Decide what labelled data may leave, and act at the moment it tries — on the endpoint, in email, in the browser and on removable media.
Data leaves an organisation through a small number of ordinary actions: an attachment on a message, a copy to a USB stick, a print, an upload in a browser tab, a paste into another application, a write to a share. None of these feel like a security event to the person doing them. Most of the time they are not.
DLP evaluates the rule at that exact moment, on that device, against the label the file already carries. The outcome can be to allow it, to warn the person, to ask them to justify it, or to stop it. Because the decision is made locally, it holds when the laptop has been off the network for three weeks — which is usually when supervision is weakest and the risk is highest.
The common failure is not missed leaks. It is controls so blunt that the business routes around them.
A rule strict enough to stop a mistaken send also stops the correct one, so it gets an exception, then another, then it is off.
Controls that need to reach a server stop applying the moment the device leaves the building, which is exactly when they are needed.
A block with no reason attached produces a support ticket, an argument, and a user who has learned nothing.
Matching on raw content alone means a blank template and a real customer list look the same to the rule.
Six capability areas, all evaluated against the labels Classification produced.
Copies to external drives, prints and clipboard moves between applications are all evaluated as movements of labelled data.
Message bodies and attachments are inspected before sending, with rules that differ by recipient rather than treating every destination alike.
Uploads and pastes into web applications, including public AI assistants, are treated as movements and judged before the content leaves the page.
Blocking is the last option, not the only one. Most rules should warn or ask first, because that is what keeps them switched on.
Labels, rules and the decision engine live on the device, so a laptop that has not checked in for weeks still enforces the same policy.
A new rule can run in observe mode first, so you see what it would have done to real traffic before it does anything at all.
Nobody wants another console to check. Every policy decision is written as a structured event your existing pipeline can consume, and a specific system is confirmed against your environment in writing.
Field teams, auditors and contractors work for weeks without a connection. Local evaluation means the controls go with them.
Instead of blocking the tools outright and pushing people onto personal devices, inspect the paste and hold back only the sensitive part.
Most email incidents are addressing mistakes, not malice. A warning at the moment of sending catches them without blocking real work.
Movement rules can tighten for a person during a notice period without changing anything for everybody else.
Graduated responses and observe mode mean a rule can be tuned into accuracy instead of being disabled after its first bad week.
The decision engine runs on the endpoint, so the control does not quietly stop applying when the device leaves the network.
Because Classification has already established what a file is, rules can be written about meaning rather than about character patterns.
An explanation at the moment of the block turns an obstacle into the most effective training the organisation has.
Yes. Labels, rules and the decision engine are on the device, so policy is evaluated in full with no connection. Events are held locally and reconcile when it reconnects.
That is the main thing to design against. Rules can allow, warn, or ask for a justification rather than block, and a new rule can run in observe mode first so you see its effect before it acts.
It works far better with it. Rules written against labels are more precise than rules matching raw content, which is what keeps false alarms low enough for the control to stay enabled.
A message at that moment saying which rule applied and why. If the rule asks for a justification, what they type is recorded with the event.
Yes, and we recommend it. Start in observe mode, roll out to one team, then widen. Policies are versioned so any change can be undone.
The four products are designed to hand work to each other. Each one is stronger for what the others produce.
Find sensitive data across the shares, endpoints, mailboxes and cloud stores you nominate — and see who can currently reach it.
Find out more →Apply your organisation's own categories to the data discovery found — automatically where the match is clear, with a reviewer where it is not.
Find out more →Know when a file, directory or permission changes against a baseline you set — including the bulk change that matters more as one event than as thousands of lines.
Find out more →The clearest demo is a single rule taken from label to enforcement, showing what the user sees and what gets recorded. Tell us the channel you care about most.