Product
Endpoint data discovery, end to end
Deploy the agent, choose what to search for, scan on the device, and work through what comes back. This page covers what the product does at each step.

Capabilities
What the platform does
Discovery, subject search, remediation tracking, and reporting, in one place.
On-device scanning
A lightweight agent matches files locally. Raw file content stays on the endpoint.
Framework mapping
Findings map to GDPR Article 30 and PCI DSS 4.0, depending on the plan you're on.
Risk dashboard
Fleet-wide posture in a single pane. Filter by severity, device, or data type.
Evidence packs
Generate an evidence bundle from the findings, with the scan history behind it.
Suppressions and exceptions
Mark false positives and set time-bound exceptions. Exclusions sync back to the agent.
MDM deployment
Deploy via Intune, Jamf, or enrolment codes. Conditional access is supported.
Subject search
Look a person up by identifier, review confidence-scored matches, export a disclosure pack.
Scheduled reports
Recurring reports and on-demand exports for auditors and the board.
How it works in depth
From scan to audit-ready evidence
Four pillars that take you from "we don't know what we hold" to an audit-ready answer.
Discovery
Find sensitive data everywhere it hides
A lightweight agent scans files locally across your endpoints. Raw data never leaves the machine; only masked previews are transmitted. Mailbox and OCR scanning are available as add-ons.
- On-device scanning - files never leave the endpoint
- Fleet-wide inventory across every scanned device
- Fingerprint dedup keeps findings grouped, not noisy
Compliance
Prove compliance in hours, not weeks
PCI DSS 4.0 and GDPR Article 30 are mapped out of the box. Turn live findings into audit-ready evidence packs with one click, and keep scope honest with suppressions and time-bound exceptions.
- PCI DSS 4.0 + GDPR Art. 30 mapped out of the box
- One-click, audit-ready evidence packs
- Suppressions, exceptions & SLA tracking built in
DSAR
Handle data-subject requests without the panic
Search every endpoint for a subject by multiple identifiers, let the identity graph correlate matches across files and devices, and assemble an audit-ready disclosure pack with a full audit trail.
- Multi-identifier subject search across the estate
- Identity-graph matching with confidence bands
- Disclosure packs with a complete audit trail
Visibility
See your whole estate at a glance
A fleet-wide risk dashboard puts posture in a single pane - filter by severity, device, or framework. Schedule the reports your auditors and board expect, and export whenever you need.
- Fleet-wide risk posture in one dashboard
- Filter by severity, device, or framework
- Scheduled reports + on-demand exports

Security by design
Search sensitive data without collecting the underlying files.
EmberHound handles the data you least want moved. Scanning runs on the endpoint, and only masked findings and the metadata needed to act on them leave the device.
- File scanning and pattern matching happen on the endpoint. The platform never reads your file system.
- Findings carry a masked preview and a fingerprint hash, not the file content.
- Encrypted in transit and at rest.
- Strict tenant isolation, enforced in the database as well as the application.
- Every action is written to an audit log your team can read.
Read the Trust Centre for the architecture, sub-processors, and data-handling detail.
Start here
Start with one device and see what comes back.
The free plan covers one device and one user. Install the agent, run a scan, and look at the findings before you decide anything else.
No card details required. Upgrade when you need more devices.