Based on the description, they're probably using
PGP Endpoint Device Control. This software is enterprise class; it requires a server to design and enforce policy. A Windows executable is deposited on the encrypted device (e.g. USB stick) that turns the encrypted volume into an new drive that can be accessed by any Windows app. I've stress tested it; it works pretty well.