Product

The platform, mechanism by mechanism.

Kiken is an endpoint-plus-canary detection and early-warning platform. This page describes what it does today, what's on the roadmap, and — scenario by scenario — where its scope ends.

Mechanism A

Endpoint Agent

A lightweight background service for macOS, Linux, and Windows that discovers where sensitive data actually lives and watches how it's handled — on the device itself, with privacy-preserving reporting.

Discovery scans

Scheduled or on-demand scans across PDF, DOCX, XLSX, PPTX, CSV, JSON, TXT and more. Built-in detectors for SSNs, credit-card numbers, emails, phone numbers, and physical addresses, alongside your own custom regex patterns.

Page-level evidence

When enabled, the agent renders an image of the exact page where a finding occurs, so analysts review in context instead of chasing file paths. Off by default, enabled per device, stored privately.

Clipboard checks

Sensitive patterns hitting the clipboard produce a match summary — the kind of data, not the data itself.

File activity

Watched paths report operation, path, and file hash using platform-native APIs — FSEvents, inotify, ETW. Copies to USB on a managed device leave a recorded endpoint event.

Remote administration

Start, pause, and resume scans, browse the file system, and deploy tracers from the dashboard over a real-time channel.

Self-updating fleet

Agents receive signed binary updates from your server with checksum verification and rollback. Configuration hot-reloads without a restart.

Mechanism B

Tracer Documents

Canary files seeded where sensitive data lives. The moment one is opened, Kiken alerts you — including when it's opened far outside your network, on a machine you've never seen.

Two ways to seed

Generate a convincing honeypot PDF, DOCX, or HTML file, or embed a tracer into copies of existing documents — one at a time or in batches across the fleet.

What an alert contains

source ip · user-agent · request headers · timestamp

Enough to answer: who opened it, from what kind of machine, and when — your earliest confirmation that a document left its lane.

Alert thresholds

First open, new source IP, and hit-count rules — so a routine internal open doesn't page anyone, and an unexpected one does.

Honest limits

A tracer reports opens of the tokenized document while it's rendered online. Offline opens, format conversion, and copy-paste strip the token — that's inherent to canary tokens, and we say so up front.

Under the hood

Built like the agent it ships.

Agent

Rust · native OS service

Server

Rust · PostgreSQL · private object storage

Dashboard

Fleet control · alerts · reports

Self-hosted in your cloud account. Findings upload in batches; evidence images live in private storage and are served only through short-lived, access-controlled links scoped to your organization's roles.

Scope and boundaries

Scenario by scenario, honestly.

Kiken complements network DLP, CASB, and rights management — it doesn't replace them. Here's exactly what you get in the situations security teams ask about.

ScenarioWhat Kiken gives you
COVEREDA tracer document is opened — anywhere, including off your networkAn alert with the opener's IP, User-Agent, and timestamp
COVEREDA file is copied, moved, or sent to USB on a managed deviceAn endpoint event — operation, path, and file hash — recorded on that device
COVEREDA file is re-uploaded to the web and downloaded by othersBest-effort tracer alerts on opens: an early-warning signal, not a per-download counter
OUT OF SCOPEA file is printed, screenshotted, re-encoded, compressed, or hex-editedGenerally outside detection scope — these strip the canary or leave no endpoint signal
OUT OF SCOPEData moves over VPN, tunnel, RDP, or SSH to another hostThe network path isn't inspected; covered only if it lands on another managed device

Today vs. roadmap

We label the difference.

Available today

  • PII/PHI discovery with custom patterns
  • Page-level visual evidence (opt-in)
  • Tracer PDF, DOCX, and HTML documents
  • Outbound webhooks with customizable payloads → SIEM/SOAR
  • Google SSO and local accounts
  • Role-based access: admin, full, read-only

On the roadmap

  • Native cloud connectors — SharePoint, Box, OneDrive
  • Pre-built SIEM connectors
  • Configurable email-alert recipients
  • Identity and asset enrichment
  • Enterprise SSO — SAML, Okta, SCIM
  • Data-classification and need-to-know access controls

Cloud-synced files are covered today when they sync to a managed device. If a roadmap item is a hard requirement, tell us — design partners set the order of that list.

Walk it through with your security engineers.

We're happy to go scenario by scenario against your threat model — including the ones we don't cover.