
Built for the environments where the stakes are highest.
Defence contractors, primes, and subcontractors handle data that is not simply commercially sensitive. It carries strategic value, export obligations, and supply chain accountability that follows every file across every boundary it crosses. Most security tools stop at the perimeter. GuardWare follows the data.
Defence use cases
Protecting design files and engineering IP
CAD drawings, DWG models, engineering specifications, and simulation outputs are the highest-value assets in a defence manufacturing environment, and the least protected. GuardWare PROTECT Design applies the world’s first persistent in-use encryption to proprietary design file formats, remaining in place through storage, transfer, and active use. A file shared with a subcontractor, taken by a departing engineer, or exfiltrated in a breach cannot be opened without authorisation. Access can be revoked instantly from a central console.
Supply chain and multi-organisation data control
Prime-to-subcontractor data sharing, joint ventures, and multi-tier defence programmes require shared governance over sensitive data without surrendering individual control. PROTECT’s Oversight Mode enables multiple independent organisations to each retain decryption authority. No single party can unilaterally access shared data. Each organisation retains independent revocation capability, enforced at the cryptographic layer.
Air-gapped and offline environments
Submarines, aircraft deployments, forward engineering teams, and remote manufacturing environments cannot depend on cloud connectivity for data protection. PROTECT’s Offline Mode provisions encryption keys directly into the device TPM, enabling authorised users to work with protected files in fully disconnected environments, with no ongoing dependency on any cloud provider.
Insider threat and contractor risk
A departing engineer who copies design files, a contractor who retains project assets after their engagement ends, a disgruntled employee sharing IP with a competitor. PROTECT ensures files taken without authorisation cannot be read, and access can be revoked immediately upon departure without physical interaction with any device.
Continuous monitoring across the defence environment
GuardWare INSIGHT monitors how sensitive data moves across endpoints, M365, cloud platforms, email, USB transfers, AI tools, and remote worker environments, 24 hours a day. Risky behaviour is detected in real time, alerts reach the right people immediately, and a complete audit trail supports internal governance and customer assurance obligations.
Sensitive data discovery across the estate
Before you can protect controlled data, you need to know where it lives. GuardWare DISCOVER locates and classifies sensitive data across every repository, including design files, specifications, and technical documentation, producing a ranked exposure report that forms the foundation of any defensible data governance program.
ITAR in summary
Australian organisations handling ITAR-controlled technical data under 22 CFR Parts 120-130 must demonstrate independent organisational control over decryption, geographic and device-based access restriction, and end-to-end encryption compliant with FIPS 140-2 or equivalent AES-128 strength under ITAR § 120.54(a)(5).
GuardWare PROTECT’s decoupled architecture separates cryptography, identity, and policy into independently governed layers, ensuring Microsoft or any cloud provider never becomes a decryption authority. ITAR Mode enables real-time enforcement of geographic and identity restrictions aligned to 22 CFR Part 125 export licence conditions. Oversight Mode supports multi-organisation joint ventures where shared governance must be enforced cryptographically, not contractually.
Real-Time Visibility for Confident Compliance










Built for
- Defence primes and subcontractors
- Aerospace and advanced manufacturing
- Joint ventures and sovereign manufacturing
- Government and defence contractors

