Skip to content

Risk engine

When no policy matches, the decision comes from the risk engine score. The app states that directly on a decision: no policy matched, decided by the risk engine score.

The score is an integer from 0 to 100. reasons is the explanation. riskLevel is LOW, MEDIUM, HIGH, or CRITICAL.

A policy can still take over. ALLOW on a policy is an explicit override of the risk engine. Other policies tighten the outcome to REVIEW or BLOCK, including by minimum risk score. See Policies.

Scores and decisions are rule-based. They do not promise that every harmful action is caught.

quotaExceeded means the organization is over its plan’s event quota. Decisions are still made. Event quotas are soft limits: the app warns you, and checks keep working. There is no overage charge. The agent limit is separate and is enforced. See Plans.

content on a check is optional. The server scans it for sensitive data and does not store the content. Matches are returned as dlpFindings. The LGPD category for each finding is returned as lgpdCategories.

Categories used by the product:

Category Examples of findings
IDENTIFICATION CPF, RG, CNH
CONTACT Email, Brazilian phone
LOCATION CEP
FINANCIAL Credit card, PIX key
HEALTH Health data. This category is marked sensitive.
COMPANY CNPJ
CREDENTIALS API keys, private keys

The live list of detectors is the unauthenticated endpoint GET /public/dlp-types. The types below are what that endpoint returned when these docs were written. Re-fetch it if you need the current detectors.

Type Category Personal data Sensitive
CPF IDENTIFICATION yes no
CNPJ COMPANY no no
RG IDENTIFICATION yes no
CNH IDENTIFICATION yes no
PIX_KEY FINANCIAL yes no
PHONE_BR CONTACT yes no
CEP LOCATION yes no
CREDIT_CARD FINANCIAL yes no
EMAIL CONTACT yes no
HEALTH_DATA HEALTH yes yes
API_KEY CREDENTIALS no no
PRIVATE_KEY CREDENTIALS no no

Detection is specific. For example, CPF requires valid check digits, CREDIT_CARD requires a Luhn check, and HEALTH_DATA looks for an ICD-10 (CID-10) code after “CID”. The detection string on each item from /public/dlp-types is the description to trust.

Separate from the per-event score, the app records anomalies against an agent’s baseline: a large record count in one action, an action the agent has never used, a new external destination, or a burst of requests in one hour. Those can notify a webhook. See Webhooks.