FILE TRANSFER / PASSPORT

Send Files You Can Still Control After They Land

Email, SFTP, and legacy managed file transfer hand off a copy and lose control the instant it's delivered. Lattix Passport wraps each file in policy that's enforced on every open — and revocable any time, anywhere it travels.

/01The Challenge

Most file transfer secures the pipe, not the file. SFTP, secure email, and managed file transfer protect data in transit, then deliver a plaintext copy the recipient can store, forward, and keep forever. Once the file lands, the sender has no visibility and no control — they cannot revoke it, cannot see who opened it, and cannot stop it from being forwarded to someone who was never authorized. For regulated and high-stakes transfers, that loss of control is the whole problem.

  • Transfer tools protect the channel but deliver an uncontrolled plaintext copy.
  • Once a file is delivered, it can't be revoked, expired, or clawed back.
  • Senders have no record of who actually opened or forwarded a file.
  • Recipients re-share files with parties the sender never authorized.
  • Legacy MFT is heavy to operate and still leaves data ungoverned at rest.
/02How Lattix Solves It
01

Wrap Files in Travelling Policy

Passport wraps each file in Zero Trust Data Format — a self-protecting envelope carrying its own access policy and keys. The file stays bound to that policy wherever it goes: in the recipient's inbox, on their disk, in their cloud, or forwarded onward.

02

Enforce Access on Every Open

Recipients — inside or outside your organization — unwrap the file only under fresh policy evaluation on every access. Attribute-based controls consider identity, organization, device, and context, so the right people get in and everyone else is denied, automatically and continuously.

03

Revoke and Expire After Sending

Because policy and keys travel with the file, you can revoke or expire access at any time — even after delivery and even on forwarded copies. A mis-sent file or an ended relationship is a click, not a crisis.

04

Audit Every Access With Proof

Every open and policy decision is recorded to a tamper-evident ledger, giving you a verifiable record of who accessed each file, when, and under what policy — full chain-of-custody for sensitive transfers.

/03What You Get

Control After Delivery

Revoke, expire, and re-scope files even after they've been sent and forwarded.

Enforced Recipients

Only authorized identities can open a file — re-sharing doesn't grant access.

Chain-of-Custody

A tamper-evident ledger records every open for verifiable proof of handling.

Works Inside and Outside

Share with partners and external parties without standing accounts or shared infrastructure.

Lighter Than Legacy MFT

Policy-bound transfer without the operational weight of traditional managed file transfer.

Protected at Rest

Files stay wrapped and governed wherever they're stored, not just in transit.

/04Aligned & Connected

Helps You Align With

Lattix provides the technical controls and audit capabilities to help your organization meet the requirements of these frameworks.

NIST 800-207HIPAAGDPRISO/IEC 27001SOC 2

Explore Further

/05Frequently Asked

How is Lattix Passport different from SFTP or managed file transfer?

SFTP and MFT secure the transfer channel but deliver an uncontrolled copy. Passport wraps each file in Zero Trust Data Format so access is enforced on every open, control persists after delivery, the file can be revoked or expired at any time, and every access is recorded to a tamper-evident ledger.

Can I revoke a file after I've already sent it?

Yes. Because the access policy and keys travel with the file, you can revoke or expire access at any time — including after delivery and on forwarded copies — and the file becomes inaccessible.

Do recipients need a Lattix account?

Passport supports sharing with external parties without standing accounts or shared infrastructure; recipients unwrap files under fresh policy evaluation based on their identity and context.

Does forwarding a file grant the new recipient access?

No. Access is enforced per identity on every open, so forwarding a wrapped file does not grant access to anyone the policy doesn't authorize.

Upgrade How You Move Sensitive Files

Tell us about your file-transfer workflows, and we'll show you how Passport keeps every file policy-bound, revocable, and auditable after it's sent.

Trouble with the form? info@lattix.io · Book a call