Your applications send business-critical data to cloud providers — CRM, finance, case management. You assume it goes directly to the vendor. Often it doesn’t: intermediaries that aren’t obvious, countries nobody chose, or a destination it was redirected to by someone else.
Is that an acceptable risk? You can’t answer that until you’ve evidenced your own data.
The findings are yours to keep, whether you go further or not.
Mapped, named, timestamped. Every outbound connection from every monitored application. Your RoPA lists the recipients you know about — this is the list of the ones you don’t.
Discovers applications and updaters connecting to intermediaries, unknown countries, or destinations they were redirected to.
DNS gives you a domain name. DataShield tells you if the IP from DNS actually maps to the application.
Mapped destination data against your regulator’s obligations — ICO, FCA, SRA and others. You get 72 hours to tell the ICO what happened. Forensic reconstruction takes longer than that.
Across the estates we’ve measured — and that figure is application flows only, before any malicious activity (which takes the number higher).
The interesting number is yours, not ours.
Submit a request, then download DataShield directly from the ZORB Portal — code-signed, SHA-256 published, no email attachment. Install on ten Windows 10 or 11 PCs: silent, invisible to users, zero performance impact.
Every outbound data flow appears in the ZORB Portal in real time. See which applications are sending data and exactly where it is going to.
A report of everything we found: applications, destinations, and anything that warrants a closer look. Plus an optional face-to-face review to walk through it. You get evidence, not a presentation.
DataShield monitors which applications are sending data and where it is going to. It does not inspect payload content — we have no visibility of your business information, documents, or communications.
That is by design, and it is permanent.
No. DataShield installs silently and runs in the background. Zero configuration, zero changes to your existing security stack, zero performance impact. Nothing is blocked.
We email you a link to the ZORB Portal — your business email is the login. You set a password, connect 2FA, and you’re in. From there you download DataShield yourself, with your account’s unique ID already in the install command. It’s code-signed, and we publish the SHA-256 so you can verify what you’ve downloaded. No email attachments, no third-party file links.
Windows 10 or 11. Admin rights to install; after that it runs as a Windows service, so it starts on boot and an ordinary user can’t stop it. No reboot needed — it starts as soon as it’s installed. It runs on Windows Server too, but we’d keep the assessment to PCs. Linux is available on request. There’s no macOS build.
The ten that would be attacked first, or the ten that use the most applications. Finance, the C-suite, anyone handling client or deal data. Ten random machines tell you the estate is fine; ten well-chosen ones tell you something worth knowing.
No obligation. The findings are yours to keep — many organisations use them to inform their existing security vendors. If you do want to act on what we found, the same agent moves from discovery to enforcement: application data goes to the vendor it’s meant for, or it doesn’t leave. That’s a separate decision, made once you’ve seen your own evidence.
Yes — and the longer it runs, the richer the evidence. Contact us at info@zorbsecurity.com and we’ll extend it to fit.
For every outbound connection: process name, destination IP, timestamp, device and user. We then add the ASN that owns the destination. Device and user are what make an event flow useful — without them you have traffic, not evidence. No payload content. Hosted in the EU. When the assessment ends the data stays yours to download for 30 days, then it’s deleted.
Yes. DataShield monitors destination and application identity only — no payload content, no business data, no client information. See exactly where your data is going to before a regulator asks you — regulators increasingly treat “we can’t show you” as a finding in its own right, separate from whether anything actually went wrong.
Possibly — contact us at info@zorbsecurity.com and if your supplier isn’t already a ZORB partner we can work with them directly. Or we can recommend one of our preferred suppliers to match your business.
We use cookies on this site. Strictly necessary cookies are always active. We'd also like to use analytics cookies to help us improve our website — these are only set with your consent. See zorbsecurity.com/cookie-policy for details.