The exact four-part check Custelis runs before a file transfer gets logged, warned, or blocked
"AI-powered DLP" is a common claim and a vague one. Here's the actual, specific model Custelis's DLP engine evaluates - no content scanning, no opaque ML score, just four checks a compliance officer can read and reason about directly.
Who / what / where / when
Every DLP rule in Custelis is defined against four clauses, evaluated in order against the context of a real data-movement event - a file copy, a USB transfer, an upload:
Who
Which employees, departments, or roles this rule applies to. Leave it blank and it's a wildcard - applies to everyone.
What
Which data classification or type - "ClientConfidential," "Aadhaar-linked," whatever your organization has defined. Also wildcards if left blank.
Where
Source and destination - a shared drive moving to personal webmail is a very different event than the same file moving to a corporate-approved cloud folder.
When
Optionally scoped to working hours or after-hours - a rule can fire differently depending on when the movement happens.
Rules are evaluated in priority order. The first rule whose who/what/where/when all match wins, and its action is what happens. If nothing matches, the event is logged with an "info" severity as a baseline - visibility first, even before you've written a single rule.
What actually happens when a rule matches
Four possible outcomes, and Custelis's engine is explicitly built to prefer stopping a problem over just recording it:
- Log - recorded, no interruption. Good for establishing a baseline before you're ready to enforce anything.
- Warn - the employee sees a warning before the transfer completes. Often the right first step once you've confirmed a rule isn't catching legitimate workflow.
- Block - the transfer is stopped outright.
- Require approval - held pending sign-off from whoever you've designated, typically a partner or compliance lead.
What it deliberately doesn't do
It doesn't read inside your files. The engine matches on classification and movement context - who, what category of data, where it's headed - not by scanning file content for patterns. That's a real architectural choice, not a missing feature: the monitoring agent doesn't send file content or even the file's real path to Custelis's servers in the first place. See how this plays out specifically for Aadhaar, PAN, and GSTIN records.
Why this matters when you're evaluating a vendor: "AI-powered DLP" that can't tell you exactly what triggered a block is hard to defend to your own team or to a client asking how their data is protected. A rule you can read - who, what, where, when, then what happens - is one you can actually explain, audit, and tune.
Related reading
See a DLP rule fire, live
No credit card to start. Intrusive features stay off until your own DPIA is recorded.
Try for free