Cloud Data Protection Software by Portal26 provides always-on encryption to keep cloud data secure and enables HYOK (hold your own key) to give security control back to data owners. It secures data from ransomware, data breaches, and insider attacks by encrypting data before it reaches the object store. It uses NIST FIPS 140-2 validated encryption and builds an encrypted search index with metadata. For structured data, it allows encrypted data to be searchable without decryption. Data from object stores is retrieved via the Portal26 Proxy and can be released in privacy-preserving formats, following existing RBAC. Portal26 allows external data owners to supply encryption keys (BYOK) or hold their own keys (HYOK). Customers can disable the use of their data by turning off keys. Portal26’s cloud data protection platform secures large volumes of data from insider threats, malicious attacks, and data privacy violations. It secures against cloud platform admins and privileged users within the enterprise. Key capabilities include seamless encryption, where all files are encrypted before reaching the object store, using keys from external key vaults and released securely based on RBAC. Portal26’s advanced cloud data protection software ensures attackers cannot exfiltrate large volumes of unencrypted data via privileged access to AWS S3, Azure Blob, or GCS. It also encrypts file names while allowing end users to search normally, further strengthening data security. Portal26 integrates with key vaults for key materials and supports Bring Your Own Key (BYOK) and Hold Your Own Key (HYOK). Keys can be applied on a per entity, department, user, or file basis for strong security and data segmentation. Searchable Encryption allows unstructured data in Portal26 protected object stores to be fully searchable without decryption, enabling data to stay encrypted longer and limiting decryption to small subsets with tight privacy controls. Portal26 Studio allows configuration and management of modules and services, with access to logs, dashboards, and reports. Portal26 encryption meets stringent data protection standards in major regulations and frameworks. Portal26 releases data in nine privacy-preserving formats for configuration with downstream systems. Compared to traditional tokenization solutions, Portal26 secures extensive data while maintaining usability. The Portal26 plugin can be operational within half a day, and the Proxy takes a few days. In attack scenarios, Portal26 offers visibility into observed, accessed, or exfiltrated data.