Document security is the discipline of making sure the organisation's files, contracts, personnel records, financials, client information, are readable by the people who need them and nobody else, for as long as they must be kept and no longer. For a small organisation the subject is less about products than about four decisions written down: what kinds of documents exist and how sensitive each kind is, who may read and edit each kind, where each kind lives, and when each kind is destroyed. Those four decisions are the data handling policy, and it is one of the six core documents the free policy sheet on this site counts into every organisation's set. This page walks the four decisions in plain terms, what the shared drive gets wrong by default, and where software helps once the policy exists, including what document security software actually adds over the drive you already pay for.
Classification before technology
Every document control fails if nobody has said which documents matter. A workable small-organisation scheme is three tiers: public, anything already shared outside; internal, the default for working files; and restricted, the payroll, the personnel files, the client data, anything whose leak is an incident. The data handling policy names the tiers, gives two examples of each, and states the rule that restricted files live only in restricted locations. That single page of policy does more for document security than any product, because every later decision, access, storage, retention, refers back to it.
Access and the shared drive default
The default state of a shared drive is that everyone can read everything, and organisations discover this at the worst possible moment. The access policy's job is one sentence long: access follows role, restricted folders are opened by named grant, and grants are reviewed when someone leaves or changes role. The leavers review is the line that actually bites, because departed accounts with live access are the commonest audit finding in small organisations. The free sheet counts the access policy in your set and prices the review time honestly at your own hourly figure.
Retention, destruction and the record of both
Keeping everything forever feels safe and is the opposite: every retained file is discoverable, breachable and subject to whatever laws govern its kind. The retention line of the data handling policy says how long each tier is kept and how it is destroyed, and for regulated kinds, health information among them, the floor is set by law rather than preference, which is one of the facts the policy sheet asks about. Hardenvo Pro generates the data handling policy with your tiers, locations and retention answers in it, files it with a review date, and prints the set with your organisation's name when the auditor or the insurer asks.
Questions people ask about document security
What is document security?
Keeping the organisation's files readable by the right people and nobody else, for the right length of time. In practice it is four written decisions, classification tiers, access rules, storage locations and retention, which together form the data handling policy the free sheet counts into your set.
What is the first step for a small organisation?
Classification. Name three tiers, public, internal, restricted, with examples, and state that restricted files live only in restricted locations. Every access grant, storage choice and retention rule then refers to the tiers. The FTC's small business guidance takes the same start-with-the-data approach.
Do I need document security software?
After the policy, sometimes. The drive you already pay for enforces access and versioning if configured to the policy; dedicated software adds watermarking, expiry and audit trails for files that leave the organisation. The document security software guide on this site walks when each is worth paying for.