Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

PK Protect · Data security platform

Find sensitive data everywhere it lives. Protect it in the same operation.

PK Protect is a data security platform. It finds sensitive data across endpoints, Microsoft 365, databases, cloud storage, and the mainframe, and protects it in the same operation that found it.

Encrypt, mask, redact, label, quarantine, or delete. On endpoints and in Microsoft 365, that happens within seconds of the file being written.

40+ yrs

protecting regulated data

21 of 25

largest U.S. commercial banks

504M records

scanned in the average z/OS risk assessment

Fig. 00The same file, two timelines
SCAN-BASED TOOLS File savedto a laptop AI agent reads it Day 6 scan Exposed forsix days. PK PROTECT Protectedin seconds. SCAN-BASED TOOLS File savedto a laptop AI agent reads it Day 6 scan Exposed for six days. PK PROTECT Protected in seconds.

Same file, same agent. On one timeline it’s already encrypted.

Protecting 21 of the 25 largest U.S. commercial banks and 30% of the Fortune 100.

JPMorgan ChaseTruistFiservWestern Union
1M+
Files a day

Fiserv, one of the world’s largest financial services providers, encrypts more than a million files daily across desktops and servers, with encrypt and decrypt built into internal applications.

18,000
Databases

A top U.S. bank runs discovery across more than 400 applications and 18,000 databases holding close to a million tables.

504M
Records

The average PKWARE z/OS data risk assessment scans 504 million VSAM records and finds 422 million credit card numbers and 450 million Social Security numbers.

Something now reads your files faster than your last scan finished.

The problem

Most companies can’t say where their sensitive data actually is.

Sensitive data spreads through normal work. Every export, backup, test refresh, and file share makes another copy, and the copies outlive the reason they were made.

Most organizations can name their systems of record. Almost none can name every place a customer’s Social Security number ended up.

It shows up when someone asks a simple question. Where is our cardholder data. What was in the folder that got exposed.

Those questions turn into two-week fire drills that end with “as far as we can tell.”

A U.S. data breach now averages $10.22M, per the IBM Cost of a Data Breach Report, 2025. Nobody tracks how many of the exposed records were copies that shouldn’t have existed.

Fig. 01 How one record becomes many Governed originUncontrolled copy
01 · ORIGIN 02 · WHERE THE COPIES LAND SYSTEM OF RECORD File shareunscanned since 2019Cloud storage bucketleft from a migrationSharePoint and OneDriveshared with a channelLaptop downloads folderdownloaded, then forgotten Your inventory lists the system of record. It doesn’t list the copies. 01 · ORIGIN SYSTEM OF RECORD 02 · WHERE THE COPIES LAND File shareunscanned since 2019 Cloud storage bucketleft from a migration SharePoint and OneDriveshared with a channel Laptop downloads folderdownloaded, then forgotten Your inventory lists thesystem of record. It doesn’tlist the copies.

Every one of those copies started as a reasonable decision by a competent person.

How it works

Finding it and fixing it are the same step.

PK Protect finds sensitive data and remediates it in the same operation, rather than producing a report somebody works through later.

01

It finds what’s there.

Discovery runs across endpoints, Microsoft 365, cloud storage, databases, and z/OS. On endpoints and in Microsoft 365, PK Protect acts within seconds of a file being written. Everywhere else, discovery runs on the schedule you set and remediation runs with it.

02

It reads what’s actually inside.

Discovery reads content, not file names or folder rules. It finds a card number in a database column, a Social Security number in a Word document, and sensitive fields inside z/OS binary datasets with no field headers.

03

It protects in the same operation.

PK Protect encrypts, masks, redacts, labels, quarantines, moves, or deletes, based on what it found and what your policy says. Protection attaches to the data, so it holds when the file is emailed, copied, or uploaded. The application SDK encrypts inline, before anything reaches disk.

04

It proves what happened.

A finding you didn’t act on is a dated record showing you knew. PK Protect produces audit-ready reporting against PCI DSS, GLBA, SOX, HIPAA, GDPR, CCPA, and FISMA.

