Listing Thumbnail

    Incydr

     Info
    Sold by: Code42 
    Deployed on AWS
    Free Trial
    AWS Free Tier
    A data protection solution to help organizations see and stop data loss from insiders
    4.2

    Overview

    Incydr allows you to see and stop data leak and theft across endpoints, browsers and cloud. It prioritizes the highest risk employee activity using over 250 contextual Incydr Risk Indicators. Incydr offers a full range of response controls to educate, contain, or block users based on the offender and offense. With Incydr, organizations gain control over data leak and theft while driving secure work habits among employees to decrease risk to data in the future.

    Get the visibility, context and controls needed to:

    Detect data theft on day 1: Protect your source code, intellectual property, and other sensitive data. Detect file exfiltration via web browsers, USB, cloud apps, email, file link sharing, Airdrop, and more. See how files are moved and shared across your entire organization without the need for policies or proxies. Incydr automatically identifies when files move outside your trusted environment, allowing you to easily detect when files are sent to personal accounts and unmanaged devices.

    Tailor your response to the offender and offense: Take action with appropriate response controls to communicate, correct, block, and contain detected risk. Leverage Code42 Instructor to correct employees when data is shared inappropriately in order to prevent risky activity from becoming the norm. Block unacceptable activity in real time for your highest risk users. Integrate with your tech stack to quickly contain insider threats while security investigates.

    Ally the business with security: Seamlessly integrate with cross functional systems such as messaging, HCM and ITMS systems. Incydr does not impact end user productivity so employees complain less about security getting in the way of work, and security teams can focus their time on bigger data risks.

    To learn more about Incydr, visit <www.code42.com/incydr/ >

    For information on Incydr's pricing dimensions as listed below, visit https://www.code42.com/incydr-plans/ 

    Contact us at https://www.code42.com/contact-sales-aws/ 

    Customer story: Hear how Lyft uses Incydr to take the blinders off of high value data movement: https://www.code42.com/case-studies/lyft/ 

    Over 65 Gartner Peer Reviews and a nearly 5 star rating: https://www.gartner.com/reviews/market/insider-risk-management-solutions/vendor/code42 

    Read the Gartner 2023 Market Guide for Data Loss Prevention Solutions: https://www.code42.com/resources/external-reports/market-guide-for-data-loss-prevention-2023 

    Our product is sold as a Private Offer through one of our Consulting Partners. To request a Private Offer, please Contact us at: https://www.code42.com/contact-sales-aws/  or email us at aws-marketplace@code42.com .

    Highlights

    • Cross platform endpoint agent: Windows, Mac, Linux to detect file exfiltration via web browsers, USB, cloud apps, email, file link sharing, Airdrop, and more. 0 to 4% CPU, up to 100MB memory.
    • API-based Exfiltration Detectors to monitor corporate cloud storage, email and business applications, including OneDrive, Google Drive, Box, Office 365 Email, Gmail and Salesforce.
    • Integrations with SIEM, SOAR, EDR, IAM, PAM and more, plus open API and developer resources.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (4)

     Info
    Dimension
    Description
    Cost/12 months
    Horizon
    Our most comprehensive plan, Premier plus support + Instructor
    $1,000,000.00
    Professional
    Our most basic plan, includes 1 Cloud storage service and Base API
    $1,000,000.00
    Enterprise
    Mid Level package, Includes premier support, full API access, and more
    $1,000,000.00
    Private Offer
    Please contact us to request a Private Offer for accurate pricing.
    $1,000,000.00

