It is an uncomfortable question because for most organisations the honest answer is that they would not, until somebody outside told them. Theft has to travel, and travelling is something you can watch.
Customer records, contracts, drawings, process recipes, source code, pricing, board papers. None of it is useful to an attacker while it sits on your file server. To have value it has to be moved somewhere they control, and that movement is observable.
This is why the absence of network detection is so expensive after the fact. Without a record of what left, an investigation cannot answer the only questions anybody will ask you: what was taken, how much, and where did it go.
The uncomfortable modern case is not an intruder. It is a capable employee, under deadline, pasting a customer list or a repository into whatever assistant works best. No malware, no intrusion, nothing for an endpoint tool to flag, and your data is now outside your control.
We report which hosts reach which AI services, what volume went, and whether it looks like documents or code. The output is a governance conversation, not an accusation, and we deliberately frame it that way.
A verdict with no substance behind it wastes your time. Every finding is built to answer the practical questions: which host and which user context, how many bytes in each direction, what the destination actually is, what else that host touched around the same time, and what to do next. If we cannot say what left, we say that instead of implying we can.
Sometimes, and we are careful about the difference. Where the transfer is observable in the clear or identifiable by protocol, we can be specific. Where it is encrypted, we report the destination, the volume, the direction and the timing, and we say plainly that the contents were not visible rather than guessing.
No, and it is worth being precise. DLP works on content, usually with agents and policies about what may leave. We work on the network view: where data went, how much, and whether that is new behaviour. The two are complementary, and we are the one that still works on a device that cannot run an agent.
Yes, as a network flow to an unsanctioned service, with the host and the volume. Whether that is a policy matter or an incident is your call, and the report is written to support that judgement rather than pre-empt it.
Tell us whether you suspect something is already inside, or whether you want to measure what your current tools would catch. Either way you get a concrete next step.
Contact us