Page 1 of 12. for Enterprise Secure File Sharing in a time of AI-driven attacks filotron.com customers@cogentlogic.com Copyright © 2026, Cogent Logic Limited · Patents-pending macOS · Windows · Linux · iOS · Android Page 2 of 12. FILOTRON FLEET FABRIC Hardware governs admission. Identity governs authorisation. 1 Every device proves itself Two devices connect only after each has proved, in hardware, that it belongs to your fleet. No password takes part in this exchange. Your Root CA created offline, pinned into your own builds mutual TLS: each proves itself to the other Key born in its HSM Key born in its HSM Certificate carries your Fleet ID Certificate carries your Fleet ID 2 Files move straight between devices Source device to destination device, with nothing in between that holds a copy. QUIC with mutual TLS post-quantum key exchange 3 Every file operation is recorded Allowed or refused, each operation becomes a single line of JSON on the device itself. Kept on the device One line of JSON Your SIEM and in your own backups allowed or refused Wazuh rules included 4 Try it on your own terms Two evaluations, both credited in full against a production licence taken within 180 days. then 2 Isolated evaluation Integrated trial our kit, sealed off from your estate your network, your directory, your SIEM FILOTRON for Enterprise Page 3 of 12. FILOTRON for Enterprise The problem Four consequences Your people share files every day. Almost every tool they use to do it leaves a copy somewhere that you do not control, guarded by a credential that can be stolen. Those two facts compound. The file stores become the most valuable targets in your estate. The password is the way in. Most of the industry then sells you ways to watch those stores more closely and to make the password harder to misuse. 1. The credential cannot be copied. Every device’s private key is generated inside that device’s own security hardware (Apple Secure Enclave, TPM 2.0, Android StrongBox or TEE) and never leaves it. It cannot be exported, mailed or pasted into anything. A device without usable hardware cannot enrol at all: FILOTRON for Enterprise refuses it rather than falling back to a software key. A phished directory password, on its own, opens nothing. FILOTRON for Enterprise removes both. The solution FILOTRON for Enterprise moves files directly between the devices your organisation already owns, encrypted from the source device to the destination, with no cloud service in between and no server anywhere that can read them. It works wherever those devices are: on your own network, across the internet or on a local network with no internet connection at all. For your people in the office, on a train, at a conference or in a hotel, it is the same product behaving the same way (no VPN). A device joins your fleet by proving it holds a key that was created inside its own security hardware and a certificate that belongs to your FILOTRON PKI. There is no fabric password, so there is no fabric password to phish. Your identity system then decides what each signed-in person may reach. Hardware governs admission. Identity governs authorisation. FILOTRON for Enterprise 2. There is no central store to take. Files move directly between users’ devices. Where a direct path is blocked, a relay forwards the traffic but can read nothing. Nothing has to be attached to an email, copied onto a file server, walked out on a USB stick or handed to a third-party cloud service. Every one of those leaves a second copy somewhere that nobody is watching. Nothing accumulates anywhere to be taken in one go. 3. Your identity system stays yours. Sign in through Microsoft Entra ID, Okta, Keycloak, Ping Identity or Microsoft AD FS, or through a directory FILOTRON supplies if you have none. Several providers can be live in one fleet at once. Permissions reside on role objects in your own directory, identifying which folders each role reaches and with what access rights. Nobody grants their own access. A person requests that access be granted to a bookmarked folder, their line manager approves or declines with a comment, then an administrator applies exactly what was approved. The approver is taken from your directory’s standard manager attribute, so approvals follow your organisation’s own reporting line rather than a second hierarchy invented by us. Even an administrator creates 3 Page 4 of 12. folders as an ordinary user, so every sharing intent travels the same path and is recorded the same way. 4. You can prove what happened. Every access decision, allowed or refused, becomes one line of plain JSON on the device itself. It stays there, is included in your backups and can be investigated on the device with or without a SIEM. It also flows to your own SIEM, with decoders, rules and a dashboard ready-made. What you operate All of it runs on hardware you own. Each customer fleet has its own Root CA, created offline on an air-gapped