    Vendor refund policy

    Please See our website for more details on our refund policy <www.code42.com >

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Incydr Detailed product documentation on our self-service support site is available for help deploying, administering, and managing Incydr. Code42 Incydr Technical Support offers help in the way you need it: by web ticket, chat, or phone. Support Engineers are available 24/7 for urgent priority issues, and are based in US offices. https://support.code42.com/hc/en-us 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Data Governance
    Top
    10
    In Data Analysis, Observability
    Top
    100
    In Data Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    32 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Cross-Platform Endpoint Detection
    Windows, Mac, and Linux endpoint agents detect file exfiltration through web browsers, USB, cloud apps, email, file link sharing, and Airdrop with minimal resource consumption of 0 to 4% CPU and up to 100MB memory.
    Cloud Application Monitoring
    API-based exfiltration detectors monitor corporate cloud storage, email, and business applications including OneDrive, Google Drive, Box, Office 365 Email, Gmail, and Salesforce.
    Risk Indicator Analysis
    Over 250 contextual risk indicators prioritize and identify highest-risk employee activity patterns.
    Threat Response Controls
    Response controls enable real-time blocking, user containment, and employee education based on specific offender and offense characteristics.
    Security Integration Capabilities
    Open API and integrations with SIEM, SOAR, EDR, IAM, and PAM systems enable cross-functional system connectivity.
    Agentless Deployment
    Discovers every datastore of every type using an agentless approach for instant deployment with a single point of integration for zero performance impact.
    Data Classification
    Detects and classifies data types leveraging both classic pattern matching and novel ML algorithms for classification accuracy.
    Risk Detection and Visibility
    Provides continuous visibility into all cloud data and associated risks across all datastores.
    Data Context and Remediation
    Provides insights including context, administrating user, access logs, data ownership and remediation guidelines to resolve identified risks.
    Multi-Datastore Support
    Maps and discovers all cloud datastores of every type within the environment.
    Shadow AI and SaaS Discovery
    Identifies and catalogs all AI applications and shadow SaaS instances in use across the organization to enforce security guardrails.
    Data Loss Prevention for AI and Web Applications
    Prevents sensitive data leakage across AI tools, SaaS applications, and web channels through content inspection and enforcement policies.
    Browser Extension-Based Security Enforcement
    Delivers security controls through an enterprise browser extension that monitors and enforces policies on user interactions with AI, SaaS, and web applications without requiring infrastructure changes.
    AI Misuse and Prompt Injection Protection
    Detects and prevents prompt injection attacks, compliance violations, and unauthorized AI usage patterns to protect against AI-specific threats.
    Agentless Architecture with Last-Mile Visibility
    Provides comprehensive visibility and control over user and agentic interactions at the browser level without requiring agent deployment on endpoints.

    Contract

     Info
    Standard contract
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    69 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    52%
    35%
    12%
    0%
    1%
    6 AWS reviews
    |
    63 external reviews
    External reviews are from G2  and PeerSpot .
    Architecture & Planning

    Incydr Delivers Clear, Centralized Visibility Into Where Company Data Is Going

    Reviewed on Aug 26, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Incydr is that it gives you a clear picture of where company data is going without making you constantly dig through logs. It’s especially helpful for spotting unusual file activity and potential data leaks early. The main upside for me is having that visibility in one place and being able to investigate issues before they turn into bigger problems.
    What do you dislike about the product?
    The main thing I’d say is that it can take some time to get everything configured and tuned properly. There’s also a lot of information available, so it can feel a little overwhelming at first when you’re trying to figure out what’s actually important. Once it’s set up though, it becomes much easier to work with.
    What problems is the product solving and how is that benefiting you?
    Incydr helps us keep better visibility over how sensitive company data is being accessed and moved. It makes it easier to identify unusual activity and potential data leaks, and gives us a way to investigate those issues without having to piece everything together manually.
    Consulting

    Real-Time Behavioral Analytics That Transforms Insider Threat Detection

    Reviewed on Aug 25, 2026
    Review provided by G2
    What do you like best about the product?
    The real-time visibility into data movement has fundamentally changed how our security team approaches insider threat prevention. What impressed me most is the behavioral analytics engine it doesn't just flag suspicious activity; it surfaces patterns we wouldn't catch manually.

    Specific example: One of our customers discovered that a departing employee was systematically downloading customer data files over three weeks. Incydr's timeline view let us see exactly which files, when, and flagged the escalating pattern automatically. That would have taken our customer's team 40+ hours to reconstruct from logs.

    Workflow improvement: The customizable alert rules cut our false-positive noise by 70%. Instead of alert fatigue, our analysts now trust the system they know each notification matters. That's freed up 8-10 hours per week for actual threat investigation.

    Unexpected benefit: The integration with Slack for incident notifications has been a game-changer for cross-team awareness. Security doesn't work in a vacuum, and having PMs and engineering see threats in real-time creates better buy-in for prevention measures.

    Impact: For our customers, this translates to faster incident response and clearer compliance audit trails. For us as a PM, it validates that there's real market demand for accessible, intelligent endpoint security it's becoming table-stakes for enterprise customers.
    What do you dislike about the product?
    The onboarding and configuration complexity has been our biggest friction point. Getting agents deployed across a heterogeneous environment took longer than expected, and the policy setup requires deep security expertise, our ops team needed multiple escalations to get it right.

