A public link is a leak that nobody caused

Upload control in the browser, discovery across five cloud stores, four coverage modes per SaaS application, and secrets stopped before they reach a commit.

A file uploaded from a browser, a cloud folder shared with a link anyone can open, and a credential committed into a repository are three different problems in three different places. Akku covers all three with the same detection engine and the same policies.

  • Out through the browser
  • Already in the cloud
  • Your SaaS applications, four ways
  • Before it reaches the repository

Out through the browser

Uploads of sensitive files to webmail, social platforms and file-sharing sites are detected and blocked at the endpoint, before the upload completes rather than after the file has landed somewhere. Because the control sits in the agent, it applies to any site rather than to a list of ones you have integrated with, and it applies when the machine is off your network.

Already in the cloud

Akku scans OneDrive, SharePoint, Google Drive, Dropbox and Amazon S3 for sensitive files and for risky exposure, including files shared by public link. A finding raises an alert and an incident, with the file, the location and the exposure named. Where a connector supports write-back, which today means Dropbox, Akku can revoke a share or delete the file. Google Drive and Microsoft Graph are read-only, so findings there are raised for you to act on rather than changed for you.

Your SaaS applications, four ways

Sanctioned cloud applications are managed from one console, and each application is covered in the mode that suits it rather than in one mode for all of them. API mode connects to the application, scans the content inside it, and remediates through a batch connector. Endpoint mode has the agent block or monitor uploads to that application's domains, which works without any integration on the application's side. Network mode uses an agentless forward proxy to monitor or block per application, for cases where no agent can be installed. Audit-log mode ingests the application's own logs for visibility where none of the others are possible.

Before it reaches the repository

With secrets in code, when you catch a leak decides what it costs. A credential caught at commit time costs one file edit. The same credential found after it has been pushed, built and shipped inside an image is a rotation, a rebuild, and a question about who pulled that image in between. Detection and blocking cover commits, CI pipelines and container images.

More in DLP

See how it works.

One console and one detection engine across the endpoint, email, the browser and your cloud storage. Every policy runs audit-only first, so you can see what it would have caught before it blocks anything.

One console, one engineAudit-only firstMonitor, block, quarantine or encrypt