Your data won't walk out with an employee
Protects your client base, trade secrets and personal data from theft and leaks. AI watches for anomalies, every access gets logged, and we handle the trade secret paperwork end to end — so the thief can be stopped and held accountable.
Based on industry information-security market research.
The biggest threat to your data isn't a hacker — it's your own employee
Almost every leak is deliberate, and most are the work of current or former employees rather than outside attackers. People steal on purpose — for money, to work for a competitor, or out of spite when they leave.
A sales rep leaves — and takes the client base
The client base is what gets stolen most often. It's not just a contact list — it's your revenue, months of deal work, and the money spent acquiring those leads. It often surfaces at a competitor within a week of the resignation.
Punishing the thief is nearly impossible
Most companies just fire the thief without going to court: there's nothing to prove it with, and without a formally established trade-secret regime, courts throw the case out — a mention in the employment contract isn't enough.
The decision to steal happens on impulse
In most cases the decision to walk off with the data is made days before the person leaves. An employee who was loyal yesterday can be exporting the base today — there's no human way to predict it, you need automatic monitoring.
Now both the company and the culprit answer for a leak
Since 2025, fines for leaking personal data have gotten painful, and leaking a database now carries a real criminal charge. Data protection went from "good practice" to a way of not losing tens of millions.
Turnover-based fine up to 4% under GDPR
For a personal-data breach — up to 4% of worldwide annual turnover under GDPR, and comparable penalties in other jurisdictions. The fine is only part of it: the customer base itself walks out of the door.
Criminal liability for leaking a database
Since December 2024 (Art. 272.1 of the Criminal Code), illegal handling of personal data can mean actual prison time. The employee now carries personal risk.
plus penalties for failing to notify in time
Failing to notify Roskomnadzor of a leak within 24 hours triggers a separate fine on top.
No trade secret regime — no case
To hold someone liable under 98-FZ for taking the database, the trade secret regime has to be set up by the book. No regime, no liability for the thief. We set it up for you, turnkey.
Figures are reference points under the current 2026 editions of the Administrative Code, Criminal Code and 98-FZ; exact amounts and classification depend on the circumstances. A lawyer should confirm applicability to your specific case.
Sees who's taking data out, and how — and stops it
Not blanket surveillance — targeted protection of what matters most: databases, documents, access. Everything that takes an expensive system and a security team at a large corporation runs here on AI, turnkey.
AI anomaly detection
The system learns each employee's baseline and catches deviations: a rep who normally views 20 records a day suddenly exports 5,000; database access at 3am; bulk downloads right before resignation. At a large corporation this is a whole analyst team's job — here, AI does it.
Access control for databases
Who has access to what, on a least-privilege basis. Limits on bulk exports, monitoring of every request to CRM, 1C, databases and file storage.
Leak channel monitoring
Email, messengers, USB drives, printing, cloud storage, attempts to photograph the screen. Suspicious actions get logged, critical ones get blocked per your rules.
Tamper-proof access log
Who opened or exported what, when, and how much. Logs are stored securely on your side — an evidence base for court, and an audit trail that stands up to data-protection requirements such as GDPR.
Resignation trigger
The moment someone files a resignation or is flagged as at-risk, access tightens automatically and monitoring ramps up — exactly when the odds of theft are highest.
Turnkey legal package
We establish a trade secret regime under 98-FZ (the protected-information list, confidentiality markings, a register of authorized staff, access procedures) and issue the required employee notices. Without this, technical protection has no weight in court — with it, the thief answers under the law.
Every workstation, protected
Not a single checkbox but layered protection: devices, media, login, channels and response. We turn on whichever layers you need — from basic USB control to encrypted "authorized-only" drives.
USB and device control
- •Allowlist: only your own USB drives work, identified by serial number
- •An outside drive brought from home simply won't read on a work PC
- •Control over USB, Bluetooth, card readers, phones used as storage, CD/DVD
Encrypted "authorized-only" drives
- •Anything written to a corporate USB drive is encrypted automatically
- •Outside the company perimeter, the files are unreadable garbage — the key never leaves
- •PIN-protected drives that wipe themselves if someone tries to brute-force the password
Hardware-token login instead of a password
- •Two-factor login to workstations, accounting software and CRM via hardware security key (FIDO2, PKCS#11)
- •Pull the token out of the port and the session locks instantly
- •Fire someone, revoke the token, and their old access is dead instantly
Antivirus and ransomware protection
- •Antivirus and anti-malware on every workstation
- •Protection from ransomware that encrypts files and demands payment
- •Only trusted programs are allowed to run — nothing else starts, viruses included
Catching data leaving — even via a photo of the screen
- •A neural network catches someone photographing the screen with a phone — in a fraction of a second
- •An invisible watermark in documents: the source of a leak can be traced even from a photo of a printout
- •Monitoring of screen sharing in video calls (Zoom, SberJazz, Telemost)
Trails, response, investigation
- •Shadow copying: we keep an exact copy of everything taken out — for court
- •Remote lock and wipe if a laptop is stolen or an employee leaves
- •Profiles, connection graphs and risk scoring: who's at risk and who they're connected to
We use hardware security keys and tokens (FIDO2, PKCS#11 and equivalents) and select the set that fits your needs and budget. Full scope is defined during the free audit.
