Resources -> Tools

What is Code42 Incydr? Benefits, use cases, and alternatives

July 21, 2026
11 min read

Traditional data loss prevention earned a reputation for two things: blocking legitimate work and missing actual theft. Code42 built Incydr as a direct answer to that failure - a product that watches data movement itself rather than trying to classify every file upfront. Instead of policy engines that must predict what sensitive data looks like, Incydr monitors how files actually move - to personal cloud accounts, USB drives, browsers, AirDrop, git pushes, Salesforce downloads - and scores the risk of each event based on context like file source, destination, and the user's employment status. That focus made it the go-to platform for the single most common insider incident: departing employees taking data with them. Now part of Mimecast following its 2024 acquisition, Incydr sits among the handful of platforms insider risk managers evaluate most, prized for fast deployment and low-noise alerting - and best understood as an exfiltration specialist rather than an all-purpose monitoring suite.

What is Code42 Incydr?

Incydr is an insider risk management platform focused on detecting and responding to data exfiltration. A lightweight endpoint agent monitors file activity across the vectors data actually leaves through - web browsers, cloud sync clients, removable media, AirDrop, source-code pushes - and correlates each movement with context: where the file came from, where it went, and risk indicators about the user (like an upcoming departure date synced from HR systems). Events are prioritized by risk score so security teams see the exfiltration that matters instead of drowning in alerts. Response options range from automated micro-trainings that correct careless behavior, to case building for investigations, to blocking controls for high-risk users. Originally built by Code42 - the Minneapolis company known for CrashPlan backup - Incydr became the company's flagship after 2020 and is now sold under Mimecast, which acquired Code42 in 2024 and folded Incydr into its human risk management platform.

Code42 Incydr Growth Trajectory

Code42 was founded in 2001 in Minneapolis and spent its first two decades known primarily for CrashPlan, one of the most widely used endpoint backup products. That backup heritage turned out to be the strategic asset behind Incydr: a company that already watched every file on the endpoint was well positioned to watch where those files went. Code42 launched Incydr in 2020, divested CrashPlan in 2022 to focus entirely on insider risk, and raised significant venture backing (including a $175M round led by ICONIQ) along the way. In 2024, email security giant Mimecast acquired Code42, positioning Incydr as the data-exfiltration pillar of its human risk management platform - a combination that pairs Incydr's endpoint telemetry with Mimecast's email and collaboration security signals.

Code42 Incydr Market Positioning

Incydr is positioned as the exfiltration-focused alternative to both legacy DLP and surveillance-style monitoring. Against traditional DLP, its pitch is speed and signal: no months of data classification before value, and risk-scored events instead of policy-violation noise. Against monitoring platforms like Teramind, its pitch is proportionality: it watches file movement, not screens and keystrokes, which makes it easier to defend to employees and works councils. Industry comparisons consistently place it among the five most-evaluated insider risk platforms alongside Teramind, Proofpoint ITM, and DTEX, with particular strength in departing-employee and source-code theft scenarios. On G2, reviewers praise its ease of use and reliable detection. The open question buyers now weigh is the Mimecast integration path - a richer platform story, but also the roadmap uncertainty that follows any acquisition.

Code42 Incydr Impact Metrics

Among the Most-Evaluated Insider Risk Platforms | Built on Two Decades of Endpoint File Telemetry | Acquired by Mimecast in 2024

Customers consistently cite two outcomes: dramatically faster time-to-value than classification-first DLP (the agent deploys quickly and surfaces real exfiltration within days), and a step-change in alert quality - risk scoring and context mean analysts investigate genuine incidents like a departing engineer pushing source code to a personal repo, rather than triaging thousands of policy violations. Security teams also report that automated response tiers pay off operationally: careless mistakes get corrected with instant micro-training videos without analyst involvement, reserving human attention for the malicious minority. For organizations with high-turnover or acquisition-heavy environments, departing-employee workflows tied to HR data are the headline capability.

Code42 Incydr Key Features & Capabilities

Exfiltration Detection Across Vectors

Monitors file movement through browsers, cloud sync apps, USB and removable media, AirDrop, git, and salesforce downloads - the actual channels data leaves through, on and off network.

Risk Indicators & Prioritization

Each event is scored using contextual risk indicators - file source and type, destination trust, off-hours activity, and user attributes like departure status - so queues surface the riskiest events first.

Departing Employee Workflows

HR system integration flags resigning and offboarding users for heightened watch during the highest-risk window for data theft.

