A Data Security Platform Built to Act: Cyera’s Latest Innovations

Sep 17, 2026
Share

Securing AI without a strong data security foundation is impossible.

We’ve heard this from hundreds of CISOs. And we believe it too. That’s why data security remains our core focus and the fundamental cornerstone behind the Cyera platform. 

We invest deeply in the ability to understand your data, understand your human and non-human identities, and their intent, then combine that with investments in native and orchestrated protection where data is accessed, used, and shared. We put that approach into practice across every critical environment, from cloud and on-prem, to the browser and the endpoint. 

With every release, our data security platform becomes stronger and more synergistic, bridging the gap between data security at rest and in motion across DSPM, DLP, Endpoint Security, Insider Risk, Privacy, and Access Governance. And in a world that changes at light speed, we wanted to take a moment and share a few recent innovations.

Cyera agents do the work

Cyera’s latest innovations are connected by an agentic layer. Cy, our AI Assistant, gives teams a plain-language interface in the console, while Cy’s Crew and specialized agents put the platform’s data, identity, and business context to work across classification, DLP, investigation, and risk.

At the platform level, the Risk Agent brings multiple violations together around the affected asset, helping teams see when individually moderate findings require a different response in combination. These agents reduce the work of understanding what happened and deciding what to do next, while people remain responsible for consequential decisions.

Native DLP enforcement for endpoints

Employees move data from cloud repositories into desktop applications and then through local channels. Cyera Endpoint brings native DLP enforcement to Windows and macOS, blocking sensitive transfers to USB and network drives, printers, web uploads, Bluetooth, and AirDrop.

Cyera uses the data classes, Topics, and learned classifiers established by DSPM, including proprietary data unique to the organization, to determine what the Endpoint agent protects. At the point of enforcement, Cyera Omni DLP adds identity, destination, and policy context. Teams can carry the same data intelligence into endpoint enforcement instead of rebuilding policies around endpoint-specific regexes and labels.

That same intelligence extends to local AI agent security. Cyera Endpoint serves as Cyera Agent Guardian’s on-device control point, discovering local AI applications and agents and monitoring file access, command execution, scripts, and tool calls. By connecting each action to the identity behind it and the data involved, Cyera can stop personal AI sessions, destructive agent actions, and data exposure as activity occurs.

Cyera Browser Shield applies this context to browser-based AI, blocking AI prompts and sensitive file uploads at the point of interaction and bringing that activity into the same policy and investigation workflow in Cyera Omni DLP. Together, Browser Shield and Cyera Endpoint extend a shared control plane from the browser to the device.

Unified DLP control plane across native and third-party enforcement

That control plane doesn’t stop at the device. Cyera Omni DLP extends the same policy, classification, and investigation framework to your existing DLP tools – Microsoft Purview, Google Workspace DLP, and Proofpoint Email – orchestrating policy decisions across the broader DLP ecosystem under one shared intelligence layer. 

For connected third-party providers, Cyera does not replace the enforcement point; it gives security teams the confidence to enforce more decisively, backed by data and identity context. Omni DLP reclassifies alerts augmented with AI/LLM analysis, enriches with business-specific context the provider's own detection logic is missing, and recommends policy improvements that reduce disruption to legitimate business activity. Organizations retain the infrastructure they already have in place; what changes is the accuracy of the decision to alert and block.

The resulting benefit is not merely broader coverage; it is less noise and faster investigation. By applying data, identity, destination, and business context to alerts across native and third-party controls, Cyera Omni DLP has reduced false positives by up to 98% and total alert volume by up to 80% in customer environments.

This value compounds through the platform’s agentic layer. DLP Memories automates the capture of analyst feedback: when an analyst marks an alert as a false positive and explains why, Memories records that judgment as reusable context – scoped to the user, department, destination, or organization-wide condition that made it valid – without requiring a separate step to document it. The next matching alert draws on that captured context automatically, so analysts stop re-explaining decisions they have already made.

That same context feeds directly into how each alert is handled next. Every alert is automatically investigated before it reaches an analyst. The DLP Triage Agent evaluates the underlying content alongside the user's identity, role, destination, channel, organizational context, and available DSPM classification. It determines whether the activity represents genuine risk, assigns an independent severity, and provides a plain-language explanation of what happened, why it matters, and the evidence behind its assessment. Analysts begin with a prioritized, context-rich investigation rather than reconstructing the event from a policy name, file path, and raw provider telemetry.

Native enforcement and third-party orchestration are not separate strategies. They are one control plane, applied consistently wherever data moves.

Access remediation that removes exposure

Some risks should be fixed before a transfer or AI interaction ever occurs.