machine and compiled into your own application and server builds by us. A certificate from another customer’s fleet is refused. A device in one of your fleets will not talk to a device in another. By default, Cogent Logic Limited operates the push-notification relays that wake a sleeping device. Customers who would rather run those themselves can. Nothing else of yours passes through us. What it runs on macOS, Windows, Linux, Android and iOS, from one shared application. Connections use mutual TLS over QUIC with post-quantum key exchange. Cryptography is FIPS-validated on macOS, Linux and Android; Windows and iOS use the same algorithms without the FIPS validation. Three editions: Standard, Advanced and High-Assurance. The certificate structure is identical in all three. Every edition keeps a local forensic record on each device. The editions differ in what is exported to your SIEM, in where your Root CA is created, in the support you receive and in how many independent fleets you can run. High-Assurance mints your Root in your own facility and allows as many independent fleets as you need, including on isolated networks. In short FILOTRON for Enterprise shares files the way your people find most natural: directly between the devices you already own, encrypted from end to end, wherever those people are working. The thing an attacker usually steals does not exist here. There is no shared store to exfiltrate and no fabric password to phish. What remains is your own directory deciding what your own people may reach, on your own hardware, with a durable record of every decision that was taken. For a friction-free, self-contained evaluation, we recommend that you purchase the isolated trial version of FILOTRON for Enterprise. You can follow that up with a limited integrated trial. The total cost of trial purchases counts as a credit against a production licence taken within 180 days. 4 FILOTRON for Enterprise Page 5 of 12. The fleet’s devices are listed on the left. Two are open side by side: a MacBook Air and a Windows PC. A photograph held on the Windows PC, previewed from the MacBook Air. A Markdown file held on another Mac, previewed as rendered text or as raw source. Disk usage of a folder on another Mac, as a treemap. FILOTRON for Enterprise The same folder’s disk usage, as a sunburst. 5 Page 6 of 12. Copying a folder from an iPhone to a Linux computer by drag and drop. Completed file operations are listed beneath. FILOTRON audit events in Wazuh. Each row is one access decision, allowed or refused. The ready-made Wazuh dashboard: decisions allowed and refused over time, with the operations refused most often. 6 FILOTRON for Enterprise Page 7 of 12. FILOTRON for Enterprise: finding a peer at a glance Three ways to find a fleet device, a silent push to wake it, then one encrypted channel that carries the files. Find the peer Ordered by reach, from the device beside you to one anywhere on the internet. then Wake it if it is asleep A silent push tells the peer to come online. It carries no file data. APNs for iOS and macOS, FCM for Android, WNS for Windows, ntfy for Linux. then Connect Device to device over QUIC with mutual TLS, E2EE, post-quantum key exchange. Three ways to find a peer Bluetooth LE mDNS STUN and ICE Nearby, with no network at all. On the same local network. Across the internet, through NATs and firewalls. A relay when a direct path is blocked. Discovery is fleet-scoped: only devices in the same fleet find each other. What goes on the wire is a one-way derived token, never a raw identity. Discovery and wake only locate and rouse the peer. Only the encrypted QUIC channel carries your files. FILOTRON for Enterprise 7 Page 8 of 12. FILOTRON for Enterprise: PKI at a glance One Root CA per customer fleet. It lives offline. Every other private key is born inside hardware and never leaves it. The Root stays offline Created on an air-gapped machine, held encrypted, backed up onto separate media. The one software key in the whole system. The operator holds the passphrase. signs The Fleet Root CA Self-signed, carrying the customer name and the Fleet ID. 30 years by default. Signs only two kinds of certificate, ever: the sign-in service and the issuing CA. signs The issuing CA signs the rest An intermediate CA on the customer’s own server. 