Frequently Asked Questions

Find Answers To Your Questions

What is AES XTS 256-Bit Hardware Encryption?

AES stands for Advanced Encryption Standard, and is a specification standard using a strong encryption algorithm implemented by the National Institute of Standards and Technology (NIST) for the security of data. It is widely trusted worldwide, used for the protection of data by governments, military and enterprise organizations.

 

256-Bit is the strongest standard for AES key length and refers to the size of the encryption key. A 256-bit key has 2 to the 256th possible combinations, meaning it is computationally infeasible with current and foreseeable technology to crack. It is considered suitable for classified and highly sensitive data.

 

Hardware Encryption, as opposed to Software Encryption, is encryption that happens inside a secure crypto chip within the device. The key never leaves the device, and it does not rely on a computer's CPU. Hardware encryption is often required for compliance (FIPS, CJIS, HIPAA, etc.). Hardware Encryption is much safer than Software Encryption.

 

In addition, XTS Mode stands for XEX-based Tweaked CodeBook mode with ciphertext Stealing, and it is specifically designed for encrypting data at rest on storage devices. This is important because it encrypts each data block independently, prevents pattern leakage (important for disk encryption), and protects against block relocation attacks.

 

In Summary, AES-XTS 256-Bit hardware encryption means that data is encrypted using the strongest AES key length, in the correct disk-encryption mode (XTS), and the encryption is performed inside a dedicated secure hardware processor within the device itself.

 

iStorage / Kanguru provides several Brands using AES XTS 256-Bit hardware encryption for maximum protection, along with a variety of other certifications and compliance specifications. 

 

Learn more about how iStorage/Kanguru products protect data with AES XTS 256-Bit Hardware Encryption

What is Digitally-Signed Secure Firmware?

Firmware is the software component on a hardware device where data and instructions are stored and operate. Because it is the "brain" of the device, it can be a target for hackers. Savvy bad-actors could manipulate the firmware of some USB devices (including printers, keyboards, cameras and computer mouse) and use it to introduce dangerous and destructive malware into an organization's network.

 

Digitally-signed, secure firmware devices means that the device self-checks every time it is plugged in, to ensure that it's signature has not been manipulated. If the firmware does not match its digital signature, the device will shut down, rendering a hack useless. This makes digitally-signed, secure firmware devices a very strong contender for white-listing as an increased option for protecting the networks and infrastructure of an organization. Secure firmware adds another level of security and helps create stronger security policies.

 

 

Learn More about iStorage/Kanguru's Digitally-Signed, Secure Firmware

 

What is a Physical Write-Protect Switch?

Sometimes you may want a storage drive to be read-only. There are several reasons to do so. Many Kanguru drives have a built-in physical write-protect switch that makes it very easy to switch to "read-only mode". Rather than having to change settings and reboot, the physical write-protection switch feature turns the drive into a "read-only" mode immediately. When the drive is plugged into a computer, files can only be read. Files cannot be saved over or rewritten to the drive, protecting the drive's contents from being overwritten or deleted.

 

This is also a great feature for making adjustments to a computer that might be compromised by a virus or infected, since nothing can be written to the drive.

 

Learn More about the Physical Write Protect Switch

 

See Kanguru Drives With A Physical Write-Protect Switch

What Are Your Best Devices for Data Security?

iStorage / Kanguru offers a wide-range of security products to meet many different requirements, including flexible and scalable solutions for a variety of compliance, security requirements, and budgetary needs.

 

For Highly-Regulated Organizations

 

For highly-regulated organizations or environments that must meet top-security standards and requirements, our high-certified solutions are best. All of our secure devices use AES XTS 256-Bit Hardware Encryption. Some devices are even IP68 Rated for waterproof, dust-proof, tamper-proof and brute-force protected.

