Data Classification

Any label, every policy. FileOrbis enforces access, encryption, approval, and lifecycle policies using Microsoft Purview and Fortra sensitivity labels, while regex and AI automatically classify unlabeled files.


Label Integration

Read existing metadata.


Regex Auto-Tagging

Classify pattern matches.


AI Classification

Analyze unstructured content.


Policy Enforcement

Control data use.

A label is only as good as the policy behind it

Trusted by Content-Critical Businesses Worldwide

Key Benefits

Label integrations

The classification tools you already run are understood natively
Spotlight · Microsoft Purview

What a Purview label does once FileOrbis reads it

Purview tells you what a file is. FileOrbis decides what happens to it, turning the label into enforced behavior across file servers, NAS, cloud repositories, and Microsoft 365. The result is data loss prevention driven by classification: confidential content cannot be over-shared, downloaded, or exfiltrated, because the label itself carries the policy with it.

Core Capabilities


Access Policy

Who can use the file
Control who can open, share,
download, or copy files,
internally and externally,
based on the file’s sensitivity.


Encryption Policy
Protection in place
Enforce encryption at rest
and in transit for sensitive
classifications, with rights that
travel with the file.


Approval Policy
Sign-off when it counts
Route sensitive actions, including external sharing and bulk downloads, through an approval workflow before they complete.


Lifecycle Policy
From creation to disposal
Apply retention, archival, and
disposition automatically, so
each classification follows its
own lifecycle.

Classification & Policy Matrix

LevelAccess & Sharing RulesEncryption & Lifecycle Controls
PUBLICOpen to internal users; external sharing
permitted with tracking.
No encryption required and standard retention applies.
INTERNALRestricted to employees and named groups; external sharing blocked by default and routed for owner approval.Encrypted at rest.
CONFIDENTIALLeast-privilege access. External sharing and bulk download require approval.Enforced encryption. A fixed retention clock and controlled disposition apply.
RESTRICTEDExplicit allow-list only, no external sharing, multi-step approval.Mandatory encryption with revocation, strict retention and secure disposal, audited on every action.
FileOrbis Native Classification Engines

No label yet? FileOrbis makes one.

Integration is only half the story. FileOrbis classifies content on its own, so unlabeled legacy shares, NAS volumes, and cloud repositories
are governed from day one, making classification-based data management reach its highest level.

Hear From Our Customers

“FileOrbis gave us a single pane of glass across on-prem and cloud content. We reduced over-permissioned access fast and finally had audit-ready visibility.”

Security & Risk Lead, Enterprise Organization

“External sharing used to be our biggest leak point. With content-aware policies and full traceability, we enabled collaboration without losing control.”

IT Manager, Regulated Industry

“We consolidated multiple tools into one governed platform. Users got faster access, and our compliance reporting became dramatically simpler.”

Head of Infrastructure, Global Company

Turn Every Label into Governance

See how FileOrbis reads your Purview and Fortra classifications, adds regex auto-tagging and AI classification, and enforces access, encryption, approval, and lifecycle policies across your entire data estate.

Frequently Asked Questions

How can we help you?

FileOrbis works two ways at once. It reads existing sensitivity labels applied by Microsoft Purview or Fortra Data Classification Suite and treats them as an authoritative source of truth, and it generates classification on its own using regex-based auto-tagging that recognizes content patterns such as national IDs, IBANs, and card numbers, and AI classification that understands document context. Every label, inherited or generated, becomes a governance trigger.

FileOrbis integrates with Microsoft Purview Information Protection (formerly Azure Information Protection, AIP, and Microsoft Information Protection, MIP) and with Fortra Data Classification Suite, including the classification schemes formerly delivered by Titus and Boldon James. It reads the labels these tools embed in file metadata and document properties and maps them to policy inside FileOrbis.

Yes. Files without an existing label are covered by two native engines. Regex-based auto-tagging applies classification the moment content matches a defined pattern, and AI classification reads unstructured content to assign a sensitivity level where no rule exists. Legacy file servers, NAS shares, and cloud repositories become classified without any manual tagging.

A single label can drive access policy (who can open, share, or download), encryption policy, approval workflows for sensitive actions, and lifecycle policy such as retention, archival, and disposition. One label can trigger many policies simultaneously, so classification becomes the control plane for the whole data estate.

Yes. Because FileOrbis enforces access, sharing, encryption, and approval based on classification, sensitive files are governed at the point of use across file servers, NAS, cloud repositories, and Microsoft 365. Classification-driven controls stop confidential content from being over-shared or exfiltrated, giving unified visibility and risk remediation for unstructured data.

Request FileOrbis Demo Today

Do you want to contact one of our representatives to get information or see FileOrbis in action? Schedule a custom live demo of Fileorbis made just for you.