Data on a laptop can walk out of the building

One agent on Windows, macOS and Linux, covering USB, clipboard, print and screenshot, on or off the network.

Once a file is on a laptop it can leave on a USB stick, through a printer, through the clipboard, or in a screenshot, and none of those touch your network on the way out. The endpoint is where they can be seen and the only place they can be stopped. Akku puts one agent there, on Windows, macOS and Linux, and keeps it enforcing whether or not the machine can reach anything.

  • One agent, three platforms
  • Removable media, two ways
  • The routes people forget
  • When blocking is too blunt
  • Off the network, still enforced

One agent, three platforms

A single agent covers Windows, macOS and Linux from one configuration, so the policy you write is not three policies with different capabilities behind them. It scans files the moment they are created, modified or copied, which includes the moment they are written to a mounted USB device rather than after the copy completes. Because the same detection engine runs here as in the console, a record that would be caught leaving in an email is caught being copied to a stick.

Removable media, two ways

You can allow or deny removable devices outright, with a whitelist for the ones you have approved, which is the right answer where no USB device has any business being connected. Or you can leave them available and control what is permitted onto them, with the content of each file deciding rather than the identity of the device. The second is usually what teams settle on, because the problem is rarely the stick and always what someone puts on it.

The routes people forget

Sensitive content leaving through the clipboard, a print job or a screenshot is detected the same way as a file copy, and screenshots specifically can be deleted or quarantined rather than merely logged. When a policy fires, the action depends on where the machine is and what the policy says: monitor, block, quarantine, or encrypt. The person at the machine gets a desktop notification telling them what happened, which is the difference between a control and a mystery.

When blocking is too blunt

Some work legitimately needs a file that a policy would stop, and a blocked user with a deadline becomes a ticket, then an exception, then a habit of exceptions. Warn-and-justify prompts the person for a business reason before the action goes through, records what they wrote against the event, and allows it. You end up with the file movement, the reason, and the name, which is more than a block would have given you.

Off the network, still enforced

Policies keep applying when the machine has no connection, from a signature-verified bundle cached on the device rather than from a call to a service. Findings queue locally and sync when it reconnects. So a laptop on a plane, in a hotel, or on a home network is under the same rules as one at a desk, and the gap between the two is a delay in reporting rather than a hole in enforcement.

More in DLP

See how it works.

One console and one detection engine across the endpoint, email, the browser and your cloud storage. Every policy runs audit-only first, so you can see what it would have caught before it blocks anything.

One console, one engineAudit-only firstMonitor, block, quarantine or encrypt