Plexus Technology Corporation — home

Insider Threat Prevention & Endpoint DLP

Stop data leaks at the endpoint, before they happen

CWAT watches what happens on the machine itself — file copies, prints, uploads, emails, USB connections — and blocks the ones that breach policy at the moment they are attempted. It keeps enforcing those rules whether or not the endpoint can reach the server.

  • Intelligent Wave Inc. (Japan)
  • In market since 2003
  • ~900 organisations
  • ~900,000 cumulative client licences (May 2025)
Intelligent Wave Inc. logo

Developed by

Intelligent Wave Inc.

Delivered, deployed and supported in the Philippines by Plexus Technology Corporation.

Where CWAT sits

Your first three lines don't watch the insider

Most organisations rely on multiple layers to stop threats — and attacks still get through, because the last one starts inside.

  1. 1st line of defense

    Firewall

    Blocks the outsider at the perimeter.

  2. 2nd line of defense

    EDR / XDR

    Detects malware and attacker behaviour on the endpoint.

  3. 3rd line of defense

    IAM

    Decides who is allowed to access what.

  4. 4th line of defense

    CWAT

    Controls what an authorised user can do with the data they can already open.

    Where CWAT operates

A firewall stops the outsider. EDR and XDR stop the malware. IAM decides who is allowed to open what. None of them stop an authenticated, authorised employee from copying a file they have every right to open — which is exactly the action CWAT governs.

Capabilities

Every route data takes out of the building

Upload, email, removable media, print, screenshot and clipboard — each one governed by policy and written to the log.

01

Real-time monitoring & blocking

File access, copy, print, upload, send and device connection are evaluated as they happen — warned on or hard-blocked at the moment of the action, not flagged in a report the next morning.

02

Removable media & device control

USB drives, external storage and smartphones are governed by policy: blocked outright, allowed read-only, or permitted with the written data encrypted.

03

Web & cloud upload control

Uploads through the browser are controlled per destination, including file-sharing services and generative-AI tools where pasted text is the leak.

04

Email & attachment control

Outbound mail and attachments are checked against policy before they leave, covering both SMTP clients and Exchange/Outlook environments.

05

Print, PrintScreen & clipboard

The quiet exfiltration paths — printing a document, screenshotting it, or copying its contents into another window — are each governed and logged.

06

Built-in file encryption

Group-key and individual-key encryption is included as standard, so a file that does leave the organisation stays unreadable outside it.

07

Sensitive-data identification

Documents are matched on keywords, credit-card number patterns, and regular expressions — so policy applies to content, not just location.

08

Two-tier logging

Audit logs capture all operations for forensics; alert logs isolate policy violations for response. Over 1,000 log types, kept separate so investigation stays tractable at volume.

09

Agent self-protection

The agent resists process termination and deletion, blocks Safe Mode circumvention, and protects log integrity against tampering.

How it works

From classification to enforcement

Four steps, and Plexus handles all of them with you.

  1. 01

    Classify

    Identify what is actually sensitive — by keyword, by pattern, by location — so policy targets the data that matters rather than everything.

  2. 02

    Author policy

    Build rules per user, per device and per organisational unit. 15 security policies are available on-premise; 14 on CWAT Cloud.

  3. 03

    Deploy the agent

    Roll out to Windows clients, including VMware Horizon and Citrix XenDesktop virtual desktops. Scales from a handful of seats to 10,000+ devices.

  4. 04

    Monitor & block

    Violations are blocked at the moment of the action and written to the alert log. Policies stay enforced on endpoints with no connection to the server.

Deployment

On-premise or cloud-managed

Same enforcement on the endpoint; the difference is who runs the management server.

On-premise

Your server, your control, the full policy set — 15 security policies. Suited to organisations that keep security infrastructure in-house or need it inside a specific network boundary.

CWAT Cloud

A managed management server with 14 security policies and nothing for you to host. Faster to stand up when there is no appetite to run another server.

Requirements

Client OS
Windows 10 / 11 Professional & Enterprise
Server OS
Windows Server 2016 – 2025
Virtual desktop
VMware Horizon, Citrix XenDesktop
Agent UI languages
Japanese, English, Simplified Chinese, Traditional Chinese, Korean
Offline behaviour
Policies stay enforced with no server connection

CWAT protects Windows endpoints. macOS, Linux and mobile clients are not supported.

Use cases

Where it earns its keep

Deployed across regulated and information-sensitive industries.

  • Banking
  • Insurance
  • Telecommunications
  • Manufacturing
  • Utilities & infrastructure
  • Government

Supply-chain information integrity

Keep drawings, specifications and pricing shared with suppliers inside the boundary they were shared into.

Generative-AI & shadow-AI leakage

Control what staff can paste or upload into AI tools, where a single prompt can carry source code or customer records out of the business.

Departing-employee monitoring

The weeks before a resignation takes effect are when client lists and project files most often walk. Watch and block that window specifically.

Overseas-subsidiary governance

Apply one consistent data policy across branches operating under different local practices, with logs centralised for review.

Plexus deploys, configures and supports CWAT

From classifying what needs protecting to writing the policies and rolling out the agent — we scope it with you and stay on after go-live.

Request a consultation

Pricing on request.