Platform Capabilities

What the Platform
Actually Does

The full capability list across all four products, described in terms of mechanism rather than outcome. If you would rather read it product by product, start from the Product page.

Our Products

Four Products, One Platform

Discovery

Scanning and Inventory

Scans are scoped by location rather than by guesswork: you nominate the shares, mailboxes, endpoints and repositories to examine, and set how often each is revisited. Everything is read in place.

  • Scope a scan by location, and schedule how often it repeats
  • Content matched against patterns your organisation defines
  • Reads inside archives and common document formats
  • Reports current permissions alongside each finding
  • Incremental re-scans, so repeat runs only cover what changed
  • No copy of your data is taken out to be examined
Where it looks

File shares, endpoints, mail stores and cloud repositories you nominate.

What comes back

An inventory of findings with location, match reason and access.

Classification

Categories, Review and Labels

Your category scheme is defined once and applied everywhere. Where a match is clear the label is automatic; where it is not, the item waits for a person rather than being guessed at.

  • Define your own category scheme and its levels
  • Document context weighed alongside the pattern match
  • Review queue for matches that need a human decision
  • Labels written so they travel with the file
  • Bulk re-labelling when a category definition changes
  • Each decision retrievable with the rule that caused it
Automatic

Applied where the pattern and the context agree.

Reviewed

Held for a person where the evidence is mixed.

Endpoint

Endpoint and Movement Controls

The agent evaluates policy locally at the moment of the action, which is what lets controls hold on a device that has been off the network for weeks.

  • Removable media: allow, restrict by label, or require justification
  • Print control for labelled documents
  • Clipboard rules between applications
  • Writes to network shares evaluated like any other destination
  • Full policy evaluation with no connection present
  • Local events reconcile when the device next connects
Decided locally

Labels and rules live on the device, so offline is not a gap.

Explained on the spot

The person is told which rule acted, and why, as it happens.

Cloud

Cloud Repositories

Cloud storage is treated as another location to inventory and another destination to govern, using the same categories and the same rules as everywhere else.

  • Inventory of labelled data held in cloud repositories
  • Sharing and permission reporting on discovered items
  • Upload and sync governed by the same movement rules
  • Findings surface in the same inventory as everything else
  • Re-scanning on the schedule you set per repository
One inventory

Cloud findings are not a separate report to reconcile.

One rule set

A label means the same thing wherever the data is held.

Email and Browser

The Two Channels People Actually Use

Most sensitive data leaves through a message or a browser tab. Both are inspected before the content goes, and both can warn rather than simply block, which matters when the sender is doing legitimate work.

  • Message bodies and attachments inspected before sending
  • Rules that differ by recipient domain and by label
  • Warning on a recipient that looks wrong for the label
  • Browser uploads inspected before the file leaves the page
  • Paste into a web application evaluated as a movement
  • Justification capture when a person proceeds anyway
Before it leaves

Inspection happens at composition and upload, not after delivery.

Warn, then block

Graduated responses keep legitimate work moving.

Prioritisation

Deciding What to Deal With First

A first scan usually returns more findings than any team can work through. Prioritisation exists so the list is ordered by something defensible rather than by scan order.

  • Findings ranked by category, exposure and reach
  • Widely readable locations surface above restricted ones
  • Repeat findings on one location grouped into a single item
  • Filter by team, location or category to split the work
  • Mark a finding as accepted, with the reason recorded
Ordered, not just listed

Exposure and category decide the order, not scan sequence.

Decisions stick

An accepted finding stays accepted across later scans.

Integrity

Watching What Changes

Integrity monitoring baselines the locations you nominate and reports change against that baseline, including the kind of bulk change that matters more as one event than as thousands of separate lines.

  • Baseline any file or directory you nominate
  • Additions, modifications, deletions and permission changes
  • Expected change windows declared, so routine work stays quiet
  • Bulk change across many files raised as one event
  • Before-and-after state retained for a monitored change
Against a baseline

Change is reported relative to a known good state.

One record

Change events sit beside policy decisions, not in a separate log.

Evidence and Reporting

Every Decision, Recorded

When a policy acts, Data Guard records what was inspected, which rule matched, who was involved and what happened next. That record is searchable, exportable and kept for as long as you decide.

Full event record The file, the user, the destination, the time and the rule that matched.
Policy trace Which version of a policy was in force, and why it produced this outcome.
Structured export Events leave the platform in a structured form your own tooling can read.
Your retention schedule Records are held for the period you set, then aged out on that schedule.
Search and filter Query across users, files, channels and time ranges without exporting first.
Grouped investigations Related events are grouped so a single incident reads as one sequence.
Integrations

How It Connects to What You Already Run

Rather than list logos, here is what the platform exposes. If your tooling can consume a structured event stream and call an authenticated endpoint, it can work with Data Guard — and you can confirm that against your own stack rather than against a compatibility chart.

  • Structured event output suitable for a log or SIEM pipeline
  • Outbound notifications triggered by policy outcome
  • Authenticated API for inventory, findings and policy state
  • Directory-sourced users and groups for policy targeting
  • Scheduled export for reporting and archive systems
  • Ask us to confirm a specific system against your environment
Surfaces, not a logo wall

We describe what the platform exposes so your architects can judge fit.

Verified per environment

A specific connection is confirmed against your stack, in writing.

Ask About the One That Matters to You

A capability list only goes so far. Tell us which of these you need to be sure about and we will show you that part working.

EN عربي
Request a Demo ›