Kiteworks Expands Data Control Plane With Agent and Human Error Prevention

Kiteworks, a provider focused on regulatory compliance and risk management for sensitive data exchanges, announced the general availability of Agent and Human Error Prevention (AHEP). The new capability extends Kiteworks’ governance, enforcement, and audit infrastructure for secure data exchange into outbound email, providing users with warnings before sensitive information is sent to an unintended recipient rather than attempting to identify the incident afterward. The launch reinforces Kiteworks’ broader strategy of using a single control plane to govern every channel, human workflow, and agent workflow involved in sensitive data exchange.

Misdirected email represents the largest category of data security incidents reported to the UK Information Commissioner’s Office, comprising 21% of all reported breaches.¹ Verizon’s research also found the human element—including misdirected and misdelivered communications—in 62% of confirmed breaches, increasing to 69% within the public sector, where large volumes of correspondence can increase the likelihood of delivery errors.² Conventional DLP tools generally search for prohibited data patterns rather than determining whether a recipient is appropriate, leaving them unable to address scenarios such as replying to 40 clients with sensitive information, sending a contract to a personal Gmail account, or introducing a single-character domain typo. Static rules cannot reliably determine user intent.

“The control plane for secure data exchange has always been about governing every send, share, receive, and use of sensitive data, for humans and agents alike,” said Tim Freestone, Chief Strategy Officer at Kiteworks. “Misdirected email has sat outside that governance for years because it isn’t a data-pattern problem, it’s an intent problem. And intent is exactly what a policy engine that already knows the sender, the recipient, and the context is positioned to catch. AHEP isn’t a new tool bolted onto the inbox. It’s a new module of the same Data Policy Engine we use to govern file sharing, MFT, APIs, and agent access, extended to the channel with the least room for a scanning-after-the-fact approach. That’s what doubling down on the control plane looks like in practice.”

What AHEP Does

AHEP evaluates several signals at the time a message is being composed, including recipient type, recipient volume, identity matching, attachment presence, and domain validity. Warnings are presented only when the relevant signals converge, helping limit false positives. The capability includes three preconfigured policies that can be deployed without custom development:

  • BCC/reply-all protection identifies potential exposure when a message is addressed to a configurable number of external “To” or “CC” recipients and allows those recipients to be moved to BCC with a single action.
  • Send-to-self detection activates when a personal-domain recipient such as Gmail, Yahoo, or iCloud is combined with a close identity match to the sender across four independent dimensions and an attachment, focusing on the specific pattern associated with insider data exfiltration.
  • Domain typo detection identifies domains that differ by a single character from a known-good address and proposes a corrected recipient. It also separately identifies addresses that lack a valid mail server record.

Administrators can configure each policy as off, on, or report-only, with either suggest or warn behavior. Every event that is displayed, dismissed, resolved, or bypassed is recorded together with the policy identity, timestamp, and user decision. The resulting activity is captured within the same audit trail Kiteworks uses across email, file sharing, SFTP, MFT, and forms.

A Platform Capability, Not a Point Product

AHEP operates entirely within the customer’s Kiteworks environment, ensuring that email metadata does not leave the platform. This architecture addresses requirements in ITAR, CMMC, and FedRAMP environments, as well as other sovereign-cloud scenarios in which sensitive information and associated metadata cannot pass through third-party infrastructure. Rather than functioning as a separate email security product, AHEP builds on the existing Data Policy Engine and control plane that Kiteworks customers already use for access governance, encryption, and compliance reporting.

“AHEP ships as a capability inside the platform our customers already run, not a new console to log into,” said Yaron Galant, Chief Product Officer at Kiteworks. “The first phase covers the three mistakes we see most often in outbound email: reply-all exposure, send-to-self, and misspelled domains. None of them need a model, just the right signals evaluated at the moment someone hits send. We built the architecture to extend the same way the rest of the Data Policy Engine does by adding phases without asking a customer to stand up new infrastructure.”

AHEP is available immediately for the Kiteworks Web App and Outlook Classic, including Outlook 2016 and later. Future development phases are expected to introduce machine-learning-based behavioral analysis. Additional information is available in the solution brief.

_______

Endnotes

1. UK Information Commissioner’s Office, “Data Security Incident Trends,” updated February 27, 2025, https://ico.org.uk/action-weve-taken/complaints-and-concerns/data-sets/data-security-incident-trends/.

2. Verizon, 2026 Data Breach Investigations Report, https://www.verizon.com/business/resources/reports/dbir/.

About Kiteworks

Kiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive, and use of private data. The Kiteworks platform provides customers with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies. Learn more at kiteworks.com.

# # #

Media Contact

David Schutzman, PR Manager

Kiteworks

dschutzman@kiteworks.com

 

Join our LinkedIn group Information Security Community!

No posts to display