Aegis Fortress by Apricorn is a hardware-based 256-bit AES XTS encrypted device with onboard keypad PIN authentication and ultra-fast USB 3.1 (3.0) data transfer speeds. It is designed for secure data transport and storage, offering cross-platform compatibility and OS agnosticism, functioning with Windows, Linux, Mac, Android, and Chrome. Aegis Fortress operates in environments where software-authenticated encrypted devices cannot, such as embedded systems with a powered USB port and storage file system but no keyboard. It features a rugged exterior with a layer of hardened epoxy protecting internal components from physical tampering and firmware locked down to prevent modifications, making it impervious to malware attacks such as BadUSB. The device is validated to FIPS 140-2 Level 2 standards, meeting U.S. government requirements for information technology and computer security. The encryption module covers 11 areas of cryptographic security, including physical security, cryptographic key management, and design integrity. The epoxy-coated boundary includes all encryption functions and Critical Security Parameters (CSPs) such as PIN storage, encryption key generation and storage, random number and seed generators, and firmware storage. The HDD/SSD that stores the encrypted data is excluded from this boundary to maximize affordability and product line flexibility. Aegis Fortress supports separate Admin and User modes, with the Admin mode controlling device settings and requiring the Admin PIN for access. User mode allows basic functions like read/write and unlock/lock. Data can be accessed with the Admin PIN in User mode. The device is unlocked by entering a PIN on its keypad, not the host computer's keyboard, and remains invisible to the host until unlocked. The embedded keypad prevents key logging by excluding the host system from the authentication process. A unique PIN must be established at setup, eliminating factory default PIN vulnerabilities. There are no factory pre-set default PINs; a unique PIN must be set by the Admin in Admin mode. User Forced Enrollment allows an Admin to program a device at setup, requiring the User to establish a unique PIN before accessing the drive. If a User PIN is forgotten, Recovery PINs can be programmed to restore access to the drive's data while keeping the Admin PIN and data intact. Once a replacement User PIN is generated, access to the drive is restored. There are two Read-Only Modes: Global, controlled by Admin, and User Mode, controlling individual settings. These modes are used to keep the drive’s contents intact for later examination. Universal Read Only is set by the admin and cannot be modified by others. The second read-only mode can be set and disabled by a user, but can also be managed by the admin. Programmable PIN Lengths: Admin designates minimum and maximum PIN lengths (7 to 16 characters). Longer PINs increase data security; odds of brute force success decrease significantly with longer lengths. Admin can set enhanced user password length requirements during User Forced Enrollment. Brute-Force Defense: Select the number of consecutive invalid PIN attempts permitted (4-20) before crypto-erase. All Aegis Secure Drives are unlocked by entering a PIN on their onboard keypad, making them immune to key-loggers and brute force attacks. They feature a 'Brute Force Hack Defense Mechanism' that deletes the encryption key after a set number of incorrect password entries, protecting the stored data. Unattended Auto Lock allows programming the length of inactivity before the drive locks. Aegis Secure Drives lock automatically when disconnected from a USB port or after a set period of inactivity. Lock Override keeps the drive unlocked during USB port re-enumeration.