
Overview
Incydr allows you to see and stop data leak and theft across endpoints, browsers and cloud. It prioritizes the highest risk employee activity using over 250 contextual Incydr Risk Indicators. Incydr offers a full range of response controls to educate, contain, or block users based on the offender and offense. With Incydr, organizations gain control over data leak and theft while driving secure work habits among employees to decrease risk to data in the future.
Get the visibility, context and controls needed to:
Detect data theft on day 1: Protect your source code, intellectual property, and other sensitive data. Detect file exfiltration via web browsers, USB, cloud apps, email, file link sharing, Airdrop, and more. See how files are moved and shared across your entire organization without the need for policies or proxies. Incydr automatically identifies when files move outside your trusted environment, allowing you to easily detect when files are sent to personal accounts and unmanaged devices.
Tailor your response to the offender and offense: Take action with appropriate response controls to communicate, correct, block, and contain detected risk. Leverage Code42 Instructor to correct employees when data is shared inappropriately in order to prevent risky activity from becoming the norm. Block unacceptable activity in real time for your highest risk users. Integrate with your tech stack to quickly contain insider threats while security investigates.
Ally the business with security: Seamlessly integrate with cross functional systems such as messaging, HCM and ITMS systems. Incydr does not impact end user productivity so employees complain less about security getting in the way of work, and security teams can focus their time on bigger data risks.
To learn more about Incydr, visit <www.code42.com/incydr/ >
For information on Incydr's pricing dimensions as listed below, visit https://www.code42.com/incydr-plans/
Contact us at https://www.code42.com/contact-sales-aws/
Customer story: Hear how Lyft uses Incydr to take the blinders off of high value data movement: https://www.code42.com/case-studies/lyft/
Over 65 Gartner Peer Reviews and a nearly 5 star rating: https://www.gartner.com/reviews/market/insider-risk-management-solutions/vendor/code42
Read the Gartner 2023 Market Guide for Data Loss Prevention Solutions: https://www.code42.com/resources/external-reports/market-guide-for-data-loss-prevention-2023
Our product is sold as a Private Offer through one of our Consulting Partners. To request a Private Offer, please Contact us at: https://www.code42.com/contact-sales-aws/ or email us at aws-marketplace@code42.com .
Highlights
- Cross platform endpoint agent: Windows, Mac, Linux to detect file exfiltration via web browsers, USB, cloud apps, email, file link sharing, Airdrop, and more. 0 to 4% CPU, up to 100MB memory.
- API-based Exfiltration Detectors to monitor corporate cloud storage, email and business applications, including OneDrive, Google Drive, Box, Office 365 Email, Gmail and Salesforce.
- Integrations with SIEM, SOAR, EDR, IAM, PAM and more, plus open API and developer resources.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
Horizon | Our most comprehensive plan, Premier plus support + Instructor | $1,000,000.00 |
Professional | Our most basic plan, includes 1 Cloud storage service and Base API | $1,000,000.00 |
Enterprise | Mid Level package, Includes premier support, full API access, and more | $1,000,000.00 |
Private Offer | Please contact us to request a Private Offer for accurate pricing. | $1,000,000.00 |
Vendor refund policy
Please See our website for more details on our refund policy <www.code42.com >
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Incydr Detailed product documentation on our self-service support site is available for help deploying, administering, and managing Incydr. Code42 Incydr Technical Support offers help in the way you need it: by web ticket, chat, or phone. Support Engineers are available 24/7 for urgent priority issues, and are based in US offices. https://support.code42.com/hc/en-us
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Incydr Delivers Clear, Centralized Visibility Into Where Company Data Is Going
Real-Time Behavioral Analytics That Transforms Insider Threat Detection
Specific example: One of our customers discovered that a departing employee was systematically downloading customer data files over three weeks. Incydr's timeline view let us see exactly which files, when, and flagged the escalating pattern automatically. That would have taken our customer's team 40+ hours to reconstruct from logs.
Workflow improvement: The customizable alert rules cut our false-positive noise by 70%. Instead of alert fatigue, our analysts now trust the system they know each notification matters. That's freed up 8-10 hours per week for actual threat investigation.
Unexpected benefit: The integration with Slack for incident notifications has been a game-changer for cross-team awareness. Security doesn't work in a vacuum, and having PMs and engineering see threats in real-time creates better buy-in for prevention measures.
Impact: For our customers, this translates to faster incident response and clearer compliance audit trails. For us as a PM, it validates that there's real market demand for accessible, intelligent endpoint security it's becoming table-stakes for enterprise customers.
Specific example: Rolling out to 500+ endpoints, we had three failed deployment waves because the documentation on group policy templates for our mixed Windows/Mac environment was sparse. We ended up doing a custom scripting pass that should have been templated.
Workflow pain: The reporting interface feels disconnected from the alerting system. Our analysts live in the alerts dashboard, but executives need compliance reports. We're constantly context-switching between two interfaces and manually exporting data to build board-ready summaries. It's added ~5 hours/week of reporting overhead.
Unexpected limitation: Pricing scales aggressively with seat count. We expected per-endpoint licensing, but the cost model hit us hard when scaling from 50 to 500 users. It made the ROI conversation with finance much harder, especially for large enterprises.
What's missing: Better SOAR integration. We're running Jira + Slack for incident workflows, but Incydr's automation hooks are limited. We're writing custom webhooks instead of using native playbooks.
Before: Our security team was operating reactively. We had a SIEM, but insider threat detection was manual analysts reviewing logs after incidents were reported by other departments. We struggled with:
Late detection (threats were often discovered after damage occurred)
No visibility into lateral movement or data exfiltration patterns
Compliance audits required weeks of log reconstruction
Alert fatigue from false positives buried real threats
After implementation:
We deployed Incydr across 800 endpoints and tuned behavioral analytics to our environment. Now we can do:
Detect threats in real-time as they're happening, not after the fact
Automate routine investigations with automated alerting to Slack + Jira
Generate compliance reports in hours instead of weeks pre-built templates handle HIPAA/SOC2 requirements
Reduce analyst time per incident from 6-8 hours to 2-3 hours
Measurable results:
40% reduction in incident response time detection to containment now averages 90 minutes vs. 5+ hours
65% fewer false positives better signal-to-noise ratio lets our team focus on real threats
2 incidents prevented that would have resulted in data loss (caught during the investigation phase)
Compliance audit cycle reduced from 6 weeks to 10 days examiners trust our automated reporting
Strategic benefit: This has shifted our narrative from "We detect breaches after they happen" to "We prevent them." That's a huge differentiator for customer trust.