Content-Aware Blocking by Fingerprint & Label

Anexet blocks outgoing transfers the instant the content being sent matches a registered digital fingerprint, file hash, sensitivity label, or thesaurus term. The file remains readable and fully audited inside the Console; it simply cannot leave. Deployed on-premise — the vendor has no access to your data. Available on the Premium plan.

Schedule a Demo
Anexet Client Console showing a blocked transfer event

When Renaming the File Is Not Enough

Protocol-level policies stop channels — content-aware blocking stops the data itself, regardless of which channel it travels through.

Most data leaks are not accidental in the way people assume. An employee knows the document is confidential. They attempt to forward it through a personal email account, drop it into a cloud drive, or copy it to a USB stick before resigning. Protocol-level policies stop some of those routes. They do not stop an employee who renames the file, changes the extension, or routes the content through an unfamiliar channel.

Content-aware blocking addresses a different layer: the content itself. Anexet analyzes what is being transferred — not just the filename or the protocol — against a library of analysis objects you define: digital fingerprints of sensitive source documents, cryptographic hashes of known files, sensitivity labels applied to classified categories, and thesaurus term sets covering industry- or company-specific vocabulary. A transfer attempt that matches any of these objects is blocked at the moment of interception, before the data leaves the endpoint.

The result is a policy that travels with the information rather than with the channel. Change the filename, switch to a different messenger, use an encrypted cloud service — if the underlying content still matches, the block still fires. In the Client Console, the security officer sees the blocked event: the user, the channel, the matched object, the timestamp. The document itself is preserved as evidence. Nothing was lost; nothing was sent.

Why it matters

  • Content beats the channel

    Renaming a file or switching to a different app cannot bypass a fingerprint- or hash-based block — the policy follows the data, not the route.

  • Four matching mechanisms

    Digital fingerprints, cryptographic hashes, sensitivity labels, and thesaurus term sets can be combined in a single blocking rule with AND/OR logic.

  • On-premise, no vendor access

    All interception, content analysis, and blocking decisions happen inside your perimeter. No data, no fingerprint library, and no policy configuration is transmitted externally.

Content-Aware Blocking Objects

All four matching mechanisms require the Premium plan. They extend the standard blocking policies available from Advanced — protocol, device, print, clipboard — with content-identity awareness.

Document-identity blocking

  • Digital fingerprint match

    Premium

    Anexet registers a fingerprint of a sensitive source document — a contract template, a technical specification, a payroll sheet. Any file derived from that source, even partially modified or reformatted, carries enough of the original signature for the fingerprint engine to recognize it. Blocked across all monitored channels: email, messengers, HTTP/FTP, cloud drives, network shares, USB.

  • File hash match

    Premium

    Exact cryptographic hashes are registered in hash banks. If an intercepted file produces the same hash, the transfer is blocked. Effective for exact-copy scenarios — known malware files, controlled documents that must never leave the perimeter, or files already flagged during a previous investigation.

Classification & vocabulary blocking

  • Sensitivity label match

    Premium

    Documents classified under a corporate sensitivity label scheme (for example, "Confidential", "Internal Only", "Restricted") carry that label in the file metadata. Anexet reads the label and enforces the blocking policy without re-analyzing the content from scratch. Label-based rules are straightforward to maintain as classification schemes evolve.

  • Thesaurus term match

    Premium

    A thesaurus is a list of words, phrases, or regular expressions meaningful to your organization — product codenames, personal data patterns, financial terminology, specific project identifiers. When outgoing content contains a concentration of those terms that meets the configured threshold, the transfer is blocked. Thesaurus search for investigation and alerting is available from Advanced; blocking on thesaurus matches is Premium.

Supporting capabilities

  • Block AI data leaks

    confirmed during the demo

    Prevent sensitive documents from being uploaded to AI chat services and generative AI tools. The same content-matching engine that protects email and cloud storage can apply to AI-service channels.

  • On-screen watermarks

    confirmed during the demo

    Visible watermarks can be applied to sensitive documents displayed on-screen, discouraging photography-based exfiltration and signalling classification to the user.

The exact channel coverage and feature availability for your environment is confirmed during the demo.

What Happens at the Moment of Interception

As data moves through a monitored channel, the Endpoint Agent intercepts it and passes the content to the Data Processing Server. The server runs the content through the registered analysis objects — fingerprint comparison, hash lookup, label extraction, thesaurus scoring — before the transfer completes. This happens in the background, invisibly to the user, on the endpoint inside your perimeter. If a match is found, the transfer is cancelled immediately.

Because Anexet is deployed entirely on-premise, no intercepted content, no fingerprint library, and no policy configuration is ever transmitted to the vendor or any external service. The blocked event — including the user, workstation, channel, matched analysis object, timestamp, and full content — is retained in the Client Console as auditable evidence.

Blocked transfer event in the Anexet Client Console
Content analysis and blocking policy configuration in Anexet

How Content-Aware Blocking Works

Four steps from a sensitive document to a blocked, logged, and evidence-ready event.

