Breaking: The USB stick grew a control towerFIPS 140-3 meets Kansas pragmatismHardware sale, software relationshipBreaking: The USB stick grew a control towerFIPS 140-3 meets Kansas pragmatismHardware sale, software relationship

Company profile / Cybersecurity / Overland Park

DataLocker Put a Panic Room Inside a Hard Drive - Then Built the Control Tower Around It

The Kansas security company learned that encrypting a drive was only half the job. The bigger business is helping governments and enterprises control what happens after the USB stick walks out the door.

A USB drive can disappear into a jacket pocket before an IT administrator has finished saying “acceptable use policy.” DataLocker built a business around that uncomfortable fact. The Overland Park, Kansas company makes encrypted flash drives and external disks for organizations that cannot simply shrug when portable data goes missing. Its products scramble files in dedicated hardware, put authentication on the device, and, when paired with SafeConsole, let administrators enforce rules long after the drive has left headquarters.

That combination matters because removable media lives in a stubborn corner of computing. Cloud storage won the office, but it did not eliminate air-gapped factories, field teams, medical equipment, evidence transfers, defense systems, offline backups, or the legal archive that still arrives on optical media. In those places, a physical drive is not nostalgia. It is infrastructure with legs.

2007Founded after a chance meeting in Korea
35+Patents reported by the company
3Active FIPS 140-3 Level 3 modules listed by NIST

The drive is the door. SafeConsole is the building manager.

The hardware is easy to understand. The DL4 FE external drive uses AES-256-XTS encryption, a color touchscreen, brute-force defenses, and a metal enclosure. It can operate without installing unlocking software on the host computer. The K350 and Sentry 5 shrink the idea into rugged flash drives. The newer DL GO aims lower in the market, pairing automatic hardware encryption with optional Windows Hello or Touch ID sign-in.

DataLocker DL4 FE encrypted external drive with its touchscreen illuminated
Small screen, serious consequences. The DL4 FE asks for credentials on the drive itself, keeping the host computer out of the unlocking conversation.

But a locked drive is only one device. A chief information security officer thinks in fleets. SafeConsole can provision encrypted drives, enforce password policies, keep an inventory, log device actions and file movement, and remotely lock or wipe supported hardware. PortBlocker flips the problem around by rejecting unapproved USB devices at endpoints. An anti-malware module scans files as they move. SafeCrypt encrypts local or cloud-synced folders. EncryptDisc serves the unfashionable but durable world of encrypted CDs, DVDs, and Blu-ray archives.

This is DataLocker’s clearest difference from a consumer encrypted drive or BitLocker To Go. The sale does not end at the object. SafeConsole is available in cloud and on-premises versions, giving security teams a recurring control plane and giving DataLocker software revenue after the hardware ships. Public pricing illustrates the ladder: the company lists SafeConsole Basic at $600 a year and Professional at $1,500, while larger deployments and add-on modules are quoted. A DL4 FE starts at $471.99 on the company’s page, and high-capacity SSD versions can run into thousands.

“Complexity is the enemy of security.”Jay Kim, DataLocker CEO

The acquisition that changed the center of gravity

DataLocker began in 2007, when Jay Kim, David Kim, and Hangsook Kim met at a hotel in Korea and pursued an encrypted-storage idea on what Jay later called a shoestring budget. Early recognition came at CES. Funding databases record roughly $1.6 million in outside capital, including a $1.2 million 2010 round meant to help develop faster USB storage. That is modest venture funding by cybersecurity standards, and the company remained private.

The more revealing events arrived later. DataLocker acquired BlockMaster and its SafeConsole service in 2015. In 2016, it joined Kingston in splitting IronKey assets: Kingston took USB technology while DataLocker acquired IronKey Enterprise Management Services. The sequence reads like a change of mind about where value accumulates. Making a tamper-resistant drive is useful. Owning the system that manages many brands and generations of drives is stickier.

That is the move worth copying. DataLocker did not abandon hardware; it wrapped hardware in policy, compliance, administration, and support. Each part makes the others easier to sell. FIPS-validated devices open government procurement. A management console helps a customer standardize more devices. More devices make audit and remote controls more valuable. A reseller network carries the bundle into accounts a 52-person company could not cover alone.

What failed first

Not the cryptography - the fingertips

Independent reviewers found the honest tradeoff. TechRadar praised the DL4 FE’s security credentials and software-free operation, then called it expensive, slow, and difficult to operate with adult fingers. The Gadgeteer liked its security and everyday use after unlocking, but repeatedly mistyped passwords on the small resistive touchscreen. DataLocker’s product documentation now explicitly explains that the screen responds to a precise press from a fingertip, card edge, or retracted pen.

