GOOGLE WORKSPACE DATA EXFILTRATION DETECTION

Detect file exfiltration
before it becomes a breach.

TripWyre watches how files move inside your Google Workspace
and tells your security team the moment normal turns abnormal.

It monitors behaviour and file activity.
Without reading your files.

Built for Google Workspace. Nothing to install.

TripWyre detects data exfiltration in Google Workspace. It monitors file activity for abnormal downloads, sharing, edits and access — alerting security teams when behaviour suggests a compromised account, an insider threat or unauthorised data movement. Without reading the files.

The dangerous user isn't
always unauthorised.

An employee, a contractor, a vendor or a compromised account may already have permission to reach your most sensitive files. Every action they take is allowed. Nothing is flagged.

Identity tells you who may open a folder. It cannot tell you that this account has just pulled eight thousand files at two in the morning, when it has never pulled more than forty.

TripWyre detects when normal file activity suddenly becomes abnormal — and puts that in front of a human while there is still something to be done about it.

This is what arrives.

Unusual bulk download 02:14
Account
contractor@company.com — permitted, external
Folder
M&A / Acquisition
Volume
8,421 files in 6 minutes
Against normal
37× this account's usual rate
Also seen
3 folders shared to a personal address

TripWyre detected the anomaly without opening a single file.

A worked example of the alert format — not a customer incident. The demo shows the same alert firing on live file activity.

Your Google permissions say
“allowed.”

TripWyre tells you when “allowed” becomes suspicious.

An account with legitimate access begins doing
something it has never done. The permission model
is satisfied, so nothing objects. Your logs record it
faithfully and nobody reads them until Monday.

TripWyre reads the same activity record
continuously, compares it to that account's own
normal, and raises a human alert when the pattern
breaks.

TripWyre learns what normal
file activity looks like.

Per account, per folder, per hour of the day. When that rhythm breaks in a way that looks like data leaving,
it says so — in plain English, to a person.

Bulk downloads

Thousands of files pulled in a
window no normal task needs.

Abnormal sharing

Sensitive folders shared outside
the tenancy, or by link, at scale.

Unusual access

An account, hour or location that
has never touched these files.

Your own procedures,
enacted across the whole estate.

Most organisations already have written rules about who may take what, from where, and when — in an IT policy, a control, an onboarding checklist. Today those rules are enforced by memory. TripWyre turns a written procedure into a trip: a condition watched continuously, company-wide or for one group, with no work at your end.

Say the rule once

In plain words: nobody outside finance bulk-downloads the payroll folder; no board material leaves the tenancy by personal link.

It runs everywhere

The trip applies across the Workspace — company-wide, or narrowed to a group, a folder, a class of account or a time of day.

It tells a named human

When the rule breaks, the person you nominate gets the account, the files, the volume and the pattern — while it is happening.

What TripWyre does, and what it doesn't.

TripWyre watches file activity in Google Workspace — downloads, shares, edits, deletions, access — and alerts a human when the pattern changes.

It does not scan file contents, cover email or endpoints, cover clouds other than Google, or take action on your systems.

Everything on this page is running in production today. You can watch it fire on real file activity in the demo.

Detect behaviour —
not people.

TripWyre reads the activity record Google Workspace already keeps — opened, edited, shared, downloaded, and by whom. It does not open documents, measure productivity, or watch screens, keystrokes or hours.

Your files stay private. TripWyre never reads file contents. Read-only by design: permission to open a file is never requested, so it can never be used.

Behaviour, not people. The alert describes what happened and when — a pattern, not a performance review.

Independent of the user. Your oversight does not depend on the account being watched — or the system it lives in — reporting honestly about itself.

Deploy in minutes.

1

Connect Workspace

A normal secure Google sign-in.
No agents, no network changes,
no rollout to your team.

2

Point it at what matters

The folders that would hurt
most if they left — finance, legal,
client data, personnel, IP.

3

Get told, not filed

A plain-English alert reaches a
named person within minutes of
the activity being recorded.

See TripWyre detect an
exfiltration attempt.

Fifteen minutes. We show the engine firing on live file activity — the account, the folder, the volume, the multiple against normal — and you tell us whether that alert would have mattered in your organisation.

Pricing is scoped on the call rather than printed here, because what it costs depends on how much of your Workspace you want watched.

No slide deck, no obligation, and we will tell you plainly if TripWyre is not the right fit yet.

Not ready for a call? Read the free field guide — what outside access to your files actually looks like, and how you would know. No meeting, no obligation.

Straight answers.

Including the ones we'd rather you heard from us first.

How is this different from our audit logs or our DLP?

Your logs record everything and interpret nothing; they are a filing cabinet you open after something has gone wrong. DLP looks at content and rules — it asks whether this file may leave.

TripWyre asks a different question: is this account still behaving like itself? It compares live activity against that account's own normal and raises a human alert when the pattern breaks — while it is still happening.

How quickly do we hear about it?

TripWyre alerts your team within minutes of the activity appearing in Google's own activity record — not the next morning, and not at the next audit.

We say minutes rather than "real time" because that is what we can stand behind: the engine reads Google's activity record continuously rather than sitting in the path of your files.

Can TripWyre stop an exfiltration?

TripWyre is an early-warning system. It detects abnormal file activity and alerts your security team quickly — with the user, the files, the volume and the pattern — so your team can revoke access, disable sharing or investigate while it still matters.

TripWyre does not block, quarantine or revoke anything itself. It is the smoke alarm, not the sprinkler, and it is deliberately built that way: a monitor that cannot change your Drive is a monitor that can never break it.

Can you read our documents or our clients' data?

No — and not merely as a promise. Connecting grants exactly two read-only permissions: see file names, and see the activity record. Permission to open a file is never requested, so it can never be used.

That matters if you hold client, patient or legal material: we can help you supervise it without ever seeing it.

Will our staff feel spied on?

TripWyre has no screen recording, no keystroke logging, no productivity scoring and no idle-time tracking. It cannot tell you who worked hard today.

It answers exactly one question: did the pattern of activity around these files suddenly change? Most organisations tell their people precisely that — and it lands as a smoke alarm, not a camera.

What do we have to install?

Nothing. No agents on machines, no network changes, no rollout to your team. It connects on the Google side and keeps working with every computer in the business switched off.

We're not on Google Workspace.

Then we're not ready for you yet. Google Workspace works today; Microsoft 365 and Dropbox are next. Tell us on the form and we'll come back to you when yours is live — we won't pretend it works in the meantime.

Who is behind it?

TripWyre was invented by Australian inventor Ric Richardson, who holds more than 200 patents, and co-invented with Dennis Groves, a partner in Deadbolt Cyber Holdings who comes from the application-security world.

It is commercialised through Deadbolt Cyber Holdings. Patent pending on the underlying method.

Your sensitive data shouldn't be
invisible to your security team.

Fifteen minutes to see whether this would have caught it.

Book a demo