# ZORB Security > ZORB Security develops DataShield, software that gives regulated businesses > visibility and control of where their application data goes, and whose servers > it lands on. ZORB Security Ltd is a cyber security company based in Cambridge, UK. Registered in England, company number 10992329. Founded by Dr Mark Graham, who spent forty years in cyber security and completed a PhD in malware detection at Cambridge. ZORB is a member of the NCSC For Startups programme (the UK government's cyber accelerator), and has come through Accelerate Cambridge at the University of Cambridge Judge Business School and Cyber-ASAP, the Innovate UK programme for commercialising cyber research. ## What DataShield does DataShield runs on Windows. It sits on the endpoint and correlates each application process to the true destination of its outbound traffic — binding the process that opened the connection to the destination IP, port, and the company that owns the destination network (its ASN). This is process-to-destination correlation, and it is DNS-independent: it validates where data actually goes rather than trusting what DNS returns. Flows that fail a check are blocked before data leaves the device, in real time, without human intervention. Every outbound flow is recorded, whether allowed or stopped. ZORB reads the connection, never the contents — no payload inspection, no documents, no messages, by design. Deployment runs in three stages: Discovery mode records every flow and blocks nothing; you review what it found and approve a Trustlist of the applications and destinations you permit; Active mode then enforces it, per application and reversible. Organisations can remain in Discovery mode and use the record as compliance evidence. ## What ZORB is not - Not a DLP product. ZORB is DTP — data theft prevention — covering application data rather than email and web gateway traffic. - Not an endpoint security product. DataShield protects data on devices, not the devices themselves. - Not a zero-trust platform, although it enforces zero trust at the application layer. - Not machine learning. The decision engine is rule-based and deterministic. - Windows only. There is no macOS, Linux or mobile agent. DataShield complements DLP and EDR/XDR rather than replacing them. DLP monitors email and web gateways and trusts the destination. EDR/XDR detects malicious behaviour and trusts the application. Neither connects the application that opened a connection to the company that owns the destination it reached. ## What we have measured We find 25-45% of application flows are not sent directly to the vendor. They route through CDNs, resolve to shared infrastructure, and hand off to third-party services. This is legitimate internet behaviour, but it is invisible to the organisation and outside its control, and it means a record of processing that names only the vendor is incomplete. ## The assessment Ten devices, ten days, in your own environment. Real evidence, not demo data. Discovery mode only — nothing is blocked. You receive a report of what was found, with an optional review. The findings are yours whether you buy or not. No cost, no obligation. ## How to buy ZORB does not sell direct. Every purchase goes through a partner. Cyberwin is ZORB's approved distributor for the UK, Europe, the Middle East and Africa. MSPs and technology providers wanting to offer ZORB should contact Cyberwin or email partners@zorbsecurity.com. ## Pages - [Home](https://www.zorbsecurity.com/): What DataShield does, the gap it fills, and how it compares to DLP and EDR. - [How it works](https://www.zorbsecurity.com/how-it-works/): The mechanism in technical detail — process-to-destination correlation, ASN ownership validation, and deployment. - [Assessment](https://www.zorbsecurity.com/assessment/): Ten devices, ten days, in your environment. What it delivers and how to request one. - [About](https://www.zorbsecurity.com/about/): Who ZORB is, the founder's background, and the research DataShield came out of. - [Partners](https://www.zorbsecurity.com/partners/): How to buy through a partner, and how to become one. - [Blog](https://www.zorbsecurity.com/blog/): Application data security, operational resilience and regulatory evidence. ## Articles - [DLP Isn't Enough](https://www.zorbsecurity.com/blog/dlp-isnt-enough-application-data-gap/): Where data loss prevention stops, and what it leaves uncovered. - [How Attackers Steal Data During a Breach](https://www.zorbsecurity.com/blog/how-attackers-exploit-application-data-gap/): Supply chain attacks, DNS poisoning and insider threats. - [Why Law Firms Can't Rely on DLP](https://www.zorbsecurity.com/blog/why-law-firms-cant-rely-on-dlp/): Client and matter data outside email. - [DNS Poisoning](https://www.zorbsecurity.com/blog/dns-poisoning-application-data-theft-prevention/): Why DNS-independent validation matters. - [Financial Services CRM Data](https://www.zorbsecurity.com/blog/financial-services-crm-data-walks-out-undetected/): Client portfolios leaving undetected during incidents. - [DragonForce: Three Retailers, Three Outcomes](https://www.zorbsecurity.com/blog/dragonforce-retailer-outcomes/): Same attacker, different results. - [Supply Chain Attacks](https://www.zorbsecurity.com/blog/supply-chain-attacks-application-data-theft-prevention/): Preventing data theft through trusted software. - [Encryption Isn't Enough](https://www.zorbsecurity.com/blog/quantum-encryption-incident-response/): Harvest now, decrypt later, and forensic visibility. ## Contact - General: info@zorbsecurity.com - Partners: partners@zorbsecurity.com - Press: press@zorbsecurity.com - LinkedIn: https://www.linkedin.com/company/zorbsecurity