Database encryption
ABBYY FlexiCapture 12 supports Transparent Data Encryption (TDE), a technology for encrypting databases and protection of keys. Data are encrypted at the server level, and backups cannot be decrypted without a valid key. Detailed information about how to encrypt data using SQL and Oracle is available on the Microsoft and Oracle websites.File and temporary folder encryption
ABBYY FlexiCapture 12 supports Windows Encryption File System (EFS), a file encryption technology offered by Microsoft. EFS is used for encrypting files and folders on servers and client computers. It protects confidential information contained in files and folders by generating a unique key that uses a combination of server and user credentials. For detailed instructions on enabling EFS, see this section of the Microsoft website. When EFS is used in ABBYY FlexiCapture 12, the following folders are encrypted:- Storage folders — The storage facility is controlled by the Application Server, so storage folders must be encrypted using the account under which the FlexiCapture 12 Web services application pool is running in IIS.
- Processing Station temp folders — Depending on which account is used to run the station, encrypt either the domain user’s temp folder or the
NetworkServicetemp folder (C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp). - Scanning Station and scanning plug-in temp folders and project folders — Encrypt these folders (
C:\Users\<username>\AppData\Local\ABBYY\ScanStationFC\4.0for the Scanning Station andC:\Users\<username>\AppData\Local\ABBYY\ScanningPlugin\for the scanning plug-in) using the account of the user that is using the Scanning Station. - Export and import folders — The Processing Station must have access to the files in the import folder and write permissions for the export folder so that it can create files there. To encrypt the import folder, the user running the Processing Station must have access permissions to these files. To encrypt files before they are sent to the export folder, the Processing Station must use the key of the user running it, which lets that user decrypt the files later.
