The modular C/S architecture of USB Disk Security and PrivateDLP delivers a flexible, secure, and user-friendly foundation for enterprise endpoint data protection. The standard workflow addresses core DLP and access control needs for small and mid-sized organizations, while the extended Pro workflow adds intelligent, privacy-compliant auditing and customizable deployment options for enterprises with advanced compliance, productivity, and data security requirements.
USB Disk Security (Standard) and PrivateDLP (Pro) are built on a robust, enterprise-grade Client/Server (C/S) architecture designed to deliver centralized, scalable, and privacy-compliant data loss prevention (DLP) and endpoint behavior management for organizations of all sizes. Optimized for Windows-based enterprise endpoints, the architecture decouples policy administration, backend orchestration, and on-device enforcement, enabling IT and security teams to govern terminal security at scale without compromising endpoint performance or employee privacy.
Architecture Core Components
The system consists of three interconnected, purpose-built layers that work in tandem to deliver full-coverage security governance:
1. Web-Based Admin Console
The unified web management portal serves as the single control plane for all security configurations and audit operations. Accessible via any standard web browser, it eliminates the need for dedicated management software and enables secure remote administration.
Centralized policy configuration for USB access, antivirus rules, network filtering, and application control
Bulk or per-device policy assignment for granular, targeted security governance
Real-time dashboard for audit logs, alert notifications, and employee productivity analytics
Role-based access control for multi-level administrator permission management
2. Central Server Layer
Acting as the orchestration hub of the entire system, the central server bridges the admin console and endpoint clients, handling data synchronization and policy distribution.
Securely stores policy configurations, system logs, and audit data (with customizable storage options for PrivateDLP Pro)
Pushes updated policies to targeted endpoint clients in real time
Processes incoming endpoint logs and triggers automated alert workflows for policy violations
Hosts AI audit integration modules for PrivateDLP Pro, supporting both third-party cloud LLMs and on-premises self-hosted large language models
3. Windows Endpoint Client
Deployed on each enterprise Windows terminal, the lightweight client runs silently in the background to execute security policies and collect required audit data locally.
Enforces all USB control, antivirus, and network/application restriction policies delivered by the server
Performs real-time USB malware scanning and file access blocking natively on the device
Captures required activity logs and transmits encrypted data back to the central server
Executes AI screen capture and preprocessing workflows for PrivateDLP Pro, with built-in privacy protection mechanisms
Standard Edition Core End-to-End Workflow
For USB Disk Security Standard, the baseline security workflow follows four streamlined, highly reliable steps:
Policy Definition & Deployment
Administrators configure USB access rules, antivirus scanning schedules, website blacklists/whitelists, and prohibited application rules via the web console. Policies can be applied to all endpoints in bulk or assigned to specific devices and user groups for granular control. The central server stores the finalized rules and queues them for distribution.
Policy Delivery & Local Caching
The central server pushes configured policies to corresponding Windows endpoint clients via encrypted transmission. Once received, clients cache the full policy set locally, ensuring all security rules remain fully enforced even when endpoints are offline or disconnected from the corporate network.
On-Device Policy Enforcement
The endpoint client runs continuous, low-overhead background monitoring to enforce all active policies:
Blocks unauthorized USB devices entirely, or restricts write access to portable storage to prevent data exfiltration
Runs real-time and on-demand virus scans for connected USB drives, isolating malicious files in a dedicated quarantine zone
Blocks access to blacklisted websites and prevents prohibited applications from launching or accessing the network
Log Synchronization & Visibility
The client compiles structured logs of all security events, blocked actions, and device status updates, then syncs the encrypted data back to the central server on a scheduled or real-time basis. Administrators can view, filter, and export all activity records via the web admin console for compliance auditing and security incident tracing.
Extended Workflow for PrivateDLP Pro Edition
PrivateDLP Pro retains the full standard workflow and adds two specialized, advanced workflows for granular data audit and AI-powered behavior analysis, with privacy protection embedded at every step of the process.
1. USB File Transfer Audit & Alert Workflow
The endpoint client monitors and logs every file transfer operation between the terminal and connected USB drives, capturing complete metadata including file names, file types, file sizes, timestamps, and associated user/device identifiers.
All transfer logs are synced to the central server for permanent, searchable audit records accessible via the web console.
When a file transfer matches administrator-defined sensitive file rules (e.g., confidential document types or specific named files), the system instantly triggers a violation alert to notify responsible administrators.
2. Privacy-First AI Screen Audit Workflow
This proprietary workflow delivers intelligent productivity tracking and hidden data leak detection without compromising employee privacy, addressing critical gaps in traditional rule-based DLP tools:
Natural Language Rule Configuration: Administrators define work, idle, and entertainment behavior criteria using plain natural language via the web console, with no complex rule coding or signature configuration required.
Scheduled Low-Impact Capture: The endpoint client captures a lightweight screen snapshot approximately every 60 seconds, with no persistent local storage of raw screenshots.
LLM-Powered Analysis: Screenshots are sent to the configured LLM (default: Gemini) for content classification. For enterprises using self-hosted LLMs, all analysis runs entirely within the corporate network. No screenshot data is ever used for third-party model training.
Productivity Data Aggregation: The LLM returns categorized activity labels (work, entertainment, offline) which are aggregated into time-based productivity statistics and displayed on the admin dashboard.
Automatic Privacy Protection: All routine screenshots are permanently and immediately deleted immediately after analysis is completed, with no residual storage of non-violation screen data.
Violation Response & Evidence Retention: If the LLM detects behavior matching pre-defined violation rules (e.g., uploading confidential data to unapproved cloud storage platforms), the system retains the corresponding screenshot as evidence, triggers an instant admin alert, and stores the evidence per the organization’s configured storage location (S3-compatible cloud, Azure, on-premises storage, or our secure hosted storage).
Key Architectural Advantages
Centralized Scalability
The C/S design allows organizations to manage hundreds or thousands of Windows endpoints from a single web console, with consistent policy enforcement across the entire device fleet and no need for on-site manual configuration.
Uncompromised Endpoint Performance
Heavy processing tasks including log aggregation, AI analysis, and report generation are offloaded to the central server, while the endpoint client maintains an ultra-light system footprint with minimal impact on daily employee device usage.
Offline Reliability
Locally cached policies ensure continuous security protection even when endpoints are disconnected from the corporate network, eliminating security gaps for remote workers or field devices.
Data Sovereignty & Compliance
For PrivateDLP Pro customers, the architecture fully supports on-premises deployment of both the central server and AI model, plus custom evidence storage, enabling enterprises to keep all sensitive internal data within their own controlled environment to meet strict regulatory and data residency requirements.
Layered Privacy-by-Design
Unlike traditional employee monitoring tools that store continuous screen recordings, the architecture’s AI audit workflow is built on a minimum data retention principle: only confirmed violation evidence is stored, and all routine analysis screenshots are destroyed instantly, balancing security oversight with employee privacy.