Solution · Sensitive-Data Discovery

Find your CUI before your assessor does.

You can’t protect what you can’t see. Point Sensitive-Data Discovery at your file shares and it shows exactly where personally identifiable information, privileged material, and Controlled Unclassified Information (CUI) markings live — a clear, defensible report of what’s where. It runs on a private appliance inside your network; nothing is ever sent to an outside cloud or AI service.

The question you have to answer

“Where does your sensitive data live right now?”

Regulators and assessors ask it directly — and “we’re not sure” is the wrong answer. Sensitive data has a way of scattering: a spreadsheet of client SSNs on a shared drive, a privileged memo in a project folder, a contract stamped CUI sitting in general storage. Discovery maps it for you.

Personally identifiable information

PII

Social Security, payment-card, and bank routing numbers are checked against their real structure — not just matched by shape — alongside tax IDs, emails, and phone numbers, so the report is signal, not noise.

Privileged & confidential

Legal

Attorney–client privilege, work-product, and “privileged and confidential” language — surfaced wherever it has spread beyond the matter it belongs to.

CUI markings

Controlled Unclassified Information

Banner and portion markings (CUI, category markings, legacy FOUO) — so you know which shares hold controlled material before an assessor finds it for you.

Every finding is shown masked — the report tells you where sensitive data is without copying it anywhere or putting it back on a screen.

Who needs to know

If a rule says “know where the data is,” this is how.

A data inventory is the first thing most safeguarding rules expect of you. Discovery produces it from your actual files — not a questionnaire.

FTC Safeguards Rule & GLBA

Financial institutions and the accountants, advisers, and firms they touch must identify where customer information is stored. Discovery is the inventory step, done for real.

IRS Publication 4557

Tax professionals must know what taxpayer data they hold and where. Point Discovery at the share and get a defensible map of the PII you’re responsible for.

CMMC & CUI handlers

Before you can protect Controlled Unclassified Information, you have to find it. Discovery locates CUI markings wherever they’ve landed across commercial shares.

Background reading on the rules that drive this: the Curtilage compliance library →

One engine, two jobs

Discovery finds it. FileFerret contains it.

Sensitive-Data Discovery and FileFerret are built on the same private engine. So the moment Discovery shows you sensitive data scattered across a commercial share, the next step is already in hand: bring those files under one private, searchable, fully controlled roof — on your premises, where nothing leaves your network.

Modern software, kept inside your walls.

Tell us about your organization and the data you need to protect. We’ll help you put capable, modern tools to work on a private system we ship, install, and support — with nothing ever leaving your network.