Data loss prevention scan
DLP scan: find the personal data already sitting in your files.
Most data loss prevention starts with a question nobody can answer: where is it? Point the scan at a folder and get a per-file, per-category answer — without a single document leaving the machine.
How a scan runs
Walk, detect, report.
The same detection engine as the anonymize flow, applied across a directory instead of a single document.
- STEP 01
Point it at a folder
The app reads every document it recognises: PDFs, Word and OpenDocument files, spreadsheets, presentations, emails, plain text, CSV exports and source code.
- STEP 02
Detect on-device
Each file is checked for personal data on your own machine. Nothing about the files leaves the laptop.
- STEP 03
Read the report
You get an aggregated risk report across the folder: which files carry which categories of personal data, and how severe each finding is.
What the report keeps
A scan that does not become the next data problem.
A data loss prevention tool that logs every secret it finds has simply moved the risk into its own database. This one records what type of thing was found, never the thing itself.
Categories and countsretained
How many findings of what type, per file and across the folder.
Severity and confidenceretained
Enough to triage what to look at first.
The matched values themselvesnot retained
The actual name, email or account number is never stored in the results.
The contents of your documentsnot retained
A file is read to check it, and then let go.
Where your files livenot retained
Nothing the scan remembers between runs records your folder structure.
Behaviour
Built to be run more than once.
A scan you run once is an audit. A scan you can run weekly is a control.
Fast the second time
A file that has not changed since the last scan is not examined again, so re-running a large folder takes a fraction of the time. The report tells you how many files were skipped that way.
Never a stale answer
Change what you are scanning for, or update the app, and everything is checked afresh. You never see a result produced under settings you have since changed.
Survives moves and renames
A document that was moved, renamed or copied is recognised as the same document, so re-organising a folder does not force a slow scan.
One bad file does not stop the scan
A file the app cannot read or fully process is recorded and the scan carries on, so you always get a report for the rest of the folder. Very large files are skipped and listed as skipped.
Who this is for
Compliance and IT, without a platform migration.
- Auditing a shared drive before a vendor gets access
- Finding personal data in exported ticket and log archives
- Checking a training or analytics dataset before it is used
- Answering "where is our personal data?" with evidence rather than a guess
- Re-running the same check on a schedule to see what changed
The scan is a discovery aid, not a compliance determination. It is best-effort like the rest of the detection, and the results should be reviewed by someone who understands the data.
Example report shape
Illustrative figures. Counts only — never the matched values.
Questions
About folder scanning.
Does the scan upload my files?
No. Your files are read and checked entirely in the app on your own device. Nothing about them is transmitted.
Which file types can the DLP scanner read?
PDFs with selectable text, Word (.docx) and OpenDocument text files, Excel and OpenDocument spreadsheets, PowerPoint presentations, RTF, emails saved as .eml or Outlook .msg, CSV and TSV exports, Markdown, plain text and common source-code and configuration files. The type is detected from each file's content rather than trusted from its extension, so a renamed file is still read correctly. A scanned, image-only PDF has no text layer to read, so check those separately.
Which plans include the DLP scan?
Folder scanning is part of the paid plans. The free plan covers rule-based text redaction and the browser extension's live warnings.
Does it produce anonymized copies of every file?
No. The folder scan produces a risk report — which files contain which categories of personal data — rather than rewriting your documents. Use the anonymize flow when you want a safe copy of a specific document.
Is the actual sensitive data stored in the report?
No. The report records what kind of personal data was found, how severe it is and how confident the app is — never the name, the email address or the account number itself.
How fast is a rescan?
Files that have not changed since the last scan are not examined again, so re-running a mostly unchanged folder is quick. You can always force a full re-scan when you want everything checked from scratch.
Can I scan a network drive or a shared folder?
If the folder is mounted and readable by your machine, the app can walk it. Everything is still processed locally — reading a file over your own network share is not the same as sending it to a vendor.