eScan Enterprise DLP: The Right Problem, an Unnamed Bank, and a Crowded Field

eScan Enterprise DLP: The Right Problem, an Unnamed Bank, and a Crowded Field

On 12 September 2026, eScan released a case study describing how eScan Enterprise DLP enabled a regional investment bank to use generative AI without leaking confidential financial data. The deployment uses endpoint DLP agents to monitor AI interactions across analyst workstations, trading floors, and mobile devices. The agent inspects content in real time before it reaches an AI platform, classifies its sensitivity, and blocks unauthorised transmission. During implementation, the solution reportedly blocked hundreds of attempted transmissions of client portfolios, trading strategies, proprietary models, and material non-public information to public AI platforms.

The problem eScan addresses is real and urgent. As financial institutions adopt AI for research, modelling, and analysis, sensitive data flowing to ChatGPT, Claude, and Gemini creates regulatory and competitive risks. Industry data quantifies the exposure: 34.8% of employee inputs to AI platforms contain sensitive data, up from 11% in 2023, per Cipher Security’s 2026 DLP analysis. Cyberhaven’s 2026 AI Risk Report for Financial Services found that AI adoption has outpaced enterprises’ ability to govern it, with shadow AI usage growing across fragmented tools and personal accounts.

But the case study has a structural weakness: the bank has no name. “A regional investment bank” cannot be verified, contacted, or benchmarked. Company reporting claims “hundreds of blocked transmissions” with no independent audit. The deployment architecture is plausible and well-described, but a CISO evaluating this solution has no reference customer to call.

Why eScan Enterprise DLP Timed This for September 2026

eScan CEO Govind Rammurthy told APAC News Network in January 2026 that “2026 will be the year of DLP deployments” and that customers are asking “how do we let employees use AI productivity tools without accidentally leaking our intellectual property?” The case study is the proof point for that prediction.

Growth in the DLP market reflects this shift. Enterprise DLP software reached $3.2 billion in 2024 and is projected to hit $12.8 billion by 2034, at a 14.9% CAGR, per Markets NXT. Exactly the problem this case study describes drives this growth: data moving to AI platforms, cloud services, and collaboration tools outside traditional security perimeters.

eScan also won the AV-TEST Award 2025 for Best Advanced Protection against ransomware and infostealers, announced in March 2026. That award validates eScan’s endpoint security capabilities. This case study extends the credibility into data protection — a category where eScan competes against much larger vendors.

The Competitive Picture: eScan Against DLP Giants

The enterprise DLP market has consolidated into three camps, and eScan is not in any of them.

Dedicated enterprise DLP suites

Symantec DLP (now Broadcom) holds approximately 28% market share with the most comprehensive coverage matrix — endpoint, network, email, storage, and cloud. Forcepoint DLP holds roughly 18% with risk-adaptive policies that adjust enforcement based on user behaviour scores. Both are billion-dollar platforms with Fortune 500 installed bases. Neither is fast at GenAI iteration, which is the gap smaller vendors are attacking.

Platform-embedded DLP

Microsoft Purview DLP ships inside M365 E5 licenses at no additional cost for Microsoft-centric organisations. It covers Exchange, SharePoint, OneDrive, and Teams natively, and Microsoft’s DSPM for AI (GA April-May 2026) extends visibility into Copilot usage. For the majority of large enterprises already on M365 E5, Purview is effectively free.

SSE-native and GenAI-specialist DLP

Zscaler and Netskope fold DLP into their security service edge platforms. Nightfall AI builds DLP specifically for SaaS and AI-era data flows, with browser extensions that inspect ChatGPT and Claude prompts. CrowdStrike Falcon Data Protection intercepts GenAI prompts at the browser layer in real time. FortiDLP (from Fortinet’s 2024 acquisition of Next DLP) offers endpoint-native ML with GenAI and shadow-AI inventory features.

Where eScan sits

eScan Enterprise DLP competes on AI Platform Data Protection — real-time inspection of data uploads to AI services including ChatGPT, Claude, and Gemini. The technology combines Neural Intelligence AI/ML, behavioural analysis, content-aware inspection, and OCR. This is credible capability, but it is not unique. CrowdStrike, Nightfall, and Forcepoint all offer GenAI prompt inspection. Forcepoint’s March 2026 proxy-free agent release specifically targets this use case.

eScan’s genuine differentiators are price and India-market focus. CEO Rammurthy has stated the company prices “for Indian enterprises realistically — world-class protection without Silicon Valley assumptions about IT budgets.” eScan works closely with CERT-In, defence procurement teams, and state cybersecurity cells. For Indian financial institutions facing DPDP Act compliance and RBI regulations, an India-origin vendor with local support has real appeal.

What the Public Data Shows

Three external data points sharpen the picture beyond the case study.

First, eScan’s company scale is small relative to competitors. Govind Rammurthy founded MicroWorld Technologies (eScan’s parent) in Mumbai in 1993. Revenue estimates vary significantly: GetLatka estimates $5.9 million (2024), LinkedIn shows $21 million, Extruct AI estimates $22 million, and Owler places the range at $5-25 million. Employee counts range from 190 (LinkedIn) to 196 (GetLatka) to “over 300 R&D professionals” per the press release. The company bootstrapped itself with zero external funding. It claims 220,000 corporate clients globally, with managed security concentrated in BFSI (40%), government (30%), and manufacturing (20%). Against Symantec, Forcepoint, and Microsoft — all multi-billion-dollar operations — eScan is a niche player.

