DSPM grades a database clean. Encrypted at rest. Access scoped to a short list of service accounts. Nothing exposed to the public internet. The report is green and the report is right. That same night, one of those service accounts pulls the whole table instead of its usual few thousand rows, in off-hours bursts, to a destination it has reached before for something smaller. DSPM has nothing to say. No posture changed.
That gap is the whole comparison. DSPM asks where your sensitive data lives and how exposed it is. DDR asks how the data is moving right now and whether this move belongs. You do not pick one. You answer both, because the move that hurts you is the one your posture already approved.
What DSPM is for
Posture is hard, and DSPM earns its place. Sensitive data sprawls. A customer table gets copied into a staging bucket for a migration, exported to a BI tool, snapshotted into a backup nobody remembers, embedded in a vector store for retrieval. DSPM finds those copies. It classifies them, scores their exposure, and tells you which ones too many identities can read or which sit in a misconfigured store.
A tool that reports "unencrypted PII in three buckets that 400 service accounts can read, one snapshot reachable from the open internet" has handed a security team a ranked list of things to close. Close them and the attack surface shrinks before anyone touches the data. That is real, and Hilt neither produces that map nor replaces it.
What DSPM measures is standing data: exposure, configuration, the state of access at a point in time. It reasons about what could happen given how things are set up. It does not watch the move happen.
Where posture runs out
Go back to the green database. Nothing about the terrain moved. The data still lives where it lived. The access was granted on purpose and is still valid. The configuration is still clean. So DSPM stays quiet, correctly, while the data walks out.
What moved was the data. The danger lives in the pattern across those moves, not in the state of any one resource. This is the blind spot every posture tool shares with every permission check. The move was allowed, so it passes. The breach is not a broken rule. It is a permitted action that does not fit.
What DDR watches
DDR watches the movement itself, at runtime, while it happens. Predictive tools guess in advance, get it wrong often, and still wave the permitted move through. Forensics is accurate and late: the disclosure letter, not the save. DDR sits between them, accurate and live, reading the move as it forms.
Hilt is runtime Data Movement Governance, the evolution of DDR. One lightweight collector watches data movement at the kernel, metadata only by default, off the path. It does not sit inline and it does not read your data to see that a pattern is wrong. Each move resolves to a probabilistic, source-dependent identity: which workload, which job, which destination, and whether this fits what that identity normally does.
Run the green-database night through it. The volume is high for that service account. The timing is off-hours against months of baseline. The destination is familiar, but the size of what heads there is not. Any one signal is noise. Together they are a pattern, and a pattern is a case, not an alert. Hilt writes the case and responds with host-level network isolation, quarantine from the control plane. The collector never blocks, drops, or alters traffic. It watches the move instead of standing in front of it.
The cost of watching is checkable: roughly 0.1% of one core and 4 to 8 MB of memory per host, single-tenant inside your own cloud, AWS, GCP, Azure, or Ali Cloud. Events never leave your account.
Where and how, side by side
Hold the two by the question each answers.
DSPM asks where. Where the sensitive data lives, who can reach it, how exposed each copy is. A map of standing risk, strongest before an incident, shrinking the surface so fewer moves are even possible.
DDR asks how. How the data is moving, resolved to the identity and the job behind it, and whether the move fits. A live read of behavior, strongest during, catching the anomalous move as it forms so you do not lose the thing.
A clean posture report does not mean your data is staying put. It means the terrain is well guarded. The data can still walk out the front door on access you granted on purpose, through a channel DSPM correctly calls fine, in a pattern visible only while it moves.
Where they reinforce each other
The seam between them is where the value compounds.
DSPM tells Hilt what to watch hardest. The buckets, stores, and paths a posture tool grades as high-value are exactly the sources where an anomalous read matters most. Posture sharpens the priors.
Hilt tells DSPM what posture cannot see alone: a resource graded clean is the origin of a move that does not fit. A green posture score plus an anomalous movement from that same source beats either signal on its own. The map says "valuable and well configured." The movement says "and something is pulling from it in a way that does not match its history." That is a case worth acting on before the data is gone.
Posture without movement misses the permitted exfiltration. Movement without posture loses the context that says which sources deserve the tightest scrutiny. Run both and you cover both questions: where the data lives, and what it actually does.
Map versus eyes
DSPM vs DDR is not a contest. One maps risk, the other watches behavior. DSPM maps where your sensitive data lives and how it is exposed, and does it well. DDR, in Hilt's case runtime Data Movement Governance, watches how that data moves and catches the pattern that no single permitted move reveals.
If your posture is clean but you cannot answer "what did this service account's data actually do tonight, resolved to the job behind it and scored against how it normally moves," you have a strong map and no eyes on the movement. That gap is where the dangerous move lives.
Want to see the kernel-level read run against your own data movement? We keep it concrete: thirty minutes, engineer to engineer, no slideware.