01 DiscoverScan every surface and find the data you didn’t know you had.
02 ClassifyLabel what’s sensitive, automatically and consistently.
Protect, in parallel
EncryptIn place and in motion.
MaskUsable data, zero exposure.
RedactStrip sensitive fields.
Quarantine/DeleteIsolate or purge on policy.
AuditProve protection was applied, to any regulator.

Your existing stack

Where PK Protect sits next to your DLP and your posture tooling.

PK Protect complements DLP, which guards the exits, and goes a step past posture management, which finds the risk and hands the fix back to you.

DLP guards the exits. PK Protect protects the data.

Your DLP blocks what shouldn’t leave, but it can’t read a file your company has no key to. PK Protect encrypts under a company-held policy key, which puts those files back in scope for your DLP. Anything that does get out is unreadable, not just unauthorized.

At one of the world’s largest financial institutions, PK Protect’s DLP enhancement put thousands of locked-out encrypted emails a month back in scope.

How PK Protect enhances DLP

Posture tells you where the risk is. PK Protect removes it.

Posture tools find and score sensitive data, then hand you a list. PK Protect does the discovery, then encrypts, masks, redacts, or quarantines what it finds under the same policy. A finding becomes a fixed file instead of a backlog item.

PK Protect and data security posture management

Nothing gets ripped out. PK Protect runs alongside the tools you already bought and does the part neither was built to do.

POSTURE TOOLING DLP DATA CREATEDDATA AT RESTDATA IN MOTIONDATA LEAVES PK PROTECT Protects it the whole way. DATA CREATED DATA AT REST DATA IN MOTION DATA LEAVES POSTURETOOLING DLP PK PROTECT Protects it the whole way.

Two of these stop at a boundary. One travels with the file.

AI

An agent can reach a new file in minutes. We protect it in seconds.

AI assistants and agents run with the permissions of whoever is using them, and they index continuously. A file with Social Security numbers in it is reachable soon after it lands. On endpoints and in Microsoft 365, PK Protect encrypts, masks, or redacts the sensitive values within seconds of the file being written.

Scheduled scanning made sense when the reader was a person who had to know the file existed. An agent doesn’t.

Some of the AI reaching your data isn’t AI you approved.Somebody pasted a customer list into a chatbot. Somebody wired an agent into a SharePoint site.

What PK Protect does about it

01Protects within seconds.

On endpoints and in Microsoft 365, remediation runs within seconds of a file being written, not on a weekly cycle.

02De-identifies what feeds the model.

Mask sensitive fields before data reaches a training set, a RAG index, or analytics. The dataset still works. The PII isn’t in it.

03Encrypts what should never be in scope.

If a repository has no business being readable by AI, it isn’t readable even when something indexes it.

04Hands your access controls something to act on.

Discovery and classification output shows which files hold sensitive data. Your access tooling uses it to keep those files away from users, and the agents running as them, who shouldn’t reach them.

Gartner® names the Shadow AI problem and what to do about it. Get the complimentary report.

Read the Gartner® report
Fig. 02 What an AI agent can reach Readable in fullProtectedLabeled
SharePoint siteLABELEDFile share (2019)ENCRYPTEDCloud bucketMASKEDLaptop folderREDACTED AI AGENT Runs with the user’s permissions. Same permissions. Different data. Everything the user can open, the agent can read. The agent still does its job. SharePoint siteLABELED File share (2019)ENCRYPTED Cloud bucketMASKED Laptop folderREDACTED AI AGENT Runs with the user’s permissions. Same permissions. Different data. Everything the user can open,the agent can read. The agent still does its job.

Same agent, same permissions. Different data underneath.

See how PK Protect securely enables AI

The quantum clock

You can’t migrate cryptography you can’t see.

Post-quantum migration stalls at the first step, which is knowing what you’re running. PK Protect scans for the encryption itself, not just the sensitive data, and sorts every algorithm it finds into quantum-safe and quantum-at-risk.

A full cryptographic bill of materials also covers the protocols and libraries inside your applications, which is a separate exercise. This is the data-at-rest half, and it’s the half most programs can’t see.

01 · Inventory

The inventory comes back already sorted.

Most programs discover their exposure by algorithm, not by guess. A scan comes back and the split between what holds and what has to be replaced is sitting there in front of you, per file, per device, per policy.

