TrellixData Security

    Data Loss Prevention

    One DLP policy engine across endpoint, network, email, web, and storage.

    Not all data can or should be protected — the hard part of DLP is finding the information that actually matters and applying policy only there. Trellix Data Loss Prevention gives visibility across data types and the full data lifecycle, covering the most common exfiltration vectors from a single console available on-premises or as SaaS. Faltrox classifies, tunes, and operates it so it stops leaks without drowning users in false blocks.

    Overview

    What Data Loss Prevention is

    Trellix Data Loss Prevention (DLP) protects the most common data-exfiltration vectors — endpoint, network, email, web, and storage — from a single console. The hard part of DLP is not blocking data; it is finding the information that actually matters and applying policy only there. Trellix DLP gives visibility across data types and the full data lifecycle so you classify only the data that requires protection, rather than trying to boil the ocean.

    It covers over 400 content types and ships policies and reports mapped to common privacy, payment, healthcare, and financial frameworks, so passing an audit does not start from a blank sheet. Its open architecture integrates with SIEM and SOAR so an incident is managed end to end in the tooling your SOC already runs. Faltrox builds and tunes the classification policy — the make-or-break of any DLP deployment — and operates the console so it stops the right data without the false-positive storm that gets DLP turned off.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Endpoints

    Data discovery, classification, coaching, and blocking on Windows and macOS workstations and servers.

    02

    Network, Email & Web

    Exact data matching and monitoring stop sensitive information leaving over the network, email, and web.

    03

    Removable Media

    Device Control blocks unauthorised device use and monitors content copied to removable media.

    04

    File Repositories

    Discover scans networks and file stores to find, classify, inventory, copy, and move sensitive files.

    05

    Regulated Data

    Recognises PII, payment, healthcare, and financial data against 400+ content types for compliance.

    06

    Insider Exfiltration

    Stops both malicious insider theft and accidental leaks, with user coaching at the point of action.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Discover

      DLP Discover finds and auto-classifies sensitive data across networks and file repositories, so you know what needs protecting and where it lives.

    2. 02

      Define Policy

      Out-of-the-box, compliance-mapped policies are tuned to your data, applying protection only to information that requires it.

    3. 03

      Monitor

      Content is monitored in real time across endpoint, network, email, and web vectors, with optional OCR for images.

    4. 04

      Enforce

      Policy violations are blocked or the user is coached on why the action was stopped, turning enforcement into education.

    5. 05

      Manage Incidents

      Open integration routes DLP events into your SIEM and SOAR so each is triaged as an incident, not another unread alert.

    Capabilities

    Key capabilities

    DLP Endpoint Complete

    Protects sensitive data on Windows and macOS workstations and servers with data discovery, classification, user coaching, and content filtering, monitoring, and blocking.

    Device Control

    Blocks unauthorised device installation and adds content monitoring, filtering, and blocking on removable media — included in Endpoint Complete or available standalone.

    DLP Network Prevent & Monitor

    Protects information over networks, email, and web with exact data matching and information capture; Monitor scans traffic in real time for anomalies, with optional OCR on both.

    DLP Discover

    Unprecedented visibility across networks and file repositories to find and classify sensitive data, with rights management, auto-classification, and the ability to inventory, copy, and move files.

    400+ Content Types

    Recognises over 400 content types across the top leak vectors — workstations, network, email, and web — so classification is not limited to a handful of obvious patterns.

    Compliance-Mapped Policies

    Out-of-the-box policies and reports map to common frameworks for privacy, payment, healthcare, and financial reporting, so passing the next audit does not start from a blank policy sheet.

    Open Architecture

    Integrates with third-party SIEM and SOAR so a DLP incident is managed end to end in the tooling your SOC already runs, rather than in an isolated console.

    Unified Console

    A single console, on-premises or SaaS, drives policy, event detection, and reporting across every vector, replacing per-channel DLP silos with one administration surface.

    Specifications

    Technical detail

    Endpoint Coverage
    Windows and macOS workstations and servers
    Vectors
    Endpoint, network, email, web, and data storage
    Content Types
    400+
    Delivery
    On-premises or SaaS, single unified console
    Integrations
    SIEM, SOAR (open architecture)

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Data Loss Prevention for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Do we have to classify all of our data before this is useful?

    No — that is the trap Trellix DLP is designed around. The point is to find sensitive information and apply policy only to the data that requires protection, so you are not trying to boil the ocean. Discover does the finding and auto-classification for you.

    02Does DLP cover both malicious and accidental leaks?

    Both. It protects against intentional exfiltration by insiders and accidental leaks by well-meaning users, and includes user coaching so people learn why an action was blocked rather than just hitting a wall.

    03Can we start with just endpoints and add network later?

    Yes. The products are sold and licensed as modules (Endpoint, Network Prevent, Network Monitor, Discover) and bundled into suites, so you can scope to the vectors that matter first and expand under the same console.

    04How does it fit our SIEM?

    Its open architecture integrates with SIEM and SOAR, so DLP events flow into your existing incident workflow. Faltrox typically wires this so a policy hit becomes a triaged incident rather than another unread alert stream.

    05What does Faltrox operate here?

    The classification policy is the make-or-break of any DLP deployment. We build and tune it to your data, run the console, and act on incidents — so DLP protects the right data without generating the false-positive storm that gets DLP turned off.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us