 

iStorage datAshur PRO+A and PRO+C Flash Drives (FIPS 140-3, Level 3 Certified, TAA Compliant, CMMC, IP68 Certified Water & Dust-Resistant, Crushproof, Independent User & Admin PINs)

 

Kanguru Defender 3000 (FIPS 140-2, Level 3 Certified, TAA Compliant, Remotely Manageable, IP68 Rating-Waterproof/Tamper Proof, CMMC)

 

Kanguru Defender Elite300 (FIPS 140-2, Level 2 Certified, TAA Compliant, Remotely Manageable)

 

Kanguru Defender HDD/SSD350 (FIPS 140-2, Level 2 Certified, TAA Compliant, Remotely Manageable)

 

KRMC-Hosted or On-Premise Edition Remote Management for Kanguru Defender Drives

 

Kanguru Defender SED300 SATA / NVMe (FIPS 140-2, Level 2 Certified, TAA Compliant)

 

iStorage datAshur PRO2 (FIPS 140-2, Level 3 Certified, Common Criteria EAL5+ Certified Secure Microprocessor, IP68 Certified, Independent User & Admin PINs)

 

iStorage datAshur PRO (FIPS 140-2, Level 3 Certified, NLNCSA DEP-V, NATO Restricted, IP68 Certified Water/Dust-Resistant, Independent User & Admin PINs)

 

iStorage diskAshur PRO2 (FIPS 140-2, Level 2 Certified, NCSC CPA, NLNCSA BSPA, NATO, TAA Compliant)

 

iStorage diskAshur DT2 (FIPS 140-2, Level 3 Certified, NCSC CPA, NLNCSA BSPA, NATO Restricted, TAA Compliant)

 

 

Data Security for Non-Regulated Organizations

 

For organizations that are not necessarily required to meet certain regulations, but still looking to use high-security devices, iStorage/Kanguru offers solutions with the same attention to security as our certified models.

 

Kanguru Defender Elite30 (TAA Compliant)

 

Kanguru Defender HDD or SSD 35 (TAA Compliant)

 

iStorage diskAshur M2 (TAA Compliant)

 

iStorage datAshur Personal2

 

Do iStorage / Kanguru Products Meet FIPS 140-3 Certification Requirements?

Yes!  iStorage/Kanguru offers highly-certified data encryption solutions with FIPS 140 Certification for organizations that must meet high-security requirements, including the very latest FIPS 140-3 Certification. In addition, many other iStorage/Kanguru products are pending the latest FIPS 140-3, Level 3 Validation.

 

FIPS 140-3, Level 3 Certification  

iStorage/Kanguru has just released two new hardware encrypted flash drives that offer the very latest in FIPS certification. The iStorage datAshur PRO+C and iStorage datAshur PRO+A have both been released with the newest FIPS 140-3, Level 3 Certification representing ultimate data protection to NIST highest standards. 

 

FIPS 140-2, Level 3 and Level 2 Certifications

Many iStorage secure drives and Kanguru Defender drives are FIPS 140-2, Level 3 Certified, or Level 2:

Kanguru Defender 3000 Encrypted Flash Drive

Kanguru Defender Elite300 Encrypted Flash Drive

Kanguru Defender HDD or SSD350 External Encrypted Drives

Kanguru Defender SED300 NVMe or SATA Internal Self-Encrypting Drives

iStorage datAshur PRO2 Pinpad Protected Encrypted Flash Drive

iStorage datAshur PRO Pinpad Protected Encrypted Flash Drive

iStorage diskAshur PRO2 HDD or SSD Pinpad Protected Encrypted Drives

iStorage diskAshur DT2 Pinpad Protected Encrypted Hard Drive

 

 

FIPS 140 Government Certification: Why It Matters

 

Learn more about iStorage / Kanguru Certifications at iStorage.com

 

Does iStorage / Kanguru Meet CMMC Requirements?

Yes.  iStorage/Kanguru meets CMMC requirements. IStorage is CMMC level 1. CMMC (Cybersecurity Maturity Model Certification) does not certify a specific storage device. Instead, it is a requirement for organizations to implement security controls (based largely on NIST SP 800-171) to protect Controlled Unclassified Information (CUI).

In short, iStorage/Kanguru hardware-encrypted drives help organizations meet CMMC requirements by protecting Controlled Unclassified Information with FIPS-validated AES-256 encryption, strong authentication, and secure management of removable media.

 

How iStorage/Kanguru Products Help Meet CMMC Requirements

 

1. Encryption of Data at Rest

 

CMMC requires strong cryptography to protect CUI.

 

Most iStorage / Kanguru secure drives use:

  • AES-XTS 256-bit hardware encryption
  • FIPS-validated cryptographic modules

 

These devices encrypt all data automatically with AES-XTS 256-bit hardware encryption, meeting federal encryption expectations for safeguarding sensitive data.

