Discovery and classification
Find sensitive data across SharePoint, OneDrive, Teams and connected clouds.
Continuous discovery and risk scoring across every data store. Himaya's agents surface exposure, misconfigurations and drift before they become incidents.
Map data residency, classify what is stored, close anonymous links in one step, and find the identities with the largest blast radius.
Describe the rule in plain language. Falcon drafts it, scopes it by source and severity, previews the impact, and adds it to your enforcement policies across Slack, Teams, SharePoint and more.

Revoke public Slack links on sensitive files
Himaya flags secrets and sensitive data posted in Teams and Slack, files shared with external meeting attendees, and guests who still have access.
Link Microsoft 365 and your cloud accounts with read access.
Himaya finds and classifies sensitive data wherever it is stored.
Posture checks and an access graph show who can reach what, and where that has drifted.
Exposure, misconfigurations and risky behavior are raised before they become incidents.
Find sensitive data across SharePoint, OneDrive, Teams and connected clouds.
Catch issues that are minor alone but dangerous together.
See who can reach each data store, and when permissions change.
Impossible travel, mass downloads, external forwarding, risky OAuth apps and ransomware patterns.
Discover the unsanctioned apps and AI tools your people are using.
Entra ID risky users, privileged actions and gaps in conditional access.
Microsoft 365 (SharePoint, OneDrive, Teams, Exchange Online, Entra ID and Power BI), Google Workspace, Slack, Zendesk, GitHub, Salesforce, SAP, Workday, Greenhouse, BambooHR, Okta and CyberArk, plus cloud accounts in AWS, Microsoft Azure, Google Cloud, Oracle Cloud and Alibaba Cloud, and data platforms such as Snowflake, Databricks, MongoDB Atlas, Firebase and Redis Cloud.
Your admin authorizes each connector through the provider's API, one at a time. Most teams start with Microsoft 365 or Google Workspace, then add SaaS apps, cloud accounts and data platforms as they go.
Personal data, financial and payment data, health records, credentials and secrets, source code, and ITAR or export-controlled material, plus your own confidential terms and trainable classifiers.
Both. Himaya revokes anonymous and external links in bulk, removes stale guest access and flags mislabeled files for their owners. Fixes follow the policies you set, including ones you build with Falcon.
Yes. Collaboration security flags secrets and sensitive data posted in chats and channels, files shared with external meeting attendees, and guests who still have access.
A set of issues that are minor on their own but create real exposure together. For example, a sensitive file shared externally from a site with stale admin access.
Yes. Himaya discovers shadow IT and GenAI apps in use across your organization.
DSPM finds and fixes sensitive data where it is stored and shared. DLP stops it leaving in outbound email. Both run on the same shared context layer, so a file DSPM classifies is recognized by DLP too.
Each module deploys on its own, and they share one context layer when you run them together.
Book a walkthrough to learn more.