GravityZone add-on

Full Disk Encryption, managed from the console you already run

GravityZone Full Disk Encryption protects business data and cuts the risk of accidental loss or theft with the native, proven encryption already built into Windows and macOS - BitLocker and FileVault - switched on, enforced and recovered from the same GravityZone console as the rest of your endpoint security.

  • 0 new agents

    Nothing extra to deploy

    no extra agent and no key management server - the Bitdefender agent you already run does the work

  • Any tier

    Add-on to every solution

    to every GravityZone endpoint security solution, enabled per policy

0 native enginesBitLocker and FileVaultdriven by GravityZone rather than replaced by a third-party driver
0 consoleKeys, status and reportsEndpoint protection, encryption status, compliance reporting and recovery keys in GravityZone Control Center
GDPR, HIPAA, PCI DSSData-at-rest requirements metwith encryption-specific reports to prove it at audit time

Three jobs

What full disk encryption is for

The three outcomes the module delivers, in the order a lost laptop makes them matter.

01 / 03

Protect data, prevent loss

Protect confidential business data and prevent accidental loss, unauthorised access or theft with native encryption for endpoint hard drives.

  • The whole drive encrypted, not selected folders
  • Useless to whoever finds or steals the device
  • Boot and non-boot volumes, both covered

02 / 03

Achieve regulatory compliance

Meet the data-at-rest requirements of GDPR, HIPAA, PCI DSS and more, with encryption-specific reports to demonstrate it for audit.

  • Encryption status per endpoint and per volume
  • Compliance reports built for the auditor, not the admin
  • Non-compliant devices surfaced, not assumed

03 / 03

Integrated, centralised management

Easy-to-use encryption management from the same centralised cloud or on-premises console you use for GravityZone endpoint security.

  • No separate encryption console to learn or license
  • Encrypt, decrypt and recover from the same policy editor
  • Recovery keys held by GravityZone, not on a sticky note

Capabilities

Safeguard business data with native encryption

Comprehensive data protection and compliance. Every screen below is the GravityZone console or the prompt your users actually see.

GravityZone policy Encryption module switched on, with Decrypt and Encrypt options and a checkbox to skip the pre-boot password when a Trusted Platform Module is active

Native, Proven Encryption

GravityZone Full Disk Encryption leverages the native encryption mechanisms provided by Windows (BitLocker) and macOS (FileVault and diskutil) to ensure compatibility and performance. There is no additional agent to deploy and no key management server to install - the module is a toggle in the policy, and the choice to encrypt or decrypt is one radio button.

  • BitLocker on Windows, FileVault and diskutil on macOS - the OS vendor's own engine
  • Encrypt or decrypt volumes from the policy, with GravityZone handling the whole process
  • Optionally skip the pre-boot password where a Trusted Platform Module (TPM) is active
Endpoint Encryption Status report with a pie chart of compliant versus non-compliant endpoints and a table filtered to non-compliant devices showing volumes encrypted per policy

Reporting and Compliance

Encryption-specific reports provide visibility and control and help prove regulatory compliance - which endpoints are compliant with their encryption settings, which are not, and how many volumes on each are done.

macOS Encrypt with FileVault prompt asking the user for system credentials to encrypt the drive

Pre-boot Authentication Enforcement

Pre-boot authentication prevents anything being read from the hard disk - the operating system included - until the user has proven they hold the correct password. That is a secure, tamper-proof environment outside the operating system, acting as a trusted authentication layer.

How it works

From a policy toggle to an encrypted, recoverable drive

The whole sequence runs from GravityZone. Minimal intervention is required from users, and none from a second product.

  1. 1

    Enable the module

    Switch Encryption on in the GravityZone policy for the endpoints you want covered and choose Encrypt. No additional agent, no key server.

    A few clicks in the policy

  2. 2

    The user sets a pre-boot password

    On the next policy sync the endpoint prompts the user for the password that will be required before the disk can be read. Where a TPM is active you can choose not to ask.

    Windows and macOS

  3. 3

    Volumes encrypt in the background

    BitLocker or FileVault encrypts boot and non-boot volumes while the machine stays in use. GravityZone handles the entire process and reports progress.

    Native OS engine

  4. 4

    Keys are stored centrally

    GravityZone stores the recovery keys needed to unlock a volume if a user forgets the password - and lets IT block or unblock an encrypted device remotely.

    Recovery from the console

  5. 5

    Compliance is reported

    The Endpoint Encryption Status report shows compliant and non-compliant endpoints and the volumes on each, ready for the auditor.

