Risk engine
When no policy matches, the decision comes from the risk engine score. The app states that directly on a decision: no policy matched, decided by the risk engine score.
The score is an integer from 0 to 100. reasons is the explanation. riskLevel is LOW, MEDIUM, HIGH, or CRITICAL.
A policy can still take over. ALLOW on a policy is an explicit override of the risk engine. Other policies tighten the outcome to REVIEW or BLOCK, including by minimum risk score. See Policies.
Scores and decisions are rule-based. They do not promise that every harmful action is caught.
Quotas
Section titled “Quotas”quotaExceeded means the organization is over its plan’s event quota. Decisions are still made. Event quotas are soft limits: the app warns you, and checks keep working. There is no overage charge. The agent limit is separate and is enforced. See Plans.
Content scanning
Section titled “Content scanning”content on a check is optional. The server scans it for sensitive data and does not store the content. Matches are returned as dlpFindings. The LGPD category for each finding is returned as lgpdCategories.
Categories used by the product:
| Category | Examples of findings |
|---|---|
IDENTIFICATION |
CPF, RG, CNH |
CONTACT |
Email, Brazilian phone |
LOCATION |
CEP |
FINANCIAL |
Credit card, PIX key |
HEALTH |
Health data. This category is marked sensitive. |
COMPANY |
CNPJ |
CREDENTIALS |
API keys, private keys |
The live list of detectors is the unauthenticated endpoint GET /public/dlp-types. The types below are what that endpoint returned when these docs were written. Re-fetch it if you need the current detectors.
| Type | Category | Personal data | Sensitive |
|---|---|---|---|
CPF |
IDENTIFICATION |
yes | no |
CNPJ |
COMPANY |
no | no |
RG |
IDENTIFICATION |
yes | no |
CNH |
IDENTIFICATION |
yes | no |
PIX_KEY |
FINANCIAL |
yes | no |
PHONE_BR |
CONTACT |
yes | no |
CEP |
LOCATION |
yes | no |
CREDIT_CARD |
FINANCIAL |
yes | no |
EMAIL |
CONTACT |
yes | no |
HEALTH_DATA |
HEALTH |
yes | yes |
API_KEY |
CREDENTIALS |
no | no |
PRIVATE_KEY |
CREDENTIALS |
no | no |
Detection is specific. For example, CPF requires valid check digits, CREDIT_CARD requires a Luhn check, and HEALTH_DATA looks for an ICD-10 (CID-10) code after “CID”. The detection string on each item from /public/dlp-types is the description to trust.
Anomalies
Section titled “Anomalies”Separate from the per-event score, the app records anomalies against an agent’s baseline: a large record count in one action, an action the agent has never used, a new external destination, or a burst of requests in one hour. Those can notify a webhook. See Webhooks.

