Qi御QiDefend,是面向上市公司、政企合作单位打造的高等级企业文档加密防护系统,主打无懈可击的全域数据安全防护,抵御外部黑客渗透、内部信息泄露风险,核心用于存放政府合同、涉密商务文件、核心项目资料、财报底稿、商业机密、核心技术文档等高敏感资产,做到访问全留痕、截图行为溯源、操作全程可审计,实现内外部双重安全壁垒。Qi Defend is a high-level enterprise document encryption and protection system designed for publicly listed companies and government-enterprise cooperation units. It focuses on airtight, comprehensive data security protection, resisting external hacker intrusions and internal information leakage risks. It is primarily used to store government contracts, confidential business documents, core project materials, financial report drafts, trade secrets, core technical documents, and other highly sensitive assets, achieving full access traceability, screenshot behavior tracking, and complete auditability of operations, thereby creating dual security barriers both internally and externally.
WHY IT MATTERS
安全不是一堵墙,而是一条覆盖数据全生命周期的控制链。Security is not a wall, but a chain of controls covering the entire data lifecycle.
Qi御 QiDefend 从身份、设备、访问、文档、外发到审计建立纵深防护。即使文件离开原系统,权限、水印和行为记录仍能继续发挥作用,让企业真正掌握核心资产的流向。QiDefend establishes layered protection from identity, devices, access, documents, outbound sharing to auditing. Even if files leave the original system, permissions, watermarks, and behavior records can continue to function, allowing enterprises to truly control the flow of core assets.
01最小权限Core Security Capabilities
人员只获得完成当前职责所需的数据与操作能力。Personnel only obtain the data and operational capabilities required to complete their current duties.
02动态策略Granular Access Control
根据身份、设备、位置和内容敏感级别实时判断访问与外发。Determine access and external sharing in real time based on identity, device, location, and content sensitivity level.
03全程取证Document Watermarking
关键操作保留可检索证据链,支持复盘、审计和责任定位。Key operations retain a traceable evidence chain, supporting review, auditing, and accountability.
Qi御QiDefend,是面向上市公司、政企合作单位打造的高等级企业文档加密防护系统,主打无懈可击的全域数据安全防护,抵御外部黑客渗透、内部信息泄露风险,核心用于存放政府合同、涉密商务文件、核心项目资料、财报底稿、商业机密、核心技术文档等高敏感资产,做到访问全留痕、截图行为溯源、操作全程可审计,实现内外部双重安全壁垒。Qi Defend is a high-level enterprise document encryption and protection system designed for publicly listed companies and government-enterprise cooperation units. It focuses on airtight, comprehensive data security protection, resisting external hacker intrusions and internal information leakage risks. It is primarily used to store government contracts, confidential business documents, core project materials, financial report drafts, trade secrets, core technical documents, and other highly sensitive assets, achieving full access traceability, screenshot behavior tracking, and complete auditability of operations, thereby creating dual security barriers both internally and externally.
核心产品能力Core product capabilities
1. 银行级全域加密存储,抗黑客攻击1. Bank-level full-domain encrypted storage, resistant to hacker attacks
系统采用多层加密隔离架构,文件落盘加密、传输链路加密、权限容器加密三重防护,核心数据分片隔离存储。抵御暴力破解、爬虫窃取、黑客渗透、漏洞嗅探等攻击手段,外部黑客难以窃取容器内原始文件,打造高安全数据保险箱,满足上市公司商业机密保护、政企合同保管的严苛安全诉求。不管是外网入侵、接口劫持,都无法直接获取原始明文资料。The system adopts a multi-layer encryption isolation architecture, with triple protection including encryption for files at rest, encryption for transmission links, and encryption for permission containers, and core data is stored in fragmented isolation. It defends against attacks such as brute force cracking, web crawler theft, hacker intrusion, and vulnerability sniffing. External hackers cannot easily steal the original files within the container, creating a highly secure data vault that meets the stringent security requirements for protecting commercial secrets of publicly listed companies and storing government and corporate contracts. Whether it is external network intrusion or interface hijacking, the original plaintext data cannot be directly obtained.
2. 全行为可溯源,每一次访问完整留底2. All actions are traceable, with a complete record of each visit.
所有人员进入系统,访问、预览、下载、转发、打印、另存、窗口读取全部记录日志。记录访问人账号、设备信息、IP地址、访问时间、操作行为、停留时长,形成不可篡改审计台账。All personnel entering the system will have all access, preview, download, forward, print, save as, and window read actions logged. The logs record the visitor's account, device information, IP address, access time, operational behavior, and duration of stay, forming an immutable audit ledger.
