Incydr in 2026: What Code42's Insider Risk Tool Sees, and What It Never Reads

Incydr in 2026: What Code42's Insider Risk Tool Sees, and What It Never Reads

Incydr, the insider risk product Code42 built and Mimecast now owns, is one of the most recognizable names in data exfiltration detection. Security teams like it for a simple reason: you install it, and within days you can see files leaving the company without writing a single DLP policy. In 2026, though, the riskiest data leaving most companies is not a file. It is a paragraph pasted into an AI prompt. If you are comparing the whole category, our guide to the best data loss prevention tools ranks the field. This post goes deep on Incydr.

The short answer

Incydr is a detection-first insider risk tool that tells you a paste or upload happened and where it went, not what it said: Mimecast's own documentation says the Incydr browser extension does not access the content of pasted data or read the contents of uploaded files, and its optional content inspection add-on scans files only after they reach an untrusted destination. dope.security takes the opposite approach. Dopamine DLP reads AI prompts and file uploads on the device before they leave, classifies them with large language models, and can block the sensitive ones in real time.

That is a testable claim. Paste a customer list into a personal ChatGPT session on a managed laptop, then check what each tool recorded: the destination, or the data.

What is Incydr?

Incydr started life at Code42, a Minneapolis company founded in 2001 and best known for years as the maker of CrashPlan backup. Over time Code42 moved away from consumer backup and toward insider risk management, and Incydr grew out of that pivot.

  • May 2022. Permira completed its take-private of Mimecast for roughly $5.8 billion.
  • July 24, 2024. Mimecast announced it had acquired Code42, saying Incydr was available to Mimecast customers immediately, with platform integration to follow.
  • 2025. Mimecast added single sign-on from its admin console into Incydr and began feeding Incydr exfiltration events into its Human Risk Command Center scoring.
  • 2026. Mimecast markets the product as Incydr Data Protection, part of its human risk management platform.

Mimecast's support documentation describes Incydr as a "SaaS data risk detection and response product" for file exposure and exfiltration risk. That framing matters. Incydr was designed to answer "who moved what file where," then help you respond. It was not designed as an inline, content-aware gate.

How Incydr works

Incydr collects events from several places and scores them with a risk engine Mimecast calls PRISM, which Mimecast says weighs more than 250 risk indicators.

  • Endpoint agent. The Incydr insider risk agent runs on Windows, Mac, and Linux. Mimecast lists minimum requirements of a 2 GHz CPU, 2 GB of RAM, and 2 GB of disk, and notes the agent is optimized for single-user devices.
  • Browser extension. The extension adds web context for uploads and pastes in Chrome, Edge, Firefox, Prisma Access Browser, and Island, with Safari 18.4 and later on macOS 15 in early access. It can only be deployed to managed browsers.
  • Cloud and SaaS connectors. Connectors cover Microsoft 365 OneDrive and SharePoint, Google Drive, and Box, with Salesforce and email available as add-ons.
  • Response. Incydr Flows automate response through tools like Slack, Teams, Okta, and Workday, and the Instructor add-on sends short training videos to employees after risky activity.

Mimecast's packaging lists Professional and Enterprise plans, with 30 and 90 days of event retention respectively, and treats content inspection and Instructor as add-ons. If you are weighing where DLP should enforce in the first place, our breakdown of endpoint DLP vs network DLP covers the trade-offs.

What Incydr does well

Credit where it is due. Incydr earns its reputation, and customers rate it highly.

  • Visibility without policy writing. Mimecast pitches "visibility from day one, no policies required," and that is the point. You see exfiltration patterns before you tune anything.
  • Insider risk context. Watchlists for departing employees, contractors, and high-risk users focus attention where it belongs. Our post on insider risk management for data in motion covers why that context matters.
  • A response loop, not just alerts. Flows and Instructor turn a detection into a ticket, a manager notification, or a training nudge.
  • Early AI destination tracking. Mimecast added AI tool risk indicators for file uploads to 14 AI tools in May 2024, extended them to paste events that July, added DeepSeek in January 2025, and added 30 more AI tools plus a catch-all "Other AI Tool" indicator in February 2025.
  • Customer ratings. Incydr holds about 4.6 out of 5 on Gartner Peer Insights across roughly 100 ratings.

If your program is about departing employees, file movement, and investigations, Incydr is a credible choice.

Where Incydr gets complicated for AI in 2026

The AI story is where Incydr's design shows its edges. Everything below comes from Mimecast's own documentation and announcements.

It sees that a paste happened, not what was pasted

Mimecast's browser extension documentation says the extension "does not access the content of the copied/pasted data" and "does not read the contents of uploaded files." It records that a paste or upload happened and where it went. Paste activity inside desktop apps is not monitored, and the paste source only appears when content is copied and pasted within the same browser. For AI, that means Incydr can tell you an engineer pasted something into ChatGPT. It cannot tell you whether that something was a source code secret or a lunch order.

Content inspection is an add-on, and it runs after the fact

Incydr does offer content inspection, as a separate add-on. Mimecast's documentation says it inspects files only when they are exfiltrated to untrusted locations, processes them in the Incydr cloud, and is "not designed for general data discovery." Built-in detectors cover PII types for a handful of countries plus credentials and tokens in source code, and custom indicators are capped at 10 terms of 500 characters each. It is file inspection after exfiltration, not prompt inspection before submission.

Blocking is based on destinations and trust lists

Incydr added real-time blocking in 2023, and today its preventative controls can block uploads and pastes to untrusted destinations, block specific destinations, browsers, and apps, block private browsing, block USB mounting, and block external cloud sharing. Those controls are useful. They are also decided by where data goes, using the admin's trusted activity list, not by what the data contains. Mimecast documents that web blocking requires the browser extension, that destination and source blocking work on Windows and macOS only, and that blocked events do not generate alerts by default.

