Every business has sensitive data that requires extra protections and safeguards. But ask any company if they can confidently say they know where it all is and who can access it, and the results will be staggeringly small. And if they don’t know where it is already, it might seem like a losing battle and impossible to retake control.
That’s where Oveka comes in.
The Radar function in Oveka is designed to help you reclaim control over your data. It helps find sensitive data across your platforms so you can retake control before it becomes a problem.
Data in the wrong place is a leak waiting to happen; Oveka finds that data for you.
Radar is a smart scanning feature in Oveka that lets you see where data is stored across connected SaaS platforms. It monitors and scans the platforms across the organization, checks for sensitive information, and sends you alerts when it finds sensitive data where it shouldn't be.
However, "sensitive data" is a broad term, and "where it shouldn't be" will vary depending on the organization, platform, and storage location within the platform. So how does Oveka make sure to surface only the information that matters?
Radar makes the alerts relevant by taking a heuristic approach to alerts. It starts by sending a broad set of alerts based on commonly relevant issues like finding PII and financial data. Then, you decide if the surfaced alerts are useful and more like them, or irrelevant and should be ignored.
These settings can be updated at any time as your needs adjust or change.
No, Oveka Radar doesn't move or delete the sensitive data that it finds. The purpose of Radar is to find sensitive data in the platforms you connect. It's up to you to decide how to handle it.
One of the reasons we build Oveka—and Radar specifically—is because so many SaaS platforms have access to the more data than they need. And a lot of times, they're able to access sensitive data they shouldn't have access to. Giving Oveka the power to move, alter, or delete the data on its own is something we thought crossed the line.
The goal of Radar is to find the data for you, then provide you with options for what you can do next. For example, suppose that an organization is using Slack, and Private Health Information (PHI) that is subject to HIPAA is sent through a chat. With Slack, data is kept for the lifetime of your workspace by default. This makes it great for collaborating across the workspace. And terrible from a compliance angle. If someone sends PHI data to someone else, even someone who should have access to it, Slack now also has access and it resides somewhere on their servers until you manually delete it. And until you've done that, you would be in breach of HIPAA.
So how does Radar help here? You'll get a couple of recommendations when you look into the alert. First, it will surface that potentially sensitive data has passed through Slack and tell you when and where it happened. From there, it might recommend that you double-check your organization's data retention settings in Slack to make sure the default is what you want.
You decide whether or not to actually take the step instead of having Oveka automatically make the adjustments. And remember, you're able to adjust the relevance of these suggestions, so if you have determined the retention period is fine, you can stop that recommendation from appearing again.
Radar supports integrating with SaaS platforms through the organization. While support for specific platforms will continue to grow, the types of platforms will generally fall into a few categories: Support & ticketing platforms, chat messages, transcription & call recordings, and CRMs.
Support and ticketing platforms are landmines for sensitive data, and unfortunately it's not often something under your control. Customers can send whatever they want. And a lot of times aren't thinking about keeping their sensitive data protected and governed; they have a problem, and they need it to be fixed.
This is complicated by the fact that a lot of personal information is genuinely needed to provide support. Customers may need to send their username, passwords, emails, and other items that can identify them. But once that kind of information is added to their ticket, that means the support/ticketing platforms now has it too.
Many of the vendors know this is an issue and have started putting in place countermeasures to combat it. Zendesk, for instance, has agents in their Agent Workspace that can mask and redact sensitive data that enters the platform. Several other vendors have similar controls. However, these are often reserved for enterprises or as part of an advanced data protection add-on.
Then there's still the problem of managing every other platform. Using advanced privacy controls with one platform may solve the platform there, but once you want to expand the coverage across other platforms, you need to enable the same controls there too. These types of features can quickly add up (if they're available at all).
Radar works as a simple way to scan multiple support and ticketing platforms at once, without the need to purchase and configure advanced privacy features for various different platforms.
Chat and messaging platforms are a standard way to quickly share information both internally and with external partners. They also introduce a new risk area. These risks come in two forms: the chat message itself, and file attachments.
Radar can scan chat messages and attachments in public and private channels for information you deem sensitive, so you can get notified when potentially sensitive information flows through these channels. Simply choose which channels to scan and what information to check for to get alerts that matter for you.
Chats are quick and convenient compared to emails and more secure sharing methods, so it's not uncommon for people to use them to quickly share information. They're especially convenient when engaging with remote colleagues (or the ones on the other side of the room). Since most businesses use business-tier plans, the users aren't always thinking about the security of their chats, so there's likely to be sensitive data like passwords, keys, or customer data sent through occasionally.
Every chat platform retains messages for a certain period. These are typically stored on their company servers. This means that if someone sends a message to a colleague that contains sensitive information, that information is retained by the vendor until the retention period ends. With some platforms, like Slack, that default period is forever because of the convenience of being able to review past conversations.
File attachments are the other place sensitive data can get lost. Once more, sending files via chat apps is more convenient (and more secure) than email, especially for groups where you can pass a file to everyone in an easy-to-follow thread.
But it also bypasses other security protocols you have in place, especially when the file with sensitive information remains on the company servers because of retention settings.
Radar can scan attachments and find sensitive information so you can regain control of how it's handled.
Since nearly every business is using cloud storage in some way, these platforms inevitably have sensitive data stored in them. Business cloud platforms like Google Workspace and SharePoint have controls to help prevent oversharing and limit exposure of sensitive data. Implementing those controls properly is a different story, and even then, completely stopping exposure requires everyone in the organization to always follow transfers and security protocols, which will never happen.
Then there's the issue of people outside the organization sending you sensitive data. Trying to enforce your internal policies and procedures across external parties is a losing battle, even with the best controls. Each organization is responsible for handling their own first-party data, but they can also limit the risk from outside parties.
A more thorough approach is to ensure the controls are in place and to also regularly check the state of the data across storage drives. Oveka can help here by having Radar connect to managed drives on cloud storage platforms and check for data types that you mark as sensitive. You can inspect entire drives or limit Oveka to scan specific subsections.
Call recordings and transcription services have made it much easier to find important information from calls, and they've helped many businesses improve training and problem resolution services. However, they've also made it much more challenging to control how sensitive information is distributed. Certain calls (like sales or a support call) could contain sensitive details, and depending on how the transcripts are stored, those details could potentially be exposed.
The risk is higher now with automated transcription services. A lot of organizations now use an AI notetaker that joins every meeting automatically and transcribes voice calls into transcripts. These transcripts are then stored as files, and depending on the notetaker being used, the files might be stored on an external platform instead of your organization's cloud storage. Many platforms will give you the option to have this type of data purged on demand, but first you have to know that it exists and where it is.
Oveka can identify this data for you. Once identified, you can decide if that type of data needs to be redacted, purged, or if it's fine as is.
CRMs regularly have detailed information about clients, partners, and customers, and as a result, have powerful controls in place to keep that information secure. But there are still ways that data can slip through the cracks.
Again, the more challenging problem is that you can't easily control what other people send you. They can fill out a contact form that has PII, confidential information, unhashed passwords, etc. and then that data is now stored somewhere like a "Form submissions" table in the CRM.
Oveka can surface potentially risky data across the CRM so you can decide what to do about it.
Since Radar is about scanning your file stores and connected SaaS tools, it doesn't scan LLMs or AI tools for things like uploaded files. However, this functionality is still important, and is covered under our PromptGuard and Databridge features.
Radar is part of the Oveka platform, and all features are included for all users. While Oveka is in early access, it will only be available by request. If you're interested, we'd love to hear from you. To learn more about Radar, the Oveka platform, or to get a demo, you can get in touch now.