Why EmberHound

Every product decision costs something. Here are ours.

This page sets out the choices behind EmberHound and what each one gives up. If a trade-off here is wrong for you, it's better you find out now than in month three.

The decisions

Six choices, and what each one gives up.

Scanning happens on the device

Files are matched on the endpoint. What leaves is a masked preview, a fingerprint hash, and the metadata needed to act on the finding. The platform never holds your file content, so a breach of us is not a breach of your data.

What it gives up

We only see devices you've enrolled. There's no agentless discovery, and no cloud or SaaS scanning today.

Uncertainty is reported as uncertainty

Where material questions are unanswered, or a rule doesn't cover your case, the result says so. Incomplete information doesn't quietly become a reassuring answer.

What it gives up

You get a clean answer less often. Some results need a person to look at them before they mean anything.

There is no compliance score

No percentage, no traffic light. The product shows what was found, where it was found, and what was done about it.

What it gives up

There's no single number for a board slide. You'll have to describe your position rather than display it.

We find data, and stop there

EmberHound reports. Your team decides what to delete, move, or protect. It never modifies the files it scans.

What it gives up

This isn't data loss prevention. If you need to block data at the point it leaves, that's a different category of product.

Findings are grouped rather than listed

Fingerprint deduplication collapses the same value across scans and devices into one entry with a confidence score, so a triage queue stays a size one person can work through.

What it gives up

Grouping is a judgement. Two separate copies holding identical content read as one entry until you open it.

Built to be run by one or two people

Deploy through the MDM you already run. There's no professional services engagement, and no dedicated analyst assumed.

What it gives up

If you have a security team of 15 and want deep SIEM integration and a custom workflow engine, this is the wrong shape.

The alternatives

Three ways to find out where your sensitive data is.

Each of these works for somebody. What separates them is what they ask of you in return, so all three are set out the same way.

Ask the people who know

Interviews and a maintained inventory

  • Captures purpose and context that no scanner can infer
  • Costs nothing but time to begin
  • Records what people remember, rather than what's on the disk
  • Needs redoing to stay current
  • Produces a document rather than evidence

A data loss prevention platform

Prevention across a whole estate

  • Blocks data in motion, not only finds it at rest
  • Covers channels an endpoint agent doesn't reach
  • Sized and priced for organisations with staff to run it
  • Policy tuning is ongoing work rather than a setup step
  • The right answer once you're at that scale

EmberHound

Endpoint discovery for lean teams

  • Evidence taken from the devices themselves
  • Runs with a team of one
  • Raw files stay on the endpoint
  • Finds and reports; doesn't block
  • Only sees devices you've enrolled

We built the third one because the first is what most lean teams can actually staff, and it doesn't produce anything you can hand an auditor.

The quickest way to judge this is to run it.

Scan one device, look at what comes back, and decide whether the trade-offs above are the right ones for you.

No card details required. One device, one user.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy