← Back to home

Product

DLP: data loss prevention

What is DLP and what does it solve for an MSP?
DLP is data loss prevention: controlling where a company's information can leave from, and knowing where it is stored. In KairosLink it is four capabilities over the managed computers: USB device control by policy, classification of the files holding sensitive data on each machine, inspection of content when data is being moved, and control of the outbound channels (email, web and cloud, clipboard, printing and USB). For the MSP it is a service you can sell and prove with evidence, not a promise.
Can I block USB only for some areas of a customer?
Yes. On top of the customer's base policy, you create additional policies and assign them to a specific computer, an Active Directory security group or an Organizational Unit. The server resolves which one governs each computer using the precedence computer, group, Organizational Unit and base policy, so Finance can be blocked and IT read only without maintaining lists by hand.
Does data classification upload my customers' files to the cloud?
No. The analysis runs on the computer and only metadata is reported: path, data type, number of occurrences, size and date. The file content and the detected text never leave the machine, are not transmitted and are not stored on the platform.
What if someone needs to use a flash drive just once?
The technician opens a temporary unlock window of 1, 4 or 8 hours on that computer, with a written reason and their password as confirmation. The computer re-locks on its own when the window expires, or earlier if the technician closes it by hand. The whole exception stays in the security audit trail.
Is there a record of the devices plugged into each computer?
Yes. Connections, disconnections and blocked access attempts, with the date in the computer's local time, the device and the Windows user signed in. The record is read only, cannot be edited or deleted from the panel, and is purged on its own when retention expires (3 years by default, adjustable per customer).
What file types does data classification analyze?
Plain text files (txt, csv, log, xml and json) up to 10 MB, in the Documents, Desktop and Downloads folders of every user profile. That is where system exports, customer lists and database dumps usually show up: the files nobody knows are there.
How is content inspection different from data classification?
Classification looks at files where they are stored and builds the fleet risk map. Content inspection acts when someone tries to move data: it reads what is being moved and recognizes whether it is sensitive before the operation completes, regardless of file name or folder. They use the same detectors, so the criteria are identical whether the data is stored or on its way out.
Which channels can it stop data from leaving through?
Email, web and cloud, clipboard, printing and USB. Each channel is configured separately and supports three responses to sensitive data: let it through, let it through and log it, or stop it. It is assigned with the same targeting as the rest of the module (computer, Active Directory group or Organizational Unit) and every block lands in the history with the computer, the user, the channel and the data type.
Talk to the team Try KairosLink free for 14 days

All modules included. No credit card.