For observability and data-platform vendors
Every customer is re-diligencing you.
Hilt governs customer data movement for observability and data platforms. The questionnaires on your desk ask for the one control you cannot show: that a connector reading a customer tenant and sending it somewhere new would be caught. Hilt watches that movement at the kernel, identity-resolved, without reading the records.
Answer with evidence, not a PDF
Post-Drift, every customer is re-diligencing you, and the questionnaires ask for the one control you cannot show: proof that customer data leaving your data plane would be caught while it moved.
- A token doing something new. An un-rotated key with no MFA does a bulk read off a broker or sync worker and ships it to a destination the DPA never named. Authorized identity, unauthorized pattern: the Snowflake leg, one layer down from Drift, on the data plane you run yourself.
- A leaver or a pipeline agent. Connector-fleet access or delegated tokens read a customer tenant and send it to a personal cloud. Every agent is a new insider nobody interviews, and you wire in more each quarter.
Why the stack cannot answer it
DSPM shows where customer data sits and who could reach it, not that a connector just read a sensitive table and shipped it somewhere new. Endpoint DLP watches laptops, email, and SaaS uploads, and never sees the production connectors, brokers, and sync workers where bulk data actually moves.
Hilt watches the movement: off the hot path, identity-resolved, metadata only, and it never reads the records.
Prove it on your own cluster. The proof runs on your hardware.