Digital Fingerprinting & Hash Data Matching

Match intercepted files against registered document fingerprints and hash banks, then alert or block exact copies before they leave your network. Available on the Premium plan.

Schedule a Demo
Anexet Client Console showing matched fingerprint incidents

The Gap That Keywords Cannot Close

Keyword search catches what employees type — it misses the original file sent without changing a word, the most damaging leak scenario of all.

Keyword and thesaurus search catches what employees type. It misses the most damaging leak scenario: someone exfiltrates the original file — a CAD drawing, a signed contract, a source code archive — without changing a single word. The document looks clean to a content scanner, yet it is exactly the file you wanted to protect.

Anexet solves this through two complementary file-identity methods. Digital fingerprinting computes a structural signature from a registered document and compares intercepted content against it — catching reformatted, renamed, or partially altered derivatives of that document (near-duplicate detection). Hash banks work differently: they store the exact cryptographic hash of each registered file and flag only byte-identical copies.

Together, the two methods cover the spectrum from exact copy to substantially derived from the original. Whether the file is sent by email, uploaded to a cloud drive, or copied to USB — if it matches a fingerprint or a hash, the policy fires before the transfer completes.

Why it matters

  • Beyond keyword search

    Catches the original file sent intact — renamed, reformatted, or archived — that content scanners miss entirely.

  • Two methods, full spectrum

    Fingerprints detect near-duplicates and derived versions; hash banks flag byte-identical exact copies across thousands of files at once.

  • Deterministic evidence

    A hash match is unambiguous — the file either matches or it does not — making incident records usable in formal investigations and legal proceedings.

Document Protection Capabilities

Digital fingerprinting and hash bank matching are Premium capabilities within the Complex Search and Blocking Policies modules.

Fingerprinting & hash matching

  • Document fingerprints

    Premium

    Structural signatures computed from registered confidential documents; detect derived or partially altered versions (near-duplicate matching) against intercepted content.

  • Hash banks

    Premium

    Collections of cryptographic hashes for entire file sets — document libraries, source repositories, archive contents. A single bank can cover thousands of files.

  • Hash-sum search

    Premium

    Query the Complex Search module by hash, retrieving every interception event where the matching file appeared — across channels and users.

  • File-bank matching

    Premium

    Incoming and outgoing files are compared against registered hash banks; matches are flagged as incidents in the Client Console.

Policies & labels

  • Confidentiality labels

    Premium

    Sensitivity markers attached to documents are carried through the interception pipeline and can trigger blocking policies independently or in combination with fingerprint matches.

  • Content-aware blocking by fingerprint/hash

    Premium

    When a Blocking Policy references a fingerprint or hash bank, Anexet blocks the transfer at the channel level — HTTP, SMTP, MAPI, FTP, XMPP, messengers, USB, print, clipboard — before data leaves the endpoint.

All capabilities above are Premium-only. Basic full-text and data-type search is available from Standard. Thesaurus search and keyword-based blocking are available from Advanced.

How Fingerprinting Protects Documents

Endpoint agents on Windows, Linux, and macOS capture outgoing data on all monitored channels. As data passes through the interception layer, two checks run in parallel: the fingerprint engine computes a structural signature of the intercepted content and compares it against registered fingerprint sets (catching reformatted or partially quoted derivatives), while the hash engine computes the exact cryptographic hash and compares it against registered hash banks (catching byte-identical exact copies). Matches from either method surface instantly in the Client Console as flagged incidents, with channel, user, timestamp, and matched document identity.

Anexet is deployed on-premise. The fingerprint registry, hash banks, and all intercepted content reside entirely on your own infrastructure — the vendor has no access to your data. Original files are never sent to Scinero Software Limited or any third party.

Fingerprint incident flagged in the Anexet Client Console
User activity timeline tied to a hash-matched file transfer

How Digital Fingerprinting Works

Four steps from registering a protected document to blocking its exfiltration.

