4

Digital Personal Data Access Gateway

SL-11

Browser-layer protection at the point where personal data is actually typed. The browser inspects the rendered page and the final destination rather than the link, because modern phishing changes where it points after the link has been scanned.

DischargesS.8(4)R.6S.8(6)
Detections (30 days)
64
Blocked
46
Data entry prevented
26
View
Government impersonation
8
Browsers protected
36
Unprotected endpoints
18
View
Blocks and prevented data entry

Blocking a site is useful; stopping a submission that was already in progress is what the classification integration adds.

How the threat arrived

Email dominates, but search and chat together are close behind — which is why email security alone is insufficient.

  • Email28
  • Search11
  • Chat10
  • Advertisement7
  • Social5
  • Direct3
Threat types

Pixel-perfect replicas and URL-rewriting abuse are the two that defeat conventional controls.

All detections
Recent blocks

What the rendered page claimed to be, and what it actually was.

Full feed
  • CriticalNational Cyber Crime Reporting Portalblocked
    https://cybercrime-report-portal.co.in/file
    Impersonated government portalImpersonates National Cyber Crime Reporting Portalyesterday
  • HighBeneficiary data collection surveyblocked
    https://forms.example-survey.net/beneficiary-data
    Personal data entry into an untrusted siteyesterday
  • CriticalDepartment of Citizen Services loginblocked
    https://citizenservices-gov-in.secure-login.net/auth
    Pixel-perfect phishing replicaImpersonates Department of Citizen Servicesyesterday
  • HighPension KYC verificationblocked
    https://pension-verification.example.biz/kyc
    Credential harvesting formImpersonates State Pension Directorateyesterday
  • HighDepartment of Citizen Services loginblocked
    https://citizenservices-gov-in.secure-login.net/auth
    Pixel-perfect phishing replicaImpersonates Department of Citizen Services2 days ago
  • CriticalMicrosoft 365 sign-inblocked
    https://urldefense.example.com/v3/__https://harvest.example.ru/login__
    Abused URL-rewriting serviceImpersonates Microsoft2 days ago
Active policies

Inspecting the rendered page and following every redirect is what separates this from domain-reputation filtering.

Configure
  • Block deceptive and impersonating sitesRendered pageRedirect chainComputer visionLanguage analysis186Active
  • Prevent personal data entry into untrusted sitesRendered pageRedirect chainLanguage analysisClassification-awareBlocks data entry44Active
  • Elevated protection for privileged usersRendered pageRedirect chainComputer visionLanguage analysisClassification-awareBlocks data entry22Active
  • Block unsanctioned AI servicesClassification-awareBlocks data entry312Active

The three modules together

Discovery knows what data is sensitive. Access Assurance knows who is accessing it. This gateway controls how and where it moves at the last point of human contact. Together they make protection preventive — stopping a disclosure before there is anything to notify anyone about, which is the only outcome that avoids the notification obligation entirely.

Related