 

Relevant CMMC control areas:
SC.L2-3.13.11 – Cryptographic protection
MP.L2-3.8.6 – Protecting media
IA.L2-3.5 – Identification and authentication

 

 

 

2. FIPS Validation (Critical for CMMC Environments)

 

Many DoD environments require FIPS-validated encryption modules.

FIPS validation ensures the encryption module has been tested through the federal cryptographic validation program.

 

This supports:
SC.L2-3.13.11
IA.L2-3.5.3
IA.L2-3.5.4

 

 

 

3. Strong Authentication for Removable Media

 

Many CMMC policies require access control for removable storage devices.

 

iStorage / Kanguru devices use:

PIN-authenticated access via onboard keypad

Separate admin and user PINs

Brute force protection

Auto-lock and self-destruct reset

These controls prevent unauthorized access if a drive is lost or stolen.

 

Relevant controls:
IA.L2-3.5.1 – Identification
AC.L2-3.1 – Access control
MP.L2-3.8.3 – Controlled use of removable media

 

 

 

4. Tamper Protection & Physical Security

Many iStorage devices include:

  • Epoxy-sealed internal components
  • Tamper-evident designs
  • Brute-force protection

These protections help satisfy media protection and device security controls.

 

Relevant controls:
PE.L2 – Physical protection
MP.L2 – Media protection
 

 

5. Remote Device Management (Important for CMMC Audits)

The Kanguru Defender platform is supported by Kanguru Remote Management Console (KRMC):

  • Centralized management
  • Policy enforcement
  • Device tracking
  • Remote wipe

This helps organizations enforce removable media policies and maintain audit visibility.

 

Relevant controls:
AU.L2 – Audit and accountability
CM.L2 – Configuration management
MP.L2 – Media control

 

Learn more about iStorage / Kanguru Certifications at iStorage.com

 

Do iStorage / Kanguru Products Meet TAA Compliance?

Yes!  Most Kanguru products including hardware encrypted drvices, non-encrypted devices, and KanguruClone duplicators meet TAA Compliance for government purchases unless otherwise stated. The TAA (Trade Agreements Act) focuses on manufactured products that must meet certain criteria for purchase by government funds, ensuring clients that the products are assembled in the U.S.A. or other approved, TAA-designated countries.

 

in addition, several iStorage products are TAA Compliant as well.

 

Learn more about Kanguru products and TAA Compliance

What Encryption Standards Are Used In iStorage / Kanguru Devices?

iStorage and Kanguru encrypted devices use advanced AES (Advanced Encryption Standard) with XTS mode and 256-bit keys (AES-XTS 256-bit hardware encryption) to protect sensitive data at rest. This is a government-grade encryption standard widely trusted by organizations handling confidential, regulated, and mission-critical information. Because encryption is performed directly on the device (hardware-based encryption), data is automatically secured in real time without relying on software, eliminating many common vulnerabilities and performance slowdowns.

 

AES-XTS 256-bit encryption is specifically designed for securing data on storage devices such as USB drives and external SSDs, providing enhanced protection against unauthorized access, data breaches, and brute-force attacks. iStorage and Kanguru products are built to meet or exceed stringent compliance requirements, including FIPS validation (on select models), making them ideal for industries such as healthcare, finance, government, and defense.

 

iStorage and Kanguru devices deliver high-assurance, standards-based encryption that keeps your data protected wherever it goes, without compromising usability or speed.

 

Learn more about Kanguru Defender Hardware Encrypted USB Devices

 

Learn more about Kanguru Defender Hardware Encrypted SED Internal Drives

 

Learn more about iStorage Hardware Encrypted Devices

How does KRMC work?

KRMC (Kanguru Remote Management Console) is a remote management platform that allows Security Policy Admininistrators, Data Security Officers and Managers to manage the permissions access, usage, location and security settings of all of their organization's Kanguru Defender secure drives. There are 2 types of platforms available: KRMC-Hosted, and KRMC-On-Premise. Both platforms have a variety of tiers for different types of control over Defender drives, and various levels of management and sub-management can be assigned.

 

Visit the Kanguru Remote Management Suite

 

Learn More About KRMC

Does KRMC work with all of your drives?

Currently KRMC only works with Kanguru Defender Hardware Encrypted Drives, but we are developing a solution to provide KRMC remote management for our iStorage drives as well. We anticipate this to be completed sometime in Q4 of 2026.  If you would like to be kept up to date on the progress, sign-up for our Newsletter to stay informed with our updates. You can also connect with us on Linkedin  and  facebook for regular updates and announcements.