Tiered Automated Response

Responses scale to risk: automated security micro-trainings for careless behavior, case building and evidence packages for investigations, and blocking controls for high-risk users.

Source Code & IP Protection

Purpose-built detection for engineering exfiltration paths - git pushes to personal repos, cloud IDE transfers - a gap in most legacy DLP.

Forensic Evidence & Case Management

Preserved file activity metadata and event timelines support HR actions and legal proceedings without continuous screen surveillance.

Code42 Incydr Use Cases

Departing Employee Data Theft

The anchor use case: detecting employees moving customer lists, deal data, or IP to personal accounts before they leave.

Source Code & IP Exfiltration

Engineering-aware detection catches source code moving to personal repos and unsanctioned destinations.

Shadow IT Data Sprawl

Visibility into files flowing to unsanctioned cloud apps and personal accounts across the workforce.

Security Awareness Correction

Automated micro-trainings respond to careless behavior at scale, improving habits without analyst time.

M&A and High-Turnover Windows

Heightened monitoring during reorgs, layoffs, and acquisitions - the periods when exfiltration risk spikes.

Code42 Incydr Integrations

Incydr is built to slot into security operations: alerts and events flow to SIEM and SOAR platforms (Splunk, Sumo Logic, and similar) for correlation and automated playbooks, HR systems feed departure and role-change context that powers its risk scoring, and identity providers supply user attributes. Ticketing integrations route cases into existing workflows, and an API supports custom pipelines. Under Mimecast, the roadmap adds correlation with email and collaboration security telemetry - extending exfiltration visibility across the channels Mimecast already monitors. The integration philosophy mirrors the product: feed risk signal into the tools security teams already use, rather than being another console to live in.

Code42 Incydr Implementation & Ease of Use

Fast deployment is one of Incydr's core selling points against legacy DLP: a lightweight agent for Windows, macOS, and Linux rolls out through standard software distribution, and because detection is based on file movement context rather than content classification policies, useful signal appears almost immediately - no months-long data discovery project first. Cloud-delivered administration keeps infrastructure burden low. The operational work concentrates in tuning risk indicator weights to your environment, wiring HR and identity integrations for departure context, and defining response playbooks (when to educate, when to investigate, when to block). Reviewers describe the console as clean and the alert volume as manageable relative to DLP norms - the product's low-noise philosophy shows up in practice, though teams wanting deep content inspection will need to adjust expectations or pair it with a DLP.

Code42 Incydr Customer Success Stories

Technology Companies

Software companies use Incydr's source-code exfiltration detection to protect their core IP, catching pushes to personal repositories that network tools never see.

High-Growth & High-Turnover Organizations

Companies with significant workforce churn run departing-employee workflows tied to HR data, reviewing risky file movement before offboarding completes.

Security Teams Replacing Legacy DLP

Organizations frustrated by DLP false positives report faster investigations and better analyst morale after shifting to risk-scored exfiltration events.

Code42 Incydr Pricing

Incydr is sold on quote-based, per-user subscription licensing, historically offered in tiered packages that scale response and integration capabilities - there is no published price list. Deals are shaped by workforce size, package tier, and increasingly by bundling within the broader Mimecast human risk management platform. Market positioning puts it in enterprise territory: more than mid-market monitoring tools like Teramind's published tiers, generally competitive against Proofpoint ITM and enterprise DLP suites it aims to displace. Buyers should ask specifically about post-acquisition packaging - Mimecast bundle pricing can change the math for organizations already using its email security - and compare against standalone platforms if exfiltration detection is the only requirement.

Code42 Incydr Security & Compliance

Incydr operates as an enterprise SaaS platform with SOC 2-audited infrastructure, role-based access control, audit logging, and data residency options. Its monitoring model is notable for compliance posture: because it captures file movement metadata rather than screens, keystrokes, or communication content, it collects substantially less sensitive data than surveillance-style platforms - a meaningfully easier conversation with privacy teams, works councils, and GDPR assessments. Evidence preservation supports defensible HR and legal action. The employer still owns monitoring-program governance - notification, retention, and proportionality analysis - and organizations with regulatory content-inspection requirements (like PCI-scoped data controls) should note that Incydr's context-over-content model may need pairing with a content-aware DLP to satisfy auditors who expect pattern-based detection.

