Everything you need to know about EmberHound
How on-device scanning works, what we do (and don't) collect, how we handle GDPR and PCI obligations, and what onboarding looks like.
Product
What is EmberHound?
EmberHound is a data discovery platform for lean IT teams, with full GDPR and PCI DSS coverage. It scans endpoints to find personal and cardholder data wherever it has ended up (mailbox scanning available as an add-on), maps your exposure, and produces audit-ready evidence - so you find regulated data before a regulator or data subject does.
How does the scanning work?
Lightweight agents run scans locally on each device, so file contents never leave the endpoint. The agent reports back only hashed identifiers, redacted snippets, and metadata, which are aggregated into a fleet-wide view in the portal.
Which operating systems does the agent support?
Windows, macOS, and Linux. Agents are signed, can be installed manually or pushed via MDM (Intune, Jamf), and self-update against a published version contract.
Who is EmberHound built for?
Lean IT and compliance teams at small-to-mid-sized companies that have GDPR or PCI obligations but no dedicated DLP team. If you're the person who will answer the next DSAR or PCI scoping question, EmberHound is built for you.
GDPR & PCI Compliance
Does EmberHound help with GDPR Article 15 DSARs?
Yes. When a request comes in, EmberHound hashes the subject's identifiers and matches them against findings across your fleet, so you can locate every place that subject's data lives and respond inside the 30-day clock with audit-ready evidence.
Does EmberHound support GDPR Article 17 (right to erasure)?
Yes, on plans where the Article 17 capability is enabled. The portal tracks erasure requests, links them to located data, and records the action taken so you have an auditable trail of compliance.
Is EmberHound a PCI DSS 4.0 compliant scanner?
EmberHound helps you meet PCI DSS 4.0 requirements around discovering cardholder data outside of approved storage (Req 3) and producing the audit logs auditors expect (Req 10.7). It is not a replacement for a QSA assessment, but it is the evidence layer underneath one.
What kinds of personal data does it detect?
Out of the box: names, emails, phone numbers, national identifiers, payment card numbers (PAN), bank details, and country-specific identifiers via rule packs. Customers on higher plans can add custom rule packs for industry-specific data types.
Can I export evidence for an audit?
Yes. Every plan includes audit-ready evidence packs - PDF and CSV exports of findings, control coverage, and remediation status - that you can hand directly to an auditor or paste into a SOC 2 or ISO control narrative.
How does EmberHound find a data subject's data across our devices?
EmberHound hashes the subject's identifiers and matches them against findings from every enrolled device, then clusters the results by where the data actually sits. You get one view of everywhere that person's data has ended up, instead of searching each machine by hand.
How long do we have to answer a DSAR, and does EmberHound help us hit the deadline?
You have one month from receiving a request. Each request in the portal carries a due date and the queue puts the closest deadlines first, so you can see what needs attention and respond in time.
Does EmberHound support data portability and rectification requests?
Yes. Alongside access and erasure, the portal handles rectification requests and lets you export a portable, machine-readable format for the data covered by Article 20 - what the subject provided you and you process by consent or under a contract, by automated means - on plans where those capabilities are enabled.
Does EmberHound help with our Article 30 ROPA?
Yes. EmberHound includes an Article 30 Record of Processing Activities with a set of worked example records you can load and adapt, a straightforward draft-to-sign-off review cycle, and a coverage summary so you can see what still needs attention.
How does keeping a ROPA make DSARs easier to answer?
An access response has to state the purposes of processing, who the data is shared with, and how long you keep it. Those are the same facts you record in your ROPA, so a current register makes each DSAR answer quicker and more consistent.
Security & Data Handling
Where is my data stored?
All scanning happens on the endpoint. The portal stores only metadata: file paths, hashed subject identifiers, redacted match snippets, and remediation status. Raw file contents are never uploaded.
How is the data the portal does store protected?
Tenant data is stored in Supabase (Postgres) with row-level security enforcing strict tenant isolation, encrypted at rest and in transit with TLS 1.3 and AES-256. Per-tenant cryptographic peppers used for DSAR identifier hashing live in Supabase Vault and are never exported to logs or environment variables.
Can EmberHound staff see my findings?
No. Platform staff have no cross-tenant read access to tenant-facing tables - this is enforced at the database level by row-level security, not just by application code. Support sessions require explicit per-incident impersonation that is fully audit-logged.
Is the scanning agent open about what it does?
Yes. The agent's API contract is published, it only sends hashed and redacted data, and every scan emits an audit event the customer can review in the portal.
Pricing & Onboarding
How does pricing work?
Plans are seat- and asset-based with a free tier for evaluation. Paid plans bundle a number of included seats and assets, with transparent overage pricing for anything beyond. Full details and a calculator live on the Pricing page.
Is there a free trial?
Yes - paid plans start with a 14-day trial. A Free plan is also available indefinitely for very small teams (1 seat, 1 asset) and includes the full feature set for evaluation.
How long does onboarding take?
Sign up, generate an enrollment code, install the agent, and run your first scan - no professional services or lengthy setup required. Larger rollouts deploy via your existing MDM alongside your other endpoint tooling.
Do you offer annual billing or volume discounts?
Yes. Annual billing is available on all paid plans, and founding-customer offers with discounted pricing are available for teams that sign up during the launch window. Contact us for volume pricing.
Still have questions?
Our team is happy to walk you through the platform or talk through your specific compliance scenario.