Business → Data loss prevention (business.dlp, Warda Business,
beta: open to every installation during the beta; internal/category
dlp.go, internal/admin/dlp.go) tells or blocks the services through
which the data of a company can leave it, from the names asked only:
Warda knows which device contacts which service, never what is sent;
nothing is decrypted.
The channels (identifier, named services of internal/services):
| Channel | Identifier | Services |
|---|---|---|
| File transfers | transfer |
WeTransfer, Smash, SwissTransfer, TransferNow, Send Anywhere, Filemail, GrosFichiers, Wormhole |
| Personal storage | storage |
Dropbox, MEGA, pCloud |
| Mixed storage (Alert only) | mixed |
Google Drive, OneDrive, iCloud Drive |
| Paste sites | paste |
Pastebin, Ghostbin, Hastebin, paste.ee, GitHub Gist, Rentry, PrivateBin, JustPaste.it, ControlC, dpaste |
| Anonymous file hosts | upload |
file.io, AnonFiles, Gofile, 0x0.st, Catbox, transfer.sh, tmpfiles.org, Uguu, temp.sh |
| Personal webmail | webmail |
Gmail, Outlook.com (personal), Yahoo Mail, Proton Mail, GMX, Tuta Mail, mail.com |
| AI assistants | ai |
ChatGPT, Character.AI, Claude, Gemini, Microsoft Copilot, Le Chat (Mistral AI), Perplexity, DeepSeek (the services of the kind AI of Services and safe search) |
The mixed storages serve work and personal accounts on the same names: the name does not tell the account, so they are only told, never blocked (the tenant restrictions of the provider do more). Gmail also serves the accounts of Google Workspace: a company allows its own with a rule.
Policy: for each channel, Allow, Tell (alert: the name
passes and is recorded) or Block (block: the name is refused, reason
dlp, origin dlp:<channel> in the query log), for the whole network, a
group, a person or a device; the most precise choice wins (the device, then
its person, then its group, then the network), a channel left out follows
the larger scope, and by default everything is allowed. An allow rule of
the network or of the device for a name comes before the policy (the
company's own storage or mail). The pauses ("something is broken", pause of
the network) do not lift a block of the data loss prevention. A blocked person may
ask to unblock the name. Without Warda Business (the
plan ended), the policy kept is no longer applied: every channel passes,
nothing is recorded, and the policy can still be cleared; it applies again
with the plan.
Events: each name told or blocked is counted by day, device, channel,
name and action (kept 90 days; the task Data loss prevention,
business.dlp, removes the older ones every day); it is told in the
alerts once a day per device, name and action (kind dlp, see
Alerts), and sent to the SIEM when the kind Data loss
prevention (dlp) is chosen (see Export to a SIEM). The
changes of the policy are written to the administration log
(dlp.policy).
The page has three tabs: Report (today, 7 or 30 days, today
included: blocked, told, devices; by channel, by device, by person, and the
last 100 events; for the accounts that read the reports, reports.read:
the others open on the policy), Policy (the channels by scope, with the choices made)
and Inform the employees. The company policy applies to every device of
the company, those of the adults who did not agree to detailed reports
included: the employees must be informed, as the law requires, of what is
recorded (the device, the service, the time) and for how long (90 days).
The tab gives the legal notes (in France: the Labour Code, article
L1222-4, the GDPR, the social and economic committee when there is one;
the register of the processing and the IT charter) and a template text to
adapt.
API (rules.read to read, rules.write to change; reports.read for the
report): GET /api/v1/business/dlp (channels: id, services,
choices; policy: the actions by scope); PUT /api/v1/business/dlp
{"scope": "all"|"group"|"person"|"device", "target": "<id>", "actions": {"transfer": "block", "mixed": "alert"}} (402 without Warda Business,
except to reset a scope to allowed: every action allow, or none; a
choice a channel does not allow is 400); GET /api/v1/reports/dlp?period=today|7d|30d. The policy is in the backups.
Coming (see the design): signals of behaviour drawn from the names (a new channel for a device, an unusual volume or time), then, maybe, the inspection of the content.