Insider threat investigations · as a service

Every person covered.
Every question answered.

We keep a continuous forensic record of your organization, and our examiners investigate what matters. You get signed verdicts with the evidence attached, not another alert queue.

read-only connectors · first events preserved within the hour · nothing to deploy
The problem

When someone leaves, your data often leaves with them.

76%

of leavers take company data with them

more data theft in the 24 hours before a layoff notice

DTEX, leavers research · Cyberhaven, 3M workers ↗
How it actually happens
Engineering

Clones the repository in their last week.

Sales

Exports the whole pipeline before the handover.

Management

Shares a folder with the wrong domain.

Some of it is theft. Most of it is carelessness. Almost all of it happens inside accounts nobody thought to question.

What it costs you
0%
of leavers take intellectual property, not just files they happened to touch
DTEX, leavers research ↗
$0M
total average annual cost of insider security incidents, per organization
Ponemon & DTEX, 2026 ↗
0 days
average time to contain a single insider incident, long after the trail went cold
Ponemon & DTEX, 2026 ↗
$0M
global average cost of a data breach, a 12% rise and a record high
IBM, 2026 ↗

40% of alerts are never investigated.

Investigating one person means reconstructing months of activity across every system they touched. Ten systems, ten different identifiers, none of them agreeing on who the person is. Twenty to forty hours of specialist work that never outranks a live incident.

SACR · 282 organizations, median 960 alerts a day ↗
Introducing

Insider threat investigations. As a service.

Your triggers and ours, every one examined. Our AI does the volume, our examiners do the judgment, and the evidence was already preserved before the question arrived.

01YOU · ONCE

Connect your systems

Read-only connections to the tools your company already runs. No agents to deploy on day one, no schema work, no queue to staff. The first events land in the record within the hour.

Microsoft 365
Entra ID
Google Workspace
GitHub
Slack
Okta
Workday
Defender
02EXCAVATE

The forensic record builds itself

Every event from every source is preserved continuously, for every person in the organization. Nothing expires and nothing is sampled, so when a question arrives the evidence already exists.

THE FORENSIC RECORD25,594,696 events
A year of the forensic record: dimmed backfilled history, then bright connected coverage, with review and investigation marks.
preserved · immutable · access logged1,412 people covered
03AUTOMATIC

A trigger occurs

An employee resigns, your HR system flags a departure, one of our rules fires, or your team requests a review in the portal. Whatever starts it, nothing needs to be noticed by a human first.

TRIGGER · DAY 0
An employee resigns
Workday · departure flagged 09:14 · last day in 14 days
or a rule firesor you request a reviewor the SOC escalates
04EXCAVATE · AI

Our AI triages every single one

Each trigger is examined against the whole record automatically, around the clock. Almost all of them resolve with a written cause and never reach your team. Nobody on your side works a queue.

AI TRIAGEautomatic · 24/7
Mass-download patternresolved · scheduled migration
Unusual sign-in geometryresolved · approved travel
External share volumeresolved · manager-approved
Mail-rule changeresolved · IT-provisioned
OAuth consent grantresolved · change ticket matched
0examined
0resolved silently
0escalated to a human
05EXCAVATE · EXAMINER

The few that matter escalate

When triage cannot close something cleanly, it goes to one of our examiners, not to you. They review it against the person’s preserved history and decide: cleared, or escalate it into a case.

250closed with a written cause
4reviewed by a human examiner
06EXCAVATE

A case opens

The escalation becomes a real forensic case with its own file, its own examiner and a legal hold on everything relevant. From here it is a digital forensics engagement, run by us.

HALCYON-INS-001Investigation open
Offboarding investigation
TYPEInsider risk · departure
EXAMINERExcavate, assigned
HOLDLegal hold applied
SCOPELast 90 days, preserved
07EXCAVATE

Endpoint evidence enriches the case

Cloud history tells us what left. The endpoint tells us how. Where you have rolled out endpoint collection, agents contribute device-level evidence: USB writes, staged archives, filesystem journals, deleted files recovered forensically.

Endpoint agents
USB write · 02:14 · 4.2 GB
Archive staged, then deleted
Filesystem journal recovered
Device identity confirmed
08EXCAVATE · HUMAN

Our examiners run the investigation

Certified examiners work the case end to end: building the timeline, testing hypotheses against evidence, and standing behind the conclusion. Not your headcount, not your weekend.

