Kiteworks has launched a new security capability designed to prevent employees from accidentally sending sensitive information to the wrong recipients, extending the company’s data governance platform further into outbound email.
Agent and Human Error Prevention (AHEP), now generally available, analyzes email activity as users compose messages and warns them when multiple signals indicate a potentially risky send. The capability operates within Kiteworks’ existing Data Policy Engine rather than as a standalone email security product.
Kiteworks targets human error in outbound email
Kiteworks is positioning AHEP around a security problem traditional data loss prevention tools can struggle to identify: situations where the content itself may be legitimate, but the intended recipient is not.
The platform evaluates signals including recipient type and volume, attachment presence, identity matches, and domain validity.
Its initial policies address accidental reply-all exposure, attachments sent to personal accounts resembling the sender’s identity, and misspelled recipient domains.
“Misdirected email has sat outside that governance for years because it isn’t a data-pattern problem, it’s an intent problem,” Kiteworks Chief Strategy Officer Tim Freestone said.
The company cited UK Information Commissioner’s Office data showing that misdirected email accounts for 21% of reported data security incidents, and Verizon research finding a human element in 62% of confirmed breaches.
Data control plane expands across human and AI workflows
AHEP also fits into Kiteworks’ broader effort to establish a unified control plane for sensitive data moving across enterprise environments.
Earlier this year, Kiteworks expanded the same strategy to AI agents with its Compliant AI platform, which applies governance controls at the data access layer and tracks interactions with sensitive information.
Channel Insider has also covered the company’s focus on data sovereignty and regulated environments, including its recent CMMC partnership with A-LIGN.
Channel partners gain another compliance control
For MSPs and other channel partners, the addition gives them another capability to position alongside secure file sharing, managed file transfer, AI governance, and compliance services as customers consolidate sensitive-data controls.
AHEP runs inside the customer’s Kiteworks environment, meaning email metadata does not leave the platform.
Kiteworks said that architecture is intended to support customers with requirements tied to frameworks and environments including ITAR, CMMC, FedRAMP, and sovereign cloud mandates.
The capability supports the Kiteworks Web App and Outlook Classic at launch, with machine-learning-based behavioral analysis planned for future phases.





