S
Stitex
CorpShield · insider leak prevention

Your data won't walk out with an employee

Protects your client base, trade secrets and personal data from theft and leaks. AI watches for anomalies, every access gets logged, and we handle the trade secret paperwork end to end — so the thief can be stopped and held accountable.

AI anomaly detectorTurnkey in 2–4 weeksHolds up in court
8 of 10
people who quit try to walk out with confidential company data
95.6%
of leaks are deliberate, not accidental
~$135K
average cost to a company from a single data leak
up to 4% of turnover
revenue-based fine for a repeat personal-data leak, in force since 2025

Based on industry information-security market research.

The biggest threat to your data isn't a hacker — it's your own employee

Almost every leak is deliberate, and most are the work of current or former employees rather than outside attackers. People steal on purpose — for money, to work for a competitor, or out of spite when they leave.

A sales rep leaves — and takes the client base

The client base is what gets stolen most often. It's not just a contact list — it's your revenue, months of deal work, and the money spent acquiring those leads. It often surfaces at a competitor within a week of the resignation.

Punishing the thief is nearly impossible

Most companies just fire the thief without going to court: there's nothing to prove it with, and without a formally established trade-secret regime, courts throw the case out — a mention in the employment contract isn't enough.

The decision to steal happens on impulse

In most cases the decision to walk off with the data is made days before the person leaves. An employee who was loyal yesterday can be exporting the base today — there's no human way to predict it, you need automatic monitoring.

How data gets stolen most often
Exporting customers from CRM or 1C to Excel on a personal laptop
Photographing the screen with a phone — bypasses copy and print restrictions
Forwarding files through messengers and to a personal email
USB drives and removable disks right before resigning
Access through accounts that weren't revoked after termination
Bulk-downloading the database "just in case" in the final days
The law got tougher

Now both the company and the culprit answer for a leak

Since 2025, fines for leaking personal data have gotten painful, and leaking a database now carries a real criminal charge. Data protection went from "good practice" to a way of not losing tens of millions.

Turnover-based fine up to 4% under GDPR

For a personal-data breach — up to 4% of worldwide annual turnover under GDPR, and comparable penalties in other jurisdictions. The fine is only part of it: the customer base itself walks out of the door.

Criminal liability for leaking a database

Since December 2024 (Art. 272.1 of the Criminal Code), illegal handling of personal data can mean actual prison time. The employee now carries personal risk.

plus penalties for failing to notify in time

Failing to notify Roskomnadzor of a leak within 24 hours triggers a separate fine on top.

No trade secret regime — no case

To hold someone liable under 98-FZ for taking the database, the trade secret regime has to be set up by the book. No regime, no liability for the thief. We set it up for you, turnkey.

Figures are reference points under the current 2026 editions of the Administrative Code, Criminal Code and 98-FZ; exact amounts and classification depend on the circumstances. A lawyer should confirm applicability to your specific case.

What CorpShield does

Sees who's taking data out, and how — and stops it

Not blanket surveillance — targeted protection of what matters most: databases, documents, access. Everything that takes an expensive system and a security team at a large corporation runs here on AI, turnkey.

AI anomaly detection

The system learns each employee's baseline and catches deviations: a rep who normally views 20 records a day suddenly exports 5,000; database access at 3am; bulk downloads right before resignation. At a large corporation this is a whole analyst team's job — here, AI does it.

Access control for databases

Who has access to what, on a least-privilege basis. Limits on bulk exports, monitoring of every request to CRM, 1C, databases and file storage.

Leak channel monitoring

Email, messengers, USB drives, printing, cloud storage, attempts to photograph the screen. Suspicious actions get logged, critical ones get blocked per your rules.

Tamper-proof access log

Who opened or exported what, when, and how much. Logs are stored securely on your side — an evidence base for court, and an audit trail that stands up to data-protection requirements such as GDPR.

Resignation trigger

The moment someone files a resignation or is flagged as at-risk, access tightens automatically and monitoring ramps up — exactly when the odds of theft are highest.

Turnkey legal package

We establish a trade secret regime under 98-FZ (the protected-information list, confidentiality markings, a register of authorized staff, access procedures) and issue the required employee notices. Without this, technical protection has no weight in court — with it, the thief answers under the law.

How we secure workstations

Every workstation, protected

Not a single checkbox but layered protection: devices, media, login, channels and response. We turn on whichever layers you need — from basic USB control to encrypted "authorized-only" drives.

