For your organisation's devices

FILOTRON for Enterprise

your fleet, your keys, your jurisdiction

Your files move between your devices. No one in between can read them. FILOTRON for Enterprise adds user authentication with your identity provider, plus access control and auditing, once devices have authenticated.

macOSWindowsLinuxiOSAndroid
Every breach you've read about this year came through one of two doors. A credential someone typed, or a file store someone else ran. FILOTRON removes both doors. What doesn't exist can't be broken into.

How it works


FILOTRON moves files straight from one of your devices to another. They are locked the whole way, from the moment they leave to the moment they arrive. And there is no central store of your files anywhere. What doesn't exist can't be broken into.

01

Your fleet, your jurisdiction

Everything runs on your own equipment: the access service, the switchboard, the relay and your SIEM. Nothing of ours in the building. Sovereignty is a structure, not a promise.

It all runs on your own equipment: the computers, tablets and phones you already own, and a few supporting services on your own servers, under your control. We never see your files and the software tells us nothing. Licensing works the way the product does: on your infrastructure, with no phone-home.

02

A stolen password has nowhere to be typed

Only your organisation's registered devices can connect, hardware first. A criminal who steals a password gets nothing, because signing in works only on those devices.

A password is no longer a perimeter. Devices mutually authenticate with hardware-bound keys before anyone can sign in at all, so a phished credential reaches nothing on its own. Whole attack classes (phishing, credential stuffing, MFA fatigue, credential-database theft) have nothing to act on.

03

Keys born in hardware: nothing extra to buy

Keys are born in the security chip already in every device and every server. Nothing exportable, with the singular exception of the offline Root CA, kept under ceremony custody.

It runs on the devices you already own and uses the security chip already built into them: Secure Enclave, TPM 2.0, Android StrongBox or TEE. Server keys live in your servers' TPMs. Private keys are never in process memory and never on disk.

04

Dual-control enrolment

A device joins only after two approvals… …from two different people: the discipline banks already use, enforced. Then, and only then, it is inside the fleet.

No device enters the fleet on one person's say-so. Enrolment needs a sponsor and an administrator (two people, two approvals), the same separation of duties banks apply to payments, applied to your fleet's membership.

The fabric underneath


Both editions run on FILOTRON Fleet Fabric. Eighty-five seconds, five chapters: keys born in hardware, mutual TLS with proof of possession against your organisation's pinned root, post-quantum key exchange, and five platforms that all reach each other. Use the chapter buttons to jump.

FILOTRON moves files between your devices with no username, no password, no passcode, and no cloud store. Here is why that is safe. Each device generates its own key pair inside its Hardware Security Module: Secure Enclave, TPM 2.0, StrongBox. Only the public key leaves, to be signed by the fleet's Certificate Authority. The app carries the FILOTRON root certificate, pinned. The app carries your organisation's own root certificate, pinned (Advanced and High-Assurance editions). Enrolment is the one moment an account or an administrator is involved. The private key never leaves the hardware. Both devices present certificates. Each checks the other's chain up to the pinned root, and the four FILOTRON certificate extensions. Then each proves it holds the private key by signing the handshake inside its hardware. A copied certificate cannot do that. Only after both proofs does a connection exist. No password was typed. There is none to type. A device outside the fleet is refused before a byte moves. The session key comes from a post-quantum key exchange: X25519 with ML-KEM-768, over QUIC. Files move directly, device to device, encrypted end to end. Traffic recorded today cannot be decrypted by a future quantum computer. If the route needs a relay, it forwards sealed blocks and holds no key. One fabric on macOS, Windows, Linux, iOS and Android. On the same network, devices find each other directly. Across the internet, a switchboard passes connection details only; it never sees a file. Any device reaches any other, with the same proofs every time. No login in the fabric. No central store. Keys that never leave the hardware. Hardware governs admission · Identity governs authorisation. You cannot phish a login that does not exist. FILOTRON Fleet Fabric, Patents-pending. FILOTRON for Enterprise adds your identity provider, roles and audit above the fabric. The fabric itself still has no credential to steal.
0:00 / 1:25

People sign in the way they already do


Staff use the same work sign-in they use every day. Microsoft and the other big names are supported, proven with Microsoft Entra ID, Keycloak and Okta, and with the built-in directory; any OpenID Connect provider can be used. No new passwords to remember.

