The alert fires after the file left. The case opens after a quarter of research already sits in someone's personal cloud drive. The disclosure letter goes out after the customer records reached a place you cannot reach them. Your tools work. They just speak in the past tense.
One question decides whether a data loss is recoverable. Did you see the move while the data was still in your environment, or did you see it once the data was already gone. Most tools only ever answer the second way. Runtime data movement governance answers the first.
The loss closes before you know it happened
Your most valuable data does not leave through a hole in the wall. It leaves on access you granted on purpose. A researcher pulls from a repository she is supposed to read. A finance analyst runs a standing export. A vendor integration uses a token that works exactly as designed. Each move is permitted, so each control you own waves it through. That is the control working, not failing.
The breach is not the move. It is the shape across moves. A bulk read that fits no job that user runs. A steady off-hours copy through an approved channel. A destination that has never taken this volume before. By the time that shape shows up in a log, the data has usually already landed somewhere you do not own.
Forensics reads that log beautifully. A good forensic tool reconstructs exactly what happened, and you want one. But reconstruction is past tense by definition. The move it describes is over. The window to keep the data inside your walls shut before anyone opened the investigation.
Three places a tool can stand, two of them too late
Picture the move as it happens. A tool sits before it, after it, or during it.
Before the move are the predictive tools, the DLP world. They guess which moves are dangerous from rules and content matches. The guessing is fast, which is worth something, and wrong often, which buries teams in false alarms. And it never catches the permitted move, because a permitted move breaks no rule to trip on. Speed, aimed at the wrong moves.
After the move is traditional detection and response. It tells you what happened with real confidence, and you need that for the cases that do get out. But the data is gone by the time it speaks. Accuracy, arriving after the thing it would have saved.
During the move is runtime governance. It watches the movement as it forms, resolves it to who is moving what and the job behind it, and surfaces the dangerous shape while the data is still inside your environment. Fast like the predictive tools, accurate like forensics, and live. Live is the part that matters, because live means there is still a move in progress to cut.
What "in time to act" costs you in architecture
Runtime is not a posture you adopt. It is a set of constraints most tools cannot meet, and the constraints are physical.
You cannot see a move forming unless you watch where moves actually resolve. Hilt watches data movement at the kernel, metadata only by default, off the path. Every read, copy, and transfer crosses that layer no matter which app or channel carried it, which is why the vantage works. Hilt does not read your data to know the data is moving in a way it never has before. It reads the shape, not the contents.
You cannot act in time if you pay for visibility in latency. A control that sits inline can stop a move, and it also taxes every move and becomes one more thing that can take down the systems it guards. That tax is why high-value environments quietly settle for partial coverage. Hilt stays off the path. The collector runs at roughly 0.1% of one core and 4 to 8 MB of memory per host. It observes the move instead of standing in it, so an environment that could never carry a heavy inline control can finally watch the shape without paying for the watching.
You cannot act with confidence on a single tripwire. Hilt resolves each move to a probabilistic, source-dependent identity: which user, which job, which destination, and whether this fits what that identity normally does. One signal alone is noise. The off-pattern job, the bulk read of high-value paths in a short window, the destination volume that breaks the baseline, taken together, are a shape. A shape is a case. You act on a case, not an alert.
What acting looks like
When the shape crosses the line, Hilt isolates the host at the network, quarantine, from the control plane. It does not block packets inline, drop traffic, or stand between your data and its destination. It cuts the host off the network so the move in progress has nowhere to go, and it writes the case as it does, resolved to the identity and the job behind the move.
Hold that next to a forensic reconstruction. Forensics tells you, accurately, that the research left two weeks ago. Isolation means the host that was halfway through copying it is off the network now, and the half it had not reached is still yours.
The change underneath is worth saying flat. Your security team stops explaining a loss after the fact and starts containing a move before it finishes. Containment and disclosure are different jobs. One of them keeps the thing.
Where this sits in a stack you already run
Runtime governance sits next to what you already run, and the honest version says exactly what it can carry. On the endpoint, Hilt can stand in for your endpoint sensor, and many clients retire their EDR once it is in place; keep an EDR alongside only if you want the malware and intrusion layer too, since that is the one thing Hilt does not do. Your network controls govern access. Your application-layer tools catch the loud exfiltration paths, the screenshot mailed to a personal account, the bulk download the week before someone leaves. Those tools earn their place where they still earn it.
None of them was built to read the shape of movement across permitted actions, at runtime, while there is still a move to interrupt. That is the layer Hilt adds. It runs single-tenant inside your own cloud, AWS, GCP, Azure, or Ali Cloud, and the events never leave your account. One collector covers a cloud workload or a user endpoint, so the runtime layer is a single thing across your estate, not two products bolted together.
Past tense is a record of losses
Forensics answers one question: what did this data do. The question that saves the data is the present one. What is this data doing right now, and is there still time to stop it. A tool that can only ever answer in the past tense is, in structure, a ledger of losses you were never positioned to prevent.
Runtime governance promises something narrower and harder than more visibility. See the move while the move is still happening, resolved to the job behind it, and act before the data is somewhere you cannot reach. That gap is the whole distance between a contained incident and a letter to your customers.
If you want to map where the runtime layer sits against what you already run, and what acting at runtime would change in your environment specifically, the next step is a 30-minute call, engineer to engineer. No demo theater, just the architecture and your real data paths.