LLE's differentiation is the combination of where protection happens, how access is authorized, and where the protected object can reside.
For applicable validated workflows, protection is designed to occur at the endpoint before the protected payload leaves the client.
The architecture aims to minimize unnecessary plaintext exposure to intermediary systems and storage.
The intended recipient can be verified with configured identity and MFA controls before protected information is presented.
Customer mailbox, customer cloud, customer data center, managed vault and hybrid options can be selected by policy.
The security model is designed not to depend on a single vendor-controlled repository.
The user can remain in Outlook or supported webmail workflows instead of learning a replacement communication platform.
LLE's broader product direction includes enabling external parties to initiate protected communications, not merely reply to a portal message.
Authorization, expiration, revocation and storage policy can remain associated with protected information.
Designed to complement XDR, email security, endpoint, SIEM, DLP, IAM and network controls.
Security vendors can add LLE's information-control layer without buying Enigma or replacing their existing platform.
Selected SaaS fields and objects can be protected where server-side processing requirements permit it.
The same authorization model can be extended toward controlling what information human, application and AI actors are allowed to consume.