The platform that governs data movement, at the kernel
Hilt is a data movement governance platform. It watches where your data goes, not just where it sits: kernel-level and observational, resolved to a real person and the exact job, metadata-only so it never reads the content, and single-tenant in your own cloud.
One detection layer is fed from three surfaces: Linux workloads (Kubernetes, containers, VMs, and bare metal), device endpoints (kernel collectors on macOS and Windows, plus browser-level events across Edge, Safari, Firefox, and Chromium browsers), and the network (wire-level egress and lateral movement).
The loop is collect, enrich, detect, respond. Collect an identity-aware stream off the hot path at about 0.1% of one core. Enrich each event to an actor (Okta, Teleport, SSH, OS identity) and the exact workload and job, where the source allows. Detect exfiltration patterns (read-then-send, sensitive-read-send, novelty bytes, cross-cluster transfers) with behavioral models. Respond by isolating a host at the network level from the control plane.
Straight on scope: metadata-only by default (content-aware inspection is available, single-tenant in your own cloud, never the resting state), host-level network isolation (quarantine), never inline. Coverage is cloud workloads plus device endpoints: kernel collectors on macOS and Windows, and a managed browser extension across Edge, Safari, Firefox, and Chromium browsers. SSO is in progress; deployment is single-tenant in your own environment with full data sovereignty.