DTEX provides an AI‑driven insider risk management platform that combines data loss prevention, user‑entity behavior analytics, and activity monitoring into a single lightweight engine. The solution collects under 5 MB of anonymized telemetry per endpoint daily, generates real‑time risk scores and adaptive DLP policies, and integrates with tools like Splunk, CrowdStrike, and Microsoft 365 to enable rapid investigation and reporting for enterprise security teams.
Funding
$50M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.




Founders
Product
Problem
Organizations struggle to detect insider threats because data loss prevention (DLP), behavioral analytics, and user activity monitoring are often deployed as separate, heavyweight solutions that generate high false‑positive rates, impose significant endpoint overhead, and expose sensitive employee data, making timely prevention of data breaches difficult.
Solution
DTEX delivers a unified insider risk management platform that fuses DLP, UEBA, and user activity monitoring into a single AI‑driven engine. The platform collects only lightweight behavioral telemetry (under 5 MB per endpoint per day) to maintain near‑zero impact on devices and networks while preserving employee privacy through patented pseudonymization. AI models generate context‑aware risk scores and dynamic policies that adapt in real time to user intent, enabling early detection of malicious, careless, or compromised behavior before data exfiltration occurs. Integrated AI‑guided investigations and one‑click, role‑based reporting provide analysts with actionable insights and reduce investigation time. Seamless integrations with security ecosystems such as Splunk, CrowdStrike, and Microsoft 365 extend visibility and enforcement across the enterprise stack.
Target Audience
Primary customers are enterprise security teams—CISOs, SOC analysts, and risk managers—in regulated sectors such as financial services, critical infrastructure, government, and large enterprises that require proactive insider threat detection and data loss prevention.
Features
- Lightweight forwarder collects <5 MB of high‑fidelity metadata per endpoint daily, scaling to >500 k endpoints with minimal performance impact.
- DMAP+ technology processes data in three layers: collection, behavioral enrichment, and risk analytics, delivering unified telemetry across on‑prem and cloud environments.
- Dynamic risk scoring baseline by role, department, and geography, automatically flagging deviations linked to insider threat indicators.
- Risk‑adaptive DLP policies that classify data based on behavior, enforce real‑time controls, and adapt as risk scores evolve.
- AI‑driven investigation assistant (Ai³) that surfaces “who, what, and why” for suspicious activity, accelerating response workflows.
- One‑click, role‑based executive and analyst reports with actionable recommendations and visual trend graphs.
- Patented Pseudonymization™ tokenizes PII to meet GDPR and other privacy regulations while retaining analytical value.
- Pre‑built integrations for Splunk, CrowdStrike, Microsoft 365, and other security tools to enrich alerts and streamline remediation.