Featured Article

Phalanx protects company data by automatically securing and tracking sensitive documents

Comment

a laptop, file folders and connected lines between head and torso icons
Image Credits: Bryce Durbin / TechCrunch

Data loss prevention (DLP) has emerged as a foundational strategy for businesses looking to prevent workers from inadvertently (or advertently) sharing sensitive data outside the confines of the company network. At its core, DLP is about solving the “people problem” — humans are often at the center of security lapses, whether it’s through sharing a confidential document with outsiders or pasting database access tokens into a public GitHub repository.

Recent history is littered with high-profile data breaches, leading to all manner of reputational, regulatory, and financial penalties that can be difficult to recover from. And it’s against that backdrop that Virginia-based startup Phalanx is setting out to help, with a lightweight DLP and document-mapping platform that automatically monitors and secures sensitive documents across the likes of Office 365, Google Workspaces, and local machines.

Presenting onstage today as part of the Startup Battlefield at TechCrunch Disrupt, CEO Ian Garrett showcased Phalanx’s technology and laid out the company’s mission at a time when companies might prefer a more “human-friendly” solution to stop their data seeping into the public domain. TechCrunch caught up with Garrett ahead of time for a product demo and to get the lowdown on the scale of the problem as he sees it.

The story so far

Founded in 2021, Arlington-based Techstars alum Phalanx was initially focused on securing AI systems using data, model validation and vulnerability scanning, using work from Garrett’s PhD. However, he says that it was a little ahead of the curve, and companies (and investors) were concerned with more pressing threats.

“When we went out for market validation, what we found across the board was that everyone thought that [what we were doing] was important, and that they would definitely pay for it — but only when enough people were being hit using that attack vector,” Garrett said. “So they were pretty much like ‘thanks, but no thanks.’”

Phalanx founding team: CEO Ian Garrett is center
Phalanx CEO Ian Garrett flanked by CTO Austin Garrett (L) and CMO Carl Kenney (R) Image credits: Phalanx

But their work up to that point was not in vain, as they had substantively been concerned with protecting datasets, leading them down a path to help companies protect their unstructured data stored in documents. And so following a late-2021 pivot, the company’s MUZE (Monitoring Unstructured data with Zero trust Encryption) platform was born, enabling companies to easily encrypt and decrypt files’ track file-related behavior, with Phalanx taking care of the underlying process automatically.

“Phalanx specifically focuses on data security, and within that unstructured data — mostly documents and files,” Garrett said. “Unstructured data is especially hard to protect and manage compared to structured data, such as that stored in databases.”

Unstructured data is so difficult to protect because it isn’t easy for organizations to even know that sensitive data exists within emails or documents, let alone who has access to those documents. And this data is easily spread across locations (physical and digital) with little footprint to show for it.

According to data from Gartner, unstructured data constitutes as much as 90% of new data generated in the enterprise, which gives an idea as to the size of the problem businesses face.

Under the hood

Phalanx allows security teams to stipulate how data and documents are stored — for example, automatically encrypting every file on a two-hour basis, or which file types or directories should be protected.

Enable auto-encryption
Enable auto-encryption. Image credits: Phalanx

Companies can also set expiration dates on shared files so that users don’t accidentally keep dozens of confidential documents stored on their laptop, and they can control the “who and how” of file downloads.

At an individual level, users can be given control over their encryption and decryption endeavors, with a right-click enabling them to access Phalanx and choose to manually encrypt a file and send it to any third party.

Encrypting and decrypting files with Phalanx
Encrypting and decrypting files with Phalanx. Image Credits: Phalanx

They can choose to allow a file to be accessed just the one time, allow anyone with the link to access the file, require email verification, and more.

Phalanx: Sharing secure link
Phalanx: Sharing secure link. Image Credits: Phalanx

There are two broad categories of users who will engage with Phalanx: the security teams in charge of deploying Phalanx and the end user (i.e., employee) who will interact with its features on a daily basis.

On the security team’s side, they have access to Phalanx’s endpoint software, which can be deployed by downloading it from Phalanx’s website, with support for documents stored locally or in the cloud, the latter of which requires a browser extension.