    GDPR, HIPAA, PCI DSS

Requirements

What it needs and what it covers

Two components, both of which you already have if you run GravityZone.

13 requirements

What it needs and what it covers
RequirementWhat applies
1Components3 itemsGravityZone Full Disk Encryption uses the following components.
The same cloud or on-premises console you use for endpoint security
Bitdefender Endpoint Security Tools, installed on Windows, Linux and Mac endpoints
Key management serverNone required - GravityZone stores the recovery keys
2Encryption engines3 itemsNative, proven mechanisms from the operating system vendor.
BitLocker
FileVault and diskutil
Optional - skip the pre-boot password where a TPM is active
3What is encrypted and reported7 itemsWhole volumes, and the evidence that they are.
Boot volumesEncrypt and decrypt from the policy
Non-boot volumesEncrypt and decrypt from the policy
Pre-boot authenticationEnforced - nothing on the disk, including the OS, is readable until the password is confirmed
Recovery keysStored by GravityZone, used to unlock a volume when a user forgets the password
Remote block and unblockEncrypted devices can be blocked and unblocked from the console
Compliance reportingEndpoint Encryption Status: compliant and non-compliant endpoints, volumes encrypted per device
Regulations addressedGDPR, HIPAA, PCI DSS and other data-at-rest requirements

Encryption itself uses the operating system's native mechanism, so the platforms encrypted are the platforms that ship one - Windows with BitLocker and macOS with FileVault. Ask us before planning a rollout on an edition of Windows that does not include BitLocker.

Why Bitdefender

Why choose GravityZone Full Disk Encryption

A native encryption solution that encrypts the hard drives on your endpoints to protect company data from accidental loss or theft and meet compliance regulations - an optional add-on to the GravityZone platform that unifies prevention, protection, detection and response across endpoints, networks, email and cloud.

Single console for endpoint security and encryption

GravityZone Control Center is one centralised console for protecting every endpoint against malware and targeted attacks, managing compliance reporting, and recovering encryption keys. That simplicity is what lets security staff stay focused and work efficiently.

Protecting business assets, limiting risk

Data is usually the most important asset a business has, and losing it can be detrimental. Full Disk Encryption limits that risk and helps the organisation meet its compliance obligations rather than explain a breach.

Simplified, efficient security

Deploys simply and intuitively with no additional management console. IT can encrypt and decrypt boot and non-boot volumes in a few clicks while GravityZone handles the whole process, with minimal intervention from users - and GravityZone stores the recovery keys for when a password is forgotten.

In production
With full disk encryption, it is easy to manage the BitLocker encryption keys from the GravityZone console. With more people working remotely, it is useful that we can manage the blocking and unblocking of encrypted devices remotely.
Mathieu Barre, IT Manager, Mews Partners

Independent evaluations

The platform underneath, judged by people who publish their methodology

Full Disk Encryption is a module of GravityZone. These are the evaluations of the platform it runs on, each with the year it was published.

AV-Comparatives 2025 Endpoint Prevention and Response test result for Bitdefender

Top protection, lowest TCO

AV-Comparatives 2025 Endpoint Prevention and Response Test: Bitdefender achieved top breach prevention and the lowest total cost of ownership, and was the only vendor to block 100 percent of attacks during the first stage.

MITRE ATT&CK Evaluations 2024 badge

High visibility, minimal noise

MITRE ATT&CK Evaluations 2024: 100 percent analytical coverage for both Linux and macOS, with zero false positives in both cases.

AV-TEST Award 2023 for Best Protection and Best Performance, business users

Best Protection and Best Performance

AV-TEST Award 2023: GravityZone Endpoint Security took both Best Protection and Best Performance in the business users category.

Forrester Wave 2024 Strong Performer badge for endpoint detection and response

Strong Performer in EDR

Named a Strong Performer in the Forrester Wave 2024 report on EDR platforms.

Gartner Peer Insights Customers' Choice 2026 badge

Customers' Choice 2026

A Customers' Choice in the 2026 Gartner Peer Insights Voice of the Customer for Endpoint Protection Platforms - the rating that comes from verified users rather than analysts.

Gartner Magic Quadrant for Endpoint Protection, May 2026, showing Bitdefender in the Visionaries quadrant

Visionary 2026

Positioned as a Visionary in the 2026 Gartner Magic Quadrant for Endpoint Protection Platforms.

Questions

Full Disk Encryption, answered

Make the next lost laptop a non-event

Tell us which GravityZone tier you run and how many endpoints, and we will quote Full Disk Encryption alongside it. Not on GravityZone yet? Start with a free trial of the platform and add the module when you are ready. Prices are for licences only and do not include implementation services.