Data theft: one way out is all it takes.
We run controlled campaigns with synthetic payloads, on the configured paths, and observe how your controls actually behave.
- Synthetic test payloads only
- Flexible deployment
- Decoys sent only to test accounts we control
Your controls are in place. Their effectiveness is assumed.
DLP, EDR, proxy, firewall: validated at installation, rarely put to the test since. Policies drift with every change. A typical case: DNS, FTP and paste sites blocked while other paths are left wide open. The posture is uneven.
Test your exit paths before attackers do.
One tactic, covered in depth: exfiltration. Keep your DLP, your EDR and your pentests. We show you what they stop, and what they let out, on the scenarios tested.
The 8 channels tested, what is not covered and how data is handled →
- 01
TestWith synthetic payloads, we run controlled campaigns on the configured paths.
- 02
ObserveFor each scenario tested: blocked; detected, not blocked; or not detected, with a dated result.
- 03
FixUpcoming versions will bring contextual, prioritised recommendations, validated by retest.
- 04
ReplayUpcoming versions will let you schedule periodic replays, or replays triggered by a change.
The data is synthetic. The exit paths are very much your own.
Workstations
The agent runs on a real Windows or Linux machine in your estate: whatever it gets out, a user or an attacker could get out too.
Corporate network
HTTPS, HTTP, DNS, FTP, ICMP: the outbound channels left open, and the volume that triggers your filtering.
Cloud and applications
Google Drive, GitHub Gist, paste sites: the cloud services through which data leaves the company.
Test payloads are synthetic; no real customer business data is used as a campaign payload. Agents in your environment, orchestration in the Enforcis cloud or in your private cloud; 100% on-premises deployment possible, subject to assessment, for critical environments. Decoys go out only to test accounts controlled by Enforcis and purged after each campaign.
Your audit files describe your controls. Add dated evidence of what they really stop, on the scenarios actually tested.
Every campaign is timestamped and repeatable: you add the date, the channel and the result to your audit file.
Data leakage prevention and monitoring activities.
Assessing the effectiveness of risk-management measures.
Digital operational resilience testing, alongside threat-led testing.
Data security outcomes, and improvements identified from security tests and exercises.
Factual material for your cybersecurity disclosures and your annual NYDFS certification.
Periodic technical evaluation of your safeguards, and transmission security for ePHI.
Where could your data get out? Three ways to find out.
The DLP Proof Kit
7 templates to fill in to show, on scenarios that have actually been tested, what your egress controls really stop, and what they let through, beyond their configuration alone. A 10-page PDF.
A 30-minute demo built around your context
From a standard browser: a campaign replayed across the channels covered by the demo scenario and the controls in place on our demo environment.
POC in a synthetic environment
Then, if you wish, a pilot on a limited production scope, with a report and prioritised findings.
Our guides to testing exfiltration, one channel at a time.
What runs in your environment, and how we get started.
Is it risky to test in production?
Our campaigns use synthetic payloads only: no real customer business data is used as a campaign payload, which is why they can run in production. The agent runs on Windows or Linux workstations and servers in your estate. You stay in control of the scope: together we define the segments tested, the agents and when each campaign runs. To get started without touching production, the POC runs in a synthetic environment.
What gets installed in our environment?
A Windows or Linux software agent, at least one per subnet tested. An orchestrator drives the agents and consolidates the results, and a console lets you launch and monitor campaigns. Agents in your environment, orchestration in the Enforcis cloud or in your private cloud; 100% on-premises deployment possible, subject to assessment, for critical environments. Upcoming versions will bring SIEM integrations.
How do we get started?
With a 30-minute demo built around your context. Next comes the POC, in a synthetic environment with no impact on production, so your team can get to grips with the console and the campaigns. Then a production pilot on a limited scope, with synthetic data only: report, prioritised findings and a prepared retest to validate the fixes. Together we set the scope, the duration and the launch date. After that, campaigns can be relaunched as needed. Upcoming versions will let you schedule periodic replays, or replays triggered by a change, depending on how critical the scope is and how fresh the evidence needs to be.
What does the deliverable look like?
Today, each campaign gives dated, traceable results within the scope actually tested: for each scenario, the state observed (blocked; detected, not blocked; not detected). Upcoming versions will bring multi-level reporting (leadership, CISO, operations), with MITRE ATT&CK mappings and, where the correspondence is established, MITRE D3FEND, as well as SIEM integrations. They will also bring contextual, prioritised recommendations, validated by retest.
How your egress controls actually behave, observed scenario by scenario.
7 templates to fill in to show, on scenarios that have actually been tested, what your egress controls really stop, and what they let through, beyond their configuration alone.

Read 3 pages of the kit before downloading →
Do your controls really stop data leaks?
Discover a new way to observe how your egress controls actually behave, scenario by scenario, and to map your exfiltration vectors. Get ahead, and act before attackers do.
An international team based in France that specialises in one thing: exfiltration.
It all started in 2021 at Holiseum, with the ransomware blank-fire exercise (Tir à Blanc de Ransomware), which won awards in 2022 (first prize at Cybernight, first prize at the Cas d’Or de la Cybersécurité). After 40 runs of that exercise and a white paper in 2023, we founded Enforcis in 2025 to focus on a single subject: data leaving the organisation.

