Skip to content

How It Works

Incydr™ Is A SaaS Solution With An Extensible Cloud Architecture

Graphic imagery for how Incydr works

Spend less time administrating and more time protecting data

What to expect

Incydr monitors all the places your data lives to identify when files move outside your trusted environment. It prioritizes the highest risk employee activity using 120+ contextual Incydr Risk Indicators (IRIs). Watchlists allow you to programmatically protect data when files are most at risk, such as during employee departure.  Incydr offers a wide range of controls to contain, resolve and educate on events via Incydr Flows, SOAR, and Code42 Instructor. Without a lot of resources, you’ll gain control over the data leaving your organization today, and drive the secure work habits needed to decrease risk to data in the future.

Cross-platform endpoint agent

  • Windows, Mac, Linux
  • 0-4% CPU, ≤ 50MB memory

Incydr Exfiltration Detectors

  • Cloud: OneDrive, Google Drive, Box
  • Email: Office365 and Gmail
  • Apps: Salesforce

Developer resources

  • Open API with published documentation
  • SDK & CLI

Integrations

  • IAM & PAM
  • SOAR/XDR
  • SIEM
  • HRIS

Tech that stands out

Native, non-disruptive agent with a history of day 1 support for new macOS versions.

Monitor Git activity to detect when source code is pushed to unsanctioned cloud repositories.

Detect exports to personal devices and gain visibility into all data fields within the report.

Get detailed event info on file uploads to web without proxies, browser plugins or TLS inspection.

Incydr uses the source of files to “classify” them without requiring data tagging or content inspection.

Download and view the actual contents of exfiltrated files to verify their sensitivity and value. Retain files as evidence.

Identify untrusted activity without policy management using Incydr’s Trust methodology. Even trusted activity is logged for reference.

Easily query a company-wide index of all metadata without strain on endpoints. The device doesn’t need to be online for investigation.

3 ways Incydr mitigates risk to data

Pinpoints Exposure

Defined and Inferred Trust capabilities automatically distinguish between trusted activity and data exposure.

Read White Paper
Prioritizes Risk

More than 120 Incydr Risk Indicators transparently score and prioritize risky file activity.

Read White Paper
Informs Response

Take a right-sized response via Incydr Flows, Code42 Instructor, and SOAR to contain, resolve and educate.

Read White Paper
Product Overview

How Incydr™ Works: A Technical Overview of the Incydr Product Architecture

Integrations

Powerful integrations to build your security ecosystem

SOAR

SOAR playbooks leverage Incydr’s context-driven alerts to automatically initiate right-sized response controls to contain, resolve and educate on data leak events via technologies like IAM, PAM and EDR/XDR.

Learn More

SIEM

Incydr sends prioritized alerts with contextual Incydr Risk Indicator intel to your SIEM, allowing you to streamline your SOC triage process through a central workflow. A single click brings you to Incydr for investigation and follow up.

Learn More

HRIS

Incydr Flows with HR Information Systems allow you to automatically add users to Watchlists based on user attributes and lifecycle milestones. For example, automatically add all departing employees to a Watchlist for enhanced monitoring before their departure.

Learn More

IAM

Incydr Flows with IAM platforms allow you to automatically add users to Watchlists as well as contain data exposure by removing user access to applications when data risk is detected.

Learn More

PAM

Incydr Flows with PAM platforms allow you to automatically add users to Watchlists as well as contain data exposure by removing user access to sensitive vaults when data risk is detected.

Learn More

Learn why the most innovative organizations use Code42 Incydr

Get faster detection, investigation and response to data loss caused by insider threats.

Contact Sales