Find sensitive data across the shares, endpoints, mailboxes and cloud stores you nominate — and see who can currently reach it.
Every organisation has an official picture of where its sensitive data lives: the core systems, the databases, the approved repositories. Alongside that sits a much larger unofficial estate — the extract someone pulled for a report in 2021, the departmental share nobody has audited since a reorganisation, the mailbox of a person who left, the folder a contractor was given access to for one project and still has.
Discovery exists to turn that second estate into something you can see. It scans the locations you nominate, in place, and returns an inventory: what was found, exactly where it sits, why it matched, and who can currently open it. Nothing else in a data protection programme works properly until that inventory exists.
Four things go wrong when the inventory is missing or out of date.
Protection gets applied to the systems everybody knows about, while the copies outside them stay untouched.
A request to say what personal information you hold about someone becomes a manual search across systems with different owners.
Folders become readable far more widely than intended, and nobody notices because nobody is looking at permissions.
A one-off mapping exercise is accurate on the day it finishes and steadily less so every week after.
Six capability areas, all configured by you rather than fixed by us.
You nominate what gets examined and how often, rather than pointing a tool at everything and hoping.
Records inside a database and a spreadsheet on a share are both findable, and both land in the same inventory.
Patterns are written in your terms for your data, not taken from a fixed dictionary of what a vendor thinks is sensitive.
A finding is only half the story. The other half is who can open it today, which is usually more people than anyone expects.
A first scan usually returns more than a team can work through. The list arrives ordered by something defensible.
Scanning is bounded by limits you set, so a discovery run never becomes the reason a business system slowed down.
Discovery output is written in a structured form your own tooling can read. We describe the surfaces rather than listing vendors, because what matters is whether it fits your stack — and that is something we confirm against your environment, in writing.
Someone asks what personal information you hold about them. A query across the inventory replaces a round of enquiries to every department.
Moving a share or a system is the one moment you are forced to know what is in it. Discovery makes that a report rather than an archaeology project.
Find the sensitive files sitting in widely readable locations and fix the access, which is usually the fastest risk reduction available.
Policies written without an inventory are guesses. A first scan turns the programme from an opinion into a scoped piece of work.
Your data is read where it lives. No copy is taken out to be examined somewhere else, which removes an entire category of risk from the exercise.
Schedules and incremental re-scans mean the inventory reflects this week rather than the week the project finished.
Every result carries who can currently open it, so you can act on exposure rather than just cataloguing it.
Findings become the work queue for Classification without an export or a second tool in between.
No. Content is read in the location where it already sits, and the finding records where it was rather than the content itself.
Scanning runs inside resource ceilings and time windows that you configure per target, and can be paused and resumed without losing progress.
Discovery answers where sensitive data is. Classification answers what it is and applies your labels to it. Discovery produces the queue that Classification works through.
Yes, and that is the intended way to use it. You define the patterns that describe your data, and you can tune a rule and re-run it against findings you already have.
Usually more findings than a team can act on immediately, which is why results arrive ranked by category, exposure and reach rather than in scan order.
The four products are designed to hand work to each other. Each one is stronger for what the others produce.
Apply your organisation's own categories to the data discovery found — automatically where the match is clear, with a reviewer where it is not.
Find out more →Decide what labelled data may leave, and act at the moment it tries — on the endpoint, in email, in the browser and on removable media.
Find out more →Know when a file, directory or permission changes against a baseline you set — including the bulk change that matters more as one event than as thousands of lines.
Find out more →The most useful demo of discovery is a scoped scan of a location you already suspect. Tell us which one and we will start there.