Product
The platform, mechanism by mechanism.
Kiken is an endpoint-plus-canary detection and early-warning platform. This page describes what it does today, what's on the roadmap, and — scenario by scenario — where its scope ends.
Endpoint Agent
A lightweight background service for macOS, Linux, and Windows that discovers where sensitive data actually lives and watches how it's handled — on the device itself, with privacy-preserving reporting.
Discovery scans
Scheduled or on-demand scans across PDF, DOCX, XLSX, PPTX, CSV, JSON, TXT and more. Built-in detectors for SSNs, credit-card numbers, emails, phone numbers, and physical addresses, alongside your own custom regex patterns.
Page-level evidence
When enabled, the agent renders an image of the exact page where a finding occurs, so analysts review in context instead of chasing file paths. Off by default, enabled per device, stored privately.
Clipboard checks
Sensitive patterns hitting the clipboard produce a match summary — the kind of data, not the data itself.
File activity
Watched paths report operation, path, and file hash using platform-native APIs — FSEvents, inotify, ETW. Copies to USB on a managed device leave a recorded endpoint event.
Remote administration
Start, pause, and resume scans, browse the file system, and deploy tracers from the dashboard over a real-time channel.
Self-updating fleet
Agents receive signed binary updates from your server with checksum verification and rollback. Configuration hot-reloads without a restart.
Tracer Documents
Canary files seeded where sensitive data lives. The moment one is opened, Kiken alerts you — including when it's opened far outside your network, on a machine you've never seen.
Two ways to seed
Generate a convincing honeypot PDF, DOCX, or HTML file, or embed a tracer into copies of existing documents — one at a time or in batches across the fleet.
What an alert contains
source ip · user-agent · request headers · timestamp
Enough to answer: who opened it, from what kind of machine, and when — your earliest confirmation that a document left its lane.
Alert thresholds
First open, new source IP, and hit-count rules — so a routine internal open doesn't page anyone, and an unexpected one does.
Honest limits
A tracer reports opens of the tokenized document while it's rendered online. Offline opens, format conversion, and copy-paste strip the token — that's inherent to canary tokens, and we say so up front.
Under the hood
Built like the agent it ships.
Agent
Rust · native OS service
Server
Rust · PostgreSQL · private object storage
Dashboard
Fleet control · alerts · reports
Self-hosted in your cloud account. Findings upload in batches; evidence images live in private storage and are served only through short-lived, access-controlled links scoped to your organization's roles.
Scope and boundaries
Scenario by scenario, honestly.
Kiken complements network DLP, CASB, and rights management — it doesn't replace them. Here's exactly what you get in the situations security teams ask about.
Today vs. roadmap
We label the difference.
Available today
- PII/PHI discovery with custom patterns
- Page-level visual evidence (opt-in)
- Tracer PDF, DOCX, and HTML documents
- Outbound webhooks with customizable payloads → SIEM/SOAR
- Google SSO and local accounts
- Role-based access: admin, full, read-only
On the roadmap
- Native cloud connectors — SharePoint, Box, OneDrive
- Pre-built SIEM connectors
- Configurable email-alert recipients
- Identity and asset enrichment
- Enterprise SSO — SAML, Okta, SCIM
- Data-classification and need-to-know access controls
Cloud-synced files are covered today when they sync to a managed device. If a roadmap item is a hard requirement, tell us — design partners set the order of that list.
Walk it through with your security engineers.
We're happy to go scenario by scenario against your threat model — including the ones we don't cover.