One scan, 126,603 files. The split between what holds and what has to move.
Migration status across every endpoint, policy, and remediation.
02 · Migration

Then you can actually track the migration.

Migration progress across endpoints, agents, targets, policies, and remediations, in one view, so the answer to “where are we on post-quantum” stops being a spreadsheet somebody maintains by hand.

AES-256 holds. RSA is the problem, and NIST sunsets RSA-2048 after 2030. The work is replacing the public-key layer, and the work starts with knowing where it is.

Quantum safe encryption

By environment

One platform. Three places your data lives.

PK Protect runs as three modules under one policy. Most customers start with one and add the others.

Users, devices, and Microsoft 365

PK Protect Endpoint Manager

“People are saving sensitive files to laptops, file shares, and SharePoint and I have no idea what’s out there.”

Finds sensitive data on desktops, laptops, servers, file shares, OneDrive, and SharePoint, and protects it within seconds of the file being written. Policies run centrally, so protection doesn’t depend on a user picking the right label.

Encryption is certificate-free, so there’s no PKI to stand up. It also covers CSVs and legacy .doc, .xls, and .ppt files that Microsoft labeling doesn’t handle.

1M+

files encrypted a day at Fiserv, across desktops and servers

See Endpoint Manager

Databases, cloud, and applications

PK Protect Data Store Manager

“My exposure is in databases and cloud storage, and my developers need realistic test data without the real values in it.”

Handles data at bulk. Discovers across structured, semi-structured, and unstructured sources, then masks by policy so the data stays protected and stays usable.

Developers get production-shaped data without production values, and datasets get ready for analytics and AI. It also finds the redundant and obsolete data you’re paying to store.

18,000

databases across 400+ applications at a top U.S. bank

See Data Store Manager

The mainframe

PK Protect for z/OS

“Our regulated data lives on z/OS and nobody can tell me what’s inside those datasets.”

z/OS datasets are often raw binary with no field headers, which is why most tools scan DB2 and stop. PK Protect reads the application’s own data definitions to find sensitive fields inside datasets others treat as unreadable, then applies encryption that holds after the data leaves the platform.

The same scan inventories the encryption you’re running, algorithm by algorithm.

88%

of scanned data held unprotected sensitive data, on average, across PKWARE z/OS risk assessments

See PK Protect for z/OS
See which module covers what
PK Protect coverage by capability and environment.
Endpoints & serversMicrosoft 365Databases & data lakesCloud & applicationsz/OS mainframe
DiscoveryPEMPEMDSMDSMz/OS
Remediation within seconds of file writePEMPEM———
Classification & labelingPEMPEMDSMDSMz/OS
EncryptionPEMPEMDSMDSMz/OS
Masking——DSMDSMz/OS
RedactionPEMPEM———

PEM = PK Protect Endpoint Manager · DSM = PK Protect Data Store Manager · z/OS = PK Protect for z/OS

One policy engine underneath all of it. Add modules as your scope grows.

Prove it on one environment

One scan tells you whether any of this applies to you.

Point PK Protect at a single file share or one database and look at what comes back. Most teams find sensitive data in places nobody on the call expected, and the conversation stops being about whether you have an exposure problem.

Proof

What this looks like at enterprise scale.

The numbers at the top of this page come from teams running it. Here’s one of them from the inside.

Proof at scale · Fiserv

One encryption layer holding the financial plumbing together.

Fiserv has run PKWARE as its encryption backbone for over five years, across a multi-cloud, post-M&A, regulated environment that never stops moving money. Encrypt and decrypt are built directly into internal applications, and more than a million files are protected every day.

Read the Fiserv case study
Fiserv case study cover: how Fiserv protects billions in daily transactions with PKWARE.
“

PKWARE has become a trusted strategic partner in strengthening Western Union’s data governance and security posture. Their solutions give us visibility into sensitive data, simplify compliance, enable our data subject access request responses, and help us to meet our privacy and protection objectives.

Craig Sharkey
Former Chief Privacy and Data Governance Officer, Western Union

The other product

PK Protect and PK Encrypt are two products under one roof.