SCENARIO MODEL · SHIELD企业数据纵深防护图QiDefend Scenario Model
从身份、终端、文档到审计建立多层控制,任何外发与访问都必须经过策略判断和全程留痕。Establish multi-layer control from identity, endpoints, and documents to auditing; any external sharing and access must go through policy evaluation and be fully traceable.
安全策略Core Security Capabilities72
权限、外发、水印与设备规则Permissions, external distribution, watermark, and device rules
受护文档Granular Access Control10,000
模拟企业知识资产规模Simulate the scale of corporate knowledge assets
操作留痕Document Watermarking100%
查看、复制、下载与外发审计View, Copy, Download and External Audit
误报水平Enterprise Compliance1.8%
策略校准后的模拟误报占比Proportion of simulated false alarms after strategy calibration
论证模型Evidence Model攻击路径与阻断数据为安全演练场景模拟QiDefend capability evidence and operating model.全部数据为能力展示与场景模拟,不代表真实客户效果All values are capability demonstrations and scenario simulations, not actual customer results.
针对截图、录屏行为做检测留痕,识别用户截屏操作,自动留存行为记录,即便对方截图保存内容,后台也会完整捕获这条操作事件,做到谁看、谁截、什么时间操作全部有据可查。支持日志导出,可用于内控审计、风险溯源、合规举证。Detect and track screenshot and screen recording actions, identify user screenshot operations, and automatically retain behavior records. Even if the other party takes a screenshot to save content, the backend will fully capture this operation event, ensuring that who viewed, who took a screenshot, and when the operation occurred are all traceable. Supports log export, which can be used for internal control audits, risk tracing, and compliance evidence.
针对政府合同、招投标文件、合作协议、财报资料设置分级权限。可以区分:仅预览、禁止下载、禁止打印、限时访问、过期自动失效、设备绑定访问。Set tiered permissions for government contracts, bidding documents, cooperation agreements, and financial reports. It can distinguish: preview only, download prohibited, print prohibited, limited-time access, automatic expiration after a period, and device-bound access.
可以设置部分人员只能查看不能导出;对外协作人员开通临时访问权限,到期自动收回权限;支持多人分权管理,高管、法务、项目人员分配不同访问边界,防止内部越权泄密。就算内部员工账号泄露,也无法越权查看未授权机密文件。It is possible to set some personnel to view only without exporting; grant temporary access permissions to external collaborators, which are automatically revoked upon expiration; support multi-person hierarchical management, assigning different access boundaries to executives, legal personnel, and project staff to prevent internal overreach and data leaks. Even if an internal employee's account is compromised, they cannot access unauthorized confidential files.
4. 涉密文档水印体系Capability 11 · Automation and Control
文档预览时自动加载动态隐形水印+显性水印,水印嵌入访问者身份、时间、设备信息。就算发生截图拍照流出,也可以反向定位泄密源头。水印无法通过简单截图、裁剪去除。Automatically load dynamic invisible watermarks and visible watermarks when previewing documents, embedding visitor identity, time, and device information into the watermark. Even if screenshots or photos are leaked, the source of the leak can be traced. The watermark cannot be removed by simple screenshots or cropping.
5. 政企&上市公司合规适配Capability 13 · Business Applications
适配上市公司内控管理、信息保密要求,满足政企项目合同保管的保密规范。内部可以存放政府采购合同、涉密项目材料、投融资资料、核心商业方案、技术源码资料。支持安全审计报表输出,方便企业内审、第三方核查。Adapted to listed companies' internal control management and information confidentiality requirements, meeting the confidentiality standards for storing government-enterprise project contracts. Internally, it can store government procurement contracts, classified project materials, investment and financing information, core business plans, and technical source code materials. Supports the output of security audit reports, facilitating internal audits and third-party verification.
