A researcher copies proprietary code over two weeks. Small chunks, after hours, through an approved FTP connection that moves legitimate data every day. No policy breaks. No alert fires. The stack she walks past cost seven figures and stayed silent the whole time.
Your insider tools were not asleep. They checked whether each move was allowed, and each move was. That is the wrong question. The breach is not one move. It is the shape across moves.
What your stack actually watches
Proofpoint Insider Risk Management and Microsoft Purview watch the application layer. Files into Dropbox. Attachments out through Outlook. Bulk pulls from Salesforce. They catch the loud cases: someone screenshots a customer database and mails it to a personal Gmail, someone drains their CRM the week before they quit. Those are real, and these tools catch them.
They do not catch the quiet case, because the quiet case never trips a rule. Permission was granted on purpose. Only the pattern is wrong.
The pattern is the part nobody scores
Go back to the researcher. Each action she takes is individually fine. The tools log it and move on, because logging an action is not the same as scoring the movement against history. None of them ask whether this user, at this hour, through this job, is moving data the way she has moved it for the last six months.
Hilt asks that. It watches data movement at the kernel, metadata only by default, off the path. It does not read the code to know the move is wrong, the way your bank flags a charge without knowing what you bought. Each move resolves to a probabilistic identity: which user, which job, which destination, and whether this fits what that identity normally does.
When the researcher copies the code, three things bend at once. The job is unusual for her. The access is a bulk read of high-value paths in a tight window. The volume to that destination is high for an approved channel. Any one of those, alone, is noise you would learn to ignore. Together they are a pattern. A pattern is a case, not an alert.
This sits between the two tools you already know. Predictive controls guess in advance and drown you in false alarms. Forensics tell you after the data is gone. Hilt reads the movement as it happens.
The latency objection, head on
Trading firms reject most security tooling for one reason, and it is not budget. An agent that adds overhead to order processing is a hard no, and the security team does not get to overrule the infrastructure team on that. So these firms run with known gaps. The endpoint agents that would close them are too heavy to sit near the workloads that matter.
A collector off the path does not have that problem. Hilt watches at the kernel at roughly 0.1% of one core and 4 to 8 MB of memory per host. It runs single-tenant inside your own cloud. It never sits inline, never blocks, drops, or alters traffic. It observes the move instead of standing in front of it, so the latency cost is effectively nothing. The firms that could never afford a heavy inline control can finally see the pattern.
Where this lands against what you own
Your stack covers most of the surface and covers it well. CrowdStrike handles known attack patterns and endpoint behavior. Zscaler controls network access. Proofpoint catches application-layer exfiltration. Hilt replaces none of them.
What is left is not negligence. It is a property of where those tools stand. They evaluate permission. They were never built to evaluate the pattern of movement across actions that were each permitted. Behavioral drift that crosses job, file access, and destination at once, run through approved channels by a real employee, lives precisely in that blind spot. Runtime data movement governance does not take anything off your shelf. It closes the one thing the shelf was never built to hold.
Questions to put to any vendor
A "we watch the kernel" line means different things from different vendors. Press on these.
Where does it sit relative to your traffic? Inline can block, but it adds latency and becomes a single point of failure. Ask whether the collector is off the path. Hilt responds with host-level network isolation, quarantine from the control plane, never by filtering packets inline.
Does it have to read your data? Ask the default vantage. Metadata only means the system sees the pattern is wrong without opening the file. Content-aware inspection is there when you want it, not the toll for entry.
Does it correlate movement, or just log actions? A baseline built on user activity alone misses the shape. A system that resolves each move to a user, a job, and a destination, then scores it against normal, is a different architecture.
Where does the data stay? For regulated firms, residency is not optional. The path from kernel event to written case should run single-tenant inside your own cloud, AWS, GCP, Azure, or Ali Cloud. Events should never leave your account.
Does it sharpen as it learns your environment? A baseline gets better the more movement it sees. Ask how it tells a new-but-legitimate pattern from an anomaly, and how it hands you the dangerous one as a case rather than another row in a queue.
Run the test on your own stack. Ask it what that researcher's data did between 11pm and 2am on three specific dates, resolved to the job behind it and scored against how it normally moves. If your tools cannot answer, that silence is the gap. A 30-minute technical call is enough to show you what answering looks like.