Knowing where your sensitive data is means watching where it goes.
Classification at rest is a snapshot. What matters is movement: which systems this data normally reaches, along which paths, at what volume, and what it means when that changes at 02:00 on a Sunday.
Classification, then lineage.
One without the other produces either a useless inventory or an unreadable stream of movement events.
Classification
Sensitive records identified by structure and context, tiered by consequence rather than filename.
Movement lineage
Every path this class of data normally travels, learned rather than declared.
Egress scoring
Volume and destination scored against history, so bulk export stands out.
Evidence trail
Who moved what, when, along which route, retained for investigation and audit.
The slow leak and the sudden one.
Exfiltration is either fast and obvious or slow and patient. Both deviate from a baseline; only one trips a volume threshold.
- Bulk exportA sudden large transfer to an unfamiliar destination, caught on volume and novelty together.
- Low-and-slow dripSmall, regular transfers that no threshold would catch but that no baseline includes either.
- Path substitutionThe same data taking a route it has never taken before, even to a known destination.
How a class of data earns a baseline.
Four stages, all observational.
Discover
Data stores and flows located by observation, including the ones nobody registered.
Classify
Records tiered by sensitivity using structure, context and your own policy.
Map
Normal movement paths and volumes recorded per class.
Watch
Deviations scored, traced and escalated with the route attached.
What this supports.
Support, not certification, the evidence trail is designed to be usable in an audit.
| Requirement | Contribution |
|---|---|
| Records of processing activity | Observed data flows, exportable |
| Breach notification timelines | Timestamped detection and containment record |
| Access accountability | Who moved what, when, along which path |
| Data residency verification | Egress destinations by region, continuously |
| Retention discipline | Movement history retained for 30 days by default |
What teams ask before they switch.
Straight answers, including the ones that make a sale harder.
Do you read our data?
Does this replace a DLP product?
What about encrypted transfers?
Can we set our own tiers?
Find out where your records actually travel.
A short engagement mapping the real movement of one sensitive data class, against what the documentation claims.