Find the sensitive data on your company devices.
EmberHound searches files, documents, and images for personal and card data - then shows your team where it lives, what presents the greatest risk, and what to fix first. Raw files stay on the device.
- Windows, macOS, and Linux
- On-device scanning
- Raw files are never uploaded
- Encrypted in transit and at rest
See where personal data is stored
Names, national ID numbers, and health data in files across enrolled company devices.
Look up a person by the identifiers you hold
Search enrolled devices by email, phone, name, or national ID, then export a disclosure pack.
Included with GDPR Data Discovery
Find card data stored where it shouldn't be
Detect card numbers, security codes, and expiry dates on the device, mapped to PCI DSS Requirement 3.
Search for both in one pass
One agent, one scan, covering personal data and cardholder data together.
Assess and govern the AI systems you use
Register each AI system, work through a guided EU AI Act assessment, and manage what follows.
Pricing on request
Try it on one device first
Deploy through the MDM you already run. Scanning happens locally, so raw file content never leaves the machine.
The problem
Sensitive data ends up in places nobody remembers.
An export made for one report. A spreadsheet emailed to a supplier. A scanned passport saved to the desktop for a Tuesday-afternoon task in 2023. Employee downloads, archives, attachments, and scanned documents leave copies on company devices long after the reason for them has gone.
EmberHound finds those copies and turns them into a list you can work through.
Copies outlive their purpose
The export that was needed for one report is still in Downloads three years later, on a laptop nobody has looked at since.
Nobody owns the search
When a request arrives, somebody has to go looking by hand, device by device, with no way to tell when they're done.
You can only act on what you can see
Deciding what to delete, move, or protect needs a list of real files with real locations, not an estimate.
What EmberHound does
Three things, done properly.
Find forgotten sensitive files
Discover personal and card data in documents, downloads, exports, archives, PDFs, and images across enrolled company devices.
Investigate a person across your estate
Search known identifiers - email, phone, name, date of birth, address, IBAN, or national ID - to locate related information when a request arrives.
Understand and reduce exposure
See which devices and files carry the most, prioritise what to deal with first, and track whether exposure is falling between scans.
How it works
From agent install to exported evidence.
Six steps. The line under each one is the screen you land on.
- 01
Deploy the endpoint agent
Push it through your existing MDM, or hand somebody an enrolment code. No firewall changes.
Devices - enrolment status
- 02
Choose what to search for
Pick a policy - personal data, card data, or both - and set which locations are in scope.
Policies - rule packs and scope
- 03
Scan locally
Matching happens on the device. Only masked previews and the metadata needed to act on a finding are sent back.
Scans - live progress, files scanned
- 04
Review by data type, device, and risk
Findings arrive deduplicated by fingerprint and grouped, each with a confidence score.
Findings - grouped list, masked preview
- 05
Investigate or assign
Search by subject identifier, or route a finding to somebody with a status and a due date.
DSAR search - remediation queue
- 06
Export evidence when you need it
Produce a PDF or CSV pack from the findings themselves, with the scan history and audit trail behind it.
Reports - evidence pack, audit log
What teams use it for
Compliance work, described as work.
Every one of these starts as data discovery. The regulation is what the output gets used for.
Find out what you're holding
Run a first scan across a sample of devices and get a real inventory of sensitive files, by data type and by location.
Locate information for a subject request
Search by the identifiers you've been given, review confidence-scored matches, and assemble the response from what the scan found.
Map where personal data lives
Turn findings into a record of what you hold and where it sits, rather than a spreadsheet somebody maintains by hand.
Find stored card data
Detect PAN, CVV, and track data at rest on endpoints, so you know what is actually inside your cardholder data environment.
Watch exposure change between scans
Scan history shows whether the number of exposed files on a device is going up or down after your team acts on it.
Show an auditor what you found
Export the findings, the scan history, and the actions taken - generated from scan results rather than assembled by hand.
Mailbox scanning, OCR for image-based documents, and cloud or external drive scanning are available as add-ons. Ask us about add-on coverage.

Security by design
Search sensitive data without collecting the underlying files.
EmberHound handles the data you least want moved. Scanning runs on the endpoint, and only masked findings and the metadata needed to act on them leave the device.
- File scanning and pattern matching happen on the endpoint. The platform never reads your file system.
- Findings carry a masked preview and a fingerprint hash, not the file content.
- Encrypted in transit and at rest.
- Strict tenant isolation, enforced in the database as well as the application.
- Every action is written to an audit log your team can read.
Read the Trust Centre for the architecture, sub-processors, and data-handling detail.
Two jobs, one platform
Practical tools for lean teams.
Find sensitive data, understand your AI use, and manage what needs attention.
Data discovery
Find sensitive personal and card data
Search files, documents, and images on enrolled company devices, see which of them present the greatest risk, and work the list down.
How data discovery worksAI Act Workspace
Assess and govern the AI systems you use
Register each AI system, complete a guided EU AI Act assessment, and manage the obligations, evidence, and decisions that follow.
See the AI Act WorkspaceFrequently asked questions
The short answers. Full details - including GDPR, PCI, security, and pricing - live on the FAQ page.
EmberHound is a data discovery platform for lean IT teams, with full GDPR and PCI DSS coverage. It scans endpoints to find personal and cardholder data wherever it has ended up (mailbox scanning available as an add-on), maps your exposure, and produces audit-ready evidence - so you find regulated data before a regulator or data subject does.
Read in fullLightweight agents run scans locally on each device, so file contents never leave the endpoint. The agent reports back only hashed identifiers, redacted snippets, and metadata, which are aggregated into a fleet-wide view in the portal.
Read in fullYes. When a request comes in, EmberHound hashes the subject's identifiers and matches them against findings across your fleet, so you can locate every place that subject's data lives and respond inside the 30-day clock with audit-ready evidence.
Read in fullAll scanning happens on the endpoint. The portal stores only metadata: file paths, hashed subject identifiers, redacted match snippets, and remediation status. Raw file contents are never uploaded.
Read in fullYes - paid plans start with a 14-day trial. A Free plan is also available indefinitely for very small teams (1 seat, 1 asset) and includes the full feature set for evaluation.
Read in fullStart here
Start with one device and see what comes back.
The free plan covers one device and one user. Install the agent, run a scan, and look at the findings before you decide anything else.
No card details required. Upgrade when you need more devices.