10 years. Certificate service, mutual-TLS gateway, signalling service, access-voucher signer. signs Every device certificate Issued when a device enrols, carrying the Fleet ID and a Device ID. 730 days. A certificate from another customer’s fleet is refused, though valid in its own. Where each private key lives The Root Servers Devices Offline, encrypted, backed up. Never on a network. Born inside the Linux host TPM 2.0 and never leaves it. Born inside the HSM. No software alternative: a device without one cannot enrol. One Root, one fleet: every chain ends at the fleet’s own Root, compiled into the customer’s own builds. No certificate outlives the one that signed it. Only a CA may sign. For two servers only, across the air gap a certificate signing request goes in and a signed certificate comes out. No private key ever crosses any boundary. Devices also trust Cogent Logic’s own Root but only for the push relays it operates, unless your push relays are used. 8 FILOTRON for Enterprise Page 9 of 12. FILOTRON for Enterprise: RBAC at a glance Your identity provider says who the person is. Your own directory says what they may reach. In the FILOTRON app, a person signs in With FILOTRON’s own sign-in or your single sign-on (Microsoft Entra ID, Okta, Keycloak, Ping Identity, Microsoft AD FS) who they are The directory decides Roles identify bookmarks* and whether read only or read and write (FILOTRON supplies the directory or point it at your own) what they may reach A permit is signed Short-lived. Bound to one device. Verified offline. the permit The device enforces it Decided on the device, even if the server is down Nobody grants their own access writes the role The owner asks Their line manager approves An administrator implements From the bookmark itself Your own reporting line Exactly what was approved Everything rides on FILOTRON Fleet Fabric: mTLS with hardware keys. Your Root CA certificate pinned. Every device’s key is born in its HSM. Every data transfer is E2EE with post-quantum key exchange. * A bookmark is a directory its user has designated from inside the FILOTRON app, which is sandboxed and can otherwise reach nothing on the device. FILOTRON for Enterprise 9 Page 10 of 12. FILOTRON for Enterprise: auditing at a glance Every access decision becomes a durable record on your own hardware, then flows to your own SIEM. A decision is made At every authorization gate: connections, discovery, incoming transfers, file operations. recorded A record is written One line of plain JSON, appended on the device. It never blocks the operation. stored It stays on the device A rotating file with a local database copy. Included in your backups. Investigable on the device itself, whether or not any SIEM is running. shipped It reaches your SIEM Desktops are tailed by an agent. Mobiles send batches to your server over mutual TLS. Decoders, rules and a dashboard ship ready-made for Wazuh. Any JSON SIEM will do. What your SIEM is told Allow Deny Five denies in a minute Recorded as informational. Raised as an alert. Escalated as a burst. The on-host record is yours: it stays on each device and host, running on your own hardware. Plain JSON, kept for as long as your own retention policy requires. Device and peer-to-peer access decisions are fully structured today. Administrative-console actions currently appear as host journal lines; structured records for them are being added. 10 FILOTRON for Enterprise Page 11 of 12. The book sets this page sideways; it is turned upright here. Egnyte Tresorit Proton Drive Sync.com r Internxt q Kiteworks m MOVEit s GoAnywhere s Cleo Harmony s Syncthing t GoodSync p iCloud Drive Seafile MEGA ShareFile Dropbox Box FILOTRON f e a h Your own Root CA, its key created and backed up air-gapped available as a configuration or plan a partly: see the note with the same letter FILOTRON for Enterprise s s s s s s t t s t s s s s u u u not described in the vendor’s public documentation s s s n e k i g j Nextcloud, ownCloud, FileCloud and CTERA: a branded build carries your name and logo but pins no Root CA. k Tresorit and OneDrive: post-quantum key exchange is announced, not yet available. m Kiteworks: post-quantum key exchange is documented for one component only. n Google Drive: post-quantum key exchange is documented for Google’s front ends, not Drive by name. p Proton Drive and GoodSync: Linux has only a command-line or browser interface. q Internxt: business workspaces are missing from its Linux and mobile apps. r Tresorit, Proton Drive, Sync.com and Internxt: the admin log omits some file operations. s ShareFile, Nextcloud, FileCloud, Kiteworks, MOVEit, GoAnywhere, Cleo Harmony and Resilio: remote files only through connections an administrator sets up. t Syncthing: remote files only as folders synced in full, not on demand. u GoodSync: previews remote files only on mobile, cannot ZIP them and shows free space, not folder usage. not offered j e Based on each vendor’s public documentation, September 2026. Product names are trademarks of their respective owners. In the second row: where you configure phishing-resistant sign-in at your identity provider. a Quick Share: sending to Apple devices by QR code holds encrypted files on Google’s servers for 24 hours. b PreVeil: browser-only Express accounts still sign in with a password. c CTERA: only device backups can be encrypted with the user’s own passphrase. d Box and Egnyte: the device is checked only at sign-in. e PreVeil, FileCloud, CTERA, Resilio, Google Drive and Quick Share: devices are authenticated, but not