Cyera’s native remediation actions can disable supported sharing permissions in Microsoft 365 and Google Workspace, apply sensitivity labels, and assign Snowflake tags. For public and organization-wide exposure, security teams can automate supported permission removals rather than stopping at a recommendation. Cyera offers dozens more of these remediation actions natively, with no third-party involved. 

And when necessary, just as with Cyera’s DLP, issues can trigger existing platform controls. A classification-driven Snowflake tag can activate a native masking policy: Cyera supplies the classification and tag, while Snowflake performs the masking. The value is in getting the appropriate protection applied, without rebuilding an enforcement engine the customer already has.

Applying Microsoft sensitivity labels similarly connects Cyera’s understanding of the data to the policies customers have configured in Microsoft. In one recent case, Cyera reclassified data for a large North American food distributor and corrected Confidential and Restricted labels, processing 15,000–30,000 files a day and covering more than 500,000 items in about two months. Once the labels were in the right place, the company’s existing DLP policies started enforcing as intended. The customer didn’t need a new enforcement engine, just labels that Purview could act on. 

When a decision requires business judgment, the Remediation Portal brings data owners into the process. Security can delegate the issue to someone who understands why the information is shared and whether that access is still needed. This has dropped median time to remediate from 10 days to two.

Classification that understands your business

A generic definition of sensitive data will only take a security program so far. Companies also need to protect information whose importance comes from the business itself.

Cyera combines Learned Classification with Organizational Context. Learned Classification discovers data types across the environment without requiring teams to define every pattern in advance. Organizational Context adds the company’s own definitions, terminology, and sensitivity requirements. Our Taxonomy Agent helps translate business taxonomies into classification Topics, letting teams describe and group concepts such as board meeting minutes. 

Custom Data Classes address organization-specific patterns, such as employee identifiers. Teams can adjust sensitivity and supply feedback to refine how Cyera interprets their information. These are different tools for different needs, not a requirement to express every business concept as a regular expression.

For one pharmaceutical customer, approximately 150 topics map business record types to sensitivity labels, supporting a labeling program across thousands of Microsoft 365 files. This helps classification serve an operational purpose: translating the organization’s own understanding of its information into protection requirements.

Our Context and Feedback Agent helps learn your business, turning classification corrections into reusable knowledge. The aim is to preserve what the customer teaches the platform rather than make teams repeat the same corrections. 

Insider investigations grounded in the data

An unusual download is a reason to investigate, not a conclusion.

A useful investigation needs to establish what the employee accessed, why the information matters, and whether subsequent activity created an exposure. Cyera supports that work through DSPM, Access Trail, and DLP. Classification establishes the sensitivity and business meaning of the data. Access Trail provides evidence of access activity, human and non-human. DLP alerts add evidence of attempted movement or policy violations.

In a departing-employee review, an analyst can use those capabilities to examine sensitive files the person accessed and review associated sharing or transfer alerts. Our Investigation Agent automatically correlates access, identity, classification, and lineage for exposure investigations and pre-termination reviews. 

Together, these capabilities reduce the work of assembling information while keeping people responsible for consequential decisions. The investigation starts with the information at risk, not just the volume of activity. These capabilities support insider-risk work without assuming that every unusual action is malicious.

That distinction becomes more important when an agent acts under an employee’s authority. The employee may authorize a legitimate task while the agent takes an inappropriate action with the data. Insider risk therefore needs to account for human and agent activity together.

Hybrid coverage at enterprise scale

A data security program can’t stop at the cloud boundary.

Cyera discovers and classifies data across on-premises databases and file systems, including Oracle, Microsoft SQL Server, NetApp, Dell PowerScale, and Windows file servers. These environments use the same classifiers, issues, and policy framework as the cloud estate.

Cyera can connect to on-premises sources so analysis can run in the customer’s own cloud account through outbound, mutually authenticated connections. Only findings reach Cyera; raw data remains within the customer’s environment. That gives infrastructure and security teams a defined deployment model with a clear data-handling boundary.

Deployment results include classifying 130 TB of Oracle data in under 24 hours and 100 TB of file-server data in under three days. These examples matter because connecting to a source is only the beginning. Customers need to know whether the platform can produce useful results at the scale of their environment.

Data intelligence and control

Cyera brings data, identity, agent activity, and business context together so teams can understand what matters and act on it. Specialized platform-wide agents apply that intelligence across classification, DLP triage, investigation, and risk analysis. Native remediation and orchestrated controls then apply the right protection wherever data moves.

For more information on how to get started with these capabilities, request a demo today or reach out to your Cyera account executive.

Share