    Specific example: Rolling out to 500+ endpoints, we had three failed deployment waves because the documentation on group policy templates for our mixed Windows/Mac environment was sparse. We ended up doing a custom scripting pass that should have been templated.

    Workflow pain: The reporting interface feels disconnected from the alerting system. Our analysts live in the alerts dashboard, but executives need compliance reports. We're constantly context-switching between two interfaces and manually exporting data to build board-ready summaries. It's added ~5 hours/week of reporting overhead.

    Unexpected limitation: Pricing scales aggressively with seat count. We expected per-endpoint licensing, but the cost model hit us hard when scaling from 50 to 500 users. It made the ROI conversation with finance much harder, especially for large enterprises.

    What's missing: Better SOAR integration. We're running Jira + Slack for incident workflows, but Incydr's automation hooks are limited. We're writing custom webhooks instead of using native playbooks.
    What problems is the product solving and how is that benefiting you?
    Problems Incydr solves & benefits we're seeing:

    Before: Our security team was operating reactively. We had a SIEM, but insider threat detection was manual analysts reviewing logs after incidents were reported by other departments. We struggled with:

    Late detection (threats were often discovered after damage occurred)
    No visibility into lateral movement or data exfiltration patterns
    Compliance audits required weeks of log reconstruction
    Alert fatigue from false positives buried real threats

    After implementation:

    We deployed Incydr across 800 endpoints and tuned behavioral analytics to our environment. Now we can do:

    Detect threats in real-time as they're happening, not after the fact
    Automate routine investigations with automated alerting to Slack + Jira
    Generate compliance reports in hours instead of weeks pre-built templates handle HIPAA/SOC2 requirements
    Reduce analyst time per incident from 6-8 hours to 2-3 hours

    Measurable results:

    40% reduction in incident response time detection to containment now averages 90 minutes vs. 5+ hours
    65% fewer false positives better signal-to-noise ratio lets our team focus on real threats
    2 incidents prevented that would have resulted in data loss (caught during the investigation phase)
    Compliance audit cycle reduced from 6 weeks to 10 days examiners trust our automated reporting

    Strategic benefit: This has shifted our narrative from "We detect breaches after they happen" to "We prevent them." That's a huge differentiator for customer trust.
    Ayoub N.

    Clear Data Visibility and Fast Security Risk Detection

    Reviewed on Aug 25, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Incydr is the clear visibility it provides into data activity, along with its ability to quickly surface potential security risks without adding unnecessary complexity.
    What do you dislike about the product?
    One area that could be improved is offering more customization options for dashboards and alerts. It would also help if certain insights were easier to find and interpret, so day-to-day monitoring can be faster and more straightforward.
    What problems is the product solving and how is that benefiting you?
    Incydr helps us identify and prevent potential data leaks and insider threats by giving us clear visibility into risky user activity and the movement of sensitive data.
    Anonymous

    Intuitive Tool, But Needs Improvement

    Reviewed on Aug 18, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate that Incydr provides me with a good visual on the state of our systems. It's intuitive, easy to use, and easy to teach to new team members. It also has a great set of tools. The phishing simulator is particularly interesting as it allows us to see the extent to which a phishing attack has reached our university community. It's quite valuable because it helps map the whole attack.
    What do you dislike about the product?
    There was a small learning curve when initially setting up Incydr, but it wasn't too difficult and we got there pretty quickly, within a couple of weeks.
    What problems is the product solving and how is that benefiting you?
    I use Incydr to prevent cybersecurity attacks, get a good visual on our systems' state, and map cybersecurity issues, which is valuable for managing our large university community.
    Rishabh G.

    Alerts That Matter: Minimal False Positives

    Reviewed on Aug 12, 2026
    Review provided by G2
    What do you like best about the product?
    Honestly, the biggest thing for me is that the alerts aren’t garbage. When it flags something, it’s usually actually worth looking at, instead of being just another false positive I have to close out.
    What do you dislike about the product?
    The reporting could definitely be better. Pulling data for management takes more clicks than it should, and I wish there were more ways to customize the dashboards so the key information is easier to surface. Pricing also isn’t cheap, especially for a smaller team.
    What problems is the product solving and how is that benefiting you?
    Our main concern is insider risk,people leaving the company and taking files with them. Before Incydr, we honestly had no visibility into that. Now, when someone gives notice, we can actually see whether they moved anything to personal drives or a USB device before they left. It saves us a ton of guesswork and cuts down on awkward conversations.
    View all reviews