Second, the “hundreds of blocked transmissions” figure needs context. Over what period were these attempts blocked? What percentage were false positives? How many analysts generated hundreds of attempts — was this 50 analysts over a week or 500 over a year? Without denominators, the number is a headline, not a metric. The case study does not provide false-positive rates, performance impact on analyst workstations, or tuning effort required.

Third, the approved AI workflow architecture is genuinely thoughtful. The bank established different AI platforms for different functions: Claude for market research, Gemini for macroeconomic analysis, ChatGPT for public financial data. Each workflow has audit logging. This is the right model — treating AI platforms as differentiated tools with different data sensitivities rather than a monolithic “AI” category. The data classification hierarchy (public, internal, client-confidential, trading-sensitive) and integration with existing compliance infrastructure are also well-designed.

What’s New vs. What’s Repackaged

New: The specific case study of applying endpoint DLP to AI platform interactions in an investment banking context. The approved AI workflow model — different AI platforms for different functions with audit logging — is a practical architecture that other financial institutions could replicate.

Repackaged: Endpoint DLP itself is a mature technology. Applying it to AI platforms is an extension of existing egress channels, not a new category. eScan’s CEO is right: “It’s straightforward endpoint monitoring — the same principle that prevents data leakage to email or USB drives, just extended to LLM/AI platforms.” The Neural Intelligence AI/ML, behavioural analysis, and OCR capabilities are standard DLP features available from every major vendor.

Improved: eScan’s AI Platform Data Protection capability adds real-time inspection of AI service uploads. This is a genuine functional extension of DLP into the GenAI era. The clipboard monitoring across WhatsApp and collaboration tools, mentioned in the CEO’s January interview, addresses a real vector.

Unclear: The unnamed bank prevents verification. The “hundreds” figure lacks a denominator. No false-positive rate, performance impact, or tuning burden appears in the study. Pricing is absent. The case study does not specify how many endpoints, analysts, or locations the deployment covered.

The Question That Wasn’t Answered

The sharpest unanswered question: which bank, and can a prospective customer talk to them?

Anonymous case studies are common in cybersecurity, where customer confidentiality is a genuine constraint. But “a regional investment bank” is so vague that it could describe hundreds of institutions. A CISO evaluating eScan Enterprise DLP against Microsoft Purview, Forcepoint, or CrowdStrike cannot verify the deployment, contact the customer, or benchmark the results. Every major DLP vendor offers named reference customers or detailed case studies with specific metrics. The absence here weakens the proof value of the entire case study.

A secondary question concerns accuracy. The case study says the DLP agent “identifies sensitive information such as client portfolios, trading strategies, proprietary models, material non-public information and confidential deal data.” How accurate is this classification? What is the false-positive rate? A DLP system that blocks legitimate research queries frustrates analysts and drives them to personal devices and accounts — making the problem worse. The case study mentions that “early adoption by senior analysts helped drive wider acceptance,” which implies friction existed.

Pricing is also absent. No licensing model, per-endpoint cost, or comparison to competitors is provided.

What This Means for You

If you are a CISO or security leader at a financial institution evaluating AI data protection, the problem framing in this case study is correct. The choice is not between banning AI and accepting data leakage. The right architecture — approved AI workflows with differentiated platforms, data classification, audit logging, and endpoint DLP — is well-described here. But evaluate multiple vendors before committing. Microsoft Purview covers M365-native environments at no additional cost with E5. CrowdStrike Falcon Data Protection intercepts GenAI prompts at the browser layer. Nightfall AI is purpose-built for SaaS and AI-era data flows. Forcepoint offers the broadest hybrid coverage with GenAI prompt inspection.

If you are an Indian financial institution with DPDP Act and RBI compliance requirements, eScan deserves a spot on the shortlist. The India-market focus, local support, CERT-In relationships, and realistic pricing for Indian IT budgets are genuine advantages. The AV-TEST Award validates the underlying endpoint technology. But ask for a named reference customer, a proof-of-concept with your data, and false-positive rate data before signing.

For industry observers, this case study confirms that AI data leakage has become the defining DLP problem of 2026. Every vendor — from Symantec to Nightfall to eScan — now markets AI platform protection. Classification accuracy, false-positive management, and deployment simplicity will determine the winners, not who describes the problem most vividly.

eScan Enterprise DLP: The Right Problem, an Unnamed Bank, and a Crowded Field

Editor’s Note

This article draws on the eScan case study press release dated 12 September 2026, supplemented by independent research. The “regional investment bank” has no name in the case study; the deployment cannot be independently verified. The “hundreds of blocked transmissions” figure is company-reported with no independent audit, no time period, and no denominator. eScan company data is from GetLatka, LinkedIn, Extruct AI, Owler, and Craft.co; revenue estimates vary significantly between sources ($5.9M to $22M).

Meanwhile, the 220,000 corporate client figure and BFSI/government/manufacturing split are from eScan CEO Govind Rammurthy’s January 2026 interview with APAC News Network. DLP market size and competitive share data are from Markets NXT and CIOPages. The 34.8% sensitive-data-in-AI-inputs statistic is from Cipher Security’s 2026 DLP comparison. GenAI prompt inspection capabilities for CrowdStrike, Nightfall, Forcepoint, and Microsoft Purview are from product pages and 2026 buyer’s guides. The AV-TEST Award 2025 for eScan Enterprise EDR is from eScan’s announcement in March 2026. This article does not constitute procurement advice.