Platform  /  Tz0 Security

Module · policy enforcement

Tz0 Security

Security policy and DLP on the endpoint

Writing the security standard is the easy part. The real question is another one: how do you guarantee it is being followed on twelve thousand machines, right now, without someone checking them one by one?

Enforces the rule even with the workstation off the network · the evidence stays on your server

A workstation with a blue shield above it and a USB stick isolated on its own pedestal

USB port

The rule travels with the machine.

It makes no difference whether the machine is on the company network, at an employee’s home or on the road: the removable-media policy travels with it. A USB stick that is not on the list will not mount, and the attempt is recorded with machine, user and time.

tz0.suaempresa.local/security/criptografia
Disk encryption compliance in the Tz0 console: 3 volumes of 27, 11.11% against a 95% target, with 13 exposed system volumes and 3 keys with no escrow
Tz0 Security · web console

Console capture from an estate in production. Machine and person identification replaced; figures untouched.

What the module does

Seven fronts of control, a single agent.

Everything below is configured in the console and enforced by the agent on the workstation — with or without a connection to the server at the moment of the attempt.

Blocks and rules

Defines what may run, what may be installed and what may leave the machine — by group, by department or by workstation.

Hardware snapshot

Photographs the machine’s physical configuration and warns when a part is swapped, removed or appears out of nowhere.

Real-time visibility

What is happening on the estate right now — not what happened during last night’s inventory run.

Tracing for lost equipment

A laptop that went missing keeps reporting: where it surfaced, on which network, under which user.

Working-hours control

Sets the window in which each group may operate and records what was attempted outside it.

Application-layer firewall

The rule is not just port and IP: it is which program may talk, to whom and through where.

Integration with Windows policy

Lives alongside the GPO you already have instead of fighting it — and covers what the GPO cannot reach.

DLP support

Stops personal data leaving where it should not and records the attempt — the backbone of a defence in a data-protection audit.

How it works

From the written rule to the stored evidence.

The whole cycle runs inside your network. No step depends on an external service.

01 Define Created in the console, by group or by department. 02 Distribute The agent receives the policy and stores it locally. 03 Enforce The block happens on the workstation, online or not. 04 Record Attempt becomes an event with evidence attached. 05 Respond Alert, report and investigation. Step 03 does not depend on the server: a workstation off the network keeps enforcing the policy and syncs its events when it returns.

Evidence

Blocking is half of it. Proving is the other half.

In an audit, nobody asks whether the policy exists — they ask what happened on the 14th, who tried, what was blocked and where the record is. Every attempt becomes an event stamped with time, machine, user and the content that triggered the rule.

14:02:11Copy to USB stick blockedlegal department workstation · spreadsheet containing personal data
14:02:11Evidence attached to the eventfile hash, destination and policy applied
14:02:12Alert sent to the data protection officerDLP rule · high severity
14:07:40Remote session opened to investigateoperator identified · session recorded
15:20:00Incident report availableexportable for the internal case file

Console

The policy is written and enforced in the browser.

Protection screen in Tz0 Security, with estate-wide antivirus, antispyware and firewall coverage and how much of it is up to date
Is the estate protected? The answer is a number. Antivirus on 68.42% of machines, firewall on 71.05%, antispyware on 2.63% — and beside each one, how much is actually up to date. This is not what the policy says: it is what the agent found.
Per-device protection table in Tz0 Security, with each machine's antivirus, antispyware and firewall and a status of vulnerable, partially protected or protected
And which machine is outside it. Device by device: which antivirus, which version, which firewall, and the verdict in the last column — protected, partially protected or vulnerable. The percentage from the previous screen turns into a task list.
Disk encryption screen in Tz0, with 11.11% compliance against a 95% target and 13 exposed system volumes
Disk encryption, against the target. 3 of 27 volumes encrypted — 11.11% against a 95% target. Thirteen system volumes fully decrypted, three keys with no escrow, twelve machines without TPM 2.0. The panel closes with the sentence that matters: an unencrypted boot disk means theft equals data in the clear.
Volume table in Tz0, with each volume's encryption state, the method used and whether the recovery key is held in escrow
Volume by volume. Every disk with its state, the method (XtsAes128 where it exists), whether the key is in escrow and whether the TPM is ready. The few greens in the middle of the red are the honest picture of nearly every company before its first encryption project.
File sharing screen in Tz0 Security, with a 34.33% risk factor and the most accessed devices, shares and files
The hole nobody remembers opening. Estate risk factor at 34.33%, calculated across 16 devices and 67 shares. Almost every company has folders that have been shared for years — opened for a migration, a backup, an intern — that nobody ever closed.
Share table in Tz0 Security, with each shared folder's path, who can reach it and its risk level
A forgotten share is an open machine. All 67 shares with path, access type and who can reach each one — including those set to Everyone, Full Control, flagged in red. Nobody opened those folders carelessly: they opened them to solve something, and forgot to close them. Tz0 finds them on its own, because the agent is already on the machine.
Policy violations screen in Tz0 Security, with 221 violations in the month, 83 blocked and 134 screen captures
A policy that reacts. 221 violations in the month, 83 blocked, 134 captured — broken down by date, origin, profile and target. A rule nobody enforces is decoration; here it has a counter.
Policy violations table in Tz0 Security, with the action taken on each occurrence: block, e-mail alert or screen recording
A ladder, not a switch. Every violation records what the product did: block, alert by e-mail or record the screen. Recording only kicks in once the rule was broken — it is evidence of the event, not continuous observation.

Screens from a real estate in production, not a demo environment. Folder paths that identified people, the internal domain and one public-sector folder were replaced with generic equivalents before publishing; figures, percentages and the interface itself are untouched.

What changes in practice

Eight things that stop depending on individual discipline.

The written standard becomes verifiable instead of an expectation.
Personal data does not leave by USB stick, e-mail or public cloud without a record.
Unauthorised software stops showing up in next month’s inventory.
A part swapped in a critical machine raises an alert the same day.
Lost equipment keeps reporting from wherever it is.
The audit receives time-stamped evidence, not a statement.
An authorised exception is documented, with an expiry date and an owner.
The policy holds for people outside the corporate network too.

In the customer’s words

The controls that were missing, inside their own environment.

We are very happy with the product, and our experience so far has been adding to the controls and security we were looking for inside our computing environment.

Translated from Portuguese

Gustavo PriuliGustavo PriuliIT Coordination · Unimed Federação Nordeste Paulista

Included with the module

Three tools in the same package.

A new report does not become a project. We do not build bespoke work for a single customer, but we look at every request: when the need serves everyone, the report goes into the product and reaches all customers in the next update.

Tz0 EIS

Report builder

Ships with the package, not sold separately. It is for people who want to build their own reports outside the browser.

Tz0 TNetX

Development platform

Carries agent communication across segmented topologies and lets the product be extended.

Tz0 Dashboard

Operations dashboard

The state of the estate on one screen, with whatever went off-target at the top. More than 600 ready-made reports, covering every module.

Who works this way

A policy built on Tz0.

“We built a security policy entirely on Tz0.”

Translated from Portuguese

Advanta
Corporate security policy

“Tz0 helps us a great deal in audits, which generally have a lot to do with security.”

Translated from Portuguese

Universidade de Caxias do Sul
Academic and administrative estate

Bring us your security standard. We will show you what can actually be enforced.

A 30-minute technical conversation: you describe the environment and the policy you have to meet, we point out what Tz0 Security enforces on its own and what still needs a process.