by mutual TLS. f AirDrop: device certificates are checked only between contacts. g OneDrive: only sign-in tokens are bound to the device, on Windows and Apple devices. h Box and PreVeil: an own-root device check is optional, and made only at sign-in or enrolment. i Nextcloud and OneDrive: an own-root option certifies users, not devices. Remote files are on another of your devices, reached directly, with nothing staged in a store or sent first. documented Analyse disk usage and free space on remote devices s s s s Rename, move, delete and ZIP/unZIP remote files s Pull remote files Preview remote files s s s r s r j s r j s h e Browse remote files Every file operation audited Works on a local network with no internet Native apps on macOS, Windows, Linux, iOS and Android Post-quantum key exchange A custom build for you, pinned to your own Root CA d Every device proves itself on every connection (mutual TLS) Security chip required: a device without one cannot join End-to-end encrypted: only your devices hold the keys Cannot share outside your own fleet: enforced by your Root CA a p ownCloud j Resilio e AirDrop Files stay on hardware you own k Nextcloud i FileCloud e CTERA c Google Drive a d PreVeil b Quick Share No central store holding your files A phished sign-in, on its own, opens none of your files Immune to MFT server-side vulnerabilities How FILOTRON compares SECURE FILE SHARING OneDrive Page 12 of 12. FILOTRON for Enterprise licensing Standard Advanced High-Assurance £14,000 £18,000 £28,000 £42 £62 £72 Trust anchor (Root CA) Customer's own Root CA, generated, air-gapped, by Cogent Logic for this customer alone; the FILOTRON certificate server is enrolled under it and issues all device certificates Customer's own Root CA, generated, air-gapped, by Cogent Logic for this customer alone; the FILOTRON certificate server is enrolled under it and issues all device certificates Customer's own Root CA, minted in the facilitated air-gapped ceremony; the FILOTRON certificate server is enrolled under it and issues all device certificates All filing-system operations audited (to the customer's SIEM) Not included Included Included Base platform fee / year includes the first 25 devices Each additional device / year above the first 25 Multiple IdP systems support Included, every edition Bespoke per-customer pinned builds Included, every edition Support Business hours, next-business-day response Security-update rebuilds 24×7 priority, defined response SLAs Custom SLAs, named contacts Unlimited: always included, every edition Isolated-network deployment (OFFICIAL-tier enclaves) Not included Security documentation pack Not included Unlimited, independent FILOTRON fleets Included, every edition architecture, cryptographic design, threat model, software bill of materials, standard questionnaire answers Accreditation services Not included Not included Included risk-board attendance, IT Health Check and penetration-test support, bespoke control mapping FILOTRON for Enterprise evaluation Product Price Description Isolated Evaluation System £8,000 + VAT A complete fleet as hardware the customer owns: a Linux server laptop running every FILOTRON service (enrolment CA, signaling, STUN, relay-only TURN and the built-in directory that acts as the identity provider), an iPad, an Android tablet and a Windows laptop, all enrolled, plus a router with a SIM slot and a switch. Delivered commissioned; nothing connects to the customer's estate. Up to 20 of the customer's own devices, on any of the five platforms, can join. The evaluation runs for 60 days from delivery. Integrated Trial Upgrade £4,000 + VAT For holders of the evaluation system: the same kit joins the customer's network and signs in through the customer's own identity provider(s), with administrative and security events streamed to their SIEM where the edition under evaluation carries audit export. Integration is remote. Orderable at any point within the 60 days and the customer chooses when it happens; the integrated trial then runs a further nominal 60 days. Up to 20 of their own devices again. VAT is charged at 20% only where the billing address is in the United Kingdom. Customers outside the United Kingdom are not charged UK VAT but may be liable for import duty on physical items shipped to them, in accordance with the regulations of the country in which they are domiciled. Travel and subsistence for on-site attendance are not included in the fees above. Where the site is reachable by rail or road within the working day, travel is included. Where an overnight stay is required, travel and subsistence are charged at cost against receipts, pre-approved and capped by agreement, with the class of travel agreed in advance. customers@cogentlogic.com · +44 749 6566 041 Registered in England and Wales, Company No. 13830535, VAT No. GB 405914408 Registered office: Cogent Logic Limited, 8 The Quadrant, Buxton, SK17 6AW, United Kingdom