Close product view of the DataLocker DL4 FE touchscreen and metal enclosure
The first breach was ergonomic. Reviewers respected the lock and wrestled with the tiny doorbell. The current screen is designed for precise taps, including while wearing gloves.

The critique does not sink the product; it defines the conditions under which the premium makes sense. A creative studio moving replaceable video files may prefer a much faster commodity SSD. A defense contractor carrying controlled information may gladly trade transfer speed for a validated cryptographic module, tamper response, audit history, TAA-compliant sourcing, and an administrator who can disable the device. Security has a price, but it also needs a threat model.

It works when...

Data must cross an air gap, leave a managed network, satisfy procurement rules, survive field use, or remain traceable after it leaves an employee’s hands.

It does not when...

Files stay inside managed cloud systems, low cost and raw speed dominate, or nobody will maintain policies, recovery accounts, inventories, and incident procedures.

Certification is the boring moat

DataLocker’s market position sits between storage manufacturers and endpoint-security platforms. Competitors include Apricorn, iStorage, SecureData, Kingston IronKey hardware, and Microsoft’s built-in BitLocker To Go. Larger security suites can control ports, while commodity drives can encrypt cheaply. DataLocker’s pitch is that buyers should not stitch those pieces together: one vendor can supply validated removable storage, fleet management, port control, malware scanning, audit, and recovery.

The slow, expensive work is certification. NIST’s public database lists DataLocker’s DL4FE and K350 as active FIPS 140-3 Level 3 hardware modules validated in November 2025, and Sentry 5 in January 2026. The new Sentry 5 also supports CAC and PIV credentials used by federal agencies, plus YubiKey PIV for commercial deployments. Those facts are not glamorous, but for buyers whose purchasing rules demand validated cryptography and traceable sourcing, they remove an objection before a salesperson enters the room.

DataLocker says two-thirds of Fortune 100 companies use its technology. It does not publish customer names, device counts, or audited revenue. Third-party business databases estimate annual revenue around $14 million and a team near 52 people; treat those as directional, not reported results. The more reliable signal is the breadth of the catalog and the company’s continuing investment in validations, management software, and reseller distribution.

The small-business experiment

In September 2025, DataLocker launched DL GO and MySafeConsole for individuals and small teams. The package keeps hardware encryption but removes some enterprise ceremony: optional familiar biometrics, a free management account, password recovery, audit, and remote disable. It is an attempt to take the logic of SafeConsole down-market without making a five-person firm pretend it has a federal security office.

That move may be DataLocker’s hardest product test. Big institutions can tolerate training, procurement cycles, and premium prices because compliance is compulsory. Smaller teams compare secure drives with cheap USB sticks, cloud links, and software already on their laptops. DL GO works only if the setup is genuinely easier than the bad habit it replaces. DataLocker’s own quick-start guide warns that skipping management also means giving up password reset and important security updates. Convenience is not decoration here; it is part of the security model.

The copyable playbook
  • Find the physical edge case. DataLocker serves data that cannot remain inside the neat boundary of cloud and corporate networks.
  • Pair the object with a control plane. Fleet policy, audit, recovery, and remote action turn a one-time device sale into an ongoing relationship.
  • Make compliance a product feature. Certifications, sourcing, reports, and erasure records shorten the buyer’s internal argument.
  • Use partnerships for reach. Kingston, anti-malware technology, and global resellers expand capability without requiring a giant payroll.
  • Test the human interface as hard as the cipher. A mistyped password can defeat adoption long before an attacker defeats AES.

There is also a warning in this playbook. A control plane creates obligations. If administrators never review logs, rehearse recovery, remove departed users, or test remote-disable procedures, the console becomes expensive wallpaper. If a managed device must reach a server but spends its life in an air-gapped room, policy design has to account for that reality. And if employees route around an awkward approved drive with personal cloud accounts, nominal compliance can make the real system less visible. DataLocker can provide the mechanisms; the customer still has to operate them. The product works best where somebody owns removable-media policy, the value of the data exceeds the convenience tax, and buying teams understand exactly which validation their contract requires.

The lesson is not that every hardware company needs a dashboard. It is that products become durable when the surrounding workflow is harder to replace than the object. DataLocker’s drives can lock themselves, erase their keys, and resist tampering. The more consequential achievement is organizational: the company made a USB stick answerable to policy after it crossed the front door.