Smart decisions make DLP finally work

Smart DLP does not replace your existing tooling. It layers AI-native decision intelligence on top: classification, policy, correlation, and risk scoring. Decide once, enforce everywhere.

Separate the decision from the enforcement

Allow-or-block decisions need cross-system context: data semantics, user identity, destination risk, cross-event history. That context is fragmented across enforcement points. Smart DLP centralizes the decision as an overlay; enforcement stays with your existing infrastructure.

L3

Intelligence

Policy Brain, correlation, risk scoring, and DataBrain classification. The core of this product.

  • Policy Brain: context-aware thresholds, deny-override precedence, hot-reload rules
  • Correlation: five statistical detectors (behavioral × propagation) injecting risk scores into every decision
  • Classification: DataBrain integrates as a sealed API service; plaintext never leaves your network
  • Event normalization: one unified model, immune to vendor differences
  • Reliability: circuit breakers, event replay, 365-day audit retention
  • Connected today: Purview / Zscaler / Proofpoint / OneDrive
L2

Orchestration

Connectors ingest vendor events into a unified model; circuit breakers, replay, 365-day retention.

L1

Execution

Your existing DLP and security infrastructure: email, network, and endpoint gateways.

  • Zero replacement: keep your email, network, and endpoint gateways
  • Decision mapping: overlay verdicts translate into local block / allow actions; untranslatable rules are flagged, never silently degraded
  • Sidecar deployment: no policy migration; the overlay deploys independently

Alerts arrive pre-analyzed

Context-aware policy decisions

A JSON rule DSL compiles and executes: destination risk × user sensitivity modulate thresholds, while behavioral and propagation factors tighten decisions multiplicatively. Deny-override precedence (block > mask > flag > audit > allow); uncovered types are never silently allowed.

  • Templates: GDPR, PCI-DSS, insider baseline, PIPL outbound baseline (14 sensitive-data types)
  • Hot-reload, versioned rules with one-click rollback; manual risk flags take effect instantly
  • Full decision × signal traceability: why it was allowed or blocked, record by record

See behavior, not just events

Three statistical detectors (exfil volume, off-hours, privilege anomalies) fuse via Stouffer’s method into one per-user behavioral risk score, injected into real-time decisions; a sensitive-value fingerprint index pinpoints the blast radius of any value in seconds.

  • UEBA baselines with triple poisoning defenses: outlier winsorizing, daily learning caps, peer-population cross-checks
  • Sensitive-value fingerprint index: any value → events / users / channels / destinations
  • Behavioral risk feeds back: high-risk users automatically face tighter thresholds

LLM pre-analysis + a memory loop

An LLM pre-analyzes alerts, advisory only and never enforcement. Analyst-confirmed false positives become decision memories injected into future triage, with one-click rule-change suggestions.

  • Machine-verifiable guardrails: LLM output stops at the advisory layer and cannot touch enforcement
  • Confirmed FPs never nag again: similar cases automatically carry the prior verdict
  • Triage queue sorted by real risk, with one-click FP marking

A workbench built for security teams

14 pages covering the full loop from real-time decisions to forensics:

Overview

A 360° view: live decision feed, routing distribution, risk trends.

Decision Timeline

Real-time decision stream filterable by triage state; analysis arrives before you do.

Rule Editor

Visual rule editing with versioning, coverage analysis, and conflict detection.

Coverage Matrix

Data type × 8 channels, tri-state: covered / blind / never seen.

Triage Queue

Real-risk-first worklist with FP badges and memory capture.

Event Forensics

Full chain per event: decision, correlated signals, triage verdict, and rule suggestions.

User Risk

Per-user behavioral profile and risk score, with manual flags.

Decision Simulator

Evaluate as you type: paste any text and preview policy verdicts before rollout.

Shadow AI Visibility

AI-site visits reported by the Browser Shield extension. Visibility only, never blocking.

Plug into the DLP you already run

Events are normalized before they reach the engine, so the connector framework is immune to vendor differences; each new source is one connector.

Connected today

Microsoft Purview
Zscaler
Proofpoint
OneDrive / SharePoint

8-channel governance model

EmailWeb uploadUSBCloud storageAI promptsChatEndpointWeb browsing

More vendor connectors are on the way. The USB channel is reserved for governance (no event source yet; the coverage matrix shows it as uncovered). Zscaler policy translation is one-directional; untranslatable rules are flagged, never silently dropped.

One-command delivery, even in isolated environments

Signed .sp packages

ECDSA-signed self-extracting packages; one command to install, upgrade, or roll back, with automatic health gates.

Full-stack orchestration

Docker Compose orchestrates 13 services: gateway, engine and business services, database and cache, plus Prometheus / Grafana / Alertmanager monitoring.

Tamper-evident audit

An append-only decision ledger (DB-level REVOKE UPDATE/DELETE) with full decision × signal × data-identity traceability.

Tell us where your DLP hurts

Share your false-positive and blind-spot pain; we will talk about how the overlay lands.

Contact us