Tessera

Standards-Compliant Data Security Solutions

Data-centric file protection and controlled cross-domain exchange for classified and sensitive environments — built to ACP-240, STANAG 4774, STANAG 4778, and ADatP-5636.

What We Do

Tessera implements NATO's and CCEB's data-centric security model — where the protection is embedded in the data itself and travels with it regardless of where it goes.

Data-Centric Maturity Level 3

Encryption and ABAC policy are embedded directly in the .ztdf archive. Every decryption request is evaluated in real time by the Key Access Service against the requester's clearance attributes — classification level, categories, and COI membership. No key is released unless every policy condition is satisfied, regardless of where the file is stored or transferred.

Controlled Cross-Domain Exchange

Information crossing between security domains is evaluated against both domain security policies simultaneously. Every flow passes through a Guard — the only permitted path — with fail-closed enforcement and a full audit trail.

NATO and CCEB Standards Compliance

All components are designed against ACP-240, STANAG 4774, STANAG 4778, ADatP-5636, and XMLSPIF. Security labels are digitally signed per ADatP-4778. Interoperability with CWIX is tested using published test vectors.

Our Products

Two complementary solutions addressing different aspects of the classified information lifecycle — protection at rest and controlled exchange in transit.

Tessera for Windows

A standards-compliant Data-Centric Security solution for the Windows desktop. Files can be cryptographically bound with a STANAG 4774 Confidentiality Label and encrypted into .ztdf archives with classification and access policy embedded — enforced at the moment of decryption by a Key Access Service.

  • Microsoft Office add-ins (Word, Excel, PowerPoint, Outlook) and Notepad++
  • Windows Explorer integration — context menu, overlay, classification columns
  • Virtual drives — decrypt on open, re-seal on close, no plaintext copy left behind
  • STANAG 4774 / 4778 / ADatP-5636 label binding with XML-DSIG
  • AES-256-GCM encryption with RSA-OAEP-SHA256 key wrap
  • ABAC policy enforced by Open Policy Agent at the Key Access Service
  • DPoP-bound key requests (RFC 9449); split keys across domains
  • XMLSPIF v2.1 and v3.0 policy support
Learn more →

Tessera for Cross Domain

A STANAG-compliant Cross-Domain Solution (CDS) — a bi-directional security gateway mediating controlled information exchange between classification domains. Every information flow is evaluated against both domain security policies; no content passes without Guard approval.

  • Dual-SPIF enforcement — both domain policies evaluated on every flow
  • Guard-only cross-domain path — no direct network connection between domains
  • Fail-closed — any error results in denial, never pass-through
  • STANAG 4778 Binding-Data validation and generation
  • Malware scanning and Content Disarm & Reconstruct (CDR)
  • Full audit trail for every decision (ALLOW and DENY)
Learn more →

Standards implemented

ACP-240 STANAG 4774 STANAG 4778 ADatP-5636 XMLSPIF v2.1/v3.0 RFC 5652 CMS

Data-Centric Security — The Model

Traditional perimeter security protects a network boundary. Once data leaves that perimeter — shared with a partner, archived, or transferred to another domain — the protection is gone.

The NATO data-centric model inverts this: the protection travels with the data. A .ztdf archive is an encrypted package whose access policy is embedded and cryptographically bound to the encrypted payload. No key is ever released without a real-time policy check against the requester's attributes.

Security labels (STANAG 4774) declare the sensitivity of the information. Binding assertions (STANAG 4778) tie those labels to the content with a digital signature that cannot be stripped or replaced without detection.

Read: How security labels work
File
encrypt →
.ztdf archive
AES-256-GCM Encrypted payload
STANAG 4774 Confidentiality Label
STANAG 4778 Binding Data Object
ACP-240 ABAC policy

Decrypt request
Key Access Service
Verify label binding
Evaluate ABAC policy
Check user clearance
ALLOW → release DEK DENY → no key, ever

The Policy Decides What the User Sees

Nothing about the classification vocabulary is built into the software. The levels, the order they rank in, and the categories allowed to qualify them are read from the domain's XMLSPIF — the machine-readable form of the security policy that the policy authority publishes.

Point the desktop at a different policy and the whole interface changes with it: different levels, different releasability groups, different compartments. That is what makes one product deployable in a national domain, a coalition mission network and a partner enclave without a rebuild.

Shown here with TESSERA, a fictional policy we publish for demonstration and testing — so nothing in the screenshot is a real classification marking.

The Tessera protect dialog showing a label under the TESSERA demonstration policy: SECRET, releasable to ARC and SYL, LODESTAR compartment, DEMO administrative marking.
A label under the TESSERA demonstration policy: a classification, a releasability group, a compartment and an informative marking — each offered because that policy defines it.

New to security labels?

Our concepts guide explains classification levels, clearances, categories, SPIFs, and multi-point enforcement — starting from physical-world analogies and building up to the NATO standards that implement them electronically.

How Security Labels Work