In addition to the endpoint software, Phalanx also serves up a centralized dashboard through the browser where security teams can view and manage everything, including users and cloud connections, and access data analysis. Indeed, the company debuted an all-new version of the dashboard at TC Disrupt today, where it showcased new data-mapping and data inventory smarts that reveal how many files there are, how many are encrypted, and across how many devices.

Phalanx dashboard
Phalanx dashboard. Image credits: Phalanx

State of play

Phalanx has entered a space that includes well-resourced incumbents such as Netskope, which hit a $7.5 billion valuation two years ago, and Proofpoint, which private equity giant Thoma Bravo took private in a $12.3 billion deal around the same time. According to Garrett, though, most of the traditional DLP tools out there are geared toward enterprise-size organizations and are substantively rules-based, which means that companies have to predict how each user in the organization will interact with data in their possession using historical patterns.

On top of that, rule and policy-based configuration requires significant technical expertise that even some of the largest organizations struggle with. Phalanx, on the other hand, is designed for same-day deployment.

“Existing DLP is difficult for security teams to deploy and manage, as well as being difficult for end users (e.g., employees) to deal with,” Garrett said. “This impacts productivity and causes human-related security issues. Document visibility is a black box, so security teams try to retrofit legacy DLP to fix the issue.”

In truth, existing DLP solutions adopt various approaches to keeping company data secure. This may involve applying rules and policies to network traffic, for example, or trying to prevent data movement beyond a defined perimeter. This could be something like “don’t let user X from department Y download file Z,” or maybe trying to stop users from moving data from a local environment to a USB stick.

Instead, Phalanx focuses on tethering user identities to files, meaning that the security “follows the file itself,” giving customers analytics based on file access.

For now, SMBs are the core target market for Phalanx, though longer term it has its eyes on the enterprise segment too. That said, Garrett reckons that bigger companies could certainly find use for Phalanx right now, perhaps where a company is already using several DLP platforms and they need a very specific solution for a subdivision where their existing DLP just isn’t providing what they need.

“Our single biggest differentiator is that we are a proactive solution, whereas traditional DLP is reactive,” Garrett said. “It’s corny, but we put the ‘prevention’ in ‘data loss prevention.’ Traditional DLP aims to catch data as it’s leaving its perimeter, while we protect it in place so no matter what happens to it, it will be secure.”

More TechCrunch

It’s a wrap: European Union lawmakers have given the final approval to set up the bloc’s flagship, risk-based regulations for artificial intelligence.

EU Council gives final nod to set up risk-based regulations for AI

London-based fintech Vitesse has closed a $93 million Series C round of funding led by investment giant KKR.

Vitesse, a payments and treasury management platform for insurers, raises $93M to fuel US expansion

Zen Educate, an online marketplace that connects schools with teachers, has raised $37 million in a Series B round of funding. The raise comes amid a growing teacher shortage crisis…

Zen Educate raises $37M and acquires Aquinas Education as it tries to address the teacher shortage

“When I heard the released demo, I was shocked, angered and in disbelief that Mr. Altman would pursue a voice that sounded so eerily similar to mine.”

Scarlett Johansson says that OpenAI approached her to use her voice

A new self-driving truck — manufactured by Volvo and loaded with autonomous vehicle tech developed by Aurora Innovation — could be on public highways as early as this summer.  The…

Aurora and Volvo unveil self-driving truck designed for a driverless future

The European venture capital firm raised its fourth fund as fund as climate tech “comes of age.”

ETF Partners raises €284M for climate startups that will be effective quickly — not 20 years down the road

Copilot, Microsoft’s brand of generative AI, will soon be far more deeply integrated into the Windows 11 experience.

