EIR — Data Classification Platform

EIR finds where your sensitive data lives — across cloud, SaaS, on-prem, and hybrid environments. It tells you who to report to under Canadian law and connects directly to a Canadian SOC for live response. One contract. 100% Canadian.

The Problem

Your sensitive data is not where you think it is.

Passwords get pasted into Jira comments. Government IDs end up in undocumented CRM fields. Cloud storage buckets go public without anyone noticing. Health records sit in support ticket attachments. Spreadsheets with personal data collect dust on file servers no one has audited in years.

Traditional DLP tools only watch network traffic and email. They can't read comment history, explore your CRM schema, or scan every object across every cloud account.

EIR does all of it — one platform, Canadian infrastructure, with a live analyst team behind every critical finding.

What EIR Classifies

EIR connects to every place where sensitive data can hide — SaaS apps, cloud platforms, databases, collaboration tools, code repos, file servers, and email archives. Every connection is read-only and no raw data ever leaves your environment.

CRM and Customer Platforms

Salesforce

Scans every standard and custom object, attached files (with OCR), and Chatter posts. Discovers custom fields automatically and stays current within five minutes of any change.

HubSpot

Contacts, companies, deals, tickets, engagement notes, call transcripts, and file attachments — including custom properties across all object types.

Dynamics 365

All standard and custom entities, document attachments via SharePoint, activity records, and Dataverse tables.

Zendesk

Full ticket history — subjects, descriptions, comments, attachments, and custom fields across all objects.

ServiceNow

Incidents, problems, changes, requests, knowledge base articles, attachments, and custom tables.

Project and Collaboration Tools

Jira Cloud & Data Center

Complete history — every issue, comment, attachment, and custom field. Built-in credential detector catches cloud keys, database passwords, and tokens. New credentials flagged within 60 seconds.

Confluence

Pages, comments, and attachments across all spaces — including version history, so data that was "edited out" is still found.

Linear, Shortcut, Asana, Monday.com

Tasks, comments, attachments, and custom fields across all projects.

Notion

Pages, database properties, and attachments. Block-level classification across your entire workspace.

Slack (Beta)

Channel and direct messages, file attachments, and workflow outputs. Credential and PII detection in message history.

Cloud Platforms

Google Cloud Platform

Cloud Storage, BigQuery, Cloud SQL, Spanner, Firestore, and Google Drive. Classification runs inside your GCP project — no data leaves your boundary.

Amazon Web Services

S3, RDS, Aurora, DynamoDB, Athena, Glue Catalog, and Redshift. Secure cross-account access with real-time change detection.

Microsoft Azure

Blob Storage, ADLS Gen2, Azure SQL, Cosmos DB, Synapse, and managed databases. Minimum-privilege access with event-driven delta scanning.

Oracle Cloud

Object Storage, Autonomous Database, and MySQL HeatWave. No credentials stored outside OCI.

Microsoft 365 & Google Workspace

SharePoint Online & OneDrive

Document libraries, files, and list items. Covers version history so "deleted" data is still found. Real-time change detection via Graph webhooks.

Exchange Online

Mailbox content, attachments, calendar items, and contact data.

Microsoft Teams

Channel and chat messages, file attachments, meeting metadata, and Planner tasks.

Google Workspace

Gmail, Drive, Docs, Sheets, Slides, and Forms. Org-unit scoping for large deployments.

Databases & Data Warehouses

Read-only connections to every major database. Column names are checked first — sensitive-sounding fields are flagged before any row data is sampled.

Relational: PostgreSQL, MySQL, SQL Server, Oracle, Aurora, Azure SQL, Cloud SQL, Db2, SAP HANA

NoSQL: MongoDB, DynamoDB, Cosmos DB, Cassandra, Couchbase, Redis

Data Warehouses: Snowflake, BigQuery, Redshift, Synapse, Databricks, Teradata

File-based: Parquet, Avro, ORC, Delta Lake tables in object storage

File Systems & Storage

On-Premises File Servers

Windows shares (SMB/CIFS), Linux NFS, and NAS systems. Single-binary agent with no dependencies — deploy via NinjaOne, Intune, Jamf, SCCM, or manually.

Cloud File Storage

Dropbox Business, Box Enterprise, and Egnyte. File content and metadata classification via OAuth.

Code Repositories

GitHub & GitHub Enterprise

Repos, issues, PRs, and wikis. Secret scanning catches API keys, tokens, and credentials committed to code.

