--- title: File Leak Prevention Solution description: Explain Babel Enterprise Drive controls for content risk detection, permissions, classification, sharing, download, data ferry, watermark tracing, network and device admission, endpoint encryption and audit. slug: file-leak-prevention lang: en category: Permissions And Security category_order: 4 order: 4 keywords: - File Leak Prevention - DLP - External Sharing Control - Classification - Dynamic Watermark - MAC Binding - Transparent Encryption - Data Ferry - Sensitive Content Recognition - Download Control - Encrypted Folder --- # File Leak Prevention Solution Babel Enterprise Drive file leak prevention is designed for the full file lifecycle: upload, preview, editing, sharing, download, sync, cross-network transfer, external delivery and audit. The goal is to reduce accidental sharing, unauthorized access, screenshot leakage, offline copying, unauthorized cross-zone movement and unauthorized local opening without blocking normal collaboration. The solution combines content risk detection, Babel's built-in permissions and classification, sharing and download approval, data ferry, network and device admission, dynamic watermark and audit, plus optional client-side closed-loop encryption or third-party transparent encryption integration. Enterprises can combine these controls by file type, user, department, network zone and security level. ## Control Matrix | Control Area | Option | Rule Description | | --- | --- | --- | | Content risk detection | Sensitive content recognition | Identify and mark risky files according to enterprise keyword policies, then restrict viewing, restrict sharing or send the file for manual review. | | Upload entry security | Online antivirus, upload allow/deny lists and file type restrictions | Private deployments can optionally scan uploads with ClamAV and block infected files. This protects the upload entry and complements DLP rather than replacing it. | | Sharing and external delivery | Disable sharing with users outside the enterprise | Enterprise users cannot share files with external accounts, and link-based external file delivery can be blocked at the system level. | | Sharing and external delivery | Disable anonymous sharing | Link sharing requires the recipient to log in before viewing files. | | Download and sync control | Preview only, download permissions, download approval and watermarked PDF | Online editing, preview and download can be separated. Sensitive files can block original-file downloads and local synchronization. | | Cross-network exchange | Data ferry (Transfer Files) | Transfer files between secure and non-secure zones or multiple Babel deployments through dedicated ports, token authentication, SSL, approval and audit logs. | | Classified access control | File security level | Files can be classified as confidential, restricted or internal, with different visibility, sharing, download, move, copy, rename, version and approval rules. | | Secondary folder protection | Encrypted folder | Add a folder password on top of normal permissions to reduce accidental access and sharing in shared workspaces. | | Traceability | Dynamic watermark and audit trail | Previewed, shared and exported files can include user name, employee ID, time and other watermark information, combined with audit logs for source tracing. | | Identity governance | SSO and organization synchronization | Integrate AD, WeCom, DingTalk, Feishu, Seeyon OA or OAuth 2.0/OIDC systems to maintain identities and organization data and reduce stale accounts or incorrect authorization. | | Network admission | IP policy | Login, upload and download can be allowed or denied by IP range, such as office network, VPN, branch network or external network. | | Device admission | MAC address binding | A user account can be bound to authorized client devices. Whether web access is included can be configured by enterprise policy. | | Network isolation | Intranet-only access and VPN | Private deployments can expose Babel only to the intranet; external users access through enterprise VPN or a secure access gateway. | | Advanced encryption | Babel client closed-loop encryption | With customization, downloaded files can remain encrypted locally and can only be opened on authorized devices through the Babel client. | | Advanced encryption | Third-party transparent encryption integration | Babel can integrate with existing transparent encryption systems such as iPG to align cloud collaboration with endpoint encryption. | | Audit and accountability | File, sharing, access and administration logs | Record access, preview, download, sharing, permission changes, approvals and cross-network transfers for review and incident response. | ## Content Detection And Upload Entry Protection Leak prevention should first answer two questions: whether a file entering the drive contains sensitive information, and whether the file itself is safe. Babel can apply sensitive content recognition, file type restrictions, upload allow/deny lists and online antivirus at the point where files enter the system. ### Sensitive Content Recognition Administrators can maintain enterprise keywords and recognition policies. Files matching a policy are marked and can be restricted from viewing, restricted from sharing or sent for manual review. This is suitable for personal information, customer lists, quotations, finance, HR, contracts, R&D documents, source code and regulated data. Security or business owners should still review false positives and approved exceptions. ![Sensitive content recognition settings](../../assets/images/sensitive-content-recognition-settings.jpg) *Sensitive content recognition identifies files that may contain sensitive information before they are shared or downloaded.