By Outcome — Veri ve Erişim Güvenliği

Data protection layers on top of your WAAP, for sensitive services

This is not classical endpoint DLP. TR7 WAAP is the foundation; for services that handle sensitive data, additional layers engage: pre-session endpoint health checks, ZeroLeak browser isolation, response-layer data masking and forensic watermark.

AI-era attackers operate at machine speed. Classical WAAP catches most of the noise, but for services that actually handle sensitive data — admin panels, customer-data dashboards, internal portals — "most" is not enough. TR7's answer is layered. The WAAP foundation stays in place; for sensitive services, extra protections engage on top: endpoint health is checked before a session opens; ZeroLeak browser isolation renders the application server-side, so the attacker on the client cannot reach the DOM, scrape source, or read raw API responses. Sensitive data in API responses is masked before it reaches the client; third-party JavaScript on the page is monitored for skimmers. And if data does end up outside the application, forensic watermark identifies the session and user that produced it. The AI-era-specific surface — anti-OCR rendering, AI agent traffic, scraper detection — is covered in detail on the AI-Era Protection page.

Built on WAAP
Foundation is TR7's web and API protection — these layers are additive for sensitive services
Server-side
Rendering happens on your platform; no DOM or source on the client
On-prem
Sensitive data and rendering decisions stay in your own network

Sensitive services need more than a classical WAAP — and they don't need an endpoint DLP agent either

AI-era threats on web applications are escalating. Automated attackers act at machine speed, chain reconnaissance with exploitation, and target the parts of an application that hold sensitive data. Most of this traffic is stopped by a competent WAAP — OWASP coverage, bot scoring, DDoS absorption — and TR7 WAAP does that work. But a small fraction of attacks reaches the application anyway: through stolen credentials, social engineering, supply-chain JavaScript, or sophisticated logic abuse. Once the attacker is on the page, the data is there.

The market answers this in two different ways. Classical DLP products (the Forcepoint / Microsoft Purview category) install endpoint agents that watch files, USB ports and print queues — a useful tool for desktop knowledge work, but the wrong place to stop data leaving through a web application. Cloud-only RBI products isolate browser sessions on someone else's edge — useful, but they pull your sensitive traffic out of your own network.

TR7 takes a third path. Data leakage prevention runs inside the same WAAP that already protects the service — on your hardware, attached to the same vService. Sensitive services pick up extra layers: device-trust signals from endpoint security gate access before a session opens; ZeroLeak isolation renders the application server-side so there is no DOM, no source code and no raw API response on the user's device; anti-OCR rendering resists AI-era screenshot exfiltration; and forensic watermark is woven into every served page so a leak — if one occurs — points back to a session and a user.

Five layers on top of your WAAP — for the services that need them

These layers are not always-on for every application. They engage where the data is most sensitive. TR7 WAAP remains the foundation; these layers are what makes the WAAP next-generation when the service warrants it.

WAAP is the foundation — these layers are additive

TR7 WAAP already handles OWASP, API security, bot management, DDoS and content-aware traffic rules across every service. Data leakage prevention adds layers on top — for the services that actually carry sensitive data, not for every static page.

Endpoint health gating before a session opens

For a sensitive service, TR7's endpoint security layer signals whether the requesting device is known and currently healthy — managed status, compliance state, posture. The access decision incorporates that signal before the application receives a single request from an unverified endpoint.

ZeroLeak add-on — the application renders on your side, not theirs

The ZeroLeak isolation gateway renders the sensitive application server-side and delivers only the rendered output to the browser. The user sees a fully working application; the attacker — or compromised browser process on the client — has no DOM to scrape, no JavaScript source to read, and no raw API response to capture. The attack surface on the client side collapses.

Multi-vector data masking and client-side defense

Beyond isolation, sensitive data flows through other paths too. TR7 redacts PII, payment data and credentials in API responses before they reach the client, and monitors third-party JavaScript on your pages to catch supply-chain skimmers that exfiltrate from the browser itself. The vectors classical DLP misses, covered at the WAAP layer.

Forensic watermark — and a trail back to the source

Every served page carries a forensic watermark that ties the rendering to a specific session, user and timestamp. If sensitive content does end up outside the application — leaked screenshot, copied frame, printed page — investigation can trace it back to where the leak started. Accountability replaces guesswork. For AI-era screen-grab threats specifically, see the AI-Era Protection page.

What TR7 brings together for data leakage prevention

Every capability below sits on the same platform as your WAAP and ADC. The layers engage where the service needs them.

Per-vService sensitivity marking

Mark a vService as sensitive and the extra layers — endpoint gating, ZeroLeak isolation, anti-OCR, watermark — engage for that service. Public, non-sensitive services keep the standard WAAP profile.

Endpoint health-aware access decisions

Device-trust signals from TR7's endpoint security layer (known device, current posture, compliance state) feed the access decision before the application receives the request. Unknown or out-of-compliance endpoints are blocked, challenged, or routed to a restricted experience per policy.

