Built for Security Teams
Deep content analysis, real-time detection, seamless integration with your existing security stack.
Deep Content Analysis
50+ File Formats
Inspect documents, archives, images with embedded data, and more. From PDFs to ZIP files, nothing escapes analysis.
Custom Pattern Matching
High-performance regex engine for custom data patterns. Define your own rules for proprietary data types.
Context-Aware Detection
Reduces false positives by understanding context. A credit card number in a test file is different from one in a customer database.
Stream-Based Processing
O(1) memory consumption regardless of file size. Scan multi-gigabyte files without breaking a sweat.
Built-in Scanners
50+ ready-to-use scanners across five categories
PII
- Social Security Numbers
- Credit Card Numbers
- Passport Numbers
- Driver's License
Credentials
- AWS Access Keys
- GCP Service Accounts
- Azure Connection Strings
- Generic API Tokens
Financial
- Bank Account Numbers
- Routing Numbers
- IBAN / SWIFT Codes
- Tax IDs
Healthcare
- Medical Record Numbers
- Health Insurance IDs
- DEA Numbers
- NPI Numbers
Code Secrets
- Private Keys
- .env File Contents
- GitHub/GitLab Tokens
- DB Connection Strings
Compliance Frameworks
Pre-built rule sets for six major compliance standards
GDPR
Personal data protection for EU residents. Detect names, addresses, and identifiers covered by the General Data Protection Regulation.
HIPAA
Healthcare information protection. Identify Protected Health Information (PHI) as defined by US healthcare privacy law.
PCI DSS
Payment card data security. Detect cardholder data including PANs, CVVs, and magnetic stripe data.
SOX
Financial records integrity. Identify sensitive financial data subject to Sarbanes-Oxley Act requirements.
CCPA
Consumer privacy for California residents. Detect personal information covered by the California Consumer Privacy Act.
ISO 27001
Information security management. Comprehensive coverage for data classified under ISO 27001 controls.
Seamless Integration
osquery Extension
Native osquery integration. Query DLP alerts with SQL, join with other osquery tables, integrate with your fleet management.
SIEM Export
Forward alerts to your security stack. Native support for Splunk, Elastic, and any syslog destination.
Performance
5.4M ops/sec
Stream-based O(1) memory. Scan without impacting endpoint performance.
Platform Support
Basic Edition
- Linux endpoints
- Up to 5 servers
- All 50+ scanners
- osquery integration
- Community support
Enterprise Edition
- macOS + Linux
- Unlimited servers
- All 50+ scanners
- osquery integration
- SIEM export
- Priority support
- Custom scanner development