* ### Online Antivirus And Upload Policies Private deployments can optionally use ClamAV for online antivirus scanning. Files are scanned during upload and infected files are blocked. Fully isolated environments can update the virus database through offline packages or an internal mirror. Upload allow/deny lists and file type restrictions can further reduce unnecessary or high-risk formats entering the enterprise repository. Online antivirus addresses malicious code propagation; it does not determine whether business information is being leaked. It should be combined with sensitive content recognition, permissions, download controls and audit. ## Sharing And External Delivery Control External leakage often comes from link sharing, anonymous access, overly broad download permissions and secondary file distribution. Babel can restrict external sharing at the enterprise level and combine sharing with login verification, access password, expiration, preview/download permissions and audit logs. ![Share invitation](../../assets/images/share-invite.jpg) *Invitation-based sharing is suitable for controlled access by partners, suppliers and customers. Administrators can restrict anonymous access and external sharing according to enterprise policy.* Recommended policies: 1. Disable external sharing for high-security departments. 2. Use invitation-based sharing for external collaboration instead of anonymous links. 3. Set expiration and access passwords for quotes, contracts, drawings, R&D documents and other sensitive files. 4. Allow preview by default and open download only when needed; high-risk files should use watermarked PDF output first. 5. Keep audit records for sharing, access, preview, download and permission changes. ### Approval, Expiration And Direct Download Links High-risk departments or files can place sharing and download behind approval by a manager, security officer or assigned approver. Invitation sharing, link sharing and generated download links should be governed separately: - Invitation sharing is suitable when recipients are known and need individual permissions and expiration dates. - Standard link sharing should use a password, expiration, login verification and download restrictions. - A generated download link can be read without login and is suitable for public files, AI access, Markdown images and image hosting. It should not be the default for sensitive files and should use a short expiration and maximum download count. - For long-running external collaboration, use project membership and file access control instead of replacing permissions with a permanent public link. ## Download, Sync And Local Storage Control Access through a web interface does not mean users must receive the original file locally. Babel can configure preview, online editing, download, client download, client editing and new-version upload as separate permissions, allowing collaboration in a controlled interface without distributing source-file copies. Recommended controls by risk: | File Type | Recommended Control | | --- | --- | | General internal files | Allow download and sync by role, while retaining access and download logs | | Contract, finance and HR files | Preview only by default, approve downloads when needed and watermark exported files | | Drawings, quotations and R&D files | Block original-file download for ordinary members; allow online preview or watermarked PDF output | | Confidential files | Disable sync and bulk download; allow access only from authorized networks and devices after approval | Synchronization creates offline copies on endpoints, so confidential directories should not rely on a sync file-type deny list alone. First determine who may obtain a file through role permissions, file access control, classification and download permissions, then decide whether those directories may be added to sync tasks. When an employee leaves, changes role or exits a project, promptly revoke account and project permissions, then inspect, transfer or remove local working files according to the enterprise endpoint policy. ## Data Ferry: Controlled Exchange Between Network Zones When secure, R&D, production and office zones are network-isolated, ordinary sharing, email, instant messaging or removable storage can bypass enterprise approval and audit. The Babel data ferry module appears as “Transfer Files” in the product and creates a controlled exchange channel between multiple Babel deployments or a designated transfer service. | Stage | Leak Prevention Control | | --- | --- | | Network boundary | Secure and non-secure zones can run separate Babel deployments and exchange through specified ports without exposing their file areas to each other | | Transfer authentication | The receiving endpoint generates a token used by the sending endpoint to establish a controlled connection | | Transport security | Files travel through an SSL-encrypted channel | | Recipient scope | A super administrator configures sending and receiving endpoints, designated recipients and reviewers | | Direction control | Deployments can support two-way transfer or a receive-only one-way path; the simplified model allows only non-secure-to-secure transfer | | Approval control | Approval can be required by direction and scenario; approved files then appear in the recipient's Transfer Files area | | Transfer granularity | Transfer works at file level and supports selecting multiple files, but not folders, reducing the risk of hiding unreviewed files in nested directories | | Audit trail | Sending, receiving, approval and transfer results are recorded in logs | A typical controlled flow is: `Sender selects files → selects receiving endpoint → reviewer approves → SSL transfer → designated recipient receives files → logs are retained`. For organizations that only need to import office-zone files into a secure zone, a one-way path prevents files from flowing back out of the secure zone. Data ferry governs the route used to cross network zones; it does not replace file classification, content detection or recipient-side permissions. After a file enters the destination zone, it remains subject to the destination Babel deployment's roles, file access control, watermark, download and audit policies. See [Data Ferry Deployment](deployment-data-ferry.md) for ports, tokens, direction and approval configuration. ## Classification And Least Privilege Babel can apply security classification during daily file circulation. Enterprises may define files as confidential, restricted or internal, then apply different default permissions, approval rules and operation limits by level. ![File access control](../../assets/images/file-access-control.jpg) *File access control adds fine-grained rules to specific files or folders beyond department roles and project permissions.