Personally identifiable and payment card data discovery across Windows, Linux, and macOS, a data breach risk baseline, vulnerability scanning with trend reporting, and per-device breakdowns of insecure data.
billed monthly
Everything discovery provides, plus dynamic encryption and decryption of files, multiple compliance profiles, and application channel allowlisting for secured data.
billed monthly
| Platforms | Windows, Linux, and macOS |
|---|---|
| Discovery targets | Personally identifiable information and payment card data at rest on endpoints |
| Risk baseline | A quantified data breach exposure figure, broken down per device |
| Vulnerability scanning | Included, with trend reporting over time |
| Encryption | Dynamic encryption and decryption of identified files, on the Enforcement line |
| Compliance profiles | Multiple profiles supported, on the Enforcement line |
| Channel control | Application and channel allowlisting for secured data, on the Enforcement line |
| Relationship to detection | Independent control. No SOC monitoring is included on either line |
| Billing | Charged each month against one endpoint |
Discovery first, and not as a formality
The two lines are deliberately ordered. Discovery finds the regulated data actually resident on your endpoints and produces a breach exposure figure with a per-device breakdown. Enforcement adds encryption, compliance profiles, and channel control on top of what discovery identified.
Running enforcement without a discovery baseline is how data protection projects acquire their reputation. Encryption applied to files nobody mapped, in workflows nobody documented, breaks things loudly and teaches the organization that the security team is the reason the month-end close was late. Map first. The map is also the artifact that makes the second purchase easy to justify.
A number your board can actually use
The most useful thing discovery produces is not a file list. It is a monetary exposure estimate: how much regulated data sits where it should not, and what that represents if it walked out.
- Per-device breakdown. Exposure concentrates. It is normally three machines and one shared folder, not the whole fleet, and knowing which three changes what you do next.
- Trend reporting. Vulnerability scanning with trend lines turns a one-off audit into a direction of travel, which is the only form of this number that survives a second quarter.
- Evidence. Auditors, insurers, and prospective clients ask what regulated data you hold and where. Discovery answers that question with a report rather than a confident guess.
Encryption that follows the file rather than the folder
The Enforcement line applies dynamic encryption and decryption to the data discovery identified, and controls which applications and channels may handle it. The practical effect is that a sensitive file remains protected when it is copied to a personal cloud folder, attached to an outbound message, or dropped onto removable media, because the protection travels with the file rather than with the location it started in.
Multiple compliance profiles matter for organizations sitting under more than one regime at once. A firm handling both cardholder data and health information should not be forced to run the strictest rule everywhere and hope nobody notices the friction.
Where these modules stop
Neither line is monitored by the SOC and neither is a detection tier. They find and protect data at rest on endpoints; they do not tell you that an attacker is currently in your environment. That remains the job of the tier you bought.
Scope is endpoints, not every system in the estate. Data living in a line-of-business database or a SaaS platform is outside what an endpoint agent can see. And encryption is not backup: an encrypted file that gets deleted is still gone, which is a different module.