Problem

Different actor. Same movement out.

Human insiders, AI agents, and shadow AI create the same runtime evidence: a permitted identity reads data, stages it, then sends it somewhere that person or job normally does not. Hilt joins those events into one identity-resolved movement sequence across Linux workloads and macOS endpoints.

Different actors. Same movement out.

A departing employee, an AI agent, and a user pasting into a personal model account look different in policy tools. At runtime they create the same evidence: a permitted identity reads data, stages it, then sends it somewhere that person or job normally does not.

Three forms of one problem

ActorSurfaceWhat changes
Human insiderShell, browser, sync client, or removable mediaThe identity, timing, volume, or destination no longer fits the person's work
AI agentCloud workload, MCP server, endpoint process, or pipelineThe job touches a new dataset or opens egress outside its established task
Shadow AIBrowser or desktop application using a personal accountA sensitive read becomes an upload to an unsanctioned model destination

How Hilt catches the sequence

Hilt watches data movement at the kernel across Linux workloads and macOS endpoints, off the path and metadata-only by default. It resolves movement to the human or non-human identity, process, workload, and job, then scores the read, stage, and send as one sequence. A finding carries the paths, volume, timing, and destination that made the movement abnormal.

Rules cover what must never happen. Behavioral detection catches what nobody predicted. With response enabled, Hilt can alert through Slack or email, block a supported endpoint transfer, or quarantine a cloud host at the network.

FAQ

Common questions about this page

Why combine insiders, AI agents, and shadow AI?

The actor and surface differ, but the movement evidence is the same. A permitted identity reads data, stages it, and sends it somewhere new. Hilt resolves that sequence to the person or non-human identity, process, workload, and job rather than maintaining three disconnected detection systems.

Can Hilt detect this without reading file contents?

Yes. Metadata-only is the default. Identity, path, process, timing, volume, sequence, and destination can show that movement is abnormal without reading the payload. Content inspection is an optional collection mode you control.

Can Hilt stop the transfer?

Response depends on the surface and is enabled where you choose. Hilt can block supported endpoint uploads and transfers, or quarantine a cloud host at the network from the control plane. The collector stays off the data path.

Where do events and findings live?

Raw events and identifiers remain single-tenant in your own cloud account. The collector is metadata-only by default, off the path, and does not create a shared data plane for your movement telemetry.

Does this replace guardrails, DLP, or insider-risk tools?

No single control answers every layer. Guardrails steer agents, DLP enforces known content policies, and insider-risk tools score users. Hilt adds the runtime movement sequence across people, agents, cloud workloads, and endpoints.