Register your analysis objects in the Administrator Console — upload source documents for fingerprinting, add hashes to hash banks, map sensitivity label identifiers, and build thesaurus term lists with match-threshold rules.

1

Create or edit a blocking rule in the Client Console under Security Policies — specify which channels the rule covers and which analysis objects trigger the block, combining them with AND/OR logic for nuanced policies.

2

As data moves through a monitored channel, the Endpoint Agent intercepts it and the Data Processing Server runs content through all registered analysis objects before the transfer completes.

3

If a match is found, the transfer is cancelled; the blocked event appears immediately in the Client Console with full details — user, channel, matched object, timestamp, and the intercepted content preserved as evidence.

4

Register your analysis objects in the Administrator Console — upload source documents for fingerprinting, add hashes to hash banks, map sensitivity label identifiers, and build thesaurus term lists with match-threshold rules.

1

Create or edit a blocking rule in the Client Console under Security Policies — specify which channels the rule covers and which analysis objects trigger the block, combining them with AND/OR logic for nuanced policies.

2

As data moves through a monitored channel, the Endpoint Agent intercepts it and the Data Processing Server runs content through all registered analysis objects before the transfer completes.

3

If a match is found, the transfer is cancelled; the blocked event appears immediately in the Client Console with full details — user, channel, matched object, timestamp, and the intercepted content preserved as evidence.

4

Arrow

Content-Aware Blocking by Plan

StandardCore employee activity monitoring.
Network traffic interception
USB control
Printers monitoring
Messengers interception
Browsers interception
and 4 more
Includes:
Anexet Activity
Most popular
AdvancedAdds DLP and deeper visibility.
Standard plan included
DLP features
Network shares monitoring
Keylogger
Webcam pictures
and 4 more
Includes:
Anexet DLP
Anexet Activity
All-in-one
PremiumAll-in-one solution.
Standard + Advanced plans included
Advanced search (digital fingerprints, hash search)
File systems monitoring
User relations analysis
Risk analysis
and 6 more
Includes:
Anexet DLP
Anexet Inventory
Anexet Activity
Anexet Ultimate

Frequently Asked Questions

Common questions about content-aware blocking in Anexet.

What is content-aware blocking?

Content-aware blocking is a policy mechanism that cancels a data transfer when the content being sent matches a defined analysis object — a digital fingerprint, a file hash, a sensitivity label, or a thesaurus term set. Unlike protocol-level blocks (which stop a channel entirely) or filename blocks (which can be bypassed by renaming), content-aware blocking evaluates the substance of what is being transferred. In Anexet, this capability is part of the Blocking Policies module and is available on the Premium plan.

Standard blocking policies in Anexet (available from the Advanced plan) trigger on channel, protocol, device type, or file category — for example, blocking all USB transfers, blocking FTP uploads, or blocking screenshots. Content-aware blocking adds a fourth dimension: the identity and substance of the data itself. A standard policy can block all outbound email attachments; a content-aware policy blocks only those attachments whose content matches a registered fingerprint, hash, label, or thesaurus pattern — everything else passes through normally.

Content-aware blocking — triggered by digital fingerprints, file hashes, sensitivity labels, or thesaurus term matches — requires the Premium plan. Basic blocking policies (protocol-based, device-based, process-based) are available from the Advanced plan. The exact feature set for your deployment is confirmed during the demo.

Anexet is deployed on-premise; the vendor has no access to your data. All interception, content analysis, and blocking decisions happen on your infrastructure, inside your network perimeter. No intercepted content, no fingerprint library, and no policy configuration is transmitted to Scinero or any external service.

No. Because Anexet runs entirely on-premise, the fingerprint library you build, the analysis objects you configure, and the intercepted data that triggers a block all remain within your environment. Scinero Software Limited has no access to your systems, your data, or your security configurations.

Content-aware blocking applies across all channels that Anexet intercepts and for which a blocking policy can be created: outbound email (SMTP, MAPI), web traffic (HTTP/HTTPS), FTP, XMPP, instant messengers (desktop and web), cloud storage (desktop and web), network shares, USB and external devices, clipboard transfers, and print jobs. The specific channel coverage in your environment is confirmed during the demo.

Renaming the file or changing its extension does not affect fingerprint-based or hash-based blocking. The fingerprint is derived from the document's content structure, not its filename; the hash is a function of the file's binary content. Thesaurus-based blocking evaluates the text content of the transfer, also independent of the filename. Sensitivity-label-based blocking reads metadata embedded in the file by the classification system.

For most channels, the transfer is cancelled at the point of interception — the file is not sent. For SMTP email specifically, Anexet's Mail Quarantine module (available from Advanced) can intercept blocked emails and hold them for review, allowing the security officer to release or permanently block the message. Every blocked event is logged in the Client Console regardless of channel.

Three professionals collaborating and looking at a tablet in a meeting

Stop Data Leaving Through Any Channel

Tell us what sensitive data you need to protect and which channels concern you most — we'll map it to the right plan and arrange a demo or a free trial of Anexet Ultimate.

I accept that my personal data can be processed in accordance with the Privacy Policy