Skip to main content
Channel Module

File Inspector.

Inspect every file upload through the same 3-tier DLP pipeline that protects your AI traffic and email. Text extraction, content-addressed storage, and quarantine for flagged files.

Platform Connection

Files get the same inspection as everything else.

The File Inspector module extracts text from uploaded documents and sends it through the platform engine. The same detectors that find PII in AI prompts find it in spreadsheets, PDFs, and Word documents.

Capabilities

What the File Inspector does.

Text Extraction

Extract text from PDF, DOCX, XLSX, and CSV files. The extracted content flows through all 3 DLP tiers — pattern detection, ML-based entity recognition, and AI-powered contextual validation.

Content-Addressed Storage

Files are stored by content hash. Duplicate uploads are deduplicated automatically. Storage is encrypted with the same BYOK envelope encryption as the rest of the platform.

Quarantine

Flagged files are quarantined with admin review workflow. Release, reject, or re-scan. Complete audit trail per file from upload through disposition.

Per-Upload Audit Trail

Every upload is logged in the tamper-proof audit log with file metadata, DLP scan results, policy decisions, and user identity. Same log, same chain, same SIEM export.

File Passthrough

Scan files before they reach cloud storage.

Connect cloud storage destinations and route uploads through the platform first. Every file is inspected before forwarding — with the same pipeline that protects AI traffic and email.

Native Connectors

Pre-built passthrough paths for Google Drive, OneDrive/SharePoint, Box, and S3-compatible destinations — including AWS S3, Cloudflare R2, Backblaze B2, Wasabi, MinIO, and DigitalOcean Spaces. Admin-configured per destination.

Unified Quarantine

Flagged files land in the same quarantine inbox as email and AI findings. Admins release, reject, or manually re-scan from one place. No separate queue per channel.

Egress-Only Scanning

Passthrough covers upload paths — files leaving the organization or reaching a shared destination. Ingress and sync workflows are not affected. Scope stays predictable.

Destination Control

Admins register and configure each destination from the admin portal. Per-destination DLP policy, quarantine thresholds, and notification settings. No changes required to the upstream application.

Read the file inspection guide

Govern every upload.

See how the File Inspector connects to the Arbitex content security engine.