HomeUse casesInsider threat
Insider threat

The biggest threat to your data already has a badge.

They don't break in they log in. Confidencial locks sensitive data down to the field, so only the people who need it can read it. The day someone leaves, you revoke their access everywhere with one clicen on files already sitting on a device you don't control.

Q1-Compensation-Review.xlsx
HR-2026-0391 · Finance division
Selective
DepartmentFinance · Operations
Headcount in scope342 employees
Base salaryEncrypted
Annual bonusEncrypted
SSNEncrypted
Access auto-revokes the moment offboarding fires — 0 manual steps.
3 of 8 fields encryptedreadable to 2 of 5 roles
38%
of breaches involved compromised credentials
Verizon DBIR, 2024
241
average days to identify and contain a data breach
IBM Cost of a Data Breach, 2025
$19.5M
average annual cost of insider incidents per organization
Ponemon, 2026 Cost of Insider Risks
The insider lifecycle

Every employee is a data access event.

From the day access is granted to the week after someone leaves, sensitive data is exposed at every step, and offboarding never reaches the copies already made.

Onboard
Access granted
Daily access
Reads sensitive files
Collaborate
Shares, exports, AI
Resign
Notice given
Post-departure
Files on personal device
Without
OVER-SCOPED
Access broader than the role needs
FULL READ
Sees every field — salary to SSN
LEAK VECTOR
Copies, emails, pastes into AI
RETAINS ACCESS
Local copies already downloaded
NO RECALL
Readable on a device you don't control
With Confidencial
ROLE-SCOPED
Encryption maps to the role on day 1
FIELD-LEVEL
Only the fields the role allows
CONTROLLED
Protect sensitive data before it reaches AI workflows
REVOKED
Access pulled across every device, one click
WENT DARK
Local copy locks, keys stay with you
Leak vector: data exposed at this phaseControlled: Confidencial holds the lineRevocable: access ends when the badge does

Five phases. One encryption layer. Access ends when the badge does.

How it works

Five steps from exposed to controlled

From first scan to full coverage. No re-architecture. No new workflow for your team.

01  Discover

Find what’s exposed before it moves

Confidencial scans OneDrive, Drive, SharePoint, S3, and on-prem shares. Built-in classifiers surface sensitive files automatically; you see what’s exposed before someone else does.

02  Protect

Encrypt only the fields that matter

Selective encryption targets specific fields inside a file. The employee sees their department, not a colleague’s salary. The file stays usable; the sensitive content stays controlled.

03  Control

Set who sees what: role, project, or time

Policy decides who reads which fields and when. Time-limited access for contractors, role-restricted visibility across clearance levels, and access expires automatically when an engagement ends.

04  Revoke

Pull access back after the file has left

Encryption travels with the data, so you revoke access from any device at any time. Encrypted fields lock instantly: no endpoint agent, no file return, no need to know where it went.

05  Block

Keep sensitive data out of AI tools

AI Guard protects sensitive content before it reaches any AI workflow: Copilot, ChatGPT, Gemini. The analyst keeps the tool. The model gets context. The sensitive field never enters the log.

See it in action

Lock it down. Pull it back.

Insider defense comes down to two moves: only the right people can read sensitive fields, and the moment someone leaves, you can take that access away on any device. Try both.

Confidencial — Insider Threat demo
Marcus Webb · Department Manager
Q1-Compensation-Review.xlsx · local copy
Active employee
Field access 5 / 8 fields readable

The file never changes. Access does — granted by role while they're employed, revoked the instant they're not. No endpoint agent, no file recall; the same on your cloud or their kitchen table.
Why existing tools fall short

Your stack watches the door. It doesn’t follow the file.

UEBA flags behavior. DLP blocks uploads. CASB logs the session. None protect what’s inside the file once it’s opened, moved, or pasted. Confidencial does.

ScenarioUEBADLPCASBConfidencial
Employee downloads files before resigning✕ Detects the anomaly after the fact. File is already gone.~May flag the volume. Can’t protect content once downloaded.~Logs the session. No protection on the local copy.Encryption travels with the file. Access revoked remotely on any device.
Contractor retains files after the engagement endsNo visibility once offboarded.Cloud access revoked. Local copy is permanent.Session ended. File already on their hardware.Encrypted fields lock instantly on revocation. No endpoint agent required.
Employee pastes sensitive data into an AI toolBehavioral signal only. Clipboard content invisible.~Some tools block file uploads. Can’t intercept prompts.~May log the session. Can’t inspect prompt content.✓AI Guard enforces least-privilege access at the span level before ingestion
Prove access control in an audit or investigation~Alert logs show anomalies. Not field-level.~Upload and block logs. Can’t prove what was seen.~Session activity only. No document-level custody.✓Cryptographic trail, including field-level access by identity, time, and device.

UEBA sees the pattern. DLP watches the upload. CASB logs the session. None of them protect the data once it’s on a device you don’t control. Confidencial is the only layer that follows the file.

Case in point

Insider access isn’t the same as data control.

Publicly reported · 2023
01 — What happened

Two former employees of a major automaker carried roughly 100GB of internal data to a foreign newspaper, including the personal records of more than 75,000 current and former staff. They had legitimate access the whole time.

02 — The gap

Access was the only control, and access wasn’t the problem. Nothing technical governed what a credentialed insider could copy, export, or carry out. By the time it surfaced, the data was already in someone else’s hands.

“The files can still walk out. The data inside them can’t be read.”

~100GB
internal data carried out by people with valid access
75,000+
employees whose personal records were exposed
0
technical limits on what a credentialed insider could take

Selective encryption and revocable access don’t depend on trust. Salary fields, the client roster, manufacturing specs - encrypted at the object level, readable only by role, revocable the moment the badge is deactivated. With Confidencial, every file becomes self-defending: automatically encrypted, access-controlled, and traceable, so insider misuse is stopped before it happens.

Common questions

Hard questions. Direct answers.

01

Can we revoke access to a file that’s already on a former employee’s personal device?

Yes, immediately and without an endpoint agent. The encryption is embedded in the file, not enforced at the storage or network layer. When you revoke authorization, the encrypted fields on any local copy, laptop, personal drive, and backup, lock instantly. The file still exists. The sensitive content inside it becomes computationally inaccessible.
02

An employee just pasted client data into ChatGPT. Is that gone?

Without data-layer protection, that content entered the provider’s infrastructure and may sit in inference logs or fine-tuning pipelines. With AI Guard, sensitive fields are redacted before the prompt is sent, regardless of which AI tool the employee uses. The model receives context. The sensitive data never leaves your environment.
03

When a contractor’s engagement ends, do we revoke every file by hand?

No. Access policies can expire automatically at a set date or on an offboarding trigger. When the policy expires, encrypted fields lock across every device the contractor ever opened them on. There is no file-by-file step, no requirement that they return, or delete anything. The data inside is simply no longer accessible.
04

How do we demonstrate insider-risk controls to auditors?

Confidencial maintains cryptographic audit trails recording who accessed which fields, in which document, when, and from which device. That’s a verifiable chain of custody for NIST 800-53, ISO 27001, SOC 2, and CMMC, the field-level evidence behavioral alert logs and folder-level histories can’t provide.
See what's already exposed

The question isn't if someone misuses access. It's what they can take when they do.

Compensation files. Client records. IP. Source code. Which of those are fully readable on a device you no longer control? The Data Exposure Assessment answers it in 20 minutes. Most teams are surprised by what they find.