GitLab Cloud & Self-Managed

Same coverage as GitHub. PAT authentication for self-managed instances.

Bitbucket Cloud & Data Center

Repo and pull request classification with workspace-level coverage.

Azure DevOps

Repos, work items, wikis, and pipeline definitions.

Email Archives

Microsoft Exchange On-Premises

Mailbox scanning via EWS API with configurable date ranges. Classifies attachments including PST files.

Email Archive Formats

PST, MBOX, and EML files via on-prem agent. Proofpoint, Mimecast, and Barracuda archive connectors.

How EIR Works

1

Discover

1–2 hours

Maps every connected data source without reading content. Builds a complete inventory — schemas, buckets, SaaS objects, and custom fields. You get a data estate dashboard before classification even starts.

2

Prioritise

Automatic

Ranks sources by risk before reading content. Sensitive-sounding field names, PII patterns, and access anomalies get scanned first. 85–90% of findings surface within the first eight hours.

3

Classify

2–72 hours

Two-tier engine runs in parallel. Tier 1: 500+ regex patterns for PIPEDA, PCI-DSS, HIPAA, GDPR, and 15+ frameworks — fully offline. Tier 2: AI-assisted classification for ambiguous findings, with local LLM fallback for air-gapped sites.

4

Alert & Respond

Real-time

Findings appear instantly with data type, sensitivity level, confidence score, location, and remediation steps. P1/P2 findings auto-escalate to MSOC for Managed Service clients.

5

Report & Comply

Automated

Each reportable finding shows the exact regulatory chain — correct regulator, deadline, pre-filled breach forms, and draft notification letters. Export the full compliance package for audit.

6

Delta

Continuous

After the baseline scan, EIR watches for changes in real time. New or modified records, files, and messages are re-classified within minutes — not on the next scheduled scan.

Regulatory Reporting Guidance

EIR goes beyond detection — it tells you exactly who to report to, by when, and with what forms. When a critical finding is discovered, you get the specific regulator, deadline, and pre-filled documents for your jurisdiction. Updated quarterly as legislation changes.

PIPEDA — Personal Information Protection

Covers private-sector organizations across Canada handling personal information.

  • Regulator: Office of the Privacy Commissioner (OPC)
  • Threshold: Real risk of significant harm (RROSH)
  • Timeline: Report to OPC as soon as feasible; notify individuals simultaneously
  • EIR provides: Pre-filled OPC breach form, RROSH checklist, sample notification letter

PHI — Provincial Health Privacy

Covers health information custodians in each province.

  • Ontario — PHIPA: IPC Ontario. Report within 90 days.
  • Alberta — HIA: OIPC Alberta. Report as soon as practicable.
  • BC — PIPA: OIPC BC. Triggered by risk of significant harm.
  • Cross-border — HIPAA: HHS OCR. 60-day window tracked automatically.
  • EIR provides: Auto-detected jurisdiction, correct commissioner, provincial templates, HIPAA checklist

PFI — Payment & Financial (PCI-DSS v4.0)

Covers any organization that stores, processes, or transmits cardholder data.

  • Report to: Acquiring bank immediately, card brands within 24 hours
  • PFI requirement: PCI Forensic Investigator for 10,000+ affected accounts
  • EIR provides: Bank contact lookup by BIN, Visa/Mastercard notification forms, PFI roster

PII — Quebec Law 25, GDPR, and CASL

  • Quebec Law 25: CAI notification within 72 hours. Pre-filled form and incident register included.
  • GDPR: Correct supervisory authority by EU member state. 72-hour deadline tracked.
  • CASL: Electronic address exposure assessment and scope documentation.

EIR regulatory guidance accelerates your breach response. It does not constitute legal advice. Engage your legal counsel for final breach notification decisions.

Data Types Detected

Eight categories, 500+ detection patterns.

Identity SINs, SSNs, passports, driver's licences, national IDs (40+ countries), date of birth combinations.
Financial Credit cards (Luhn-validated), IBANs, SWIFT codes, bank accounts, routing numbers, tax IDs.
Health & PHI Health cards (all provinces), medical records, ICD-10 codes, prescriptions, insurance IDs.
Authentication & Secrets API keys (60+ services), OAuth/JWT tokens, private keys, database connection strings, env files, container secrets.
Contact & Personal Names with contact info, emails, phone numbers, addresses, IPs tied to individuals.
Corporate Sensitive Financial projections, M&A materials, IP, strategic plans, personnel records, legal correspondence.
Network & Infrastructure Internal IPs, hostnames, VPN credentials, firewall configs, IaC files with embedded secrets.
Regulated Data Structured personal data matched against applicable regulatory frameworks.

