Sensitive-data discovery · Exfiltration early warning

Know where your data lives. Know the moment it surfaces.

Kiken finds PII and PHI across your endpoint fleet, and seeds tracer documents that call home the instant they're opened — anywhere in the world, on or off your network.

Runs on macOS, Linux, and Windows. Alerts land in your dashboard and your SIEM.

detectsSSN 000-00-0000CARD 4111 ····EMAILPHONEADDRESS/your-custom-pattern/in PDF · DOCX · XLSX · PPTX · CSV · JSON · TXT

The platform

Discovery on the endpoint. Tripwires beyond it.

Two distinct mechanisms, kept deliberately separate — because they answer two different questions: where is my sensitive data? and has it gone somewhere it shouldn't?

Mechanism A

Endpoint Agent

Knows your managed devices inside out.

  • Sensitive-data discovery. Scans PDF, DOCX, XLSX, PPTX, CSV, JSON, TXT and more for SSNs, card numbers, emails, phone numbers, addresses — plus your own custom patterns.
  • Visual evidence. Optionally captures an image of the exact document page where a finding occurs. Off by default; you enable it per device.
  • Clipboard awareness. Detects sensitive patterns copied to the clipboard and reports a match summary — not the contents.
  • File activity trail. Records operation, path, and file hash for activity on watched paths, using platform-native APIs.
  • Tunable footprint. Scan paths, schedules, file-type scope, and size limits are all configurable to keep endpoint impact low.
Mechanism B

Tracer Documents

Works where the agent can't follow.

  • Canary files, your way. Generate honeypot PDF, DOCX, or HTML documents — or embed tracers into copies of your real files, individually or in batches.
  • Alert on open. The moment a tracer is opened, you get the opener's IP address, User-Agent, headers, and timestamp.
  • Beyond your perimeter. Tracers fire from unmanaged machines too — your earliest signal that a document has surfaced somewhere unexpected.
  • Threshold controls. First open, new source IP, or hit count — delivered in-app and pushed to your tools via webhook.

Honest limits: tracers are a tripwire, not DRM. They report opens of the tokenized document — they don't follow raw bytes through re-encoding. See scope and boundaries

From signal to workflow

Detections that land where you already work.

  1. 1

    Detect

    An agent finding on a managed device, or a tracer opened anywhere in the world.

  2. 2

    Alert

    Real-time dashboard notifications with context — and page-level visual evidence when you've enabled it.

  3. 3

    Route

    Outbound webhooks with customizable payloads push every detection into your SIEM or SOAR — Splunk, Securonix, and friends.

Custom detection patterns are a name and a regex in the dashboard — pushed to your whole fleet. No engineering required.

Scope and boundaries

What Kiken is not.

Security teams get burned by overclaiming, so we don't do it. Every capability statement we publish is accuracy-checked against the shipped product.

Not an inline blocker

Kiken detects and alerts. It tells you sensitive data exists or a tracer was opened, and routes that signal into your response workflow — it doesn't sit in the egress path.

Not DRM

Tracers report when a tokenized document is opened. They don't follow a file's raw bytes once contents are extracted, re-encoded, or transformed.

Not a network tap

The agent observes local file and process activity on managed devices. It doesn't inspect traffic or name the network destination of an upload.

Fleet operations

Deployed like infrastructure, not a science project.

  • Single installer per device; enrollment tokens for secure onboarding
  • Central configuration push — scan paths, schedules, patterns, tags
  • Runs as a managed OS service ordinary users can't casually stop
  • Role-based access: admin, full-access, read-only
  • Google SSO and local accounts today; SAML, Okta, and SCIM on the roadmap
  • Evidence stored privately, served only through short-lived, access-controlled links

Seed your first tracer this week.

A pilot takes one installer and one planted document. You'll know it works the first time something opens a file it shouldn't have.