dtwo Policy Store

Policies tagged "exfiltration"

bigquery · ingress

Block BigQuery Exfiltration and Cross-Project Writes

Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…

bigqueryguard-warehouse-exportingresssqlexfiltrationsoc2pci-dssgdpr-ccpa

snowflake · ingress

Block Bulk Export & External Staging (Snowflake)

Blocks Snowflake SQL-execution tool calls whose query text moves whole tables off the Snowflake perimeter — bulk export to cloud storage or a stage, and…

snowflakeguard-warehouse-sqlexportexfiltrationingresssoc2pci-dssgdpr-ccpa

linear · ingress

Block Linear Webhook Creation

Unconditionally denies any Linear tool that creates, updates, or deletes a webhook — linear createWebhook, linear deleteWebhook, and update variants.

linearguard-webhook-persistenceingresswebhookexfiltrationsoc2

power-bi · ingress

Guard DAX Whole-Table Dumps in Power BI

Power BI semantic models front the warehouse: a model imports or DirectQueries lakehouse/warehouse tables — finance, HR, customer PII.

power-biguard-warehouse-sqlingressdaxexfiltrationsoc2gdpr-ccpa

slack · ingress

Slack: Block Agent Posts to External Channels

Denies Slack message-write calls whose destination is an externally shared Slack Connect channel.

slackguard-external-sendslack-connectexfiltrationingresssoc2gdpr-ccpahipaa