
Overview
Incydr allows you to see and stop data leak and theft across endpoints, browsers and cloud. It prioritizes the highest risk employee activity using over 250 contextual Incydr Risk Indicators. Incydr offers a full range of response controls to educate, contain, or block users based on the offender and offense. With Incydr, organizations gain control over data leak and theft while driving secure work habits among employees to decrease risk to data in the future.
Get the visibility, context and controls needed to:
Detect data theft on day 1: Protect your source code, intellectual property, and other sensitive data. Detect file exfiltration via web browsers, USB, cloud apps, email, file link sharing, Airdrop, and more. See how files are moved and shared across your entire organization without the need for policies or proxies. Incydr automatically identifies when files move outside your trusted environment, allowing you to easily detect when files are sent to personal accounts and unmanaged devices.
Tailor your response to the offender and offense: Take action with appropriate response controls to communicate, correct, block, and contain detected risk. Leverage Code42 Instructor to correct employees when data is shared inappropriately in order to prevent risky activity from becoming the norm. Block unacceptable activity in real time for your highest risk users. Integrate with your tech stack to quickly contain insider threats while security investigates.
Ally the business with security: Seamlessly integrate with cross functional systems such as messaging, HCM and ITMS systems. Incydr does not impact end user productivity so employees complain less about security getting in the way of work, and security teams can focus their time on bigger data risks.
To learn more about Incydr, visit <www.code42.com/incydr/ >
For information on Incydr's pricing dimensions as listed below, visit https://www.code42.com/incydr-plans/
Contact us at https://www.code42.com/contact-sales-aws/
Customer story: Hear how Lyft uses Incydr to take the blinders off of high value data movement: https://www.code42.com/case-studies/lyft/
Over 65 Gartner Peer Reviews and a nearly 5 star rating: https://www.gartner.com/reviews/market/insider-risk-management-solutions/vendor/code42
Read the Gartner 2023 Market Guide for Data Loss Prevention Solutions: https://www.code42.com/resources/external-reports/market-guide-for-data-loss-prevention-2023
Our product is sold as a Private Offer through one of our Consulting Partners. To request a Private Offer, please Contact us at: https://www.code42.com/contact-sales-aws/ or email us at aws-marketplace@code42.com .
Highlights
- Cross platform endpoint agent: Windows, Mac, Linux to detect file exfiltration via web browsers, USB, cloud apps, email, file link sharing, Airdrop, and more. 0 to 4% CPU, up to 100MB memory.
- API-based Exfiltration Detectors to monitor corporate cloud storage, email and business applications, including OneDrive, Google Drive, Box, Office 365 Email, Gmail and Salesforce.
- Integrations with SIEM, SOAR, EDR, IAM, PAM and more, plus open API and developer resources.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
Horizon | Our most comprehensive plan, Premier plus support + Instructor | $1,000,000.00 |
Professional | Our most basic plan, includes 1 Cloud storage service and Base API | $1,000,000.00 |
Enterprise | Mid Level package, Includes premier support, full API access, and more | $1,000,000.00 |
Private Offer | Please contact us to request a Private Offer for accurate pricing. | $1,000,000.00 |
Vendor refund policy
Please See our website for more details on our refund policy <www.code42.com >
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Incydr Detailed product documentation on our self-service support site is available for help deploying, administering, and managing Incydr. Code42 Incydr Technical Support offers help in the way you need it: by web ticket, chat, or phone. Support Engineers are available 24/7 for urgent priority issues, and are based in US offices. https://support.code42.com/hc/en-us
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Intuitive Tool, But Needs Improvement
Alerts That Matter: Minimal False Positives
Good signal on insider risk, needs a longer runway to prove out
Incydr Makes Data Security Risks Easy to Spot with Clear, Actionable Insights
Email security has protected against phishing and impersonation while improving threat response
What is our primary use case?
I am using Mimecast Insider Risk Management and Data Protection, and I used it in my previous company for around two to three years.
We are leveraging Mimecast Insider Risk Management and Data Protection for email security, and it is acting as our primary email gateway, through which all our emails are entered. We have all the policies and security configuration implemented on Mimecast Insider Risk Management and Data Protection as our main gateway.
Mimecast Insider Risk Management and Data Protection is an email gateway, so all our email passes through our primary security device. It is used for all the security checks, policy checks, all the block checks, and URL rewriting. Our work mainly revolves around email work such as tracing emails and applying some blocking or remediation configurations.
We are leveraging Mimecast Insider Risk Management and Data Protection for email security, which includes URL sandboxing, URL shorteners, URL sand details, and headers.
What is most valuable?
Mimecast Insider Risk Management and Data Protection is a very robust and highly reliable gateway. We are very satisfied with its excellency with the anti-spam and URL rewriting feature. We are also leveraging it to stop phishing and malware attempts that our company receives. It has a good capability to deal with day-to-day trends and also has a good interface.
Regarding the best features Mimecast Insider Risk Management and Data Protection offers, it has highly customizable policies. It also has reliable, dynamic rewriting and blocking of URLs. Additionally, it provides instant threat remediation and is very good in identifying impersonation and BEC attacks. We have good admin visibility.
Mimecast Insider Risk Management and Data Protection has impacted our organization positively in several ways. It has good threat remediation and good attachment protection. It also has good impersonation and BEC protection. For our organization, these three are the most critical threat vectors that an attacker can leverage to enter the company. Mimecast Insider Risk Management and Data Protection has good control over these threat vectors. Apart from that, it has a good interface and good integration with other tools.
What needs improvement?
Regarding improvement for Mimecast Insider Risk Management and Data Protection, I believe there is one area that needs attention: QR code phishing. I can see it is still allowing some emails that have phishing QR codes inside them or some phishing attachments. It needs to slightly improve on the QR-ishing side.
For how long have I used the solution?
I have been in this field for around six years and am working as a SOC incident responder.
What do I think about the stability of the solution?
Mimecast Insider Risk Management and Data Protection is stable.
What do I think about the scalability of the solution?
Regarding Mimecast Insider Risk Management and Data Protection's scalability, as we have a public cloud, there should not be an issue with scalability.
How are customer service and support?
Customer support for Mimecast Insider Risk Management and Data Protection is good. I have interacted with them multiple times regarding any kind of ongoing issues, and I can confirm that customer support is good.
Which solution did I use previously and why did I switch?
I am using only Mimecast Insider Risk Management and Data Protection because I am working in an incident response team where we need to work for different clients. The choice of devices totally depends on what the client is using.
How was the initial setup?
I am not the implementer; Mimecast Insider Risk Management and Data Protection was already there at the customer premises. We learned it, applied it, and used it.
What about the implementation team?
The accuracy of Mimecast Insider Risk Management and Data Protection is good. We do not see any kind of mis-data or misinterpretation. From the accuracy side, I can confirm that it is reliable and there are no issues.
What was our ROI?
Mimecast Insider Risk Management and Data Protection is time-saving. From the employee perspective, it is neutral. From the security perspective, Mimecast Insider Risk Management and Data Protection is helping in reducing the ongoing threats for the organization.
What's my experience with pricing, setup cost, and licensing?
I am from the incident response team, and regarding pricing and cost, I am not very familiar with this. I cannot comment on the pricing part.
Which other solutions did I evaluate?
We do not have a business relationship with this vendor other than being a customer.
What other advice do I have?
I will give one piece of advice regarding Mimecast Insider Risk Management and Data Protection: be sure about zero-day attacks because it might be missing in applying any remediation or security controls on any kind of zero-days. This is applicable for all the security equipment we are using on a daily basis. Just be assured if there is a zero-day. I gave this review a rating of 8.