Smart decisions make DLP finally work
Smart DLP does not replace your existing tooling. It layers AI-native decision intelligence on top: classification, policy, correlation, and risk scoring. Decide once, enforce everywhere.
Separate the decision from the enforcement
Allow-or-block decisions need cross-system context: data semantics, user identity, destination risk, cross-event history. That context is fragmented across enforcement points. Smart DLP centralizes the decision as an overlay; enforcement stays with your existing infrastructure.
Intelligence
Policy Brain, correlation, risk scoring, and DataBrain classification. The core of this product.
- Policy Brain: context-aware thresholds, deny-override precedence, hot-reload rules
- Correlation: five statistical detectors (behavioral × propagation) injecting risk scores into every decision
- Classification: DataBrain integrates as a sealed API service; plaintext never leaves your network
- Event normalization: one unified model, immune to vendor differences
- Reliability: circuit breakers, event replay, 365-day audit retention
- Connected today: Purview / Zscaler / Proofpoint / OneDrive
Orchestration
Connectors ingest vendor events into a unified model; circuit breakers, replay, 365-day retention.
Execution
Your existing DLP and security infrastructure: email, network, and endpoint gateways.
- Zero replacement: keep your email, network, and endpoint gateways
- Decision mapping: overlay verdicts translate into local block / allow actions; untranslatable rules are flagged, never silently degraded
- Sidecar deployment: no policy migration; the overlay deploys independently
Alerts arrive pre-analyzed
Context-aware policy decisions
A JSON rule DSL compiles and executes: destination risk × user sensitivity modulate thresholds, while behavioral and propagation factors tighten decisions multiplicatively. Deny-override precedence (block > mask > flag > audit > allow); uncovered types are never silently allowed.
- Templates: GDPR, PCI-DSS, insider baseline, PIPL outbound baseline (14 sensitive-data types)
- Hot-reload, versioned rules with one-click rollback; manual risk flags take effect instantly
- Full decision × signal traceability: why it was allowed or blocked, record by record
See behavior, not just events
Three statistical detectors (exfil volume, off-hours, privilege anomalies) fuse via Stouffer’s method into one per-user behavioral risk score, injected into real-time decisions; a sensitive-value fingerprint index pinpoints the blast radius of any value in seconds.
- UEBA baselines with triple poisoning defenses: outlier winsorizing, daily learning caps, peer-population cross-checks
- Sensitive-value fingerprint index: any value → events / users / channels / destinations
- Behavioral risk feeds back: high-risk users automatically face tighter thresholds
LLM pre-analysis + a memory loop
An LLM pre-analyzes alerts, advisory only and never enforcement. Analyst-confirmed false positives become decision memories injected into future triage, with one-click rule-change suggestions.
- Machine-verifiable guardrails: LLM output stops at the advisory layer and cannot touch enforcement
- Confirmed FPs never nag again: similar cases automatically carry the prior verdict
- Triage queue sorted by real risk, with one-click FP marking
A workbench built for security teams
14 pages covering the full loop from real-time decisions to forensics:
Overview
A 360° view: live decision feed, routing distribution, risk trends.
Decision Timeline
Real-time decision stream filterable by triage state; analysis arrives before you do.
Rule Editor
Visual rule editing with versioning, coverage analysis, and conflict detection.
Coverage Matrix
Data type × 8 channels, tri-state: covered / blind / never seen.
Triage Queue
Real-risk-first worklist with FP badges and memory capture.
Event Forensics
Full chain per event: decision, correlated signals, triage verdict, and rule suggestions.
User Risk
Per-user behavioral profile and risk score, with manual flags.
Decision Simulator
Evaluate as you type: paste any text and preview policy verdicts before rollout.
Shadow AI Visibility
AI-site visits reported by the Browser Shield extension. Visibility only, never blocking.
Plug into the DLP you already run
Events are normalized before they reach the engine, so the connector framework is immune to vendor differences; each new source is one connector.
Connected today
8-channel governance model
More vendor connectors are on the way. The USB channel is reserved for governance (no event source yet; the coverage matrix shows it as uncovered). Zscaler policy translation is one-directional; untranslatable rules are flagged, never silently dropped.
One-command delivery, even in isolated environments
Signed .sp packages
ECDSA-signed self-extracting packages; one command to install, upgrade, or roll back, with automatic health gates.
Full-stack orchestration
Docker Compose orchestrates 13 services: gateway, engine and business services, database and cache, plus Prometheus / Grafana / Alertmanager monitoring.
Tamper-evident audit
An append-only decision ledger (DB-level REVOKE UPDATE/DELETE) with full decision × signal × data-identity traceability.
Tell us where your DLP hurts
Share your false-positive and blind-spot pain; we will talk about how the overlay lands.
Contact us