Outbound email DLP · Early access

Same file. Different risk.

Aegis reads who is sending sensitive data, to whom, and whether that is normal, then applies your policy.

Book a demo> book_demo→↵Early Access·Same Connection as Inbound·No MX Change
Trusted by leading
security teams at:
The problem

A pattern sees the file. Not where it is going.

Regex rules fire on routine payroll and miss the leak to a personal inbox, so teams tune them down until real leaks pass.

72%

of the actions behind employee-caused breaches were misdelivery: data sent to the wrong person.

Verizon 2025 Data Breach Investigations Report
See it work

Autocomplete picks the wrong person. Aegis holds the email.

Before the email is delivered, Aegis checks what is in it, who it is going to and whether that is normal for the sender, then applies your policy.

Illustrative example. Names and domains are fictional.
Available policy actions can differ by platform during early access.
What it catches

The other ways data leaves. Pick one to see it.

Outbound · Forward7:14 PM
From: dana.k@northwind.example · To: dana.k.home@gmail.com

Fwd: payroll-2026-09.xlsx, forwarded to a personal account after hours.

  • RecipientPersonal address in the sender's own name
  • FileSocial security numbers ×214, account numbers ×214
  • PolicyPayroll data
High risk: company file to a personal inboxSecurity alerted
Illustrative example. Names and domains are fictional.
How it works

How Aegis reads an outbound email

Seven agents look at the content, the attachment, the recipient and the sender's habits. Your policy decides what happens next.

Built in

Nothing new to deploy.

3
Finding types on every outbound email: personal data, financial data and secrets.
0
New connectors. DLP runs on the API connection inbound already uses.
For your security team
  • Test before it acts.Run a policy in audit on live outbound mail, then raise it to alert.
  • Your own policies.Start from compliance packs or build rules from the detector catalog, scoped by sender and recipient.
  • Private by default.A flagged snippet stays masked until an admin opens it.
FAQ

What your security team will ask

Can Aegis block a message before delivery?

Actions depend on the platform, and pre-delivery blocking is not available on Google Workspace. During early access we confirm which actions your tenant has.

Does it need MX or transport-rule changes?

Not for detection. It uses the same API connection as inbound.

Can we write our own policies?

Yes. Start from compliance packs or build rules from the detector catalog, scoped by sender and recipient.

Can we test a policy before it acts?

Yes. Run it in audit on live outbound mail, then raise it to alert.

Your turn

See it on your own tenant.

Early access runs on the connection you already have. Start a policy in audit, then decide.

Same connection as inboundNo MX changeAudit mode first

See what Aegis finds in your environment.

Connect a tenant, run in monitoring mode, and compare against what your current stack delivered.