Five situations that come up repeatedly, and what Data Guard actually does in each one. No two organisations are the same, but these are the shapes the problem usually takes.
How banks and public agencies put Data Guard to work. Open any card for the full challenge, approach and outcomes.
Label-aware DLP that stops account numbers, card data and statements from leaving the bank, without burying analysts in false alerts.
Label cardholder and customer data consistently across the bank, so every control — from DLP to access — inherits the same context.
Find and label citizen personal data spread across legacy shares, databases and endpoints — the foundation of any data-protection programme.
Field engineers, auditors, site teams and contractors work for long stretches without a connection. Controls that depend on reaching a server stop applying the moment the device leaves, which is also the moment supervision is weakest.
A laptop is away from the network for three weeks. Files are copied to a personal drive on day four. Nothing is evaluated, nothing is recorded, and the first anyone knows of it is when the device reconnects — if the tooling reconstructs it at all.
Policy is evaluated on the device itself. Labels, rules and the decision engine live locally, so a copy to removable media is judged and acted on with no connection present.
The same controls on and off the network, and a local event record that reconciles when the device next connects.
People paste contracts, customer lists and source code into public assistants to summarise or rewrite them. It is fast, it is well intentioned, and it leaves no trace in any system the security team watches.
Blocking the sites outright pushes people onto personal devices, where there is no visibility at all. Allowing them freely means sensitive text leaves through a channel nobody is inspecting. Most organisations pick one and live with the consequences.
Paste and upload are inspected in the browser against the same labels used everywhere else. A rule can allow, warn, ask for a justification, or stop the action before the text leaves the page.
A usable middle ground: the tools stay available, the sensitive material does not go with them, and the warning teaches people where the line is.
An institution knows roughly which systems hold card and account data. What it cannot produce on request is a current list of every file outside those systems that contains the same values — the extract someone took in 2021, the reconciliation spreadsheet, the mailbox attachment.
The work is done by hand ahead of each review, then goes stale within weeks. Manual labelling is inconsistent between teams, and nobody can explain afterwards why a particular file was categorised the way it was.
Discovery locates files matching the patterns you define. Classification applies your categories to them consistently, with a reviewer step where the match is ambiguous, and records the rule behind every decision.
An inventory that refreshes on a schedule instead of before a deadline, and a defensible answer to why each file carries the label it does.
Clinical work runs on sharing. Records move between departments, referrals go out by email, images are exported for a second opinion. The same openness that makes care possible is what makes the data hard to keep track of.
Controls strict enough to stop a mistaken send also stop legitimate clinical correspondence, so they get switched off or worked around. Meanwhile exports accumulate in shared folders long after the case that needed them closed.
Rules are written per destination rather than per file type, so an internal referral and an external address are treated differently. Discovery keeps finding the exports that outlived their purpose.
Clinical sharing that keeps working, a warning at the point an address looks wrong, and a record of what was sent where.
Agencies accumulate decades of case files, correspondence and departmental archives. Systems are inherited through reorganisations, and the people who knew what a given share held have usually moved on.
When someone asks what personal information the agency holds about them, answering means a manual search across systems with different owners and no shared index. The answer takes weeks and is never certain to be complete.
Discovery runs across those shares and archives in place, reporting what was found, where it sits and who can currently open it — without moving the records out of the systems that hold them.
A searchable inventory that turns a multi-week manual exercise into a query, and permission reporting that shows where access has drifted.
Tell us what you are actually trying to work out and we will build the demo around that rather than around a script.