Protection without data leaving your organization

Data Loss Prevention (DLP), content and email security

We deploy systems that control the exit of sensitive data from your organization at the content level and scan email for malicious content, on your organization's own servers (on-premise, meaning on your own hardware). Content filtering and email scanning are performed in-house; your data never leaves.

Explainer

What is data and email security?

Data Loss Prevention (DLP) is the layer that controls, at the content level, the unauthorised exit of sensitive data (personal data, contracts, technical documents) from the organization. Email security protects email, the most common attack surface, against phishing, malicious attachments and spoofed senders. For organizations, the critical question is usually not the technology itself but where the content is scanned. Sending sensitive email and files to cloud services is unacceptable for most public sector and healthcare institutions.

C3T is an implementing partner, not a product vendor. We securely deploy open source content filtering and the email gateway, integrate them with existing systems and operate them.

How do on-premise DLP and email security work?

C3T deploys data and email security on the organization's own servers, without data ever leaving. There are two main layers: (1) Data Loss Prevention — Squid/Ziproxy content filtering and data classification with on-premise AI block policy-violating transfers at the exit points of sensitive data; (2) email security — Proxmox Mail Gateway and local NLP provide antispam, phishing detection, malicious attachment and link filtering, sender spoofing checks and quarantine. Email and file content is not sent to cloud services for scanning. This approach is aligned with the technical measures of KVKK Article 12 and the data security topics of BİGR.

What we do: DLP and email security

We design data and email security in two main layers: content-level Data Loss Prevention and email threat protection. Both run on-premise and are fully auditable.

Data Loss Prevention (DLP)

Controls the exit of sensitive data from the organization at the content level.

  • Content filtering (Squid / Ziproxy proxy layer)
  • Data classification with on-premise AI
  • Blocking of policy-violating data transfers
  • Web and egress point control
  • Auditable egress logging

Email security

Scans inbound and outbound email without content ever leaving.

  • Email gateway with Proxmox Mail Gateway
  • Antispam and phishing detection with local NLP
  • Malicious attachment and link filtering
  • Sender spoofing checks
  • Quarantine and reporting

Malicious site and content filtering

The Squid/Ziproxy proxy layer filters access to malicious and policy-violating sites; web egress is logged in an auditable way. Filtering rules are defined specifically for your organization and the system runs on-premise, on the organization's own infrastructure.

Open source stack and on-premise AI

We build data and email security on three principles: an open source stack, on-premise AI and an implementer approach.

Open source stack

Deployed with Squid/Ziproxy content filtering and Proxmox Mail Gateway, with no licence costs and no vendor lock-in.

On-premise AI

Data classification and email NLP models run on the organization's own hardware; email and file content never leaves the organization.

Implementer approach

C3T does not sell products; we securely deploy the open source stack, integrate it with existing systems and operate it.

What we have built

Concrete examples showing scope and capability level, without naming organizations for confidentiality reasons.

Email gateway running inside the organization

Antispam/phishing filtering with Proxmox Mail Gateway and local NLP; quarantining of malicious attachments and links. Email content is not sent outside the organization for scanning, and audit logs are kept in-house.

On-premise content filtering and DLP layer

Content filtering on a Squid/Ziproxy proxy and data classification with on-premise AI; blocking policy-violating transfers at the exit points of sensitive data, with auditable logging. Access to malicious sites and content is filtered.

Compliance context

Which compliance obligations does it address?

This on-premise approach, which scans content and email inside the organization, directly contributes to the technical data security measures under Article 12 of KVKK Law No. 6698 and to the data leakage prevention topics of the Presidency's BİGR (Turkey's Information and Communication Security Guide). It records the exit points of sensitive data in an auditable way and keeps data within the organization's boundaries. We cover the full compliance obligation on the compliance consulting page.

Frequently asked questions

Does any content leave the organization for email and data scanning?

No. The email gateway (Proxmox Mail Gateway) and the content classification model run on the organization's own servers, on-premise (on your own hardware). Email bodies, attachments and file contents are not sent to cloud services for scanning, so KVKK (Turkish Personal Data Protection Law) and data sovereignty requirements are preserved.

Will DLP and email security work with our existing infrastructure?

In most cases, yes. Content filtering relies on a Squid/Ziproxy-based proxy layer, while email security relies on a gateway positioned in front of on-premise or cloud email services. Your existing network topology and email flow are assessed during the free feasibility call; new hardware is not mandatory.

Which compliance obligations does it address?

It directly contributes to the technical data security measures under Article 12 of KVKK Law No. 6698 and to the data leakage prevention topics of the Presidency's BİGR (Turkey's Information and Communication Security Guide). It records the exit points of sensitive data in an auditable way.

Is open source DLP mature enough?

A ready-made, end-to-end open source DLP product is limited; we say this openly. C3T turns this layer into practical and auditable protection by combining content filtering, on-premise AI data classification and an email gateway. For critical needs, it is designed together with SOC/SIEM and incident response layers.

Can it be used together with cloud email services?

Yes. The email gateway can be positioned in front of cloud email services as well as on-premise servers; inbound and outbound traffic is routed through the gateway so that antispam, phishing and malicious attachment checks are performed within the organization.

Who operates the system after deployment?

C3T is an implementing partner, not a consultant who writes a report and leaves. We install the system, put it into operation and, on request, take over its day-to-day operation; rules, the classification model and quarantine policies are matured together over time.

Is data and email security right for your organization?

Let's assess your current email flow and data exit points together. Find out what can be done without your data ever leaving your organization, in a free security feasibility call.