Prove Compliance and Manage Risk With Advanced Reporting
Extend the comprehensive activity and policy reporting in the base Data Policy Engine with purpose-built reports for proving compliance with specific regulations, right out of the box. Reduce the work to demonstrate compliance—and fix problems before the audit—with one-click, audit-ready reports for CMMC 2.0, insider and outsider threats, GDPR, and HIPAA across email, file sharing, managed file transfer, SFTP, web forms, and APIs. Simplify legal hold for eDiscovery with defensible, fully documented chain-of-custody reporting, and increase end-user message tracking from two dashboards to unlimited so recipient follow-up never slips. And because every DLP, ATP, and CDR result is logged and reportable, you get full visibility into how your data-protection controls are performing.
CMMC 2.0 Compliance Report
Reduce CMMC audit risk and preparation cost by automatically gathering data governance information for each compliance control the system can detect. Get automatic pass/fail statuses, fix problems before the audit, and demonstrate CMMC compliance with confidence.
Insider Threat Compliance Report
Ensure accountability and enforcement by investigating suspicious insider activity, tracking the actions of a suspected user to pinpoint risky behavior. Instantly gather details of email and file exchanges, files accessed, downloads, and other actions, and assemble the information you need for HR and legal action.
Outsider Threat Compliance Report
Monitor the activity and data exchanges of external users or domains that have access to your system. In the event of a potential risk or attack from outside your organization, compliance officers can generate Outsider Threat reports to investigate.
HIPAA Compliance Report
Stay audit-ready for complete HIPAA compliance with Kiteworks’ one-click reports. Demonstrate implementation of Administrative Safeguards like inactive account controls, Technical Safeguards such as key rotation, Physical Safeguards status per AWS and Azure SOC 2 attestations, and access management details like DLP integration and incident response plans.
GDPR Compliance Report
Get GDPR-ready with comprehensive visibility of internal and external data exchanges in a one-click, audit-ready report. Capture and report who’s sending what to whom, when, from which connected on-premises and cloud data sources, to where. Detailed reports allow for data analysis down to the file level, and show which files have passed or failed AV, DLP, and ATP scans.
Unlimited Message Tracking Dashboards for End-users
Enable users who email many recipients to track their access. Employees can instantly pinpoint recipients who have not read or downloaded the data so they can follow up. Save time and tighten processes involving legal notices, billing, negotiations, content reviews, project management, and more. Limited to two dashboards per user with the base Kiteworks Data Policy Engine, but unlimited with the Advanced Reporting add-on.
Legal Hold for eDiscovery
Preserve all third-party data exchanges for litigation: files, versions, emails, and activity traces. Secure the data and protect it from spoliation within the Kiteworks hardened virtual appliance to maintain a provable chain of custody that’s transparent to end-users. It supports successful investigations and litigation with detailed reporting, as well as integrations with email archiving and eDiscovery.
DLP Data File Scanning, Blocking, and Visibility
Protect your outgoing data from inadvertent or intentional leaks, using your best-in-class DLP solution to identify PII, PHI, IP, or other sensitive information in files being sent outside the organization. The Kiteworks platform logs metadata about the data and the DLP result and notifies appropriate admins of all failures. Or you can set it to block sending of failing files, and designate admins who can unlock any false positives. Visualize all activity in context with the CISO Dashboard, drill in with reports, and feed it continuously to your SIEM.
ATP Scanning, Quarantine, and Visibility
Protect your enterprise from zero-day threats by automatically feeding incoming files through your advanced threat protection (ATP) system. Kiteworks quarantines failing files and notifies appropriate security personnel. All activity is fully logged and visible via reporting and the CISO Dashboard, and continuously fed to your syslog and SIEM.
Content Disarm and Reconstruction (CDR) and Sanitization Integration
Sanitize incoming data with commercial CDR servers like Forcepoint Zero Trust CDR via ICAP to protect your organization from malware without processing delays or quarantines.
Frequently Asked Questions
Reduce CMMC audit risk and preparation cost by automatically gathering data governance information for each compliance control the system can detect, with automatic pass/fail statuses to fix problems before the audit.
It tracks the actions of suspected users to pinpoint risky behavior, instantly gathering details of email and file exchanges, files accessed, downloads, and other actions for HR and legal action.
It demonstrates implementation of Administrative Safeguards like inactive account controls, Technical Safeguards such as key rotation, Physical Safeguards per SOC 2 attestations, and access management details including DLP integration and incident response plans.
It offers comprehensive visibility of internal and external data exchanges in a one-click report, capturing who is sending what to whom, with file-level analysis showing which files passed or failed AV, DLP, and ATP scans.
Featured Resources
CMMC 2.0 Compliance Mapping for Private Data Exchanges