The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Drive Encryption overview

Prev Next

Trellix Drive Encryption features deliver encryption that protects data from unauthorized access, loss, and exposure using preboot authentication and a powerful encryption engine.

The Drive Encryption suite provides multiple layers of defense against data loss with integrated modules that address specific areas of risk.

Drive Encryption allows you to:

  • Enforce access control with pre-boot authentication

  • Use certified encryption algorithms (FIPS, Common Criteria)

  • Support mixed device environments, including solid-state drives

  • Support Trusted Computing Group (TCG) Opal v1.0 self-encrypting drives

Drive Encryption provides protection for individual computers and roaming laptops with Basic Input Output System (BIOS) and Unified Extensible Firmware Interface (UEFI). The software supports UEFI-based tablets and uses a ePO - On-prem Tablet Test tool to verify if the preboot environment responds to the tablet touch interface. For more information about this tool, see KB78050.

The Drive Encryption software includes the encryption software that is installed on client systems, and the managing component on the servers. It is deployed and managed through Trellix ePolicy Orchestrator - On-premises.

Policies determine how Drive Encryption software functions on the user's computer. The disk encryption process is transparent to the user and has little impact on the computer's performance.