Data encryption
At rest and in transit, with keys managed apart from the content. Stolen media yields no documents, only bytes.
Constellio protects your documents in layers: encrypted at rest and in transit, scanned on every deposit, logged on every action, and restorable to a precise moment. One layer falling does not open the next.
Content on the media
8f2a 41d7 0c93 be55 7a1e d0f4 22b8 9ce6 5310 aa7fReadable only after authorization
Copies kept off site
















HOW IT WORKS
Protection that rests on a single mechanism is protection with a single point of failure. These are independent: each one holds even if the one before it has been crossed.
Content on the media
8f2a 41d7 0c93 be55 7a1e d0f4 22b8 9ce6 5310 aa7fReadable only after authorization
Documents are encrypted on the media and on the wire. Outside Constellio and its permissions, a file is a block of bytes, including for anyone who reaches the disk.
Every deposit is scanned before it reaches the repository. Anything suspicious goes to quarantine instead of being filed, and whoever uploaded it finds out immediately.
Copies kept off site
Regular backups, off-site copies and restore points: content deleted, overwritten or encrypted by ransomware is brought back to the state it was in before.
What is encrypted stays unreadable even if somebody gets hold of the media: the next layer doesn’t have to be perfect.
FOUR LAYERS, ONE DOCUMENT
Follow one site quote while people try to reach it. Each step adds a defence to the record and a line to the security log, and the second one shows what happens when something bad knocks at the door.
The content is encrypted at rest and in transit. Anyone getting a copy of the media would not get the document: they would be missing the key, managed separately and rotated regularly.
Every upload is scanned before filing. The infected file goes to quarantine, never appears in the repository, and the incident is reported to the uploader and the administrator alike.
Opens, edits, shares, refused attempts: all recorded with who, when and from where. This log is the evidence when a regulation requires you to show who saw what.
Backups are kept off site and can be replayed to a precise moment. An accidental deletion, an overwrite or ransomware leaves no permanent hole in the repository.
Protections in place
Content on the media
8f2a 41d7 0c93 be55 7a1e d0f4 22b8 9ce6 5310 aa7f 6b21 ef08 94cd 1a63 7f42 b0d9 c7e5 3846 12fa 9d70 68b3 25ce af14 5209 Key · managed separately · rotated 1 March
Quarantine
invoice_scan.exe
Malware found on upload: the file never reached the repository
See the scan reportAudit log
Restore points
Off-site copies · recovery tested quarterly
REAL-WORLD USE CASES
Two situations where security stops being a paragraph in a contract: working with outsiders without opening the repository, and going back in time after an incident.

For work with outsiders
Documents are shared with partners without a copy emailed out and without an account created in your directory. The link is encrypted, dated, revocable, and every open leaves a line in the log.
See access management
For sensitive data
Health records, employee files, court exhibits: the content whose loss costs the most and whose leak costs more. Encryption, logging and off-site backups answer all three of an auditor’s questions.
See compliance managementWhat the platform applies to security
Six mechanisms, four layers
IN DEPTH, NOT IN WIDTH
The other diagrams on this site follow content that moves. This one doesn’t move at all: your documents sit in the middle, and everything coming from outside has to cross layers that don’t depend on each other. Most attempts stop well before the centre.
At rest and in transit, with keys managed apart from the content. Stolen media yields no documents, only bytes.
Every deposit is scanned before filing. Anything suspicious goes to quarantine and never reaches the repository or the people who read from it.
Every action and every refusal leaves a dated, attributed line: what an auditor asks for, and what a regulation like the GDPR requires.
See access management ↗OUR KEY FIGURES
Most incidents don’t come from a sophisticated attack but from a file in the wrong place. One repository, encrypted and logged, removes half the opportunities.
Figures published by Constellio ↗−0%
Reduction in search time
Incidents
−0%
Reduction in search costs
Incidents
−0%
Reduction in security incidents
Incidents
Why choose Constellio
A high level of protection on your sensitive data, with the confidentiality of your information held up by several independent mechanisms.
Audit and traceability features answer data protection regulations, the GDPR included.
Share and work on documents with colleagues and partners without leaving the perimeter.
Access to information stays fast: security applies without adding a step for the people entitled to read.
Organizations running on Constellio
















YOUR PERIMETER
Book a demo and walk the four layers with your security team: encryption, scanning, access control and recovery, on your own content.
Or write to contact@constellio.com. Open source at its core, hosted the way you want it.
