EIR finds where your sensitive data lives — across cloud, SaaS, on-prem, and hybrid environments. It tells you who to report to under Canadian law and connects directly to a Canadian SOC for live response. One contract. 100% Canadian.
Your sensitive data is not where you think it is.
Passwords get pasted into Jira comments. Government IDs end up in undocumented CRM fields. Cloud storage buckets go public without anyone noticing. Health records sit in support ticket attachments. Spreadsheets with personal data collect dust on file servers no one has audited in years.
Traditional DLP tools only watch network traffic and email. They can't read comment history, explore your CRM schema, or scan every object across every cloud account.
EIR does all of it — one platform, Canadian infrastructure, with a live analyst team behind every critical finding.
EIR connects to every place where sensitive data can hide — SaaS apps, cloud platforms, databases, collaboration tools, code repos, file servers, and email archives. Every connection is read-only and no raw data ever leaves your environment.
Scans every standard and custom object, attached files (with OCR), and Chatter posts. Discovers custom fields automatically and stays current within five minutes of any change.
Contacts, companies, deals, tickets, engagement notes, call transcripts, and file attachments — including custom properties across all object types.
All standard and custom entities, document attachments via SharePoint, activity records, and Dataverse tables.
Full ticket history — subjects, descriptions, comments, attachments, and custom fields across all objects.
Incidents, problems, changes, requests, knowledge base articles, attachments, and custom tables.
Complete history — every issue, comment, attachment, and custom field. Built-in credential detector catches cloud keys, database passwords, and tokens. New credentials flagged within 60 seconds.
Pages, comments, and attachments across all spaces — including version history, so data that was "edited out" is still found.
Tasks, comments, attachments, and custom fields across all projects.
Pages, database properties, and attachments. Block-level classification across your entire workspace.
Channel and direct messages, file attachments, and workflow outputs. Credential and PII detection in message history.
Cloud Storage, BigQuery, Cloud SQL, Spanner, Firestore, and Google Drive. Classification runs inside your GCP project — no data leaves your boundary.
S3, RDS, Aurora, DynamoDB, Athena, Glue Catalog, and Redshift. Secure cross-account access with real-time change detection.
Blob Storage, ADLS Gen2, Azure SQL, Cosmos DB, Synapse, and managed databases. Minimum-privilege access with event-driven delta scanning.
Object Storage, Autonomous Database, and MySQL HeatWave. No credentials stored outside OCI.
Document libraries, files, and list items. Covers version history so "deleted" data is still found. Real-time change detection via Graph webhooks.
Mailbox content, attachments, calendar items, and contact data.
Channel and chat messages, file attachments, meeting metadata, and Planner tasks.
Gmail, Drive, Docs, Sheets, Slides, and Forms. Org-unit scoping for large deployments.
Read-only connections to every major database. Column names are checked first — sensitive-sounding fields are flagged before any row data is sampled.
Relational: PostgreSQL, MySQL, SQL Server, Oracle, Aurora, Azure SQL, Cloud SQL, Db2, SAP HANA
NoSQL: MongoDB, DynamoDB, Cosmos DB, Cassandra, Couchbase, Redis
Data Warehouses: Snowflake, BigQuery, Redshift, Synapse, Databricks, Teradata
File-based: Parquet, Avro, ORC, Delta Lake tables in object storage
Windows shares (SMB/CIFS), Linux NFS, and NAS systems. Single-binary agent with no dependencies — deploy via NinjaOne, Intune, Jamf, SCCM, or manually.
Dropbox Business, Box Enterprise, and Egnyte. File content and metadata classification via OAuth.
Repos, issues, PRs, and wikis. Secret scanning catches API keys, tokens, and credentials committed to code.
Same coverage as GitHub. PAT authentication for self-managed instances.
Repo and pull request classification with workspace-level coverage.
Repos, work items, wikis, and pipeline definitions.
Mailbox scanning via EWS API with configurable date ranges. Classifies attachments including PST files.
PST, MBOX, and EML files via on-prem agent. Proofpoint, Mimecast, and Barracuda archive connectors.
Maps every connected data source without reading content. Builds a complete inventory — schemas, buckets, SaaS objects, and custom fields. You get a data estate dashboard before classification even starts.
Ranks sources by risk before reading content. Sensitive-sounding field names, PII patterns, and access anomalies get scanned first. 85–90% of findings surface within the first eight hours.
Two-tier engine runs in parallel. Tier 1: 500+ regex patterns for PIPEDA, PCI-DSS, HIPAA, GDPR, and 15+ frameworks — fully offline. Tier 2: AI-assisted classification for ambiguous findings, with local LLM fallback for air-gapped sites.
