Product
DLP: data loss prevention
DLP stands for data loss prevention: the set of controls that keeps a company's information from ending up where it should not. In KairosLink it means four capabilities over the computers you already manage: device control, which defines what storage each computer can use; data classification, which shows where sensitive files are stored; content inspection, which recognizes sensitive data the moment someone tries to move it; and channel control, which decides where it is allowed to go. Everything is defined by policy from the panel, applied without touching the machine, and logged.
There is no appliance and no separate console: all four capabilities run on the same agent you already installed for monitoring, patching and remote control, and are managed from each customer's record.
USB device control
Each policy defines what the computer does with removable storage, in three modes: Block denies all access, Read only allows reading but not writing, and Audit blocks nothing and just reports the state. The change takes effect when the device is reconnected: no reboot, and no need to kick the user out of their session.
The restriction can be extended to MTP portable devices (phones, cameras, media players) and to CD/DVD writers. For the hard cases there is strict mode, which also disables the USB disk driver and does not affect keyboards or mice: the computer stays usable, the flash drive does not.
Each customer has a base policy, the fallback that applies to every computer matching no assignment, plus as many additional policies as needed. Each additional policy is assigned to a specific computer, an Active Directory security group or an Organizational Unit, with an explicit precedence: computer, then group, then Organizational Unit, and finally the base policy. Among assignments of the same type the lower priority number wins and, if the tie remains, the most restrictive mode does. That way Finance stays blocked and IT does not, with no hand-written computer lists.
The engine checks online computers every 6 hours and re-applies the policy if someone moved it: the drift shows up in the panel and is corrected on the next cycle. If a domain GPO already manages that key, KairosLink detects it, reports it and does not overwrite it. And if a customer has no active policy, nothing is written to their computers' registry.
Data classification: where the sensitive files are
Blocking USB answers where information can leave from. Data classification answers the other half: what information is lying around on the computers. The scan detects files containing credit cards, IBAN, national ID numbers (DNI/NIF/NIE), Argentine tax IDs (CUIT/CUIL) and email addresses in bulk, reported from 50 distinct addresses in a single file.
Content never leaves the computer. What travels to the panel is metadata only: the file path, the type of data found, the number of occurrences, the size and the modification date. The detected text is not transmitted, not stored and not displayed on any screen.
The scan walks the Documents, Desktop and Downloads folders of every user profile, over plain text files (txt, csv, log, xml and json) up to 10 MB, and excludes system folders and developer tooling folders so the report does not fill up with noise. It runs once a week over online computers and also on demand, computer by computer, whenever you need it. The result is a risk map grouped by computer, filterable by data type and exportable to CSV.
Content inspection: the data is recognized as it is being moved
Classification looks at files where they are stored. Content inspection acts one step later: when someone tries to move data, the engine reads what is being moved and recognizes whether it is sensitive before the operation completes. The file name and the folder do not matter: what gets evaluated is the content.
The detectors are the same ones used by classification, so a piece of data is sensitive under the same criteria whether it is stored or on its way out: credit cards, IBAN, national ID numbers (DNI/NIF/NIE), Argentine tax IDs (CUIT/CUIL) and email addresses in bulk. The policy sets the threshold per type, because a single card number in an email is not the same as a spreadsheet with two hundred.
The analysis runs on the computer, using the policy the agent already downloaded. Inspected content does not travel to the panel: what gets logged is the event (which type of data, how many occurrences, through which channel and on which computer), not the data itself.
Channel control: where each piece of data is allowed to go
Recognizing the data is useful if you can decide what happens to it. Channel control defines, channel by channel, what the computer does when inspection finds something sensitive: let it through, let it through and log it, or stop it.
The covered channels are the five that information actually leaves through: email, web and cloud (browser forms and uploads), clipboard, printing and USB. Each one is configured separately, so you can stop cloud uploads while leaving corporate email open, or allow printing and block the flash drive.
Configuration uses the same model as the rest of the module: a base policy per customer plus additional policies assigned to a computer, an Active Directory security group or an Organizational Unit, with the same precedence. And every block lands in the same history, with the computer, the Windows user, the channel and the data type.
Device history: the evidence you will be asked for
Every computer with an active policy reports its removable device history: connections, disconnections and blocked access attempts, with the date in the computer's local time, the device and the Windows user who was signed in. Collection runs every 6 hours over online computers.
That history is read only: it cannot be edited or deleted from the panel, not even by an administrator. It is purged on its own when retention expires, which is 3 years by default and adjustable per customer. When a customer asks which flash drive was plugged into the treasury workstation and who was using it, the answer exists and does not depend on anyone's memory.
Exceptions with a name, a reason and an expiry
Blocking USB only works as long as the business can keep running. That is why a technician can open a temporary unlock window on a computer, for 1, 4 or 8 hours, without dismantling the customer's policy.
The exception is deliberately expensive to request: it requires typing a reason, explicitly acknowledging that the computer is unprotected during the window, and re-entering the technician's password. All of it lands in the security audit trail. When the window expires the computer re-locks on its own, and if the job finished earlier the technician closes the window by hand from the panel.
DLP is available on the Enterprise plan.
Frequently asked questions
What is DLP and what does it solve for an MSP?
Can I block USB only for some areas of a customer?
Does data classification upload my customers' files to the cloud?
What if someone needs to use a flash drive just once?
Is there a record of the devices plugged into each computer?
What file types does data classification analyze?
How is content inspection different from data classification?
Which channels can it stop data from leaving through?
All modules included. No credit card.