← Back to Knowledge Base

Core C/S Architecture & Workflow Explained

Getting Started

The modular C/S architecture of USB Disk Security and PrivateDLP delivers a flexible, secure, and user-friendly foundation for enterprise endpoint data protection. The standard workflow addresses core DLP and access control needs for small and mid-sized organizations, while the extended Pro workflow adds intelligent, privacy-compliant auditing and customizable deployment options for enterprises with advanced compliance, productivity, and data security requirements.

USB Disk Security (Standard) and PrivateDLP (Pro) are built on a robust, enterprise-grade Client/Server (C/S) architecture designed to deliver centralized, scalable, and privacy-compliant data loss prevention (DLP) and endpoint behavior management for organizations of all sizes. Optimized for Windows-based enterprise endpoints, the architecture decouples policy administration, backend orchestration, and on-device enforcement, enabling IT and security teams to govern terminal security at scale without compromising endpoint performance or employee privacy.

Architecture Core Components

The system consists of three interconnected, purpose-built layers that work in tandem to deliver full-coverage security governance:

1. Web-Based Admin Console

The unified web management portal serves as the single control plane for all security configurations and audit operations. Accessible via any standard web browser, it eliminates the need for dedicated management software and enables secure remote administration.

  • Centralized policy configuration for USB access, antivirus rules, network filtering, and application control

  • Bulk or per-device policy assignment for granular, targeted security governance

  • Real-time dashboard for audit logs, alert notifications, and employee productivity analytics

  • Role-based access control for multi-level administrator permission management

2. Central Server Layer

Acting as the orchestration hub of the entire system, the central server bridges the admin console and endpoint clients, handling data synchronization and policy distribution.

  • Securely stores policy configurations, system logs, and audit data (with customizable storage options for PrivateDLP Pro)

  • Pushes updated policies to targeted endpoint clients in real time

  • Processes incoming endpoint logs and triggers automated alert workflows for policy violations

  • Hosts AI audit integration modules for PrivateDLP Pro, supporting both third-party cloud LLMs and on-premises self-hosted large language models

3. Windows Endpoint Client

Deployed on each enterprise Windows terminal, the lightweight client runs silently in the background to execute security policies and collect required audit data locally.

  • Enforces all USB control, antivirus, and network/application restriction policies delivered by the server

  • Performs real-time USB malware scanning and file access blocking natively on the device

  • Captures required activity logs and transmits encrypted data back to the central server

  • Executes AI screen capture and preprocessing workflows for PrivateDLP Pro, with built-in privacy protection mechanisms

Standard Edition Core End-to-End Workflow

For USB Disk Security Standard, the baseline security workflow follows four streamlined, highly reliable steps:

  1. Policy Definition & Deployment

    Administrators configure USB access rules, antivirus scanning schedules, website blacklists/whitelists, and prohibited application rules via the web console. Policies can be applied to all endpoints in bulk or assigned to specific devices and user groups for granular control. The central server stores the finalized rules and queues them for distribution.

  2. Policy Delivery & Local Caching

    The central server pushes configured policies to corresponding Windows endpoint clients via encrypted transmission. Once received, clients cache the full policy set locally, ensuring all security rules remain fully enforced even when endpoints are offline or disconnected from the corporate network.

  3. On-Device Policy Enforcement

    The endpoint client runs continuous, low-overhead background monitoring to enforce all active policies:

  • Blocks unauthorized USB devices entirely, or restricts write access to portable storage to prevent data exfiltration

  • Runs real-time and on-demand virus scans for connected USB drives, isolating malicious files in a dedicated quarantine zone

  • Blocks access to blacklisted websites and prevents prohibited applications from launching or accessing the network

  1. Log Synchronization & Visibility

    The client compiles structured logs of all security events, blocked actions, and device status updates, then syncs the encrypted data back to the central server on a scheduled or real-time basis. Administrators can view, filter, and export all activity records via the web admin console for compliance auditing and security incident tracing.

Extended Workflow for PrivateDLP Pro Edition

PrivateDLP Pro retains the full standard workflow and adds two specialized, advanced workflows for granular data audit and AI-powered behavior analysis, with privacy protection embedded at every step of the process.

1. USB File Transfer Audit & Alert Workflow

  • The endpoint client monitors and logs every file transfer operation between the terminal and connected USB drives, capturing complete metadata including file names, file types, file sizes, timestamps, and associated user/device identifiers.

  • All transfer logs are synced to the central server for permanent, searchable audit records accessible via the web console.

  • When a file transfer matches administrator-defined sensitive file rules (e.g., confidential document types or specific named files), the system instantly triggers a violation alert to notify responsible administrators.

2. Privacy-First AI Screen Audit Workflow

This proprietary workflow delivers intelligent productivity tracking and hidden data leak detection without compromising employee privacy, addressing critical gaps in traditional rule-based DLP tools:

  1. Natural Language Rule Configuration: Administrators define work, idle, and entertainment behavior criteria using plain natural language via the web console, with no complex rule coding or signature configuration required.

  2. Scheduled Low-Impact Capture: The endpoint client captures a lightweight screen snapshot approximately every 60 seconds, with no persistent local storage of raw screenshots.

  3. LLM-Powered Analysis: Screenshots are sent to the configured LLM (default: Gemini) for content classification. For enterprises using self-hosted LLMs, all analysis runs entirely within the corporate network. No screenshot data is ever used for third-party model training.

  4. Productivity Data Aggregation: The LLM returns categorized activity labels (work, entertainment, offline) which are aggregated into time-based productivity statistics and displayed on the admin dashboard.

  5. Automatic Privacy Protection: All routine screenshots are permanently and immediately deleted immediately after analysis is completed, with no residual storage of non-violation screen data.

  6. Violation Response & Evidence Retention: If the LLM detects behavior matching pre-defined violation rules (e.g., uploading confidential data to unapproved cloud storage platforms), the system retains the corresponding screenshot as evidence, triggers an instant admin alert, and stores the evidence per the organization’s configured storage location (S3-compatible cloud, Azure, on-premises storage, or our secure hosted storage).

Key Architectural Advantages

Centralized Scalability

The C/S design allows organizations to manage hundreds or thousands of Windows endpoints from a single web console, with consistent policy enforcement across the entire device fleet and no need for on-site manual configuration.

Uncompromised Endpoint Performance

Heavy processing tasks including log aggregation, AI analysis, and report generation are offloaded to the central server, while the endpoint client maintains an ultra-light system footprint with minimal impact on daily employee device usage.

Offline Reliability

Locally cached policies ensure continuous security protection even when endpoints are disconnected from the corporate network, eliminating security gaps for remote workers or field devices.

Data Sovereignty & Compliance

For PrivateDLP Pro customers, the architecture fully supports on-premises deployment of both the central server and AI model, plus custom evidence storage, enabling enterprises to keep all sensitive internal data within their own controlled environment to meet strict regulatory and data residency requirements.

Layered Privacy-by-Design

Unlike traditional employee monitoring tools that store continuous screen recordings, the architecture’s AI audit workflow is built on a minimum data retention principle: only confirmed violation evidence is stored, and all routine analysis screenshots are destroyed instantly, balancing security oversight with employee privacy.