Examiner working the case
Timeline assembled from the preserved record
Hypotheses tested against evidence
Chain of custody documented
Findings written up and signed
09YOU · THE ONLY STEP

You read the verdict

A written report with the findings, the evidence behind each one, and a named examiner’s signature on the conclusion. It holds up in front of counsel, an arbitrator or a court. One decision is yours: what happens next.

Report · verdict
Violation confirmed
signed by a certified examiner · chain of custody intact · delivered before the last day
the record preserves from the systems you already run
The client portal

Every answer, already assembled.

The portal is not a queue and not a pile of logs. Your record arrives parsed into timelines, conclusions and plain-English answers, so nobody on your side has to dig for them.

Data hub

The whole record in one instrument

Every trigger has a name, a rule and a written resolution, and any row opens into what fired, what we examined and why it closed. Filter by person, source, rule or date, export it for an audit, or just ask Excavate.

The Data hub: the record histogram over six months, the funnel line, and the named trigger ledger.
Ask Excavate

Ask in plain language

Type a question and the answer comes back from your record, with a link to the data behind it. No query language, no filters to learn, no analyst required.

The Ask Excavate conversation: a question about departures answered with a link to the data.
Investigations

When something is real, you see all of it

A confirmed case carries its findings, hypotheses, timeline, evidence and report in one file, each finding preserved forensically.

An investigation timeline: the resignation, the first personal-webmail uploads and a full repository clone, each tagged by severity.
Readiness

Know where you stand

A forensic-readiness assessment scores every domain, ranks the gaps by severity and tracks each one to closure with a named owner.

The forensic-readiness assessment with a domain radar and severity-ranked gap analysis.
Person record

One person, one instrument

The same record scoped to a single person: their history, their reviews in plain English, and a parsed activity timeline where every entry names its source.

A person record with preserved history, reviews and a source-attributed timeline.
Offboarding

Every offboarding ends with an exit review, included with coverage.

Why it exists

Data theft starts climbing up to two hundred days before anyone resigns, and spikes in the final hours before a departure is announced. By the time HR tells you someone is leaving, most of it has already happened, which is why the review has to run against history you already hold.

Cyberhaven · 3M workers, 831k exfiltration events ↗

How it runs

The resignation lands in your HR system and opens the review on its own, with nothing to request. An examiner works the person's last ninety days in the record: files, downloads, external shares, repositories, sign-ins and AI use. You receive a verdict in writing before their last day.

Why the record makes it possible

Evidence has to exist before you need it, because nothing can be collected retroactively from a returned laptop. The record preserved everything continuously, so the review takes an examiner minutes instead of weeks of forensic recovery, and if a matter escalates, chain of custody has been intact since day one.

Resignation logged
day 0 · automatic trigger
The record is already there
last 90 days preserved
Exit review opens
same day · no request needed
Examiner concludes
files · shares · repos · sign-ins
Verdict in writing
before the last day
Included for every offboarding · no per-case invoice · concluded before the badge is returned
Use cases

What people actually call us about.

Coverage runs the same way underneath. These are the situations it gets used for.

Departing employees

The highest-risk window in any employment relationship is the last few weeks. Every departure gets an exit review of the preserved record, concluded in writing before the badge is returned.

IP and trade secret theft

Source code, customer lists, pricing models and roadmaps leaving through USB drives, personal webmail or cloud sync. We preserve the trail and prove it forensically.

Accidental exposure

Most leakage is a mistake: the wrong recipient, an over-shared folder, a public link. We catch it, establish the blast radius and tell you whether anything left.

HR and workplace investigations

Harassment, policy violations, conflicts of interest. When an allegation needs electronic evidence, you get a defensible answer without your HR team becoming investigators.

Litigation and legal holds

Trade secret suits, employment disputes and arbitration. Chain of custody from before the dispute existed, with reports written to survive scrutiny.

Post-incident scoping

Your SOC contained something and now the board, your insurer or a regulator wants to know exactly what was touched. We work the forensics while your team moves on.

See it live

Walk the portal yourself, then talk to us.

3-minute self-serve

Walk a real quarter of coverage, end to end

No login required. The live portal plays a full story of the record filling, triggers being examined, a review, an investigation and the final report, and then hands you free roam of everything you just watched.

Launch the live demo best on desktop · opens in a new tab