← Home

SECURITY AND TRUST

Security and trust: what stays with you, what leaves, and why

Beams of light running through a data centre, like data looking for a way outAgents in your environment · synthetic payloads only

The essentials in 30 seconds

  • Agents in your environment, orchestration in the Enforcis cloud or in your private cloud; 100% on-premises deployment possible, subject to assessment, for critical environments.
  • Test payloads are synthetic; no real customer business data is used as a campaign payload.
  • The test payloads that leave are synthetic decoys, sent by design to test accounts controlled by Enforcis and purged after each campaign.
  • Your vendor assessment needs more than this page: we answer in writing.

What runs in your environment

  • Lightweight agents on Windows or Linux machines, deployed in your own environment.
  • Orchestration in the Enforcis cloud or in your private cloud; 100% on-premises deployment possible, subject to assessment, for critical environments.
  • Upcoming versions will bring SIEM integrations and deployment options that make it possible, in particular, to keep logs and evidence in your environment.
  • Test payloads are synthetic; no real customer business data is used as a campaign payload.

What leaves, and where it goes

An exfiltration test only means something if something actually tries to leave. That is why the test payloads that leave are decoys, by design: synthetic data built to look real enough to trigger your rules (synthetic IBANs, synthetic HR files, “Confidential” labels), with no value of its own.

  • For the cloud channels, the test destinations are GitHub Gist, Google Drive and DPaste accounts controlled by Enforcis.
  • These accounts are purged after each campaign.
  • The scope (machines, channels, decoy categories) is defined with you before any campaign in production.
  • If you prefer to start without touching production, the proof of concept runs in a synthetic environment.

How decoys are designed is detailed in Synthetic data: testing exfiltration in production without using any real business data.

What version 1.0 covers, and what it does not

Version 1.0 tests 8 channels: HTTPS, HTTP, DNS, FTP, ICMP, GitHub Gist, Google Drive and DPaste. It does not replay removable media (USB), printing, OT networks, outbound email or native Microsoft 365 locations. The full list, and the controls usually involved for each channel, is on the Platform page.

Your vendor security assessment

Bringing a testing tool into your information system rightly calls for more than this page. As part of your vendor assessment, we answer in writing questions such as:

  • What privileges do the agents need on Windows and on Linux?
  • How are the agents, the orchestrator and the console updated? Are the binaries signed?
  • How do users authenticate to the console, and which roles exist?
  • Which network flows does a campaign generate: ports, protocols, endpoints for each channel?
  • Which logs and results are produced, where are they kept, and what reaches the Enforcis cloud when orchestration runs there?
  • How are vulnerabilities in the platform handled?
  • Which subcontractors are involved, and under which data processing agreement?

These are also the questions we recommend asking any vendor in Choosing a DLP testing tool: criteria and questions for the vendor.

Vendor security review

Send us your questionnaire.

Choose “Vendor security review” as the subject of the demo form: we come back to you with written answers.

This website

  • Audience measurement with Matomo, without cookies, with truncated IP addresses and data hosted on our own server.
  • Forms (demo, kit) are processed by our processor HubSpot; the form itself states what is collected and why.
  • Forms are protected against automated submissions by an internal check, with no third-party service and no cookie.

Details are in the privacy notice. For a security question about Enforcis or this website, write to contact [at] enforcis.com.

Frequently asked questions

Is Enforcis a SaaS service?

It depends on the architecture you choose. Agents in your environment, orchestration in the Enforcis cloud or in your private cloud; 100% on-premises deployment possible, subject to assessment, for critical environments.

Does Enforcis see our data?

Test payloads are synthetic; no real customer business data is used as a campaign payload. Where findings and logs are kept depends on where the orchestration runs: in the Enforcis cloud, in your private cloud or, subject to assessment, on your premises. We detail it in writing during your vendor assessment.

Where do the decoys go during a test?

For the cloud channels, to GitHub Gist, Google Drive and DPaste accounts controlled by Enforcis and purged after each campaign. Decoys leave by design: that is how a test shows whether your controls stop them.

How do we get the answers our vendor assessment needs?

Ask for a vendor security review: choose that subject in the demo form and we answer your questions in writing.

How your egress controls actually behave, observed scenario by scenario.

With synthetic payloads, we run controlled campaigns on the configured paths and observe how your controls actually behave, scenario by scenario.