Register protected documents: the security officer uploads confidential files to the Administrator Console; Anexet computes and stores a fingerprint and hash for each file — originals never leave your server.

1

Endpoint agents on Windows, Linux, and macOS intercept outgoing data across all channels — email, web, FTP, messengers, cloud storage, USB, printers, and clipboard.

2

As data passes through the interception layer, fingerprint and hash checks run in parallel; matches surface instantly in the Client Console with channel, user, timestamp, and matched document identity.

3

If a Blocking Policy references the matched fingerprint or hash bank, the transfer is blocked before completion; the incident record — with full evidence — is preserved for investigations and legal proceedings.

4

Register protected documents: the security officer uploads confidential files to the Administrator Console; Anexet computes and stores a fingerprint and hash for each file — originals never leave your server.

1

Endpoint agents on Windows, Linux, and macOS intercept outgoing data across all channels — email, web, FTP, messengers, cloud storage, USB, printers, and clipboard.

2

As data passes through the interception layer, fingerprint and hash checks run in parallel; matches surface instantly in the Client Console with channel, user, timestamp, and matched document identity.

3

If a Blocking Policy references the matched fingerprint or hash bank, the transfer is blocked before completion; the incident record — with full evidence — is preserved for investigations and legal proceedings.

4

Arrow

Digital Fingerprinting by Plan

StandardCore employee activity monitoring.
Network traffic interception
USB control
Printers monitoring
Messengers interception
Browsers interception
and 4 more
Includes:
Anexet Activity
Most popular
AdvancedAdds DLP and deeper visibility.
Standard plan included
DLP features
Network shares monitoring
Keylogger
Webcam pictures
and 4 more
Includes:
Anexet DLP
Anexet Activity
All-in-one
PremiumAll-in-one solution.
Standard + Advanced plans included
Advanced search (digital fingerprints, hash search)
File systems monitoring
User relations analysis
Risk analysis
and 6 more
Includes:
Anexet DLP
Anexet Inventory
Anexet Activity
Anexet Ultimate

Frequently Asked Questions

Common questions about digital fingerprinting, hash banks, and document protection in Anexet.

What is digital fingerprinting in data protection?

Digital fingerprinting creates a structural signature of a document that captures its content characteristics — not a simple cryptographic hash, but a representation that supports similarity matching. In a DLP context, the system registers fingerprints of protected files and then compares every intercepted file against those fingerprints, flagging derived or partially altered versions of the original (near-duplicate detection). If the intercepted content matches, a policy can alert or block the transfer — regardless of filename or metadata. In Anexet, this is a Premium capability within the Complex Search and Blocking Policies modules. Hash banks complement fingerprints by catching byte-identical exact copies using cryptographic hashing.

A fingerprint covers one specific document. A hash bank is a collection of hashes — you can register an entire document library, source code repository, or archive, and the system matches against any file in that collection. Hash banks make it practical to protect hundreds or thousands of files simultaneously without creating a separate policy for each one.

All channels that Anexet intercepts: email (SMTP, MAPI, IMAP, POP3), web traffic (HTTP), FTP, desktop and web messengers, desktop and web cloud storage, USB and external devices, network and local printers, and clipboard. Blocking fires at the endpoint before data leaves the device.

Digital fingerprints, hash banks, hash-sum search, and blocking by fingerprint, hash, or label are Premium-only. Standard includes interception and full-text search; Advanced adds thesaurus search and keyword-based blocking policies.

Yes. Anexet is deployed on-premise; the vendor has no access to your data. The fingerprint registry, hash banks, and all intercepted content reside entirely on your own infrastructure. No data is sent to Scinero Software Limited or any third party.

Three professionals collaborating and looking at a tablet in a meeting

Protect Your Most Sensitive Documents

Tell us about the document libraries and file types you need to protect — we'll map fingerprinting and hash bank coverage to your environment and arrange a demo or a free trial of Anexet Ultimate.

I accept that my personal data can be processed in accordance with the Privacy Policy