Government employees: how to protect sensitive official documents on your computer
Government offices handle files that matter to millions of people: draft policies, RTI applications, tender documents, personnel and service records, grievance data with citizens' details. Many of these sit on an ordinary office desktop or a laptop. This guide explains how to protect sensitive official files, and, just as important, when a third-party tool is not the right answer.
First, check what your department requires
- Classified material follows your ministry's or department's security instructions and the advice of your IT and security officers. Those rules come first, always.
- CERT-In's Guidelines on Information Security Practices for Government Entities (30 June 2023, issued under Section 70B of the IT Act) apply to ministries, departments and their attached and subordinate offices. They include encrypting sensitive or personal data, multi-factor authentication and audits, and have a separate section on employees' responsibilities.
- Official email: use your government (NIC) account for official communication, as your department's policy requires, not personal email.
- Software: install only what your department permits. If you want to use a file-encryption tool, ask your IT cell or CISO first. This page explains what to ask about.
Where encryption helps (unclassified but sensitive files)
- Draft documents before they are final or public.
- Personnel data: service books, ACR/APAR-related notes, salary and leave statements.
- Citizens' data: RTI applications, grievance petitions, beneficiary lists with Aadhaar or phone numbers.
- Procurement: tender comparisons and bid evaluations before award.
- Shared office PCs used by several staff, and computers sent out for repair.
How to protect them (once your IT cell agrees)
- Install Clavis Encrypt. It installs per user, without administrator rights, and works fully offline. It goes online only to check for signed updates, and that check can be switched off in Settings.
- Create a vault with a strong password, and keep the one-time recovery key as your office requires, for example sealed with your section officer.
- Encrypt sensitive files: right-click → Clavis → Encrypt. File names are hidden too.
- Use separate vaults (Pro) for different sections or subjects, each with its own password.
- Back up the encrypted files to the storage your office approves. They stay encrypted there.
What to tell your IT cell about Clavis Encrypt
| Question they'll ask | Answer |
|---|---|
| Does it send data anywhere? | No. Files are encrypted on the computer; there is no account or cloud. The only network use is an optional update check that downloads signed updates. |
| What encryption? | AES-256-GCM for files, Argon2id for passwords, X25519 + ML-KEM-768 (post-quantum) for the recovery key. See the security page. |
| Does it need admin rights? | No. It installs per user; a portable ZIP is also available. |
| Can someone recover files if the password is lost? | Only with the recovery key. The developer cannot. |
| Is it approved for classified data? | No. It is not certified for classified information; follow your department's instructions. |
Questions
How can a government employee protect sensitive official files on a computer?
Follow your department's security instructions first; classified material must stay on approved systems. For unclassified but sensitive files, such as drafts, RTI records and personnel data, encrypt them on your work computer with a tool your IT cell approves. Clavis Encrypt works offline with AES-256-GCM and needs no account.
Can I use a third-party encryption app for classified documents?
Not unless your department has approved it. Classified information must be handled as your ministry's or department's security instructions require, typically on approved, often stand-alone systems. Clavis Encrypt is not certified for classified data.
What do the CERT-In guidelines say for government entities?
CERT-In's Guidelines on Information Security Practices for Government Entities (June 2023, under Section 70B of the IT Act) cover ministries, departments and their offices, and include measures such as encrypting sensitive or personal data, multi-factor authentication and audits, with a separate section for employees.
Does Clavis Encrypt need internet or administrator rights?
No. It installs per user without administrator rights and works offline. It goes online only to check for signed updates, and that can be turned off.
Sources
- CERT-In — Guidelines on Information Security Practices for Government Entities (2023), overview
- MediaNama — CERT-In cybersecurity guidelines for government entities
- Clavis Encrypt — security design (AES-256-GCM, Argon2id)
This guide explains general practice, not legal advice. Laws and rules change; check the current text or ask a lawyer for your situation.