THE RISK BRIEF
DTEX: HUMAN + DATA + AI RISKCAPITALG LED $50M SERIES E / MARCH 2024AI RISK MANAGEMENT / PRIVATE PREVIEW

COMPANY / CYBERSECURITY

DTEX catches the trouble before the file leaves

A copied folder can be routine work. A copied folder, a renamed file and an unusual destination can tell another story. DTEX sells the context that connects them.

Roger copies a folder. Then he renames a file. Then company information finds its way into a generative AI prompt. Roger is fictional, the recurring character in DTEX’s product demonstrations. His usefulness is that he is terribly ordinary. None of those actions, considered alone, supplies much of a plot. Put them together, and a security analyst has a question worth asking.

THE STORY IN FOUR POINTS
  • DTEX connects behavior, data movement and AI activity to investigate insider risk.
  • Its customers include enterprises and government agencies with sensitive information to protect.
  • Adaptive controls and pseudonymized identities are central to its product approach.
  • The practical lesson: examine the sequence before you judge the actor.

This is the small observation on which DTEX has built a substantial business. A person can have legitimate access and still use it badly. A system can record a suspicious event and still miss its meaning. DTEX tries to fill that gap with behavioral intelligence: evidence about what happened before, during and around an action, assembled into something an investigator can use.

Permission is only the beginning

Consider the difference between opening a document and collecting a set of documents that has nothing to do with your job. The first is a permission problem. The second requires context. DTEX’s platform combines insider risk management, user activity monitoring, behavior analytics and data loss prevention. Its endpoint telemetry helps analysts follow activity across work devices; integrations add information from cloud applications and other security systems.

Risk-Adaptive DLP turns that context into controls. Policies can change as behavior, data sensitivity and risk change. DTEX describes both content-based classification and behavior-based classification, the latter using file attributes and activity to infer sensitivity. That matters when the valuable thing is source code, an image or a video, rather than a neatly labeled document.

AN ILLUSTRATIVE WORKFLOW
01GatherCollect activity and data movement.
02ConnectCompare patterns with expected work.
03InvestigateReview context before intervention.
The folder is innocent until the rest of the itinerary becomes interesting.

The delicate part is that the subject of this analysis is often a colleague. DTEX uses pseudonymization to mask personal identifiers in activity data. That gives investigators a way to examine behavior with less identity exposure. It does not make every monitoring decision wise. Someone still has to determine the purpose of collection, who may reveal an identity and what constitutes enough evidence to act.

Nor does DTEX own the idea of privacy-conscious insider risk. Microsoft Purview also pseudonymizes users by default. Proofpoint combines behavioral insights and data movement; Forcepoint offers risk-adaptive protection. DTEX’s proposition is the combination of its telemetry, behavioral analysis, controls and investigative expertise. A buyer has to test that combination against the work their people actually do.

The people who have to answer the alert

DTEX’s audience is the security team that must turn an alert into a defensible decision. Historical customer announcements name the US Defense Information Systems Agency, Williams F1 & Advanced Engineering and Freshfields Bruckhaus Deringer. Their information differs: government systems, engineering work, legal matters. Each provides a reason to care about trusted access, and about mistakes as well as malice.

On DTEX’s DLP page, an unnamed pharmaceutical insider-risk director says, “Prior to DTEX, we were reactionary.” A separate technology customer describes DTEX detecting exfiltration after internal controls or another security tool failed to stop it. These are company-published testimonials, but they locate the problem precisely: the existing defenses had left investigators recovering events after the fact.

“Prior to DTEX, we were reactionary.”

Director of Insider Risk, pharmaceuticals
Customer testimonial published by DTEX

The software is only part of the response. DTEX’s i³ team provides insider intelligence, risk analysis, investigations and training. Its partnership with MITRE, announced in 2022, adds program review and knowledge transfer through Inside-R Protect. MITRE reported that a large Australian bank was incorporating the program’s recommendations. The research relationship makes human behavior an operating concern, rather than a decorative reference to psychology.

DTEX co-founders Mohan Koo, left, and Christiaan Nillissen, right
THE BUILDERS Mohan Koo and Christiaan Nillissen. An insider-risk company whose co-founders are happy to be identified. Photo: DTEX.

Co-founder Mohan Koo has described a change in emphasis: the early challenge was building technology that could scale; later work concentrated more heavily on human behavioral research. That shift explains why the company talks about signals from security, physical activity and organizational life. An HR detail and a file transfer may mean little separately. Together, they can change the investigation.

It also explains a limit. If departments cannot share relevant context, or nobody has authority to investigate proportionately, another dashboard will struggle to help. This is an organizational practice with software inside it. A team needs a clear route from evidence to decision, including the possibility that an alarming pattern has a perfectly reasonable explanation.

A $50 million vote of confidence

In March 2024, CapitalG led DTEX’s $50 million Series E. The announcement reported $138 million in cumulative funding and earmarked the money for US engineering and global commercial expansion. DTEX also reported 118% growth in its SaaS business in fiscal 2023 and a government deal covering more than 100,000 endpoints. Those are company-reported figures, attached to a particular year.

THE MARCH 2024 ROUND$50M

Series E led by CapitalG
For engineering and global expansion

The business model is enterprise software contracts plus specialist services. AWS Marketplace lists InTERCEPT as SaaS and displays $100,000 for a 12-month contract. It also specifies negotiated private offers and custom pricing. That figure is a purchasing reference, not the price every customer pays; contract scope and additional infrastructure costs matter.

The colleague without a coffee mug

Now DTEX is applying the same logic to AI. Its current AI Risk Management page invites customers into a private preview covering shadow AI discovery, prompt inspection and agent oversight. Triage Guardian pairs an analyst agent with a reviewer agent to investigate and challenge alert conclusions, with human oversight. Threat Hunter looks for emerging behavioral risk, while Risk Assistant helps analysts interpret it.

The useful thing to copy is the method. Pick one workflow, such as departing employees moving files. Agree on the context an investigator needs. Test visibility and controls, then measure time to a defensible conclusion. When the actor becomes an AI agent, repeat the exercise. The coffee mug disappears. The need to understand what happened remains.