Where Code42 Incydr Falls Short

Incydr's focus is also its boundary. It is not a user activity monitoring platform - no screen recording, no keystroke capture, no productivity analytics - so investigations get file-movement evidence but not the visual context platforms like Teramind or Proofpoint ITM provide, and organizations wanting workforce analytics need a separate tool entirely. Its historically context-over-content detection means limited deep content inspection compared to traditional DLP; some reviewers and analysts note that classification-driven compliance requirements may still demand a DLP alongside it. Real-time blocking has matured but remains narrower than enforcement-first platforms - Incydr leans detect-and-respond over prevent-by-default. Enterprise quote-based pricing puts it out of casual reach for smaller teams, and the Mimecast acquisition introduces the usual integration-era uncertainties around roadmap, packaging, and support that buyers should probe during evaluation.

Code42 Incydr Alternatives

Teramind

Full user activity monitoring with behavioral DLP, screen recording, and published per-seat pricing - deeper surveillance and enforcement where Incydr stays metadata-focused.

Proofpoint ITM

Enterprise insider threat management with user activity timelines and screen capture around risky events, integrated with Proofpoint's email DLP ecosystem.

DTEX

Behavioral insider risk intelligence with privacy-by-design pseudonymization, consolidating UAM, UBA, and DLP signals for large enterprise and government programs.

Cyberhaven

Data lineage-based detection and response that traces content as it moves and transforms across apps - the most direct architectural rival to Incydr's exfiltration focus.

Veriato

AI risk scoring with forensic screenshot capture for investigation-heavy monitoring programs.

Safetica

Mid-market DLP and insider risk with published pricing - a lighter-weight, budget-friendlier route to data protection.

Code42 Incydr vs. PixieBrix

Category Code42 Incydr: Data Exfiltration Detection & Response PixieBrix: Browser-Native Guardrails & Workflow Control
Deployment Endpoint agent for Windows, macOS, and Linux plus cloud console - fast for its category, but still a fleet-wide agent rollout. PixieBrix deploys instantly via a browser extension through existing enterprise browser management. No endpoint agent required.
Monitoring Scope File movement telemetry across endpoints - browsers, cloud sync, USB, AirDrop, git - with metadata context rather than content or screens. Focused on in-app behavior in the browser: the copies, pastes, form entries, and data access where SaaS-era leaks actually start.
Insider Threat Response Detects exfiltration and responds after the event - micro-trainings, cases, and blocking for flagged users. The file has often already moved. Prevents risky actions at the point of work: blocking sensitive clipboard copies, redacting PII before exposure, and requiring justification before high-risk changes.
Employee Experience Proportionate by design - no screens or keystrokes - and its micro-training responses coach rather than punish, though feedback arrives after the mistake. Transparent guardrails coach users in the moment - explaining why an action was blocked and what to do instead, before any incident exists.
Analytics Risk-scored event queues, exposure dashboards, and investigation timelines built from file activity. PixieBrix Insights tracks workflow execution, guardrail interventions, and automation usage - showing where risk and friction actually occur in workflows.
Integrations SIEM, SOAR, HR, and identity integrations feed risk context in and alerts out; Mimecast ecosystem correlation growing post-acquisition. Integrates with any web app directly in the browser - no APIs needed - and pushes events to tools like Slack, Jira, and Zendesk.
Ease of Maintenance Risk indicator tuning, HR data wiring, and response playbook upkeep by the security team. Ops and security teams maintain guardrails through a no-code editor, updating and deploying policies to every user instantly.
Governance and Security Metadata-first collection is privacy-friendlier than surveillance platforms, but event archives still require access and retention governance. Minimizes collected data by design: enforcement happens locally in the browser, and no activity archives accumulate.
Total Cost of Ownership Quote-based enterprise per-user licensing, with packaging now tied to the Mimecast platform. Low-cost, fast-to-deploy browser layer that prevents incidents before they enter anyone's response queue.

Stop Exfiltration Before It's an Event with PixieBrix

Incydr made insider risk manageable by scoring exfiltration events instead of drowning teams in DLP noise - but an event queue, however well-prioritized, is still a record of data that already moved. PixieBrix works one layer earlier: inside the browser, where the copy, paste, download, or upload is still just an attempted action. The customer list a departing employee tries to copy out of Salesforce is blocked at the clipboard with an explanation, not scored after it lands in a personal drive. The sensitive record is redacted on screen before it can go anywhere. High-risk actions require justification that creates its own audit trail. For teams running Incydr, that means fewer events worth investigating; for everyone else, it is exfiltration prevention that deploys in minutes as a browser extension, managed by a no-code editor - no agent rollout, no event backlog, just risky actions that fail safely.

Related content

2026 PixieBrix, Inc.