What is the difference between your KRMC-Hosted, and KRMC On-Premise Editions?

KRMC-Hosted is a hosted online version of remote management for Defender hardware encrypted drives, allowing an administrator to manage the security aspects of secure drives. It is hosted on Kanguru's first-class secure servers. Using KRMC requires purchase of a 1, 2, or 3 year license to manage drives. A KRMC-Hosted account can be easily accessed directly from the menu on our website: www.kanguru.com, on the right side of the navigation menu. Once logged in, you can begin managing all Kanguru Defender drives that have been assigned to your KRMC account. Note: you can manage Defender drives remotely, provision, and manage many account permissions, however KRMC does not provide access to the data, which remains secure on the drive. Learn More About KRMC-Hosted.

 

KRMC On-Premise is for larger corporations who may be required to meet specific security compliance or regulations with an internally-installed system for remote management. KRMC On-Premise offers all of the same benefits of KRMC-Hosted, but it is self-hosted on the organization's secure servers. Learn More About KRMC On-Premise.

How do Kanguru Defender Drives work with Remote Management?

Kanguru Remote Management Console (KRMC) is a separate interface that allows IT Administrators and Data Security Officers to manage assigned Kanguru Defender hardware encrypted drives remotely - anywhere in the world. Sold separately as a management feature for Kanguru hardware encrypted drives, KRMC is an administrator account that Kanguru Defender drives can be assigned to for full remote management capability. 

 

Every Kanguru Defender Secure USB drive is independent, secure, and protected with AES 256-Bit XTS-Mode Hardware Encryption built in. However, the drives have the ability to be remotely-managed with KRMC if it is enabled in the settings on the drive by an administrator.  This allows an organization to provision drives and remotely manage them once purchased by their organization. However, all data on the Defender drives remains secure within the drive itself, inaccessible through KRMC. An administrator can use Kanguru Remote Management to monitor location, restrict domains, message users, change passwords, and even delete lost or stolen drives using KRMC, along with many other security features. This provides an excellent "checks and balances" for enforcing strong security policies throughout an organization.

 

See all of our Kanguru Defender hardware external encrypted drives

 

See All Kanguru Remote Management Console (KRMC) options

What are Kanguru Defender SEDs (Self-Encrypting Drives?)

Kanguru Defender SEDs are internal, hardware encrypted solid state drives that not only can lock down the data on the drive, but the OS of the computer as well, providing an added benefit over external hardware encrypted drives. These drives deliver full disk data security at rest, keeping your operating system locked and protected.  SED stands for Self-Encrypting Drive. These drives are ideal for securing data on computers, laptops, and tablets. 

Several of the Kanguru Defender SEDs are FIPS 140-2 Certified for organizations like Government, Defense, and others who may be required to meet certain highly-regulated requirements. Kanguru also ensures TAA Compliance.

Kanguru provides convenience with both NVMe SEDs for excellent performance, as well as legacy SATA SEDs for flexibility in legacy environments.

Kanguru Defender SEDs also contain digitally-signed secure firmware for added protection against malware and other threats.

 

Learn more about Kanguru Defender SEDs here

Are iStorage Encrypted Drives remotely manageable?

The short answer is no, but we are working on integrating our Kanguru Remote Management Console (KRMC) with iStorage pinpad encrypted drives. Currently KRMC only works with Kanguru Defender Hardware Encrypted Drives, but we are developing a solution to provide remote management for our iStorage PIN-authenticated drives as well. We anticipate this to be completed sometime in Q4 of 2026.  If you would like to be kept up-to-date on our progress, sign-up for our Newsletter to stay informed with our updates. You can also connect with us on Linkedin and  facebook for regular updates and announcements.

How do I use a KanguruClone NVMe Duplicator to duplicate SATA drives?

You can duplicate SATA Hard drives and SSDs on our NVMe Duplicator. See these instructions for a step-by-step guide to duplicating SATA drives on a KanguruClone NVMe Duplicator.

See "Connecting Standard SATA Drives" in the KanguruClone 11 NVMe Duplicator User Manual 

Can I duplicate several different types of drives simultaneously?

Yes, the 11 M.2 NVMe PRO Duplicator allows a variety of drives to be duplicated, however, this requires separate adapter cables to do so. (sold separately-See our Duplicator Adapters).