* Typical rules: | Level | Default Access | Sharing Rule | Operation Limits | | --- | --- | --- | --- | | Confidential | Visible only to creator, project owner, file owner, department manager or other authorized roles by default | Sharing requires approval from a security officer or assigned approver | Ordinary users cannot move, copy, upload new versions, download, rename or view versions | | Restricted | Ordinary members usually have read-only access | Sharing requires supervisor or assigned approver approval | Download, copy, move, version viewing and external delivery can be restricted | | Internal | Circulates inside the department or enterprise | Sharing outside the department may require supervisor approval | External sharing and anonymous access can be restricted by department policy | Classification should be designed together with organization structure, department roles, project permissions, file access control and approval workflows. For documents that require long-term protection, the classification policy should become part of the enterprise security process instead of relying on ad-hoc user judgment. ## Watermark And Traceability Dynamic watermarking keeps traceability when access is allowed. Babel can add user name, employee ID, account, timestamp, enterprise name or classification level to previews, shared files and exported outputs. Even if a file is screenshotted, photographed or redistributed, watermark information and audit logs can identify the visitor and time. ![Watermark settings](../../assets/images/watermark-settings.jpg) *Administrators can configure watermark text, position, opacity, density, color and effective scope, and combine watermarking with sharing, download and classification policies.* Recommended combinations: - General internal documents: enterprise or department watermark. - Contract, finance and HR documents: account watermark, download audit and external delivery restriction. - Drawings, quotes, proposals and R&D files: account watermark, original-file download restriction and watermarked PDF download. - Highly confidential files: dynamic watermark, classification, approval and access log review. ## Network And Device Admission Leak prevention depends not only on file permissions, but also on whether the identity, access entry point and endpoint are trusted. Babel can tighten login and file operation boundaries through unified identity and organization synchronization, IP policies, MAC binding, intranet-only access and VPN access. ![Secure transmission chain](../../assets/images/security-transmission-chain.jpg) *Private deployments can place Babel behind the enterprise network boundary and build a trusted access chain through HTTPS, reverse proxy, VPN, IP policies and audit logs.* ### Unified Identity And Organization Synchronization Private deployments can integrate AD, WeCom, DingTalk, Feishu, Seeyon OA and SSO systems supporting OAuth 2.0/OIDC. A unified account and organization source helps apply permissions by department, role and employment status, reducing duplicate accounts, stale accounts after departure and authorization that remains after organization changes. ### IP Policy IP policy can restrict login, upload, download or access to specific resources by IP range. For example, only office network and VPN addresses may download files, while external networks only allow preview. Core departments can use stricter download ranges. ### MAC Address Binding MAC binding is suitable for PC client device control. After binding, unauthorized devices cannot log in to the client with that account, reducing account sharing, personal-device login and residual access risk after employee turnover. Whether the web portal is included can be configured according to the enterprise's work model. ### Intranet Isolation High-security private deployments can avoid exposing public ports. Remote employees, branches or traveling users access Babel through enterprise VPN, zero-trust gateway or a unified secure access platform. This is suitable for R&D, design, finance, archive and confidential project scenarios. ## Encrypted Folders And Secondary Directory Protection An encrypted folder adds a password check on top of department, project and file access control. Even a user who can see the folder entry must enter the correct password before opening it. This is suitable for temporary sealing, unreleased documents, contracts, HR, finance or files shared among a small group of authorized people. ![Encrypted folder access](../../assets/images/encrypted-folder-locked.png) *An encrypted folder displays a lock and requires the folder password before entry; normal file permissions still apply inside the folder.* Encrypted folders reduce accidental access, accidental sharing and ordinary permission configuration mistakes. Passwords do not replace organization permissions, classification or audit, and should not be distributed through public chat groups or uncontrolled documents. Long-term confidential files should also use file access control, watermark, download restrictions and audit logs. ## Advanced Encryption Options When permission, watermark and network admission controls are not enough, file encryption can be introduced. Encryption options should be assessed together with endpoint environment, existing DLP architecture, file formats, online preview, client editing and operational cost. ### Babel Client Closed-Loop Encryption With customization, Babel can keep downloaded files encrypted on local storage. The file can only be opened on an authorized device after the user signs in with an authorized account through the Babel client. Applicable scenarios: - Prevent downloaded files from being