Published: September 08, 2026  |  5 min read
Share the article

ShareFile for Your Firm

Secure document workflows your team and clients will actually use

Get Started
Key Takeaways
Let's take a quick mental journey comparing how Progress ShareFile protects your data digitally, like the Fed would do it physically, as your data is your gold.

Eighty feet beneath the bustling streets of Manhattan sits perhaps the world’s most secure financial structural masterpiece: the Federal Reserve Bank of New York’s gold vault. Built directly onto the solid bedrock of New York City, it safeguards nearly a quarter of the world’s official monetary gold.

But in the current corporate world, gold is not in bars. It comes in data.

How Fed Security Practices Are Reflected Digitally

For organizations managing sensitive corporate files, legal documentation or healthcare records, building a physical fortress is impossible. However, building a digital one is completely within reach. Let’s see.

1. Physical Bedrock -> Certified Cloud Architecture

The New York Fed vault relies on nature’s strongest foundation: Manhattan’s solid bedrock. This prevents any possibility of subterranean tunneling or structural undermining.

In the cloud ecosystem, your data must reside on an equally unyielding structural foundation. Progress ShareFile software replaces physical granite with highly audited infrastructure hosted within globally certified cloud environments (such as AWS and Microsoft Azure). These facilities feature strict, biometric physical boundaries and are validated against elite compliance frameworks including SOC 2 Type II and ISO 27001.

2. The Airtight Cylinder Door -> 256-Bit Cryptographic Seals

To enter the Federal Reserve vault, you won’t pass through a hinged door. Instead, you face a 90-ton rotating steel cylinder. When shut, it rotates to drop slightly into its frame, creating a completely airtight and watertight seal.

Progress ShareFile software replicates this using 256-bit AES encryption, TLS protocols, HMAC verification and secret-key validation. If a malicious entity attempts to modify or intercept data, the cryptographic seal is designed to fail immediately.

3. The Rule of Three -> Multi-Factor & Identity Authentication

No individual can open the New York Fed’s vault alone. Entry requires a Control Group—three distinct people from separate departments.

Progress ShareFile software provides a modern Rule of Three through multi-factor authentication (MFA) and advanced authorization workflows, strict lockout policies and eIDAS-supported Advanced and Qualified Electronic Signatures (AES/QES).

4. Segmented Mesh Vaults -> Granular Permissions and Client Portals

Inside the main Fed vault, gold is segregated into 122 individual mesh compartments, each locked with double combinations and auditor seals.

Progress ShareFile software mirrors this through Granular Access Controls and branded Client Portals. External clients see only assigned folders, supported by isolated permissions, unique per-file encryption keys and robust audit telemetry.

5. Physical Security Guards -> Digital Security Options

Upon entering the vault, you will be asked to hand over an identification document, and a fingerprint match.

Progress ShareFile software reflects this with the option to enable MFA where you both need your username and password, as well as an additional identification method, be it phone, SMS or an already installed authentication app on your device.

Note: For all certificates and documents regarding cybersecurity, please visit trust.sharefile.com

How to Harden Your Digital Vault

Let us now list the possibilities to harden your digital vault, and a quick look at how to configure them.

Security Insights

We will start with the Security Dashboard. This is your Fed control room, where you as an admin have an overview of everything that is suspicious happening in your facility.

Suspicious activity, as defined by yourself, will be displayed and easily accessible to take the needed actions.

Antivirus

We’ve all been there, secure environments where you don’t just walk in with all your belongings. There’s a line, with a belt, with a machine. It X-rays the content of all the bags, packages or pieces of luggage you carry with you.

Progress ShareFile software does the same for you (automatically) or when you use ShareFile with your on-premises storage, through ICAP.

You can switch the strictness of the AV according to your needs, with the following parameters*:

(*Please contact the support team to change the setting.)

Data Loss Prevention

Available for customers who use their own storage zone controller, you can select how thorough you scan and report your files content. Just as in the real world, these scanners are third-party (hence only available when you have a storage zone controller), but you can allow or restrict certain people and/or “items” from being considered flagged.

Sign-in Policy

Ever walked into a government facility with an employee badge and maybe afterward with a visitor badge? Or do you know people who’ve been through those different processes?

Same goes for your Progress ShareFile setup. You can allow and deny multiple methods of signing in, make it easier or make it harder if you want.

Let’s cover a couple of options:

1. Username/Password

Let’s begin with the easiest, used on every platform: Username/Password.

Even though this is not used at the Fed vault (for obvious reasons), we can take a little loop in the story, and bring in the password. Passwords have length, given only to an authorized person and expire after a while.

2. Multi-Factor Authentication

More secure, however, is Multi-Factor Authentication.

We’ve touched on this topic a bit before, but repeating security guidelines never hurts. (Pun intended for frequent airplane travelers.)

There’s of course also the possibility that you work together with instances which you trust. Our example, the Fed vault, will for example trust people with a badge from the FBI or the NRA.

3. SSO and SAML

Let’s move on and take a look at how to secure the login for our internal employees.

At the vault, we have a badge which is connected to the central system. With Progress ShareFile, you can set up your SAML in order to achieve the same.

As you can see below, the configuration is pretty straightforward. You create a virtual corridor with two doors: one being your ShareFile, one being your Authenticator (EntraID for example)

You give the paths, the keys and the type of key (HTTP/HTTPS), and you open the login possibility.

Additional Security Options

Security measures might change a bit over time, so also in Progress ShareFile you have the ability to mitigate ad-hoc changes.

Trusted Domains, as an example: you can specify which companies’ domains you trust and give them a lower security check.

Or specify more when and who would need security alerts:

For additional security reports, you can also configure one of our available SIEM integrations (ShareFile Enterprise and above) and/or configure your SCIM.

And oh, one more thing.

Do you know this?


Image generated with AI

If you are in need of Top Secret documents, enable our Watermarking option when sharing:

Even though you might not prevent your recipient from screenshotting or taking pictures of your document, the dynamic texts you select will be included.

And now, really, the last remark:

Just like the vault of the Fed, and every institution which guards valuables (physical or digital), there are security guards. Real-life agents might alert you in case of emergency and point to the right exit. Progress ShareFile software also looks out for your safety and possessions. If our teams reach out in such cases, please follow our instructions to mitigate potential risks.


Learn more about how Progress ShareFile software is designed to embed data security and compliance support into every workflow.

Topics

Subscribe to ShareFeed Today

Stay ahead with the latest ShareFile releases, feature enhancements, and product updates delivered monthly straight to your inbox.

Loading animation

Matthias Van Steen

Matthias Van Steen works as a Progress ShareFile Sales and Customer Success Engineer for Benelux, France and DACH (and any English speaker who might need him). Belgium born, Matthias now resides in Bulgaria with his wonderful wife and two sons. In his free time (who has that with two kids?) he likes a good beer, a game of bowling or billiards, or just some board games or a good movie. (Lord of the Rings anyone?) He welcomes meeting and collaborating with all, and he is happy to help out with any technical questions regarding ShareFile.

MORE FROM THE AUTHOR
Follow ShareFile

Related Posts