Comparison

Hilt vs DDR: Runtime Governance Built on the DDR Idea

March 28, 2026 Hilt 7 min

Your most valuable data leaves on access you granted on purpose. DDR watches data movement and responds when it turns anomalous. Where Hilt extends DDR to runtime governance at the kernel, and how the two relate.

Hilt vs DDR: Runtime Governance Built on the DDR Idea cover image

"Hilt vs DDR" frames a choice that does not exist. Hilt is not the rival of DDR. Hilt is what DDR becomes when you run it at the kernel, at runtime, and carry it through to a response. The right comparison is not Hilt against DDR. It is DDR against the place most DDR products actually watch from.

DDR named a real shift, and it named it correctly. This post says what the shift got right, where Hilt extends it, and what Hilt leaves alone in the stack you already run.

What DDR got right

Classification-first tooling spent a decade chasing data at rest. Find the sensitive files. Label them. Write policy against the labels. Pray the labels survive every copy, transform, and move. They never do. A labeled file copied into a new path is an unlabeled file, and the policy goes blind the moment the data is interesting.

Data Detection and Response (DDR) is a category, not one product. It moved the question. The event worth watching is not where a sensitive record sleeps. It is where the record goes, who moves it, and whether that fits. When the move turns anomalous, DDR responds.

Hilt is built on that exact premise. Your most valuable data does not leave through a hole in the wall. It leaves on access you granted on purpose, down channels you approved, carried by identities you trust. Every move is permitted, so every permission check waves it through. The breach is the pattern across moves, not any one of them. DDR put movement at the center. That call was correct.

Where the DDR label goes soft

A category name stretches until it stops meaning anything. Several architectures now wear the DDR badge, and they do not watch from the same place.

Some "DDR" products read cloud audit logs and API events. They rebuild the move after the fact from what the provider chose to log. Real visibility, yes, but it is the move as the control plane recorded it: minutes late, and only where logs exist. Some watch inside one SaaS app and stop at its edge. Some are last year's DLP wearing a new acronym, still grading content against rules.

None of these are useless. Each covers real ground. But the label hides the one fact that decides everything: where does the tool sit relative to the move, and how late does it see it. A log-replay tool and a runtime tool can both call themselves DDR. They are not the same instrument.

Where Hilt extends it: the vantage

Hilt watches data movement at the kernel. That single choice does most of the work.

The kernel is where the move happens. Before the log line. Before the audit trail. Before the application finishes reporting what it did. Watch there and you see the move itself, live, not a reconstruction stitched together after the fact. A log-replay tool tells you a file left after it has already left. Hilt sees it leave. That is what fast and accurate at the same time means: accurate because it is the real event, fast because it is happening now.

A single move never carries enough to judge it. The verdict comes from the pattern. A workload reads high-value paths in a shape it has never read, at an hour it never runs, bound for a destination it never talks to. No one of those signals is an alarm. Hilt resolves each move to a probabilistic, source-dependent identity, scores it against how that identity normally behaves, and reads the signals together. Apart they are noise. Together they are a case.

Metadata is the default, and it is enough. Hilt does not read your data to see that a pattern is wrong. The shape of the move, tied to an identity and graded against its own history, tells the story. Content inspection is there when you want it. It is never the cost of entry and never the default.

Where Hilt extends it: off the path

The label hides a second thing: overhead and posture.

Sit inline, between the data and its destination, and you can interrupt the move. You pay in latency, and you become a single point of failure in the data path. Rebuild the move from logs and you skip the latency. You pay in lateness, and in the gaps where logs run thin. Every DDR architecture picks one of those bills.

Hilt pays neither. The collector stays off the path. It watches the move instead of standing in it, on the order of 0.1% of one core and 4 to 8 MB of memory per host. It never sits inline. It never blocks, drops, or alters traffic. When a pattern crosses into a case worth acting on, Hilt isolates the host at the network from the control plane, a quarantine, never a chokepoint in the move it was watching. Decisive at the response, invisible in the path.

That is why Hilt runs where heavier controls were never allowed: latency-sensitive infrastructure that took partial coverage over added weight in its data path.

Where the events stay

DDR asks the right question about data movement. Then it has to answer one about itself: where does the movement data go.

A security tool that ships your movement metadata to a vendor's multi-tenant SaaS hands a regulated firm a fresh exposure to explain. Hilt runs single-tenant inside your own cloud: AWS, GCP, Azure, or Ali Cloud. The path from a kernel event to a written case stays inside your account end to end. The events never leave. The same collector covers a cloud workload or a user endpoint, so cloud and endpoint are one model, not two products bolted together at the seam.

What Hilt leaves alone

The additive part, said straight.

Hilt does not replace your EDR. Endpoint detection handles known attack patterns, malware, and process behavior, and it is strong there. Hilt does not replace your CSPM. Posture management finds the misconfiguration and the exposed bucket before anything moves through them. Hilt does not replace your SaaS or email controls. They catch the loud exfil: the customer database mailed to a personal account, the bulk download on a last day.

What Hilt adds is the layer none of them was built to cover. The pattern of data movement across permitted actions, seen at the kernel, at runtime, resolved to the identity and job behind each move. DDR put data movement at the center of the question. Hilt watches the movement where it happens and answers all the way to a response, without reading your data and without standing in its path.

The short of it

DDR was right: data movement is the event worth watching. Hilt extends the idea three ways. It watches at the kernel instead of replaying logs. It stays off the path instead of sitting inline or arriving late. It keeps the events single-tenant in your own cloud. Additive to the stack you run, not a swap for it.

Weighing DDR options and want to know exactly where a kernel-vantage, off-path architecture fits against what you have today? That is an engineer-to-engineer conversation. A 30-minute technical call usually maps it to your environment, and tells you honestly where Hilt adds a layer and where it does not.