Microsoft wants to make Windows an AI operating system, launches Copilot+ PCs

Hello and welcome back to TechCrunch Space. For those who haven’t heard, the first crewed launch of Boeing’s Starliner capsule has been pushed back yet again to no earlier than…

TechCrunch Space: Star(side)liner

When I attended Automate in Chicago a few weeks back, multiple people thanked me for TechCrunch’s semi-regular robotics job report. It’s always edifying to get that feedback in person. While…

These 81 robotics companies are hiring

The top vehicle safety regulator in the U.S. has launched a formal probe into an April crash involving the all-electric VinFast VF8 SUV that claimed the lives of a family…

VinFast crash that killed family of four now under federal investigation

When putting a video portal in a public park in the middle of New York City, some inappropriate behavior will likely occur. The Portal, the vision of Lithuanian artist and…

NYC-Dublin real-time video portal reopens with some fixes to prevent inappropriate behavior

Longtime New York-based seed investor, Contour Venture Partners, is making progress on its latest flagship fund after lowering its target. The firm closed on $42 million, raised from 64 backers,…

Contour Venture Partners, an early investor in Datadog and Movable Ink, lowers the target for its fifth fund

Meta’s Oversight Board has now extended its scope to include the company’s newest platform, Instagram Threads, and has begun hearing cases from Threads.

Meta’s Oversight Board takes its first Threads case

The company says it’s refocusing and prioritizing fewer initiatives that will have the biggest impact on customers and add value to the business.

SeekOut, a recruiting startup last valued at $1.2 billion, lays off 30% of its workforce

The U.K.’s self-proclaimed “world-leading” regulations for self-driving cars are now official, after the Automated Vehicles (AV) Act received royal assent — the final rubber stamp any legislation must go through…

UK’s autonomous vehicle legislation becomes law, paving the way for first driverless cars by 2026

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

SoLo Funds CEO Travis Holoway: “Regulators seem driven by press releases when they should be motivated by true consumer protection and empowering equitable solutions.”

Fintech lender SoLo Funds is being sued again by the government over its lending practices

Hard tech startups generate a lot of buzz, but there’s a growing cohort of companies building digital tools squarely focused on making hard tech development faster, more efficient and —…

Rollup wants to be the hardware engineer’s workhorse

TechCrunch Disrupt 2024 is not just about groundbreaking innovations, insightful panels, and visionary speakers — it’s also about listening to YOU, the audience, and what you feel is top of…

Disrupt Audience Choice vote closes Friday

Google says the new SDK would help Google expand on its core mission of connecting the right audience to the right content at the right time.

Google is launching a new Android feature to drive users back into their installed apps

Jolla has taken the official wraps off the first version of its personal server-based AI assistant in the making. The reborn startup is building a privacy-focused AI device — aka…

Jolla debuts privacy-focused AI hardware

The ChatGPT mobile app’s net revenue first jumped 22% on the day of the GPT-4o launch and continued to grow in the following days.

ChatGPT’s mobile app revenue saw its biggest spike yet following GPT-4o launch

Dating app maker Bumble has acquired Geneva, an online platform built around forming real-world groups and clubs. The company said that the deal is designed to help it expand its…

Bumble buys community building app Geneva to expand further into friendships

CyberArk — one of the army of larger security companies founded out of Israel — is acquiring Venafi, a specialist in machine identity, for $1.54 billion. 

CyberArk snaps up Venafi for $1.54B to ramp up in machine-to-machine security

Founder-market fit is one of the most crucial factors in a startup’s success, and operators (someone involved in the day-to-day operations of a startup) turned founders have an almost unfair advantage…

OpenseedVC, which backs operators in Africa and Europe starting their companies, reaches first close of $10M fund

A Singapore High Court has effectively approved Pine Labs’ request to shift its operations to India.

Pine Labs gets Singapore court approval to shift base to India

The AI Safety Institute, a U.K. body that aims to assess and address risks in AI platforms, has said it will open a second location in San Francisco. 

UK opens office in San Francisco to tackle AI risk

Companies are always looking for an edge, and searching for ways to encourage their employees to innovate. One way to do that is by running an internal hackathon around a…

Why companies are turning to internal hackathons

Featured Article

I’m rooting for Melinda French Gates to fix tech’s broken ‘brilliant jerk’ culture

Women in tech still face a shocking level of mistreatment at work. Melinda French Gates is one of the few working to change that.

2 days ago
I’m rooting for Melinda French Gates to fix tech’s  broken ‘brilliant jerk’ culture

Blue Origin has successfully completed its NS-25 mission, resuming crewed flights for the first time in nearly two years. The mission brought six tourist crew members to the edge of…

Blue Origin successfully launches its first crewed mission since 2022