A contractor rolls off at the end of a milestone. In their last week, they clone the engine repo, sync a Perforce depot, and copy a working directory home for the weekend. Every action is signed off. Their access is legitimate. The work in front of them needed most of it. Nothing they touched broke a rule, and a build of your unannounced title can still walk out the door behind them.
That is where the blind spot opens.
A studio's most valuable data does not sit still. Source lives in repos that hundreds of engineers pull from daily. Unreleased builds pass through build farms, QA labs, localization vendors, and external porting houses. Player data flows out of telemetry into analytics, support tooling, and marketing platforms. The studio granted every one of these accesses on purpose. The work does not happen without them.
Game security usually gets framed as a leak problem. A build shows up on a torrent. A cutscene posts before the reveal. A creator with early access breaks embargo. So studios lock accounts, watermark, and sign harder NDAs. Reasonable moves. They aim at the wrong target. The expensive losses do not come from someone who lacked access. They come from someone who had it, used it the way it was meant to be used, and moved the data in a pattern that was wrong.
Three kinds of data, three ways they leave
Studios reason about leaks one asset at a time. Worth keeping that habit, because each asset moves through its own pipeline and leaves through its own door.
Source code is the slow loss. Engine, netcode, anti-cheat. The value is not one file. It is the architecture those files add up to. Source leaves through the channels engineers live in all day: a repo clone, a depot sync, a working copy on a personal machine. Each action is permitted. The contractor offboarding at milestone end has a real reason to touch most of the tree. The access is not the danger. A bulk read of high-value paths, off-hours, to a destination that does not match what that identity normally does: that is the danger.
Unreleased builds are the fast loss, and the public one. A pre-release build of an unannounced title is worth more to a leaker the day before reveal than at any other point, and it touches the most hands. Internal QA. External test labs. Localization. Console certification. Marketing capture. Every handoff is a deliberate transfer to someone meant to receive it. The build that surfaces where it should not usually went through a door the studio built on purpose.
Player data is the regulated loss. Accounts, payment tokens, age data, chat logs, behavioral telemetry. By design it moves out of production into warehouses, support consoles, and third-party platforms. Rarely a dramatic breach. More often a steady trickle to a destination approved once and never revisited, or an export that looks normal in shape and is wrong in volume for the identity running it.
Three asset classes. One shared property. The move is allowed. The pattern across moves is the breach.
Why the existing stack does not catch this
A serious studio already runs serious tooling. Endpoint detection on developer machines. A CASB or DLP watching uploads to cloud storage. Identity controls gating who reaches which repo. A SIEM stitching the logs. Strong tools. Keep all of them.
They all ask one question: was this action permitted. Identity confirms the engineer may clone the repo. DLP confirms the upload destination sits on the allowlist, or flags it when it does not. EDR confirms the process is not malware. Each tool grades a single move against a policy. A permitted move passes.
One class of loss walks straight through that gate. The move that is individually permissible and collectively the breach. The contractor who pulls the engine source in small chunks across two weeks through an approved sync tool. The QA lead whose build transfers are all clean until the one that lands on a personal cloud drive at 1am. The analytics job that has shipped player data to the same warehouse for a year, then starts quietly sending a wider slice to a new endpoint. No single action trips a rule. The pattern is what is wrong, and a policy check cannot see a pattern. It was never built to.
Where the pattern is visible: at runtime, on the move
You get three moments to act. Before the move, predictive tools guess who is risky, throw false alarms, and still wave the permitted action through. After the move, forensics reconstruct what happened once the build is already on a forum. The third moment is during the move, while the data is in motion. That is the only place the pattern shows itself as it forms.
Runtime Data Movement Governance watches that moment. Hilt runs one lightweight collector at the kernel, the single vantage where every copy, sync, upload, and export is visible no matter which application or pipeline drove it. Metadata by default. It sees that source moved, in what volume, by which identity, to what destination, without reading the files. Want content inspection, you can turn it on. It is not the price of admission.
The collector stays off the path. It does not sit between a build farm and a vendor, and it does not slow a Perforce sync or a telemetry export. Figure 0.1% of one core and 4 to 8 MB of memory per host, single-tenant inside the studio's own cloud, AWS, GCP, Azure, or Ali Cloud. It never blocks, drops, or alters traffic.
What it does is resolve each move to an identity, probabilistic and source-dependent: which user or service account, which job, which destination, and whether this fits what that identity normally does. The contractor's bulk read of the engine tree lands off-hours, against a destination they have never used. Three weak signals line up at once. The job is unusual for that identity. The access is a large read of high-value paths in a short window. The destination is new. Any one of them is noise. Together they write a case, not an alert, with the identity and the job behind the move already in it.
What this changes for a studio
The gap a studio carries is not negligence. It is structural. The installed tools were built to grade permission, and they grade it well. The behavioral pattern of movement across permitted actions lives in a layer they were never pointed at.
For source, that is the slow accumulation made visible: the contractor touching more of the tree on the way out than the work requires. For builds, it is the one handoff that breaks the shape of every legitimate transfer before it, caught in time to isolate the host instead of reading about the build on a forum. For player data, it is a regulated export drifting in volume or destination while it happens, which is the difference between a contained internal finding and a disclosure letter.
When a pattern crosses the line, Hilt responds with host-level network isolation, quarantine from the control plane, never inline. The studio keeps its stack. Hilt adds the layer those tools were not built to provide: how the data actually moves, resolved to the job behind it and scored against normal.
Ask your current tooling what a departing contractor's access to the engine repo actually did, resolved to the job behind it and scored against how source normally moves, across the two weeks before they rolled off. If it cannot answer cleanly, that is the blind spot, and it is where the next leak is forming.
If that is a question your team has been unable to answer, it is worth thirty minutes, engineer to engineer, to walk through where the collector sits in a studio's pipelines and what it surfaces.