 support

As the exclusive EMEA distributor for u.trust LAN Crypt, OTOKO® combines delivery of the solution with technical implementation at your organization. We handle customer-specific adaptations and modifications, installation and commissioning. First, we determine which systems and workflows are to be connected, which functions are needed and who will administer the solution afterward. This results in an agreed implementation scope, a pilot and a rollout plan. Modifications are documented and assessed against the respective approval: the approval of the original version does not automatically apply to every modified setup.

After commissioning, maintenance and Level 1-3 support remain part of our offering. Level 1 handles structured intake and initial triage, Level 2 the in-depth analysis of configuration and integration, Level 3 the resolution of complex technical root causes and the required coordination with the vendor. Support scope, availability, response times and permitted remote access are agreed to fit the project. In classified environments, we take the permitted access and communication channels into account. Maintenance changes are assessed and tested in a traceable way and put into operation through the agreed approvals.

Illustrative project scenario

Example: a supplier’s development data

A supplier wants to protect confidential development documents with u.trust LAN Crypt. OTOKO® maps project roles and key responsibilities, integrates the solution into the intended file storage and tests access changes and recovery. For VS-NfD documents, version 13.0.x is planned within the approved deployment conditions. Acceptance combines technical function, documented configuration and the handover to maintenance and support.

Before you start

Questions about File & folder encryption.

Is this solution intended only for VS-NfD or large organizations?

No. Our offering also covers regular business use, from small businesses through midsize companies to enterprises. We size the solution according to your data, users and workflows. VS-NfD, EU or NATO requirements are considered separately and apply only to the specific version and configuration for which they are documented.

Does file encryption also protect data when the device is switched on?

It protects content according to the permission and key model of the chosen solution. For an authorized application, however, the data can be available in plaintext. It therefore replaces neither endpoint protection nor controls for the permitted handling of data.

Is every file-and-folder solution approved for VS-NfD?

No. What matters is the specific product, the version and the permitted deployment and operating conditions. This check belongs in the project before selection and rollout.

Is LAN Crypt 13.0.x also approved for NATO RESTRICTED?

The BSI-VSA-10966 entry used here names VS-NfD and does not include an EU or NATO approval. We do not carry over the NATO RESTRICTED approval of DiskEncrypt to LAN Crypt. If you need file encryption at that level, separate, suitable evidence must be in place.

Can small businesses start with this?

Yes. A defined data area with a few roles can serve as a pilot. Protection needs and operating procedures determine the solution; a small group of users does not remove the requirements that apply to classified data.

Does OTOKO® also provide adaptations, maintenance and support?

Yes. As the exclusive EMEA distributor, we offer customer-specific adaptations and modifications as well as installation, commissioning, maintenance and Level 1-3 support. Scope of services and service hours are agreed. For approved use cases, we review the effect on the scope of approval before making changes; a vendor approval does not automatically cover every modification.

Related services

Go to the cybersecurity overview

File & folder encryption with OTOKO®

Describe your project. We will clarify the right starting point.

Tell us your use case, the approximate number of devices or users and the desired scope of protection. We discuss standard editions and special requirements separately and plan procurement, rollout and support to fit your organization.

Discuss File & folder encryption

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.