When a device leaves your hands, the question is not whether you had encryption. It is whether the encryption stays with the data.
Picture this: your laptop goes missing. Maybe it was left somewhere. Maybe it was taken. Either way, someone now has the device and everything on it.
What happens next depends entirely on where your encryption lives.
Software encryption and its limits
Software encryption protects data through the operating system. It runs on the host, depends on the OS being present and intact, and sits above the hardware. If the OS is bypassed or the drive is removed and placed in another machine, the protection software encryption provided is no longer in the picture.
This is not a theoretical gap. It is the scenario that plays out in every device theft, every improper disposal, and every situation where a drive ends up where it should not be.
What hardware encryption changes
Hardware encryption in a TCG Opal self-encrypting drive works differently. The encryption engine is built into the drive controller itself. It encrypts every byte of data written to the drive and decrypts it on read, entirely at the hardware level. The process does not depend on the OS being present or intact. Remove the drive. Connect it to another machine. The encryption holds regardless.
TCG stands for Trusted Computing Group, an industry standards body that developed the Opal Storage Specification to ensure self-encrypting drives offer strong, standardized security across manufacturers. Opal Lock by Fidelity Height supports drives conforming to TCG Opal 1.0, Opal 2.0, Pyrite 1.0, and Pyrite 2.0.
There is no performance overhead. Because the encryption runs inside the drive controller, the host CPU carries none of that load. Encryption and decryption happen in real time with no impact on system performance.
What Opal Lock manages
Opal Lock is a Windows application that activates and manages the hardware encryption already built into compatible TCG Opal and Pyrite drives. It does not add encryption to a standard drive. It gives users and IT teams control over the encryption engine inside a compatible drive.
Drive Status and Info: Opal Lock scans the system, finds compatible Opal drives, and provides drive status and information before any configuration begins.
Setup: Users set up a password to enable locking. From that point, the drive requires authentication to unlock.
Unlock Drives: After setup, a drive can be unlocked through a pre-OS boot environment on the drive, a bootable USB, or a separate unlocked Windows system.
Query Drive: Users can view additional information about the drive’s state, locked ranges, and credentials directly from within the application.
View Audit Log: Opal Lock provides access to the drive’s on-board event log, which is stored on the drive itself rather than in the OS. The log persists through OS wipes and system replacements.
Revert and Cryptographic Erase: Users can remove the lock and keep all data, or revert the drive using a cryptographic erase that makes all data permanently unrecoverable. The operation works using the admin password or the PSID printed on the drive label. A Certificate of Sanitization is generated after a successful erase.
Premium features for IT teams
Opal Lock Premium adds three capabilities specifically useful for larger deployments.
Multidrive Feature: Setup, lock, unlock, and password change operations can be performed across multiple drives in a single click rather than one drive at a time.
Setup/Remove User: A second password with limited authority can be configured, allowing an administrator and an end user to have separate access levels on the same drive.
USB Password: A password saved to a USB drive can be used to authenticate automatically when the USB is inserted, removing the need for manual password entry each time.
Opal Lock Lite also includes the USB Password feature and is designed for users who only need to unlock a compatible external USB Opal drive.
Who it is for
Opal Lock is built for anyone managing self-encrypting drives on Windows, from individuals securing a single laptop to IT teams and MSPs managing a fleet of devices across multiple locations.
If you lose a device, the hardware encryption configured through Opal Lock keeps the data unreadable without the correct credentials, regardless of what machine the drive ends up in. If a drive needs to be retired, cryptographic erase and a Certificate of Sanitization close the decommissioning gap permanently.
The encryption engine is already inside compatible drives. Opal Lock activates it and manages it from first setup to final erase.
Compare Opal Lock editions at fidelityheight.com/shops/
Ready to buy
Secure your drives. Buy your license now.
Activate hardware encryption on compatible Opal drives in minutes. Select your edition and complete purchase below.