Why not just "buy an off-the-shelf DLP"
The market splits in two: heavy enterprise DLP is expensive and takes months, while employee-monitoring software doesn't actually protect against leaks. CorpShield closes that gap for mid-size business.
| Enterprise DLP heavy enterprise systems | Employee monitoring productivity time-trackers | Stitex CorpShield | |
|---|---|---|---|
| Data leak protection | yes | no — time tracking only | yes |
| Who it's for | large enterprise | anyone, but it isn't protection | mid-size business |
| Rollout | months (sometimes 10) | fast | turnkey, 2–4 weeks |
| Who reviews the alerts | your security team | — | AI + our support |
| Legal package | on you | none | turnkey trade secret regime |
| Price | quote-only, from hundreds of thousands | cheap, but not about leaks | transparent, scaled to headcount |
Who this is critical for
Sales teams
The client base, pipeline, deal terms — the top target when a rep walks out
IT and development
Source code and credentials people take to a competitor or their own startup
Finance and accounting
Payment data, contracts, cost structure, management reporting
Companies holding customer PII
Banks, healthcare, retail, services — exposed to revenue-based fines up to 500M ₽
Manufacturing and engineering
Process know-how, drawings, formulas — the plant's trade secrets
Mid-size business without an in-house security team
For companies where enterprise DLP is overkill and overpriced, but protection is needed now
Transparent, scaled to your headcount
Price per workstation plus a one-time turnkey rollout fee. A fraction of what corporate systems cost, and unlike them, you know the number upfront. Final quote is based on headcount and the modules you need.
Start
basic control- ✓USB and port control, blocking of unauthorized drives
- ✓Antivirus and ransomware protection
- ✓Access log for databases and files
- ✓Reports and violation alerts
Business
most popular- ✓Everything in Start
- ✓AI anomaly detector and employee risk scoring
- ✓Channel control: email, messengers, printing, cloud storage
- ✓Shadow copying and resignation trigger
- ✓Turnkey trade secret regime
Maximum
full protection- ✓Everything in Business
- ✓Encrypted "authorized-only" USB drives + full drive encryption
- ✓Watermarking and remote lock/wipe
- ✓Deployment on an isolated server
- ✓Priority support
Integrations with 1C, CRM and Active Directory — from $600. Prices are indicative and depend on headcount and requirements; deploying on your own server lowers the monthly fee. We calculate the exact quote after the free audit.
How we roll it out — turnkey
You don't need your own security team. We handle the setup, the legal paperwork, and the first round of alert triage.
Audit
We map where your critical data lives, who has access to it, and which channels it could leak through
Install and configure
We deploy inside your environment and tune the rules and anomaly thresholds to your processes — we do this, not you
Legal package
We establish the trade secret regime and issue the notices, so the protection holds up in court
Ongoing support
For the first stretch we review alerts together with you, train your team, and hand it over
Need maximum secrecy? CorpShield can run on your own isolated server — so logs and data never leave the company, even in theory.
Frequently asked questions
Related reading
How to protect your data from leaks — read our blog
How to Protect Your Customer Database From Employees
Most customer-base leaks come from people who already have legitimate access. Three layers that work together: least-privilege access, anomaly detection and a trade-secret regime.
How to Detect Data Theft Before an Employee Resigns
A leak before resignation shows up as a pattern, not one download: bulk exports, access outside someone’s scope, forwarding to personal mail. What to watch for and what to do.
DLP for Mid-Sized Business Without a Security Team
Enterprise DLP is built for teams with a security staff. Mid-sized companies need a lighter stack: access control, AI anomaly detection, and a trade-secret regime, turnkey.
Find out where your data is leaking
We'll run a free audit: show you who has access to your database, which channels it could leak through, and what a leak would cost the company. No obligations.