Findings appear instantly with data type, sensitivity level, confidence score, location, and remediation steps. P1/P2 findings auto-escalate to MSOC for Managed Service clients.
Each reportable finding shows the exact regulatory chain — correct regulator, deadline, pre-filled breach forms, and draft notification letters. Export the full compliance package for audit.
After the baseline scan, EIR watches for changes in real time. New or modified records, files, and messages are re-classified within minutes — not on the next scheduled scan.
EIR goes beyond detection — it tells you exactly who to report to, by when, and with what forms. When a critical finding is discovered, you get the specific regulator, deadline, and pre-filled documents for your jurisdiction. Updated quarterly as legislation changes.
Covers private-sector organizations across Canada handling personal information.
Covers health information custodians in each province.
Covers any organization that stores, processes, or transmits cardholder data.
EIR regulatory guidance accelerates your breach response. It does not constitute legal advice. Engage your legal counsel for final breach notification decisions.
Eight categories, 500+ detection patterns.
| Level | Description | Default Response |
|---|---|---|
| Public | Approved for external distribution | No action required |
| Internal | Internal use only, no regulatory obligation | Periodic review |
| Confidential | Business sensitive, limited distribution | Access review, DLP policy update |
| Restricted | Regulatory or legal sensitivity — PII, PHI, payment data, credentials | Remediation required |
| Secret | Highest sensitivity — government IDs, cryptographic keys, M&A materials | Immediate response |
Classification levels are configurable and can be mapped to your existing data classification policy.
| Framework | Jurisdiction | Sector |
|---|---|---|
| PIPEDA | Canada — Federal | All private sector |
| Quebec Law 25 | Quebec | All private sector |
| PHIPA | Ontario | Health |
| HIA | Alberta | Health |
| PIPA | British Columbia | Health |
| GDPR | European Union | All |
| HIPAA | United States | Health |
| PCI-DSS v4.0 | Global | Payment |
| CASL | Canada | Electronic communication |
| SOX | United States | Public companies |
| OSFI B-10 | Canada | Financial institutions |
| NIST SP 800-53 | United States | Federal / government |
| NIST CSF 2.0 | United States | All |
| ISO/IEC 27001 | International | All |
| CIS Controls v8 | International | All |
Every major data classification vendor is US-based and subject to the US CLOUD Act — meaning a US subpoena can access your data without telling you. For CRTC, OSFI, or provincially regulated organizations, that's a deal-breaker.
Mjolnir is a Canadian corporation running EIR from Canadian datacenters. Classification happens inside your cloud boundary — only finding metadata leaves, never raw data. No US authority can compel disclosure through Mjolnir.
When EIR finds a critical exposure, it opens an incident in MSOC — staffed by Canadian analysts. Remediation guidance is issued before your team even sees the dashboard alert. No other classification platform includes findings-to-analyst response under one contract.
EIR plugs into the full Mjolnir platform:
Fixed slab pricing, locked at contract. No per-user fees. No per-connector surprises. No premium support tiers. Contact us for a quote.
Tier 1 engine runs fully offline with no external dependencies. Tier 2 AI supports a local LLM fallback. Full air-gapped deployment available for classified environments.
EIR reads content in memory, classifies it, and immediately discards it. Only finding metadata (data type, sensitivity, location) is sent to Mjolnir's Canadian servers — never raw data.
Discovery takes 1–2 hours. First findings appear within 2–8 hours. Full classification completes in 48–72 hours, with 85–90% of risk findings surfaced in the first eight hours.
Critical findings trigger instant dashboard alerts. Managed Service clients get automatic escalation to MSOC where an analyst begins response immediately. Self-serve clients get alerts with remediation steps and regulatory guidance.
No. Mjolnir is a Canadian corporation operating from Canadian datacenters. Not subject to the US CLOUD Act.
Yes. Tier 1 runs fully offline with no dependencies. Tier 2 supports a local LLM fallback. Full air-gapped deployment available.
Yes. Custom connectors can be built for legacy ERPs, proprietary databases, and sector-specific platforms. Contact us to discuss.
Guidance is reviewed and updated quarterly. Managed Service clients are proactively notified of regulatory changes affecting their data.
Covers PIPEDA, PCI-DSS, HIPAA, GDPR, Quebec Law 25, and 40+ country ID formats. Runs entirely offline.
Canadian corporation. Canadian datacenters. Not subject to the US CLOUD Act.
P1 findings trigger active incident response in MSOC with a Canadian analyst — not just a dashboard alert. Findings to analyst under one contract.
Start with a one-hour scoping call. First findings delivered within 48 hours of access.