A laptop is left in a taxi and a USB stick walks out the door. Neither should carry readable data — Matrix42 Endpoint Data Protection, the former EgoSecure, encrypts disks, folders, USB drives and cloud folders with keys you hold, and decides which ports, devices and programs each user may use — all from a server you run.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Matrix42 Endpoint Data Protection — the endpoint encryption and device-control product, formerly EgoSecure. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Encryption keeps data unreadable on a lost device, and device control decides where data may be copied in the first place.
What consolidation actually replaces, dimension by dimension.
| Dimension | Open USB ports, unencrypted laptops | Matrix42 Endpoint Data Protection |
|---|---|---|
| A laptop goes missing | A reportable breach and a long audit | An encrypted disk behind a pre-boot login |
| Someone plugs in a USB stick | Anything copies, nothing is logged | Per-user rules, optional encryption, a log entry |
| Files in a synced cloud folder | Readable by whoever holds the account | Encrypted with keys kept in your organisation |
| Unapproved software | Found at licence-audit time | Blocked by a per-user program list |
| Unusual data movement | Noticed after the damage, if ever | IntellAct flags it against normal values |
| What it is NOT | — | Rights management, content-aware DLP, or a published price |
The cheapest test is the 30-day trial: one department, audit-only rules for a week, then encrypt five laptops and rehearse a key recovery.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
An agent on every Windows PC enforces encryption, device and program rules locally and registers with the EgoSecure server; Matrix42 keeps separate update guides for agents.
The server syncs your directory, holds tenants, administrators and licence activations, and keeps its data in a SQL database; Microsoft SQL Server and Azure SQL are both documented.
A separately installed Full Disk Encryption component locks the drive before Windows starts, with smart-card logon documented; a BitLocker Management module is the native route.
UUX extends the console across UEM and EgoSecure, and its service bus allows hybrid estates, for example EgoSecure and Empirum on-premises with Silverback in the cloud.
An agent on every Windows PC and a server you run — data encrypted at rest, every port and program under a rule.
Matrix42 Endpoint Data Protection encrypts what sits on your endpoints and controls every route data can take off them.
Full-disk encryption with Preboot Authentication keeps a stolen laptop’s drive unreadable even if Windows login is bypassed.
Local Folder, Removable Device and Permanent Encryption modes protect files and pen drives as well as the system disk.
Folders synced to cloud storage are encrypted with keys Matrix42 says remain inside your organisation; a mobile app decrypts them.
Rules decide which users can use Bluetooth, WiFi, smartphones and USB devices, and to what extent, on each endpoint.
The same access rules extend to cloud services and storage, so an upload channel can be limited like a USB port.
Per-user program allow and block lists stop unlicensed installs; a documented setup makes Empirum the only trusted installer.
Data transfers are logged and stored under EU-GDPR rules, and access to the log can be limited to named team members.
IntellAct Automation compares audit data with normal values, flags anomalies and fires predefined triggers without an admin.
Workflow Studio can turn an IntellAct finding into further Matrix42 actions and processes, chosen by network status.
Matrix42 has published one official video on this product: a 2020 Experience Day session, in German and under the EgoSecure name, on why organisations deploy it and how they implement data protection. No newer or English video exists on the official channel.
In German and from 2020, before the rename: why organisations deploy EgoSecure and how they put data protection into practice. It is the only official video on this product.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
EDP does both jobs many tools split: whole-disk encryption behind a pre-boot login, folder and USB encryption, and per-user rules for Bluetooth, WiFi, phones and USB devices, from one agent and one console. One policy set covers the lost laptop and the copied file.
The EgoSecure server is software you install, so policy, the audit trail and recovery material sit in a data centre you pick, and Matrix42 says cloud-folder keys stay within your organisation. With no Matrix42 region in India, that is the residency route.
Paired with Unified Endpoint Management, EDP becomes what Matrix42 calls Secure UEM, run through the Unified User Experience console. Application Control can make Empirum the only trusted installer, and IntellAct findings can start Workflow Studio processes.
It is device-level protection, not rights management: a file sent outside is not tracked or revocable, and no content classification is documented. Disk encryption is Windows-first, the price is quote-only, the one official video is German from 2020, and support keeps European hours.
List laptops, desktops and the USB, Bluetooth and cloud-storage use each team needs, so rules start from real work.
Install the EgoSecure server in your Indian data centre, sync the directory and set tenants and administrator roles.
Roll the agent to one department with Secure Audit on and rules permissive, and read where data actually moves.
Turn on full-disk encryption with pre-boot login, run a Windows patch cycle on them, and rehearse a key recovery.
Switch USB and program rules to enforce, add IntellAct triggers, then extend group by group across the estate.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We set USB sticks to read-only for everyone except finance, and the audit log showed who still tried to copy to them.”
“A field engineer lost a laptop at a station. Pre-boot encryption made it a write-off for the asset team, not an incident.”
“Application Control finally stopped unlicensed tools appearing on shop-floor PCs; only Empirum packages install now.”
