Talk to an Expert

Tell us about your stack and the privacy problems you're trying to solve. We typically respond within one business day.

Prefer to skip the form? Pick a time on our calendar →
or send a message

PII flow monitoring and alerting

Phield

Phield is intelligent monitoring that tracks how PII moves through your systems and alerts on suspicious activity, unexpected volumes, or unusual access patterns. Think of it as the privacy equivalent of endpoint detection — but for sensitive data in motion.

View on GitHub

Why Phield

Real-time flow tracking

See PII move between systems as it happens. Counts per entity type, per context, per pipeline — built from the same detection layer the rest of the toolkit uses.

Baseline-aware alerts

Phield learns each pipeline's normal traffic shape and pages only when something is meaningfully anomalous. No flood of low-signal alarms from routine activity.

Audit-ready logs

Every detection is logged with timestamp, entity type, count, and source. Hand the log directly to auditors or regulators when they ask what flowed where.

Plug into your SIEM

Exports detections to Splunk, OpenSearch, Datadog, or any system that ingests structured JSON. Phield doesn't replace your security pipeline — it feeds it the signal it was missing.

Policy-aware

Uses the same Phileas policies as Philter and Phinder. The entity types you redact are the entity types Phield monitors — one definition, three behaviors.

Self-hosted

Runs entirely inside your perimeter. No SaaS dashboard, no third-party log shipping, no chance of your detection telemetry leaking out the side.

Ready to use Phield?

Three ways to get going — deploy the open source yourself, spin it up from a cloud marketplace, or work with our team directly. Pick the path that fits.

See your options