Warda-DNSDocs Warda: from ward — to protect, guardian
v0.6.9

Data loss prevention

Business → Data loss prevention (business.dlp, Warda Business, beta: open to every installation during the beta; internal/category dlp.go, internal/admin/dlp.go) tells or blocks the services through which the data of a company can leave it, from the names asked only: Warda knows which device contacts which service, never what is sent; nothing is decrypted.

The channels (identifier, named services of internal/services):

Channel Identifier Services
File transfers transfer WeTransfer, Smash, SwissTransfer, TransferNow, Send Anywhere, Filemail, GrosFichiers, Wormhole
Personal storage storage Dropbox, MEGA, pCloud
Mixed storage (Alert only) mixed Google Drive, OneDrive, iCloud Drive
Paste sites paste Pastebin, Ghostbin, Hastebin, paste.ee, GitHub Gist, Rentry, PrivateBin, JustPaste.it, ControlC, dpaste
Anonymous file hosts upload file.io, AnonFiles, Gofile, 0x0.st, Catbox, transfer.sh, tmpfiles.org, Uguu, temp.sh
Personal webmail webmail Gmail, Outlook.com (personal), Yahoo Mail, Proton Mail, GMX, Tuta Mail, mail.com
AI assistants ai ChatGPT, Character.AI, Claude, Gemini, Microsoft Copilot, Le Chat (Mistral AI), Perplexity, DeepSeek (the services of the kind AI of Services and safe search)

The mixed storages serve work and personal accounts on the same names: the name does not tell the account, so they are only told, never blocked (the tenant restrictions of the provider do more). Gmail also serves the accounts of Google Workspace: a company allows its own with a rule.

Policy: for each channel, Allow, Tell (alert: the name passes and is recorded) or Block (block: the name is refused, reason dlp, origin dlp:<channel> in the query log), for the whole network, a group, a person or a device; the most precise choice wins (the device, then its person, then its group, then the network), a channel left out follows the larger scope, and by default everything is allowed. An allow rule of the network or of the device for a name comes before the policy (the company's own storage or mail). The pauses ("something is broken", pause of the network) do not lift a block of the data loss prevention. A blocked person may ask to unblock the name. Without Warda Business (the plan ended), the policy kept is no longer applied: every channel passes, nothing is recorded, and the policy can still be cleared; it applies again with the plan.

Events: each name told or blocked is counted by day, device, channel, name and action (kept 90 days; the task Data loss prevention, business.dlp, removes the older ones every day); it is told in the alerts once a day per device, name and action (kind dlp, see Alerts), and sent to the SIEM when the kind Data loss prevention (dlp) is chosen (see Export to a SIEM). The changes of the policy are written to the administration log (dlp.policy).

The page has three tabs: Report (today, 7 or 30 days, today included: blocked, told, devices; by channel, by device, by person, and the last 100 events; for the accounts that read the reports, reports.read: the others open on the policy), Policy (the channels by scope, with the choices made) and Inform the employees. The company policy applies to every device of the company, those of the adults who did not agree to detailed reports included: the employees must be informed, as the law requires, of what is recorded (the device, the service, the time) and for how long (90 days). The tab gives the legal notes (in France: the Labour Code, article L1222-4, the GDPR, the social and economic committee when there is one; the register of the processing and the IT charter) and a template text to adapt.

API (rules.read to read, rules.write to change; reports.read for the report): GET /api/v1/business/dlp (channels: id, services, choices; policy: the actions by scope); PUT /api/v1/business/dlp {"scope": "all"|"group"|"person"|"device", "target": "<id>", "actions": {"transfer": "block", "mixed": "alert"}} (402 without Warda Business, except to reset a scope to allowed: every action allow, or none; a choice a channel does not allow is 400); GET /api/v1/reports/dlp?period=today|7d|30d. The policy is in the backups.

Coming (see the design): signals of behaviour drawn from the names (a new channel for a device, an unusual volume or time), then, maybe, the inspection of the content.