“Encrypting the synced cloud folder with our own keys answered the client’s question about the provider reading files.”
“A Windows update left two encrypted laptops unbootable until the knowledge-base fix went on. Pilot every patch ring first.”
“It does what we need, but support answers in European hours and the quote took weeks. Budget for that from India.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint encryption market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
EgoSecure heritage; sold mostly into Europe on quote.
The grid nobody publishes — how many places a product encrypts data vs how much control it gives over the ports, devices and programs data leaves through.
Disk, folder, USB, cloud folder; ports, devices, programs and audit.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Trellix Data Encryption, ESET PROTECT Advanced, Seqrite Encryption, WatchGuard Full Encryption and Safetica Platform — on engine, platforms, USB and port control, keys, price and India.
| Dimension | Matrix42 Endpoint Data Protection | Trellix Data Encryption | ESET PROTECT Advanced | Seqrite Encryption | WatchGuard Full Encryption | Safetica Platform |
|---|---|---|---|---|---|---|
| What it is | Encryption + port rules | Encryption family | Endpoint tier with FDE | India-built disk + USB | BitLocker add-on | DLP + insider risk |
| Deployment | Your EgoSecure server | ePO, on-prem or SaaS | Cloud or own server | Console here or hosted | Vendor cloud only | Cloud; On-Prem separate |
| Encryption engine | AES; own FDE | Certified own engine | FIPS 140-2, AES-256 | Choice of four ciphers | BitLocker only | Not documented |
| Platforms | Windows; mobile app | Windows and macOS | Windows, macOS 10.14+ | PCs and Macs (2018) | Windows; Mac unclear | Endpoints + M365, Google |
| Pre-boot authentication | Pre-boot, smart cards | Smart card, MFA | TPM and OPAL aware | Pre-boot login | PIN or passphrase | Not applicable |
| Removable media | Encrypt or restrict USB | Dedicated media product | Disks, not pen drives | USB + Traveller Tool | Prompts to encrypt USB | Controls, not encrypts |
| Device and port control | Ports, devices, cloud | Separate Device Control | Built into the agent | In Seqrite EPP tiers | In the endpoint tiers | USB, print, clipboard |
| Key custody and recovery | Keys kept in-house | ePO escrow, self-help | Kept in the console | Central recovery store | Cloud, by key ID | No keys to hold |
| Pricing model | Point product, quoted | Per endpoint, by product | Per device, whole tier | Per endpoint, quoted | Add-on, licence bands | Per user, three tiers |
| Published entry price | Not published | Not published | ~$55/device/year | Not published | Not published | From $72/user/year |
| Included vs add-on | Modules in one product | Pick and combine | FDE inside the tier | Separate product | Base licence required | Tiers add features |
| India key location | Your server in India | ePO on your servers | On-prem console option | Pune-built, on-prem | No India region | On-Prem for residency |
| Lock-in and exit | Own FDE format | Own engine or native | ESET format on Windows | Proprietary format | Standard BitLocker | Nothing encrypted |
| Best fit | Matrix42 UEM estates | Standardised on ePO | Price before the call | Local vendor wanted | WatchGuard MSP clients | Leak channels first |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Matrix42 Endpoint Data Protection is one of 21 encryption & rights management products TechBag carries. The Encryption & Rights Management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (endpoints you protect; IT staff-hour cost). Estimates model the staff time spent on USB exception requests, lost-device reports and gathering evidence of who copied what, at an assumed 1.5 hours per endpoint a year, with 70% of it saved by central encryption, port rules and an audit trail. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Matrix42 publishes no price for Endpoint Data Protection: its pricing page lists it among five point products sold through a quote request, and the pricing FAQ offers each product free for 30 days. It can also be bought with Unified Endpoint Management as the Secure UEM bundle, and Premium Services (24/7 priority support) is an add-on. Matrix42 shows no rupee or dollar price and has no Indian office or partner verified. TechBag maps your endpoints and channels first, then quotes in INR with GST.
Best for encryption and port control on its own
Best for a broader rollout
Best for estates already on Matrix42 UEM
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is the risk a lost device and a copied file, or a document sent outside? EDP handles the first; rights management the second.
Are your endpoints Windows? Ask Matrix42 in writing about any Macs, since no macOS disk encryption was documented.
EgoSecure Full Disk Encryption or the BitLocker Management module? The choice decides your exit path.
Which users need USB, Bluetooth, WiFi tethering or cloud storage, and should each be blocked or audited?
Where will the EgoSecure server and its SQL database run, and who in India administers and patches it?
Is there a pilot ring for Windows updates? Matrix42’s knowledge base logs boot problems after specific updates.
Can you live with European-hours support, or will a partner or Premium Services cover your shifts?
Does the quote state the licence unit, modules, term and any UEM bundle discount? Ask for INR with GST.
Count your endpoints and the cost of handling USB requests and lost laptops first, or let a TechBag advisor place the server in India and run an audit-only pilot.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.