copied to unauthorized people. - Prevent users from taking files outside the controlled endpoint environment. - Protect R&D materials, design drawings, contract drafts and core proposals offline. - Use the Babel client as the local file opening and authorization checkpoint. This option usually involves client capability, file format support, authorization policy and project customization. Cost and implementation scope should be evaluated per project. ### Third-Party Transparent Encryption Integration If the enterprise already uses a transparent encryption system such as iPG, Babel can integrate with the existing endpoint encryption environment. A typical workflow is: files entering Babel remain suitable for online preview and collaboration; when files are downloaded to endpoints, the enterprise encryption engine re-encrypts them for local storage and continued endpoint protection. Applicable scenarios: - The enterprise already has a mature DLP or transparent encryption system. - Local editing, copying, external delivery and printing are already controlled by a third-party endpoint system. - Cloud drive collaboration and endpoint security need to work together instead of being managed separately. - Medium and large enterprises want to preserve existing security investment and reduce user workflow fragmentation. ## Audit, Review And Incident Response Audit closes the leak prevention loop. Babel can record file access, preview, upload, download, sharing, permission changes, approval, deletion, administration actions and data-ferry transfers. File logs, sharing access logs and enterprise access logs should use a retention period defined by enterprise policy and be reviewed regularly by security auditors or authorized administrators. Priority review areas include: - Downloads, bulk operations and external sharing of classified files. - Anonymous access, generated download links, unusual IP addresses, off-hours use and high-frequency access. - Permission expansion, approval bypass, project membership changes and activity from departed-user accounts. - Viewing, sharing and disposition of files matched by sensitive content policies. - Transfer direction, reviewer, recipient and result for exchanges between secure and non-secure zones. When suspicious activity is found, expire the share or download link, revoke account or project permissions, suspend the affected endpoint, preserve log evidence and review local copies and downstream distribution according to the enterprise incident response process. ## Recommended Policy Combinations | Scenario | Recommended Combination | | --- | --- | | General department documents | Department role permissions + file access control + sharing expiration | | External project collaboration | Invitation sharing + logged-in access + expiration + operation audit | | Contract, finance and HR documents | Sensitive content recognition + classification + dynamic watermark + download approval + download audit | | Drawings, proposals and R&D files | File access control + original-file download restriction + watermarked PDF + IP policy | | Exchange between secure and non-secure zones | Data ferry + defined direction + approval + designated recipient + transfer logs | | Highly confidential documents | Intranet or VPN access + MAC binding + classification approval + sync disabled + client closed-loop encryption | | Enterprises with existing DLP | Babel permissions + third-party transparent encryption integration + unified audit | ## Implementation Recommendations 1. Map files and network zones: classify files as general, internal, restricted or confidential, and define allowed data directions between office, production, R&D and secure zones. 2. Unify identity and least privilege: define who can view, edit online, download, sync, share, approve and audit, with access revocation for onboarding, role changes and departures. 3. Move risk detection earlier: enable sensitive content recognition, file type restrictions and online antivirus for external uploads, high-value repositories and confidential directories. 4. Tighten external delivery and local storage: restrict or approve external sharing, anonymous access, original-file download, sync, bulk download and direct download links by classification. 5. Use data ferry for cross-network exchange: fix the sending endpoint, receiving endpoint, direction, reviewer and recipient instead of bypassing logs with temporary tools. 6. Enable watermark and audit for important files: make external delivery, preview, download, permission changes and cross-network transfers traceable. 7. Add network, device and endpoint protection for confidential departments: use IP policy, VPN, MAC binding, client closed-loop encryption or third-party transparent encryption to reduce offline leakage. ## Capability Boundaries No single technology can eliminate file leakage. Permissions and approval reduce unauthorized actions, watermark and logs improve traceability, encryption reduces the usefulness of files outside a controlled environment, and data ferry constrains cross-network routes. However, an authorized viewer may still photograph, manually transcribe or otherwise remove information. Enterprises still need role policies, confidentiality training, endpoint security, log review and incident response. Online antivirus, backup, file versioning and high availability are also important but serve different purposes. Antivirus primarily blocks malicious code, while backup and versioning protect availability and integrity. They do not replace DLP controls for content, permissions, external delivery, endpoints and audit. ## Related Sections - [Permission System](permissions.md) - [Security and Audit](security.md) - [Watermark](watermark-security.md) - [Sensitive Content Recognition](sensitive-content-recognition.md) - [Encrypted Folder](encrypted-folder.md) - [Online Antivirus](online-antivirus.md) - [Data Ferry Deployment](deployment-data-ferry.md) - [Sharing and External Delivery](file-sharing.md) - [File Synchronization](sync-client.md) - [Third-Party SSO Login](third-party-sso.md)