Classification Levels

Level Description Default Response
Public Approved for external distribution No action required
Internal Internal use only, no regulatory obligation Periodic review
Confidential Business sensitive, limited distribution Access review, DLP policy update
Restricted Regulatory or legal sensitivity — PII, PHI, payment data, credentials Remediation required
Secret Highest sensitivity — government IDs, cryptographic keys, M&A materials Immediate response

Classification levels are configurable and can be mapped to your existing data classification policy.

Compliance Frameworks

Framework Jurisdiction Sector
PIPEDA Canada — Federal All private sector
Quebec Law 25 Quebec All private sector
PHIPA Ontario Health
HIA Alberta Health
PIPA British Columbia Health
GDPR European Union All
HIPAA United States Health
PCI-DSS v4.0 Global Payment
CASL Canada Electronic communication
SOX United States Public companies
OSFI B-10 Canada Financial institutions
NIST SP 800-53 United States Federal / government
NIST CSF 2.0 United States All
ISO/IEC 27001 International All
CIS Controls v8 International All

Why Mjolnir Security

Canadian Sovereignty

Every major data classification vendor is US-based and subject to the US CLOUD Act — meaning a US subpoena can access your data without telling you. For CRTC, OSFI, or provincially regulated organizations, that's a deal-breaker.

Mjolnir is a Canadian corporation running EIR from Canadian datacenters. Classification happens inside your cloud boundary — only finding metadata leaves, never raw data. No US authority can compel disclosure through Mjolnir.

Live SOC Response

When EIR finds a critical exposure, it opens an incident in MSOC — staffed by Canadian analysts. Remediation guidance is issued before your team even sees the dashboard alert. No other classification platform includes findings-to-analyst response under one contract.

Ecosystem Integration

EIR plugs into the full Mjolnir platform:

  • YGGDRASIL — Findings become tracked remediation cases with evidence chain
  • HEIMDALL-DLP — Findings auto-generate network detection rules
  • MUNINN — Credentials cross-referenced against dark web databases
  • FORSETI — Compliance findings feed into GRC reporting
  • MSOC — Auto-escalation for live analyst response

Transparent Pricing

Fixed slab pricing, locked at contract. No per-user fees. No per-connector surprises. No premium support tiers. Contact us for a quote.

Air-Gap & Sovereign Cloud

Tier 1 engine runs fully offline with no external dependencies. Tier 2 AI supports a local LLM fallback. Full air-gapped deployment available for classified environments.

Security & Architecture

Frequently Asked Questions

Does EIR read our raw data?

EIR reads content in memory, classifies it, and immediately discards it. Only finding metadata (data type, sensitivity, location) is sent to Mjolnir's Canadian servers — never raw data.

How long does the initial scan take?

Discovery takes 1–2 hours. First findings appear within 2–8 hours. Full classification completes in 48–72 hours, with 85–90% of risk findings surfaced in the first eight hours.

What happens when a critical finding is discovered?

Critical findings trigger instant dashboard alerts. Managed Service clients get automatic escalation to MSOC where an analyst begins response immediately. Self-serve clients get alerts with remediation steps and regulatory guidance.

Is our data subject to US law?

No. Mjolnir is a Canadian corporation operating from Canadian datacenters. Not subject to the US CLOUD Act.

Do you support air-gapped environments?

Yes. Tier 1 runs fully offline with no dependencies. Tier 2 supports a local LLM fallback. Full air-gapped deployment available.

Can EIR connect to sources not listed here?

Yes. Custom connectors can be built for legacy ERPs, proprietary databases, and sector-specific platforms. Contact us to discuss.

How does EIR handle regulatory framework updates?

Guidance is reviewed and updated quarterly. Managed Service clients are proactively notified of regulatory changes affecting their data.

🔍

500+ Detection Patterns

Covers PIPEDA, PCI-DSS, HIPAA, GDPR, Quebec Law 25, and 40+ country ID formats. Runs entirely offline.

🇨🇦

100% Canadian

Canadian corporation. Canadian datacenters. Not subject to the US CLOUD Act.

🛡

Live SOC Response

P1 findings trigger active incident response in MSOC with a Canadian analyst — not just a dashboard alert. Findings to analyst under one contract.

Related Services

Find Your Sensitive Data Before Someone Else Does

Start with a one-hour scoping call. First findings delivered within 48 hours of access.