Apply your organisation's own categories to the data discovery found — automatically where the match is clear, with a reviewer where it is not.
Discovery tells you a file contains something that looks sensitive. That is not yet enough to act on. A policy cannot decide whether a document may be emailed to an external address until somebody has said what kind of document it is — and said it in terms the organisation actually uses, not in terms a scanning engine invented.
Classification is where that judgement gets made once and then reused everywhere. Your category scheme is defined a single time. Where the evidence is unambiguous the label is applied automatically; where it is mixed, the item waits for a person rather than being guessed at. Either way, the decision is recorded with the rule that produced it, so it can be explained months later.
Every downstream control depends on this step being right.
Without a label, a rule can only match on raw content, which is how controls end up blocking a template because it looks like a customer record.
When every team decides for itself what counts as confidential, two departments classify the same document differently within a month.
Labelling new documents at creation is manageable. The years of files already sitting on shares are not, without automation.
If a label cannot be traced to a reason, a disputed decision turns into an argument about judgement rather than a look at the record.
Six capability areas covering both new documents and the backlog behind them.
Levels, names and meanings are yours. Defined once centrally, then used by every part of the platform without redefinition.
Pattern matches are weighed against the surrounding document, which is what separates a real record from something that merely resembles one.
Ambiguous matches go to a queue for a person instead of being forced into a category the evidence does not support.
The person creating a document usually knows best what it is. They can set the category at the moment of creation, within the scheme you defined.
The category is written so it stays with the file when it moves, rather than living in a side database that the file leaves behind.
Classifying new work is the easy half. Bulk classification works through the years of files already on your shares.
A classification scheme is only useful if the rest of your estate can read it. Categories and decisions are exposed in a structured form, and we confirm a specific system against your environment in writing rather than showing you a logo.
Movement rules need something to reason about. Classifying first is what stops the first week of enforcement from being a wall of false alarms.
Years of unlabelled documents on departmental shares, worked through in batches rather than by asking teams to do it by hand.
A visible marking on a document changes behaviour on its own, before any control has to intervene.
When two teams categorise the same kind of document differently, one central scheme with a recorded reason ends the debate.
Ambiguous matches go to a reviewer instead of being forced into a category. Over-labelling destroys trust in a scheme faster than under-labelling.
The surrounding document is weighed alongside the match, which is the difference between finding a customer record and finding the blank form for one.
Every label can be traced back to the rule and the version of the scheme that produced it, however long ago that was.
Working directly from discovery findings means the years of existing files are in scope, not just documents created from today onwards.
No. You define the levels, their names and what each one means. The platform applies your scheme rather than imposing one.
It can be corrected, the correction is recorded, and the rule that produced it can be tuned and re-run against findings you already hold.
The category is written so it travels with the file rather than living in a separate database the file leaves behind.
Yes. Bulk classification works from discovery findings, in batches by location or team, with a preview before a batch is committed.
Not strictly, but the two are designed to work together. Without discovery you can classify new documents as they are created; with it, the existing backlog is in scope too.
The four products are designed to hand work to each other. Each one is stronger for what the others produce.
Find sensitive data across the shares, endpoints, mailboxes and cloud stores you nominate — and see who can currently reach it.
Find out more →Decide what labelled data may leave, and act at the moment it tries — on the endpoint, in email, in the browser and on removable media.
Find out more →Know when a file, directory or permission changes against a baseline you set — including the bulk change that matters more as one event than as thousands of lines.
Find out more →If you already have one on paper, we can show you it running against a sample of your own documents. If you do not, that is a good conversation to have first.