A researcher copies a proprietary code library out of your trading firm over two weeks. Small chunks, off-hours, through an internal transfer path that legitimate jobs use every day. You bought a tool to stop exactly this. It scored every move she made and waved each one through, because each one was clean.
Most comparisons of these tools sort them by features. Which product reads email, which watches USB ports, which assigns each user a risk number. That grid tells you what each tool inspects. It does not tell you the thing you actually need to know, which is whether any of them can see the breach the researcher just walked out the door. Her breach was not a move. It was the shape of forty moves, and every tool on the grid evaluates moves one at a time.
So sort them by a different question. Does it judge the individual move, or the pattern across moves. Three approaches answer that question three ways.
Channel and content tools
Proofpoint, Microsoft Purview, Forcepoint. They sit at the application and channel layer and inspect what leaves: email attachments, uploads to a sanctioned drive, print jobs, copies to removable media. They are good at it. A customer list pasted into a personal webmail draft, a bulk SaaS export the week before someone resigns, these tools catch and block at the egress point. That is the job they were built for and they hold it.
What they read is the content crossing a channel. They do not assemble a sequence of permitted transfers into a verdict, because each transfer, read on its own, is permitted.
Behavior and analytics tools
DTEX, Microsoft Insider Risk Management, the UEBA layer inside several SIEMs. These model the person. A behavioral baseline per user, a score that climbs when activity drifts: odd hours, access outside a role, the signals of a flight risk. DTEX runs light endpoint telemetry, sequences behavior well, and does it with real attention to employee privacy. When the question is which people are acting unusually, this layer answers it.
The unit is the user, not the data. Our researcher sat at her own machine, on systems she was cleared to touch, doing what researchers do. Her score never climbed, because nothing about her behavior was unusual. What was unusual was where specific files went.
Runtime data movement governance
This is where Hilt sits, and it watches the movement itself. At the kernel, resolved to the identity and the job behind each move: which user, which workload, which destination, at what volume, in what window, scored against how that identity normally moves data over months of history. The unit of analysis is the data movement. The signal is the deviation across a run of permitted moves, not any single move.
The three layers do not compete. Channel tools own the egress points. Behavior tools own the user model. Runtime governance owns the pattern across moves. Teams run two of the three and still lose data because the breach lives in the seam none of them watches.
The seam, walked through
Replay the researcher against all three. The channel was sanctioned, so the content tool saw an approved transfer and stayed quiet. Her sessions never spiked a behavior score, so the analytics layer read a researcher doing researcher things. Each tool evaluated the thing it was built to evaluate and got the right answer for that thing.
What none of them assembled was the cross-move pattern: a slow, low-volume, high-value read of specific paths, routed through an approved channel, by an identity whose normal job does not move this class of data this way. Every move was permitted. The pattern was the breach. Tools that score moves one at a time cannot see a pattern by construction, and the person running the exfiltration knows it. The whole method is to keep every individual move inside the lines.
What the third layer adds
One lightweight collector watches data movement at the kernel, metadata only by default, off the path. It does not sit inline. It does not stand between your data and where it is going. It does not block, drop, or alter traffic. The footprint runs around 0.1% of one core and 4 to 8 MB of memory per host, single-tenant inside your own cloud, and events never leave your account.
What that buys you is the cross-move view. Each movement resolves to a probabilistic, source-dependent identity, the user and the workload and the job behind it, scored against months of that identity's history. When the researcher's slow drain is underway, the deviation shows up across signals at once. The job is wrong for her identity. The access is a sustained read of high-value paths in narrow windows. The destination volume is wrong despite the approved channel. Any one signal alone is noise. Together they are a pattern, and a pattern is a case, not an alert.
Security leaders ask about metadata-only first, so state it plain. Hilt does not have to read your data to see that a pattern is wrong. Content-aware inspection is there when you want it and never the price of admission. Your bank flags the charge that does not fit without ever seeing what you bought. Hilt does the same for your data.
Where Hilt does not replace what you run
Keep Proofpoint or Purview. They own the egress points, the content inspection, the loud smash-and-grab export, and the channel-level compliance report your auditor expects. Keep DTEX or your UEBA layer. The per-user model and the flight-risk signal are real coverage, and they answer questions Hilt does not try to answer. Hilt does not score people. It does not own the mail gateway. It does not write the DLP report.
Hilt adds the one view the other two share a blind spot on: the pattern across permitted moves, resolved to the job behind each one, at runtime, while the data is moving. Predictive tools guess before it happens. Forensics arrive after the data is gone. This is the layer in between, and it closes a seam your stack was never built to cover instead of re-covering ground it already holds.
Sorting them yourself
Side by side, the questions that actually separate these tools are not on the feature grid.
Does it judge the individual move or the pattern across moves. A tool that scores each egress or each session in isolation will pass a run of individually permitted moves by design. Make the vendor walk a slow, low-volume exfiltration through a sanctioned channel and show you where it surfaces.
Where does it sit relative to your traffic. A control that sits inline can interrupt a move, and it also adds latency and becomes a single point of failure. Ask whether the collector is off the path and how it responds. Hilt responds with host-level network isolation from the control plane, never by filtering packets inline.
Does it have to read your data. Metadata-only by default means the system sees the pattern without inspecting content, with content-aware inspection available on demand rather than required.
Does it resolve moves to the job behind them. A baseline built on user activity alone, or channel events alone, misses the seam. Tying each move to an identity and the workload behind it is a different architecture, not a different dashboard.
Where does the data stay. For regulated firms and trading desks, residency is not optional. The path from kernel event to written case should run single-tenant inside your own cloud, AWS, GCP, Azure, or Ali Cloud, and events should never leave your account.
The right comparison does not crown one tool. It maps three layers and names the seam you are still exposed in. If your stack cannot answer what this identity's data actually did, resolved to the job behind it and scored against how it normally moves, across these off-hours windows, that is the seam, and it is the one runtime governance was built to close.
A 30-minute technical call is the fastest way to run this against a real cross-move pattern in your own environment. Engineer to engineer, the architecture, not a slide deck.