The Aegis Secure Key 3NXC is a hardware-encrypted USB-C flash drive with a keypad on the body. You unlock it by entering a PIN on the drive itself, and everything stored on it is encrypted in real time with 256-bit AES-XTS handled by the drive's own hardware. Because the PIN never touches the computer, there is no software, app or driver to install, and the key is OS- and platform-independent: it behaves the same on Windows, macOS or Linux.
That on-device model is the point. A keylogger on the host sees nothing, because you never type the PIN there, and the drive doesn't care what machine it meets. That suits field kit, shared workstations and computers you don't control.
For managed environments there are real controls. You can set separate admin and user PINs, deploy drives under forced enrolment, and lock a key to read-only so staff can't copy new data onto it. Brute-force defence wipes the encryption key after a set number of wrong PINs, and the Aegis line is validated to FIPS 140-2 Level 3, the standard regulated and government buyers tend to ask for by name.
For Australian buyers that maps to common obligations. If you carry client records or backups off-site, a lost drive that wipes its own key rather than exposing plaintext is a much easier conversation under the Notifiable Data Breaches scheme, and it gives you an auditable answer for data-at-rest on removable media.
Our take: reach for this if you move sensitive files physically and want encryption that doesn't rely on the host being trusted. The 512GB capacity suits image sets, VM files and large backups rather than a single document. It is not full-disk encryption, not cloud sync, and no defence against credential phishing; that is a job for a security key, not a storage key. It also asks more of users than an ordinary thumb drive: forget the PIN and trip the wipe, and the data is gone by design.






