Your Data Is Already Moving

Every day, employees send emails with attachments, copy files to USB drives, upload documents to cloud storage, print sensitive reports, and paste data into AI tools. Most of it is legitimate work. But without visibility, you can't tell the difference between business as usual and a data breach in progress.

532

data breaches notified to the OAIC in the first half of 2025

Health (18%), finance (14%), and government (13%) were the most affected sectors.

$4.4M

average cost of a data breach

Shadow AI adds another $670K on average.

37%

of Australian data breaches caused by human error

Wrong recipients, accidental uploads, and misconfigured sharing. Not hackers.

Data Leaves Through Channels You're Not Watching

Traditional DLP tools focus on network perimeter and email gateways. But data walks out the door on USB drives, through personal cloud accounts, via print jobs, and increasingly through AI prompts. ActivityPulse watches every exit point.

Physical Media

USB drives, external hard drives, and SD cards remain the most common exfiltration vector for insider theft. Most organisations have no visibility into what files are copied to removable media.

Cloud & AI Services

Personal Dropbox, Google Drive, and AI tools like ChatGPT are the new blind spots. Employees upload sensitive files without realising they’re creating data loss events.

Human Error

37% of Australian data breaches are caused by human error, not malicious intent. Wrong recipients, accidental uploads, and misconfigured sharing permissions.

How ActivityPulse Detects Data Loss

Six data channels logged in real time, with rules-based detection and automated response when policies are breached.

Complete Coverage Across Every Exit Point

USB & Removable Media

Device connections, file copies, file reads, device serial numbers, and storage capacity. USB drives, phones, SD cards, optical drives. 3 DLP rules: large transfers, sensitive file types, standard transfers.

Downloads

File name, path, size, source URL, and browser. Detects executable downloads, incognito downloads, and large archive files. 3 DLP rules with severity classification.

Web & Cloud Storage

Browsing activity to file hosting sites (WeTransfer, Mega) and personal cloud storage (Dropbox, Google Drive, OneDrive). 2 DLP rules for upload detection.

Email & Attachments

Sender, all recipients including BCC, subject, attachment names, count, and total size. Mass email detection by recipient count. 1 DLP rule for outbound attachments.

Print Jobs

Document name, printer, page count, colour and duplex settings. 2 DLP rules: large jobs (>20 pages) and standard print logging.

Clipboard

Content type, text preview, file paths, source application, and data size. 1 DLP rule for file clipboard operations between applications.

Rules-Based Data Movement Detection

Configure rules to detect suspicious data movement patterns across all six channels. Respond automatically with alerts, notifications, and retention holds.

Fri 4:42 PM
USB drive connected (Kingston DataTraveler, 64GB)
Fri 4:43 PM
23 files copied from \\server\finance\ to E:\backup
Fri 4:51 PM
Emailed client-contracts-2026.zip to personal Gmail (BCC)
Fri 4:55 PM
Uploaded employee-salaries.xlsx to personal Google Drive
Fri 4:58 PM
Printed “Board Strategy Q2 2026.docx” (14 pages, colour)
Fri 5:01 PM
USB drive disconnected
Fri 5:03 PM
Submitted resignation via email

The Investigation Timeline shows every data movement in chronological order across all six channels. Filter by module, user, or date range. Export as branded PDF or DOCX for legal and compliance records.

Instant Alerts with Automated Protection

Pre-built Rule Templates

DLP-specific scenarios: large USB transfers, external email with attachments, cloud uploads, AI file uploads, after-hours printing

Automatic Retention Hold

When a rule fires, automatically preserve all data for the matched user, preventing routine data purge from destroying evidence

Slack, Teams & Email Alerts

Formatted evidence cards delivered to your security team’s channels within seconds of the event occurring