Know where your data lives — without moving a byte of it.
Netgraph's DSPM discovers, classifies and monitors sensitive data across the cloud estate and on the endpoint itself. The unified endpoint agent scans path-scoped locations on-host and sends back only classification labels — file contents never leave the machine. Classified locations become nodes on the security knowledge graph, so every alert can answer the question that actually sets its priority: does this host hold PII?
What ships in the module
Classification that the whole platform consumes.
Policy in, labels out
One Fleet policy. Every host classified. Zero contents exfiltrated by your own tooling.
You define scan scope and recognizers once in Fleet policy; the agent-side classifier applies them at scan time on each host. What returns is a compact map of labels and locations — enough to drive graph context, UEBA risk and DPDP evidence, and nothing an attacker (or an auditor) could mine for the data itself.
- Path-scoped: include / exclude / custom paths per policy.
- Multi-select recognizer packs — Aadhaar, PAN, bank account, passport, health — plus custom.
- Labels-only telemetry: classification results, never file contents.
- Results land as graph nodes and flow to UEBA risk and compliance evidence.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Data discovery & classification | Discover, classify and monitor sensitive data across cloud estate and endpoints | DSPM pages |
| Endpoint scan policy | Path-scoped discovery — include / exclude / custom paths — pushed to the unified agent | Fleet policy (Fleet Manager) |
| Recognizer packs | Aadhaar, PAN, bank account, passport, health identifiers — multi-select, plus custom recognizers | Fleet policy ▸ DSPM configuration |
| Labels-only telemetry | Agent-side classifier applies recognizers at scan time; only labels leave the host | Unified endpoint agent |
| Graph fusion | Classified locations become graph nodes; blast radius includes data sensitivity | Security knowledge graph |
| UEBA risk factor | Data sensitivity feeds entity risk scoring | UEBA entity risk |
| Compliance evidence | DPDP Act 2023-aligned evidence trail of where personal data lives | Compliance / DPDP evidence |
Works with everything on the graph
Cloud Security
CSPM findings gain teeth when the graph knows what the misconfigured resource actually holds.
Explore→Agentic AI SOC
Agents weigh data sensitivity when triaging — an alert on a PII-holding host reads differently from the same alert elsewhere.
Explore→NextGen SIEM
Detection and enrichment run on the same graph DSPM labels — sensitivity context arrives with the alert, not after it.
Explore→