Product

Data Guard DLP

Decide what labelled data may leave, and act at the moment it tries — on the endpoint, in email, in the browser and on removable media.

Overview

The Decision Has to Happen Where the Data Moves

Data leaves an organisation through a small number of ordinary actions: an attachment on a message, a copy to a USB stick, a print, an upload in a browser tab, a paste into another application, a write to a share. None of these feel like a security event to the person doing them. Most of the time they are not.

DLP evaluates the rule at that exact moment, on that device, against the label the file already carries. The outcome can be to allow it, to warn the person, to ask them to justify it, or to stop it. Because the decision is made locally, it holds when the laptop has been off the network for three weeks — which is usually when supervision is weakest and the risk is highest.

Why It Matters

Why Most DLP Gets Switched Off

The common failure is not missed leaks. It is controls so blunt that the business routes around them.

It blocks legitimate work

A rule strict enough to stop a mistaken send also stops the correct one, so it gets an exception, then another, then it is off.

It stops at the network edge

Controls that need to reach a server stop applying the moment the device leaves the building, which is exactly when they are needed.

It cannot explain itself

A block with no reason attached produces a support ticket, an argument, and a user who has learned nothing.

It has no idea what the file is

Matching on raw content alone means a blank template and a real customer list look the same to the rule.

Capabilities

Coverage Across the Channels People Actually Use

Six capability areas, all evaluated against the labels Classification produced.

Endpoint and removable media

Copies to external drives, prints and clipboard moves between applications are all evaluated as movements of labelled data.

  • Removable media rules per label and per person
  • Print control for labelled documents
  • Clipboard rules between applications

Email

Message bodies and attachments are inspected before sending, with rules that differ by recipient rather than treating every destination alike.

  • Inspected at composition, before it leaves
  • Different rules for internal and external
  • Warning when a recipient looks wrong for the label

Browser and web applications

Uploads and pastes into web applications, including public AI assistants, are treated as movements and judged before the content leaves the page.

  • Upload inspected before the file is sent
  • Paste into a web application evaluated as a movement
  • Allow the tool, hold back the sensitive part

Graduated responses

Blocking is the last option, not the only one. Most rules should warn or ask first, because that is what keeps them switched on.

  • Allow, warn, require a justification, or block
  • The reason is shown to the person as it happens
  • Justifications captured and reviewable later

Works with no connection

Labels, rules and the decision engine live on the device, so a laptop that has not checked in for weeks still enforces the same policy.

  • Full policy evaluation while offline
  • Events held locally and reconciled on reconnect
  • Policy updates applied on the next connection

Safe rollout

A new rule can run in observe mode first, so you see what it would have done to real traffic before it does anything at all.

  • Observe mode before a rule starts acting
  • Roll out to one team before the whole estate
  • Policies versioned, so a change can be undone
Open by Design

Feeds the Tools Your Team Already Watches

Nobody wants another console to check. Every policy decision is written as a structured event your existing pipeline can consume, and a specific system is confirmed against your environment in writing.

  • Structured event output for every evaluation, allowed or blocked
  • Outbound notifications triggered by policy outcome
  • Authenticated API for policy state and incidents
  • Directory-sourced users and groups for policy targeting
  • Reads Classification labels directly, with no sync step
Where Teams Use It

Four Situations DLP Is Built For

Laptops that work offline

Field teams, auditors and contractors work for weeks without a connection. Local evaluation means the controls go with them.

Public AI assistants

Instead of blocking the tools outright and pushing people onto personal devices, inspect the paste and hold back only the sensitive part.

The wrong recipient

Most email incidents are addressing mistakes, not malice. A warning at the moment of sending catches them without blocking real work.

Departures and transfers

Movement rules can tighten for a person during a notice period without changing anything for everybody else.

What Sets It Apart

Why This DLP

01

It survives being switched on

Graduated responses and observe mode mean a rule can be tuned into accuracy instead of being disabled after its first bad week.

02

Offline is not a gap

The decision engine runs on the endpoint, so the control does not quietly stop applying when the device leaves the network.

03

It judges labels, not just content

Because Classification has already established what a file is, rules can be written about meaning rather than about character patterns.

04

The user is told why

An explanation at the moment of the block turns an obstacle into the most effective training the organisation has.

Questions

Frequently Asked

Does it work when the device is off the network?

Yes. Labels, rules and the decision engine are on the device, so policy is evaluated in full with no connection. Events are held locally and reconcile when it reconnects.

Will it block people from doing their jobs?

That is the main thing to design against. Rules can allow, warn, or ask for a justification rather than block, and a new rule can run in observe mode first so you see its effect before it acts.

Do we need Classification for DLP to work?

It works far better with it. Rules written against labels are more precise than rules matching raw content, which is what keeps false alarms low enough for the control to stay enabled.

What does the user see when a rule acts?

A message at that moment saying which rule applied and why. If the rule asks for a justification, what they type is recorded with the event.

Can we roll it out gradually?

Yes, and we recommend it. Start in observe mode, roll out to one team, then widen. Policies are versioned so any change can be undone.

The Rest of the Platform

Works With

The four products are designed to hand work to each other. Each one is stronger for what the others produce.

Watch One Policy Make One Decision

The clearest demo is a single rule taken from label to enforcement, showing what the user sees and what gets recorded. Tell us the channel you care about most.

EN عربي
Request a Demo ›