Product

Data Guard Discovery

Find sensitive data across the shares, endpoints, mailboxes and cloud stores you nominate — and see who can currently reach it.

Overview

Most of What You Hold Was Never Written Down

Every organisation has an official picture of where its sensitive data lives: the core systems, the databases, the approved repositories. Alongside that sits a much larger unofficial estate — the extract someone pulled for a report in 2021, the departmental share nobody has audited since a reorganisation, the mailbox of a person who left, the folder a contractor was given access to for one project and still has.

Discovery exists to turn that second estate into something you can see. It scans the locations you nominate, in place, and returns an inventory: what was found, exactly where it sits, why it matched, and who can currently open it. Nothing else in a data protection programme works properly until that inventory exists.

Why It Matters

You Cannot Secure What You Cannot Find

Four things go wrong when the inventory is missing or out of date.

Controls guard the wrong places

Protection gets applied to the systems everybody knows about, while the copies outside them stay untouched.

Answers take weeks

A request to say what personal information you hold about someone becomes a manual search across systems with different owners.

Access quietly drifts

Folders become readable far more widely than intended, and nobody notices because nobody is looking at permissions.

The picture ages fast

A one-off mapping exercise is accurate on the day it finishes and steadily less so every week after.

Capabilities

From a Blank Map to a Working Inventory

Six capability areas, all configured by you rather than fixed by us.

Scoped scanning

You nominate what gets examined and how often, rather than pointing a tool at everything and hoping.

  • File shares, endpoints, mail stores and cloud repositories
  • Per-location schedules, from daily to quarterly
  • Incremental re-scans that cover only what changed

Structured and unstructured

Records inside a database and a spreadsheet on a share are both findable, and both land in the same inventory.

  • Database columns and table content
  • Documents, spreadsheets and plain text
  • Reads inside archives and nested attachments

Detection you define

Patterns are written in your terms for your data, not taken from a fixed dictionary of what a vendor thinks is sensitive.

  • Pattern, keyword and structural matching
  • Document context weighed alongside the match
  • Tune a rule and re-run it against past findings

Permission reporting

A finding is only half the story. The other half is who can open it today, which is usually more people than anyone expects.

  • Current effective access per location
  • Widely readable locations surfaced first
  • Changes in access reported between scans

Prioritised results

A first scan usually returns more than a team can work through. The list arrives ordered by something defensible.

  • Ranked by category, exposure and reach
  • Repeat findings grouped into one item
  • Accept a finding with the reason recorded

Safe to run in production

Scanning is bounded by limits you set, so a discovery run never becomes the reason a business system slowed down.

  • Resource ceilings you configure per target
  • Scan windows restricted to agreed hours
  • Pause and resume without losing progress
Open by Design

The Inventory Does Not Stay Locked In Here

Discovery output is written in a structured form your own tooling can read. We describe the surfaces rather than listing vendors, because what matters is whether it fits your stack — and that is something we confirm against your environment, in writing.

  • Authenticated API for inventory, findings and scan state
  • Structured event output suitable for a log or SIEM pipeline
  • Scheduled export for reporting and archive systems
  • Directory-sourced users and groups for access reporting
  • Findings feed Classification directly, with no export step
Where Teams Use It

Four Situations Discovery Is Built For

Answering a records request

Someone asks what personal information you hold about them. A query across the inventory replaces a round of enquiries to every department.

Before a migration

Moving a share or a system is the one moment you are forced to know what is in it. Discovery makes that a report rather than an archaeology project.

Reducing exposure

Find the sensitive files sitting in widely readable locations and fix the access, which is usually the fastest risk reduction available.

Starting a protection programme

Policies written without an inventory are guesses. A first scan turns the programme from an opinion into a scoped piece of work.

What Sets It Apart

Why This Discovery

01

Scans in place

Your data is read where it lives. No copy is taken out to be examined somewhere else, which removes an entire category of risk from the exercise.

02

Continuous, not a one-off

Schedules and incremental re-scans mean the inventory reflects this week rather than the week the project finished.

03

Access is part of the finding

Every result carries who can currently open it, so you can act on exposure rather than just cataloguing it.

04

It hands work onward

Findings become the work queue for Classification without an export or a second tool in between.

Questions

Frequently Asked

Does scanning move or copy our data?

No. Content is read in the location where it already sits, and the finding records where it was rather than the content itself.

Will it slow down our production systems?

Scanning runs inside resource ceilings and time windows that you configure per target, and can be paused and resumed without losing progress.

How is this different from Classification?

Discovery answers where sensitive data is. Classification answers what it is and applies your labels to it. Discovery produces the queue that Classification works through.

Can we use our own detection rules?

Yes, and that is the intended way to use it. You define the patterns that describe your data, and you can tune a rule and re-run it against findings you already have.

What does a first scan realistically produce?

Usually more findings than a team can act on immediately, which is why results arrive ranked by category, exposure and reach rather than in scan order.

The Rest of the Platform

Works With

The four products are designed to hand work to each other. Each one is stronger for what the others produce.

Run It Against One Share

The most useful demo of discovery is a scoped scan of a location you already suspect. Tell us which one and we will start there.

EN عربي
Request a Demo ›