Find the sensitive data on your company devices.

EmberHound searches files, documents, and images for personal and card data - then shows your team where it lives, what presents the greatest risk, and what to fix first. Raw files stay on the device.

  • Windows, macOS, and Linux
  • On-device scanning
  • Raw files are never uploaded
  • Encrypted in transit and at rest
Personal data discovery

See where personal data is stored

Names, national ID numbers, and health data in files across enrolled company devices.

Subject requests

Look up a person by the identifiers you hold

Search enrolled devices by email, phone, name, or national ID, then export a disclosure pack.

Included with GDPR Data Discovery

Card data discovery

Find card data stored where it shouldn't be

Detect card numbers, security codes, and expiry dates on the device, mapped to PCI DSS Requirement 3.

Personal and card data

Search for both in one pass

One agent, one scan, covering personal data and cardholder data together.

AI Act Workspace

Assess and govern the AI systems you use

Register each AI system, work through a guided EU AI Act assessment, and manage what follows.

Pricing on request

Start here

Try it on one device first

Deploy through the MDM you already run. Scanning happens locally, so raw file content never leaves the machine.

The problem

Sensitive data ends up in places nobody remembers.

An export made for one report. A spreadsheet emailed to a supplier. A scanned passport saved to the desktop for a Tuesday-afternoon task in 2023. Employee downloads, archives, attachments, and scanned documents leave copies on company devices long after the reason for them has gone.

EmberHound finds those copies and turns them into a list you can work through.

Copies outlive their purpose

The export that was needed for one report is still in Downloads three years later, on a laptop nobody has looked at since.

Nobody owns the search

When a request arrives, somebody has to go looking by hand, device by device, with no way to tell when they're done.

You can only act on what you can see

Deciding what to delete, move, or protect needs a list of real files with real locations, not an estimate.

What EmberHound does

Three things, done properly.

Find forgotten sensitive files

Discover personal and card data in documents, downloads, exports, archives, PDFs, and images across enrolled company devices.

Investigate a person across your estate

Search known identifiers - email, phone, name, date of birth, address, IBAN, or national ID - to locate related information when a request arrives.

Understand and reduce exposure

See which devices and files carry the most, prioritise what to deal with first, and track whether exposure is falling between scans.

How it works

From agent install to exported evidence.

Six steps. The line under each one is the screen you land on.

  1. 01

    Deploy the endpoint agent

    Push it through your existing MDM, or hand somebody an enrolment code. No firewall changes.

    Devices - enrolment status

  2. 02

    Choose what to search for

    Pick a policy - personal data, card data, or both - and set which locations are in scope.

    Policies - rule packs and scope

  3. 03

    Scan locally

    Matching happens on the device. Only masked previews and the metadata needed to act on a finding are sent back.

    Scans - live progress, files scanned

  4. 04

    Review by data type, device, and risk

    Findings arrive deduplicated by fingerprint and grouped, each with a confidence score.

    Findings - grouped list, masked preview

  5. 05

    Investigate or assign

    Search by subject identifier, or route a finding to somebody with a status and a due date.

    DSAR search - remediation queue

  6. 06

    Export evidence when you need it

    Produce a PDF or CSV pack from the findings themselves, with the scan history and audit trail behind it.

    Reports - evidence pack, audit log

EmberHound

Security by design

Search sensitive data without collecting the underlying files.

EmberHound handles the data you least want moved. Scanning runs on the endpoint, and only masked findings and the metadata needed to act on them leave the device.

  • File scanning and pattern matching happen on the endpoint. The platform never reads your file system.
  • Findings carry a masked preview and a fingerprint hash, not the file content.
  • Encrypted in transit and at rest.
  • Strict tenant isolation, enforced in the database as well as the application.
  • Every action is written to an audit log your team can read.

Read the Trust Centre for the architecture, sub-processors, and data-handling detail.

Common questions

Frequently asked questions

The short answers. Full details - including GDPR, PCI, security, and pricing - live on the FAQ page.

EmberHound is a data discovery platform for lean IT teams, with full GDPR and PCI DSS coverage. It scans endpoints to find personal and cardholder data wherever it has ended up (mailbox scanning available as an add-on), maps your exposure, and produces audit-ready evidence - so you find regulated data before a regulator or data subject does.

Read in full

Lightweight agents run scans locally on each device, so file contents never leave the endpoint. The agent reports back only hashed identifiers, redacted snippets, and metadata, which are aggregated into a fleet-wide view in the portal.

Read in full

Yes. When a request comes in, EmberHound hashes the subject's identifiers and matches them against findings across your fleet, so you can locate every place that subject's data lives and respond inside the 30-day clock with audit-ready evidence.

Read in full

All scanning happens on the endpoint. The portal stores only metadata: file paths, hashed subject identifiers, redacted match snippets, and remediation status. Raw file contents are never uploaded.

Read in full

Yes - paid plans start with a 14-day trial. A Free plan is also available indefinitely for very small teams (1 seat, 1 asset) and includes the full feature set for evaluation.

Read in full

Start here

Start with one device and see what comes back.

The free plan covers one device and one user. Install the agent, run a scan, and look at the findings before you decide anything else.

No card details required. Upgrade when you need more devices.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy