Sensitive data never leaves: not by email, not on a USB stick, not in a cloud upload, not in a developer's commit.

Detection against your own records, enforcement on every channel data can leave through.

Akku DLP finds the sensitive data you hold and controls how it moves. Detection runs on your own records, indexed as fingerprints, so a policy fires on a real customer record rather than on anything shaped like one. The same engine runs on the endpoint, at the mail-transfer hook, in the browser and inside your cloud storage, so a policy written once behaves the same way wherever it applies. Enforcement is graded rather than binary: monitor, block, quarantine, encrypt, or prompt the person for a business reason and record what they say.

What is data loss prevention?

Data loss prevention is the practice of stopping sensitive data leaving an organisation, whether someone means to take it or attaches the wrong file to an email. It has two halves. The first is knowing what you hold and where it sits, because you cannot protect a customer record you have not found. The second is watching the routes out, which today means the endpoint, removable media, email and chat, the browser, sanctioned cloud storage, and increasingly source code. Akku does both from one console. It scans content wherever it lives, using the same detection engine everywhere, and enforces on each channel with the depth that channel allows: inline blocking before an email is delivered, action on the machine as a file is copied to a USB stick, and detection and incident raising in cloud storage you have connected.

Detection and classification

Detection that fires on your actual records.

You point Akku at your structured records, customer tables, employee data, account numbers, and it indexes them as irreversible fingerprints, so what protects your customer data is not another copy of it. Akku then recognises those exact records in anything it scans. Where the data is not in a table, 16 built-in detectors cover card numbers, identity numbers, passports, medical records and cloud keys, each with checksum validation so a number that could not be real does not raise an alert, and you can define your own. OCR reads text inside images, screenshots and scanned PDFs. Everything found is graded public, internal, confidential or restricted.

Learn more

Endpoints and removable media

Control on the machine, including when it is off the network.

One agent covers Windows, macOS and Linux from a single configuration, scanning files as they are created, modified or copied, including onto a mounted USB device. Removable media can be allowed or denied by device with an approved list, or left available with the file content deciding what is permitted onto it. Clipboard, print and screenshot are covered, and screenshots can be deleted or quarantined outright. Where blocking would be too blunt, a warn-and-justify prompt asks the person for a business reason and records it. Policies keep applying with no connection, from a signature-verified bundle cached on the machine, and findings sync when it reconnects.

Learn more

Email and collaboration

Inline inspection of every outbound message.

Every outbound message and attachment is inspected in real time, inline at the mail-transfer hook, then blocked, quarantined or allowed before delivery. Attachments are opened and read rather than judged by name or type, with text inside images extracted by OCR. Slack, Google Chat and Microsoft Teams messages and shared files are monitored through webhooks, so an incident is raised as it happens rather than at the end of a scan, and a scheduled batch import through Google Vault can pull in history. Audit-only mode runs across real traffic first, so you see what a policy would have stopped without stopping anything.

Learn more

Web, cloud and code

Your browser, your SaaS applications, and your repositories.

Uploads of sensitive files to webmail, social platforms and file-sharing sites are detected and blocked at the endpoint before the upload completes. OneDrive, SharePoint, Google Drive, Dropbox and Amazon S3 are scanned for sensitive and over-shared files, public links included, raising an alert and an incident. Sanctioned SaaS applications are covered in four modes, from API scanning to an agentless forward proxy, chosen per application. And secrets and customer data are detected and blocked in commits, in CI pipelines and in container images, before they reach a repository.

Learn more

Nothing gets blocked before you have seen what would have been

Every new policy runs audit-only first, across real traffic, so you can measure what it would have blocked and tune it before anything is blocked. A violation becomes a case with severity, evidence, an owner and comments rather than a line in a log, filtered by channel, status and severity from one dashboard. One-click policy packs cover HIPAA, PCI-DSS and GDPR with regulation tags on the policies they create. And the audit trail is cryptographically chained per workspace, so any attempt to alter what it recorded is detectable rather than merely against the rules.

See how it works.

One console and one detection engine across the endpoint, email, the browser and your cloud storage. Every policy runs audit-only first, so you can see what it would have caught before it blocks anything.

One console, one engineAudit-only firstMonitor, block, quarantine or encrypt