The agentic AI controls are still rolling out

At Black Hat on August 3, 2026, Mimecast unveiled an Agent Risk Center with desktop app blocking, browser upload and paste blocking, and user nudges. Mimecast says it is in early access in September 2026, with general availability planned for January 2027. That is a promising roadmap, but it is not something you can roll out to every laptop today.

Customers report a policy learning curve

Gartner Peer Insights reviewers praise Incydr's reporting and training, while one notes that configuring new policies "can feel like coding in a user interface," and a May 2026 reviewer reports limitations on shared Azure Virtual Desktop hosts. These are customer reports, not universal truths, but they are worth testing in a proof of concept.

Incydr vs dope.security: the head-to-head

Both products want to stop sensitive data from walking out the door. They answer different questions. Here is the comparison, line by line.

  • What gets inspected. Incydr's browser extension records that a paste or upload happened and its destination, without reading the content. dope.security Dopamine DLP extracts the text of AI prompts and file uploads on the device and classifies it before it leaves.
  • When content is analyzed. Incydr's content inspection add-on scans files after they reach an untrusted location. Dopamine DLP classifies prompts and uploads in line, so a sensitive prompt can be blocked before the AI tool ever receives it.
  • How blocking decides. Incydr's preventative controls block by destination, source, browser, or app against a trusted activity list. dope.security blocks on the meaning of the data, using large language models through zero-retention OpenAI APIs, with no data retention and no training on your data.
  • Corporate vs personal AI accounts. Incydr's documented controls work on destinations and trust lists. dope.security Cloud Application Control allows the approved enterprise tenant and blocks personal ChatGPT, Claude, Google, and Microsoft 365 logins, and for Claude the control covers both browser and desktop app usage with OS-level enforcement.
  • Policy effort. Incydr gives visibility with no policies required, then asks you to tune risk indicators and trust lists. Dopamine DLP needs no rule configuration and runs in Block, Monitor, or Off mode, with a plain-language Dopamine Summary explaining each detection.
  • Endpoint footprint. Incydr lists a minimum of 2 GB of RAM for its agent. dope.endpoint runs natively on Mac and Windows using under 100 MB of RAM.
  • Web security. Incydr is an insider risk and data protection product, not a secure web gateway. dope.security is a Fly-Direct secure web gateway first, with SSL inspection, URL filtering, and anti-malware running on the device.
  • Investigations and training. Incydr's watchlists, Flows, and Instructor videos are built for insider risk programs and investigations. dope.security focuses on prevention at the moment of egress, with AI Usage Analytics showing which AI apps people use and how much.

Dopamine DLP is protected by US Patent 12,464,023. Read how it works in meet Dopamine DLP.

Replace Incydr, or run dope.security alongside it?

For many teams, this is not either-or. Incydr is strong at insider risk investigations. The AI prompt layer is where the gap sits.

Deployment is the part teams worry about, and it goes fastest. A Fortune 100 company scaled dope.security from 900 to more than 18,000 devices in weeks, deployed silently through Intune.

The bottom line on Incydr

Put simply: Incydr is excellent at showing you that data moved and who moved it, and its documentation is clear that its browser extension never reads the pasted text or uploaded file, which leaves the content of AI prompts outside its view. If you want every AI prompt and upload read, classified, and stopped on the laptop when it is sensitive, with personal AI accounts blocked and corporate ones working, that is what dope.security was built to do. Explore Dopamine DLP and the Fly-Direct Secure Web Gateway, or book a 20-minute demo and we will run the pasted customer list test live.

Frequently Asked Questions

Who owns Code42 Incydr?

Mimecast owns Incydr. Mimecast announced its acquisition of Code42 on July 24, 2024, and Mimecast itself has been privately owned by Permira since May 2022. Mimecast now markets the product as Incydr Data Protection within its human risk management platform.

Is Incydr a DLP tool?

Incydr is best described as an insider risk and data exfiltration detection and response product. It detects file movement across endpoints, cloud storage, and email, and adds preventative controls that block by destination, source, or app. Content inspection is a separate add-on that scans files after they reach untrusted locations, which is different from classic content-aware DLP.

Can Incydr see what employees paste into ChatGPT?

Incydr can detect that a paste or upload to ChatGPT happened, through its browser extension and AI tool risk indicators. Mimecast's documentation says the extension does not access the content of pasted data or read uploaded file contents. dope.security Dopamine DLP reads the prompt text and uploads on the device and can block sensitive content before submission.

Does Incydr block data exfiltration?

Yes, with limits. Incydr's preventative controls can block uploads and pastes to untrusted destinations, specific destinations, browsers and apps, private browsing, USB mounting, and external cloud sharing, applied to watchlists or all users. Web blocking requires the browser extension, and destination and source blocking work on Windows and macOS only.

What are the Incydr agent requirements?

Mimecast lists a 2 GHz CPU, 2 GB of RAM, and 2 GB of disk as minimums for the Incydr agent, on 64-bit Windows, Mac, and supported RHEL and Ubuntu releases. By comparison, dope.endpoint runs natively on Mac and Windows using under 100 MB of RAM.

Can I run dope.security alongside Incydr?

Yes. Many teams keep Incydr for insider risk investigations and add dope.security on the endpoint for web security and AI governance: Cloud Application Control for corporate AI tenants, Dopamine DLP for prompts and uploads, and CASB Neural for overshared files in OneDrive and Google Drive, all in one console.

Data Loss Prevention
Data Loss Prevention
Comparisons & Alternatives
Comparisons & Alternatives
AI Security
AI Security
Endpoint Security
Endpoint Security
← back to blog Home