6. 入侵风险主动告警Capability 15 · Scalable Delivery
SYSTEM FLOW · CONCEPT MODELQi御 QiDefend能力工作流QiDefend Capability Workflow
从需求输入到结果回流的项目机制示意Schematic of the project mechanism from demand input to result feedback
当前节点 / 01Current Stage / 01ACTIVE STAGE
核心产品能力Core product capabilities
1. 银行级全域加密存储,抗黑客攻击 系统采用多层加密隔离架构,文件落盘加密、传输链路加密、权限容器加密三重防护,核心数据分片隔离存储。抵御暴力破解、爬虫窃取、黑客渗透、漏洞嗅探等攻击手段,外部黑客难以窃取容器内原始文件,打造高安全数据保险箱,满足上市公司商业机密保护、政企合同保管的严苛安全诉求。不管是外网入侵、接口劫持,都无法直接获取原始明文资料。 2. 全行为可溯源,每一次访问完整留底 所有人员进入系统,访问、预览、下载、转发、打印、另存、窗口读取全部记录日志。记录访问人账号、设备信息、IP地址、访问时间、操作行为、停留时长,形成不可篡改审计台账。 针对截图、录屏行为做检测留痕,识别用户截屏操作,自动留存行为记录,即便对方截图保存内容,后台也会完整捕获这条操作事件,做到谁看、谁截、什么时间操作全部有据可查。1. Bank-level full-domain encrypted storage, resistant to hacker attacks. The system adopts a multi-layer encrypted isolation architecture, providing triple protection through file-at-rest encryption, transmission link encryption, and permission container encryption. Core data is stored in isolated fragments. It defends against brute-force attacks, crawler theft, hacker infiltration, and vulnerability probing. External hackers find it difficult to steal original files within the container, creating a highly secure data safe that meets the stringent security requirements for protecting the business secrets of listed companies and storing government-enterprise contracts. Whether it is external network intrusion or interface hijacking, original plaintext data cannot be directly obtained.
2. Fully traceable operations, complete records of every access. All personnel entering the system have their access, preview, download, forwarding, printing, saving-as, and window-reading activities fully logged. The system records the user account, device information, IP address, access time, operation behavior, and duration of stay, forming an immutable audit ledger. Screenshots and screen recording behaviors are detected and tracked; user screenshot operations are identified, and behavior records are automatically retained. Even if the other party takes a screenshot to save content, the backend will completely capture this operation event, ensuring that who accessed, who captured, and the time of the operation are all traceable.
前置输入Required Input
项目目标、品牌资料与业务约束Project objectives, brand information, and business constraints
节点产出Stage Output
可进入下一环节的「核心产品能力」成果、配置与过程记录Results, configuration, and process records of 'core product capabilities' that can enter the next stage
验收重点Acceptance Criteria
内容完整、规则可执行、异常有记录,并明确下一节点责任与依赖Content is complete, rules are executable, exceptions are recorded, and the next node's responsibilities and dependencies are clearly defined
能力结构根据产品资料整理 · 非软件界面截图Capability structure derived from product materials · Not a software screenshot
系统内置安全监测引擎,识别异常访问行为:异地陌生IP登录、短时间高频访问涉密文件、批量预览下载、频繁截图录屏行为,实时触发风险告警,推送消息给到安全管理员,可一键冻结对应账号访问权限,阻断泄密风险。The system has a built-in security monitoring engine to detect abnormal access behaviors: logins from unfamiliar IPs in different locations, high-frequency access to confidential files in a short period, batch preview and downloads, frequent screenshots and screen recordings. It triggers risk alerts in real time, sends messages to security administrators, and allows one-click freezing of the corresponding account's access permissions to block data leakage risks.
产品核心优势Core Product Advantages
1. 抗攻击能力强:多层加密隔离架构,抵御黑客入侵、数据窃取,打造近乎无懈可击的机密容器;1. Strong attack resistance: Multi-layer encrypted isolation architecture, resisting hacker intrusions and data theft, creating an almost invincible confidential container;
2. 内外双重防护:既防外部黑客窃取,又防内部人员截图、拍照、拷贝泄密;2. Dual internal and external protection: prevents both external hackers from stealing data and internal personnel from taking screenshots, photos, or copying information that could lead to leaks;
3. 操作行为全留痕:访问、截图、录屏、下载全部记录存档,泄密行为有据可追溯;3. All operational actions leave traces: visits, screenshots, screen recordings, and downloads are all recorded and archived, making any leakage behavior traceable.
4. 高密文档专属存放,适合存放政府合同、上市公司财报、投融资材料、核心商业机密;4. Exclusive storage for highly confidential documents, suitable for storing government contracts, financial reports of listed companies, investment and financing materials, and core business secrets;
5. 细粒度权限体系,灵活管控不同人员的访问边界,临时授权可自动回收;5. Fine-grained permission system, flexibly controlling the access boundaries of different personnel, with temporary authorization that can be automatically revoked;
6. 审计报表完整输出,适配企业内控、合规审计需求。6. Complete output of audit reports, adaptable to corporate internal control and compliance audit requirements.
提示:本系统为安全防护工具,需配合企业内部保密管理制度共同使用。Note: This system is a security protection tool and should be used in conjunction with the company's internal confidentiality management policies.