Hardware governs admission · Identity governs authorisation. The devices prove themselves to each other first; the person signs in afterwards, and their roles decide what they may reach.

First, the devices prove themselves to each other: hardware governs admission. Then the person signs in with the identity provider you already use. Their roles decide what they may reach: identity governs authorisation.

You decide who sees what


Give each person or team exactly the folders they need. Access is granted per device, per folder, read-write or read-only, built entirely by ticking, with no paths typed. Change your mind and access is gone in minutes.

From your desk, a lost phone can be eliminated from the system. Sign-in stops immediately; its live session ends within one staple poll (drilled at 120 seconds); and every peer refuses its voucher, which is in any case bounded at 12 hours.

Tick a cell: that team gains that folder on that device. Change your mind and it's gone in minutes. A lost phone, eliminated from your desk: sign-in stops immediately… …its live session ends at the next staple poll, and every peer refuses its voucher.

Your business stays your business


It all runs on your own equipment and every action is recorded in your own records. Every device refusal and every voucher issued lands in your SIEM; administrative actions sit on the access server's own records, which you also own. Every edition retains local forensic logging on every host, so an incident can always be investigated from on-host records.

Nothing in this product asks you to trust us with a log. We never see your files, and the software tells us nothing.

Every device refusal… …and every voucher issued lands in your SIEM. Administrative actions sit on the access server's own records, which you also own.

The product, as it runs


Real screens from the FILOTRON for Enterprise app administering a live test fleet. Nothing is mocked.

The FILOTRON for Enterprise main screen: a Devices panel listing a MacBook Air and a Pixel Fold, both online, and the Administration button in the app bar.
The main screen. The fleet's devices on the left, each online. The Administration button in the app bar exists only for administrators.
Administration, Devices: five enrolled devices listed with platform, role and opaque device id, a filter field and a Refresh list button.
Administration → Devices. Five enrolled devices across four platforms, each holding a non-exportable hardware key and a certificate the fleet's own CA signed. Nothing else can join.
User Accounts with the Add a person dialog: username, optional full name and email, and an initial password entered twice.
User Accounts → Add a person. No email invitation and no self-service sign-up page: nothing an attacker can phish. The administrator hands the initial password over in person, and the directory this writes to is yours.
The New role dialog: member and group chips, the devices the role may reach, a device's bookmarks as chips with read-write or read-only, and role capabilities.
Roles → New role. Built entirely by ticking: members, groups, a device, then that device's own bookmarks as chips, read-write or read-only. No paths typed, ever.

The seven logical layers, from finding a device to moving a file: a three-minute silent explainer. Nothing loads until you press play.

Three editions


The same fabric in every edition. The editions differ in who holds the root of trust and in how far the records travel. Ask us for the rate card.

Standard

For organisations that want the fabric with their existing identity provider or the built-in directory.
  • Trust root: the shared FILOTRON for Enterprise root
  • Identity provider sign-in, roles and dual-control enrolment
  • Local forensic logging on every host

Advanced

For organisations that want their own root of trust and their audit trail in their SIEM.
  • A dedicated Root CA generated for you, and a certificate server of your own
  • Everything in Standard
  • Audit export to your SIEM

High-Assurance

For regulated and government estates at the OFFICIAL / RESTRICTED tier, including isolated networks.
  • Your own Root CA, minted in an air-gapped ceremony you control
  • Everything in Advanced
  • Accreditation support and documentation

Built on trusted standards


X.509 mutual TLSQUICpost-quantum key exchange (X25519 + ML-KEM-768)built on the FIPS 140-validated AWS-LC moduledesigned to align with NIST SP 800-207 tenetsOFFICIAL / RESTRICTED tier, incl. isolated networkspatents-pending, four UK patent applicationsmacOS · Windows · Linux · iOS · Android

Works on Mac, Windows, Linux, iOS and Android. One app, everywhere. On the same network or over the internet.

See it for yourself, on your own devices.

We will happily set up a trial installation in your own office, for your own testing. Your IT team can ask us for the full technical description.

customers@cogentlogic.com   +44 749 6566 041