Insider Threat Prevention & Endpoint DLP
Stop data leaks at the endpoint, before they happen
CWAT watches what happens on the machine itself — file copies, prints, uploads, emails, USB connections — and blocks the ones that breach policy at the moment they are attempted. It keeps enforcing those rules whether or not the endpoint can reach the server.
- Intelligent Wave Inc. (Japan)
- In market since 2003
- ~900 organisations
- ~900,000 cumulative client licences (May 2025)

Developed by
Intelligent Wave Inc.
Delivered, deployed and supported in the Philippines by Plexus Technology Corporation.
Your first three lines don't watch the insider
Most organisations rely on multiple layers to stop threats — and attacks still get through, because the last one starts inside.
- 1st line of defense
Firewall
Blocks the outsider at the perimeter.
- 2nd line of defense
EDR / XDR
Detects malware and attacker behaviour on the endpoint.
- 3rd line of defense
IAM
Decides who is allowed to access what.
- 4th line of defense
CWAT
Controls what an authorised user can do with the data they can already open.
Where CWAT operates
A firewall stops the outsider. EDR and XDR stop the malware. IAM decides who is allowed to open what. None of them stop an authenticated, authorised employee from copying a file they have every right to open — which is exactly the action CWAT governs.
Every route data takes out of the building
Upload, email, removable media, print, screenshot and clipboard — each one governed by policy and written to the log.
Real-time monitoring & blocking
File access, copy, print, upload, send and device connection are evaluated as they happen — warned on or hard-blocked at the moment of the action, not flagged in a report the next morning.
Removable media & device control
USB drives, external storage and smartphones are governed by policy: blocked outright, allowed read-only, or permitted with the written data encrypted.
Web & cloud upload control
Uploads through the browser are controlled per destination, including file-sharing services and generative-AI tools where pasted text is the leak.
Email & attachment control
Outbound mail and attachments are checked against policy before they leave, covering both SMTP clients and Exchange/Outlook environments.
Print, PrintScreen & clipboard
The quiet exfiltration paths — printing a document, screenshotting it, or copying its contents into another window — are each governed and logged.
Built-in file encryption
Group-key and individual-key encryption is included as standard, so a file that does leave the organisation stays unreadable outside it.
Sensitive-data identification
Documents are matched on keywords, credit-card number patterns, and regular expressions — so policy applies to content, not just location.
Two-tier logging
Audit logs capture all operations for forensics; alert logs isolate policy violations for response. Over 1,000 log types, kept separate so investigation stays tractable at volume.
Agent self-protection
The agent resists process termination and deletion, blocks Safe Mode circumvention, and protects log integrity against tampering.
From classification to enforcement
Four steps, and Plexus handles all of them with you.
- 01
Classify
Identify what is actually sensitive — by keyword, by pattern, by location — so policy targets the data that matters rather than everything.
- 02
Author policy
Build rules per user, per device and per organisational unit. 15 security policies are available on-premise; 14 on CWAT Cloud.
- 03
Deploy the agent
Roll out to Windows clients, including VMware Horizon and Citrix XenDesktop virtual desktops. Scales from a handful of seats to 10,000+ devices.
- 04
Monitor & block
Violations are blocked at the moment of the action and written to the alert log. Policies stay enforced on endpoints with no connection to the server.
On-premise or cloud-managed
Same enforcement on the endpoint; the difference is who runs the management server.
On-premise
Your server, your control, the full policy set — 15 security policies. Suited to organisations that keep security infrastructure in-house or need it inside a specific network boundary.
CWAT Cloud
A managed management server with 14 security policies and nothing for you to host. Faster to stand up when there is no appetite to run another server.
Requirements
- Client OS
- Windows 10 / 11 Professional & Enterprise
- Server OS
- Windows Server 2016 – 2025
- Virtual desktop
- VMware Horizon, Citrix XenDesktop
- Agent UI languages
- Japanese, English, Simplified Chinese, Traditional Chinese, Korean
- Offline behaviour
- Policies stay enforced with no server connection
CWAT protects Windows endpoints. macOS, Linux and mobile clients are not supported.
Where it earns its keep
Deployed across regulated and information-sensitive industries.
- Banking
- Insurance
- Telecommunications
- Manufacturing
- Utilities & infrastructure
- Government
Supply-chain information integrity
Keep drawings, specifications and pricing shared with suppliers inside the boundary they were shared into.
Generative-AI & shadow-AI leakage
Control what staff can paste or upload into AI tools, where a single prompt can carry source code or customer records out of the business.
Departing-employee monitoring
The weeks before a resignation takes effect are when client lists and project files most often walk. Watch and block that window specifically.
Overseas-subsidiary governance
Apply one consistent data policy across branches operating under different local practices, with logs centralised for review.
Plexus deploys, configures and supports CWAT
From classifying what needs protecting to writing the policies and rolling out the agent — we scope it with you and stay on after go-live.
Request a consultationPricing on request.