PK Protect finds what you don’t know about. PK Encrypt protects what you already do, inside the z/OS and IBM i batch jobs moving it tonight.

See PK Encrypt

Integrations

PK Protect connects to what you already run.

DatabasesDSM
  • Oracle
  • SQL Server
  • Postgres
  • Db2 LUW
  • Amazon Redshift
  • Google CloudSQL
Cloud and data lakesDSM
  • AWS S3
  • Azure Data Lake
  • Snowflake
  • Hadoop
ApplicationsDSM
  • Salesforce
  • Dynamics CRM
Microsoft 365PEM
  • OneDrive
  • SharePoint
  • Exchange Online
  • Microsoft Purview
Mainframe dataz/OS
  • VSAM
  • Sequential
  • PDS
  • PDSE
  • DA
  • Db2 for z/OS

See all integrations

Straight answers

Data discovery and protection, answered.

A data security platform from PKWARE that finds sensitive data and protects it in the same operation, across endpoints, Microsoft 365, databases, cloud storage, and z/OS.

On endpoints and in Microsoft 365, that happens within seconds of a file being written.

On endpoints and in Microsoft 365, remediation runs within seconds of a file being written. Across databases, cloud storage, and the mainframe, discovery runs on your schedule and remediation runs in the same operation.

AI agents index continuously, so a file that sits unprotected is available to answer questions the whole time it sits there. On endpoints and in Microsoft 365, PK Protect closes that window to seconds.

For data stores, the window is whatever scan interval you set, and the remediation still happens automatically when the scan finds something.

Encrypt it, mask it, redact it, apply a classification label, quarantine it, move it, or delete it. Encryption attaches to the data itself, so it survives being emailed, copied, or uploaded.

Masking keeps the data usable downstream. You set the rule once, centrally, and it runs everywhere without the user’s involvement.

DLP watches the exits. It monitors network traffic, blocks devices, and enforces perimeter controls to stop data from leaving.

PK Protect secures the data itself, wherever it sits or travels, so a file that does get out is unreadable rather than merely unauthorized. The two work together rather than competing for the same job.

No. They do different jobs and work better together. DLP enforces controls at the boundary.

PK Protect secures the data itself, so protection holds after the file leaves. And because PK Protect encrypts under a company-held policy key, your DLP can inspect files employees encrypted instead of routing them for manual review.

Posture management finds sensitive data, classifies it, and scores the risk. PK Protect does that and then remediates, encrypting, masking, redacting, or quarantining what it finds under the same policy.

A finding becomes a protected file instead of a line on a list. If your posture reports never close out, remediation is the missing piece.

Purview classifies and labels inside the Microsoft ecosystem. PK Protect extends that to the rest of the organization and to file types Microsoft labeling doesn’t support, including CSVs and legacy Office formats. It integrates with Purview to apply sensitivity labels centrally, based on what’s in the file, instead of relying on a user to pick one.

On endpoints and in Microsoft 365, remediation runs within seconds of a file being written, so the protected version is what gets indexed. For training sets and RAG indexes, masking removes the sensitive values and keeps the data usable.

PK Protect supports compliance with PCI DSS, GLBA, SOX, HIPAA, GDPR, CCPA, and FISMA. It provides automated policy enforcement, audit-ready reporting, and pre-built sensitive data types you can customize to match how your organization defines sensitive information, so the evidence an auditor asks for already exists when they ask.

Endpoints, servers, file shares, OneDrive, and SharePoint. Oracle, SQL Server, Postgres, Db2 LUW, Amazon Redshift, and Google CloudSQL. Hadoop, AWS S3, Google Cloud Storage, and Azure.

Salesforce and Dynamics. And IBM z/OS datasets and Db2 for z/OS, under the same policy.

They’re two products on one protection engine. PK Protect leads with discovery and classification across endpoints, cloud, Microsoft 365, and the mainframe. PK Encrypt leads with protection inside z/OS and IBM i batch jobs.

If you don’t know where your sensitive data is, start with PK Protect. If you do, start with PK Encrypt.

Start here

Know what you have. Protect it when it lands. Prove it when someone asks.

Most programs are stuck at the first step. Point PK Protect at one environment and find out what’s already out there.