USB and device control

  • Allowlist: only your own USB drives work, identified by serial number
  • An outside drive brought from home simply won't read on a work PC
  • Control over USB, Bluetooth, card readers, phones used as storage, CD/DVD

Encrypted "authorized-only" drives

  • Anything written to a corporate USB drive is encrypted automatically
  • Outside the company perimeter, the files are unreadable garbage — the key never leaves
  • PIN-protected drives that wipe themselves if someone tries to brute-force the password

Hardware-token login instead of a password

  • Two-factor login to workstations, accounting software and CRM via hardware security key (FIDO2, PKCS#11)
  • Pull the token out of the port and the session locks instantly
  • Fire someone, revoke the token, and their old access is dead instantly

Antivirus and ransomware protection

  • Antivirus and anti-malware on every workstation
  • Protection from ransomware that encrypts files and demands payment
  • Only trusted programs are allowed to run — nothing else starts, viruses included

Catching data leaving — even via a photo of the screen

  • A neural network catches someone photographing the screen with a phone — in a fraction of a second
  • An invisible watermark in documents: the source of a leak can be traced even from a photo of a printout
  • Monitoring of screen sharing in video calls (Zoom, SberJazz, Telemost)

Trails, response, investigation

  • Shadow copying: we keep an exact copy of everything taken out — for court
  • Remote lock and wipe if a laptop is stolen or an employee leaves
  • Profiles, connection graphs and risk scoring: who's at risk and who they're connected to

We use hardware security keys and tokens (FIDO2, PKCS#11 and equivalents) and select the set that fits your needs and budget. Full scope is defined during the free audit.

Why not just "buy an off-the-shelf DLP"

The market splits in two: heavy enterprise DLP is expensive and takes months, while employee-monitoring software doesn't actually protect against leaks. CorpShield closes that gap for mid-size business.

Enterprise DLP
heavy enterprise systems
Employee monitoring
productivity time-trackers
Stitex CorpShield
Data leak protectionyesno — time tracking onlyyes
Who it's forlarge enterpriseanyone, but it isn't protectionmid-size business
Rolloutmonths (sometimes 10)fastturnkey, 2–4 weeks
Who reviews the alertsyour security teamAI + our support
Legal packageon younoneturnkey trade secret regime
Pricequote-only, from hundreds of thousandscheap, but not about leakstransparent, scaled to headcount

Who this is critical for

Sales teams

The client base, pipeline, deal terms — the top target when a rep walks out

IT and development

Source code and credentials people take to a competitor or their own startup

Finance and accounting

Payment data, contracts, cost structure, management reporting

Companies holding customer PII

Banks, healthcare, retail, services — exposed to revenue-based fines up to 500M ₽

Manufacturing and engineering

Process know-how, drawings, formulas — the plant's trade secrets

Mid-size business without an in-house security team

For companies where enterprise DLP is overkill and overpriced, but protection is needed now

Pricing

Transparent, scaled to your headcount

Price per workstation plus a one-time turnkey rollout fee. A fraction of what corporate systems cost, and unlike them, you know the number upfront. Final quote is based on headcount and the modules you need.

Start

basic control
from $7 /mo per workstation
rollout from $1,100
  • USB and port control, blocking of unauthorized drives
  • Antivirus and ransomware protection
  • Access log for databases and files
  • Reports and violation alerts
Get a quote

Business

most popular
from $15 /mo per workstation
rollout from $2,300
  • Everything in Start
  • AI anomaly detector and employee risk scoring
  • Channel control: email, messengers, printing, cloud storage
  • Shadow copying and resignation trigger
  • Turnkey trade secret regime
Get a quote

Maximum

full protection
from $25 /mo per workstation
rollout from $4,700
  • Everything in Business
  • Encrypted "authorized-only" USB drives + full drive encryption
  • Watermarking and remote lock/wipe
  • Deployment on an isolated server
  • Priority support
Get a quote

Integrations with 1C, CRM and Active Directory — from $600. Prices are indicative and depend on headcount and requirements; deploying on your own server lowers the monthly fee. We calculate the exact quote after the free audit.

How we roll it out — turnkey

You don't need your own security team. We handle the setup, the legal paperwork, and the first round of alert triage.

1

Audit

We map where your critical data lives, who has access to it, and which channels it could leak through

2

Install and configure

We deploy inside your environment and tune the rules and anomaly thresholds to your processes — we do this, not you

3

Legal package

We establish the trade secret regime and issue the notices, so the protection holds up in court

4

Ongoing support

For the first stretch we review alerts together with you, train your team, and hand it over

Need maximum secrecy? CorpShield can run on your own isolated server — so logs and data never leave the company, even in theory.

Frequently asked questions

Classic DLP are heavy enterprise-grade systems: rollout drags on for months (10-month cases are known), you need an in-house security team to tune hundreds of policies and manually triage thousands of alerts a day, and pricing is "on request", from hundreds of thousands to millions. CorpShield does the same thing at its core — catches leaks — but turnkey and for mid-sized business: we configure it, AI finds the anomalies instead of a staff of analysts, and the price is transparent.

Find out where your data is leaking

We'll run a free audit: show you who has access to your database, which channels it could leak through, and what a leak would cost the company. No obligations.

Contact

See it in a live demo

Tell us what needs protecting — we will show the system on a live stand and quote for your headcount.

Telegram
@StitexBot
Response time
Within one business day