Blog · How it works

The exact four-part check Custelis runs before a file transfer gets logged, warned, or blocked

"AI-powered DLP" is a common claim and a vague one. Here's the actual, specific model Custelis's DLP engine evaluates - no content scanning, no opaque ML score, just four checks a compliance officer can read and reason about directly.

Who / what / where / when

Every DLP rule in Custelis is defined against four clauses, evaluated in order against the context of a real data-movement event - a file copy, a USB transfer, an upload:

Who

Which employees, departments, or roles this rule applies to. Leave it blank and it's a wildcard - applies to everyone.

What

Which data classification or type - "ClientConfidential," "Aadhaar-linked," whatever your organization has defined. Also wildcards if left blank.

Where

Source and destination - a shared drive moving to personal webmail is a very different event than the same file moving to a corporate-approved cloud folder.

When

Optionally scoped to working hours or after-hours - a rule can fire differently depending on when the movement happens.

Rules are evaluated in priority order. The first rule whose who/what/where/when all match wins, and its action is what happens. If nothing matches, the event is logged with an "info" severity as a baseline - visibility first, even before you've written a single rule.

What actually happens when a rule matches

Four possible outcomes, and Custelis's engine is explicitly built to prefer stopping a problem over just recording it:

Log Warn Block Require approval

What it deliberately doesn't do

It doesn't read inside your files. The engine matches on classification and movement context - who, what category of data, where it's headed - not by scanning file content for patterns. That's a real architectural choice, not a missing feature: the monitoring agent doesn't send file content or even the file's real path to Custelis's servers in the first place. See how this plays out specifically for Aadhaar, PAN, and GSTIN records.

Why this matters when you're evaluating a vendor: "AI-powered DLP" that can't tell you exactly what triggered a block is hard to defend to your own team or to a client asking how their data is protected. A rule you can read - who, what, where, when, then what happens - is one you can actually explain, audit, and tune.

Related reading

See a DLP rule fire, live

No credit card to start. Intrusive features stay off until your own DPIA is recorded.

Try for free

← Back to the blog