ZeroLeak browser isolation (add-on)

The sensitive application renders on the TR7 platform; only the rendered visual output reaches the browser. No DOM, no source code, no raw API response delivered to the client. The data the user sees is the only data their machine ever has.

Anti-OCR rendering (cross-link)

Rendered output is shaped to resist automated OCR and vision language model pipelines. Legitimate users see normal content; AI-era screen-grab tools find recovery unreliable. For the full AI-era threat model — agent classification, scraper detection, AI-era watermark mechanics — see the AI-Era Protection page.

Forensic watermark on every served page

Watermarking is woven into the rendered content — visible or steganographic — tied to session, user identity and timestamp. A leaked screenshot or printed page points back to the source.

Sensitive data masking in API responses

Even for services that don't run under full isolation, response-layer masking redacts PII, payment data, credentials and other sensitive patterns per policy before they reach the client. Useful for partial-isolation deployments or for API-only services.

Client-side / Magecart defense

Third-party JavaScript on your pages is monitored at the browser. Unauthorized script changes, suspicious form-data exfiltration patterns and supply-chain skimming attacks surface before customer data is harvested.

Session recording and audit trail

Sessions on isolated sensitive services are recorded at a level appropriate for investigation. Combined with the watermark, audit trails support regulatory review without an additional product.

Content-aware traffic rules

Rate-limit, challenge or block on any traffic attribute — header values, cookie contents, URL parameters, parsed JSON body values. Useful for limiting how much data a single session can request, even before isolation engages.

Same vService model and same console

All of the above attach to the existing vService configuration. One operator console covers ADC delivery, WAAP signals, ZTA access and these data-leakage layers. One audit trail for everything.

On-prem — your data stays in your own network

Rendering, isolation, masking and watermarking all run on your hardware. No third-party edge in the path of your sensitive data.

BW model — blocked attempts don't count

Bot floods, scraping attempts and other denied requests against your sensitive services are excluded from the bandwidth meter, like everywhere else on the platform.

How a sensitive service is protected end-to-end

A request to a service marked sensitive in TR7 takes a slightly different path through the platform — one that closes off exfiltration avenues before they open.

01

Pre-session: endpoint check

Before any application logic runs, TR7's endpoint security layer is consulted. Is the device known? Is its posture current? Is it compliant with policy? Unknown or out-of-compliance endpoints don't get a session on the sensitive service at all.

02

Identity and trust evaluation

Identity verified through the access management layer (SSO, MFA, OAuth/OIDC/SAML). Continuous trust evaluation watches for context changes during the session — the trust granted at login does not stay granted unconditionally.

03

WAAP inspection on every request

OWASP signatures, bot scoring, behavioral analysis, content-aware rules — the full WAAP layer runs as it does everywhere else on the platform. Most attacks never reach the application layer.

04

ZeroLeak server-side rendering (for isolated services)

For services configured with ZeroLeak isolation, the application is rendered on the TR7 platform. The browser receives the rendered visual output, not the application's DOM or source. There is nothing on the client side to scrape.

05

Anti-OCR-shaped output

The rendered output is shaped to resist AI-era OCR pipelines. Users see normal content; automated screen-grab extraction finds recovery unreliable.

06

Forensic watermark

Every rendered page is watermarked — session, user identity, timestamp — woven into the content. If a leak occurs, this is the trace that points back to the source.

07

Response masking and audit

Where data flows are not fully isolated, sensitive patterns in responses are masked. Every decision is logged in the same console used to manage the vService and WAAP policy.

Where this outcome shows up

Internal admin panels and operations consoles

Privileged web consoles that operate over sensitive infrastructure. Endpoint health required, application rendered server-side, every admin action watermarked and audited.

Customer-data dashboards in regulated industries

Banking back-office, healthcare clinician portals and insurance claim systems where exposure of an unmasked record is a regulatory event. Isolation and response masking work together so sensitive data is never on the client device.

Third-party and contractor access to internal apps

Users on devices you do not directly manage need scoped access. Endpoint signals plus ZeroLeak isolation give them the application they need without giving them the underlying data to copy.

Anti-OCR for AI-era screenshot exfiltration

Modern automation captures screens and runs OCR at scale. Anti-OCR rendering makes that pipeline unreliable for sensitive content — humans see it, machines struggle to extract it.

Post-incident forensic traceability

Sensitive content appearing outside the application is the moment forensic watermark earns its place — the leaked artifact points to a session, a user and a timestamp.

Public-sector portals with data residency

Citizen-data services where data residency forbids third-party traffic interception. The on-prem deployment of WAAP plus ZeroLeak isolation keeps every byte inside the citizen-data network.

11 features

Features that implement this solution

Capabilities referenced by this solution — the technical pieces that compose the controls described above.

Anti-OCR Protection

TR7 ZeroLeak
AI-Era ProtectionData Leakage PreventionHIPAA Compliance

Server-rendered pages with pixel-level modifications — readable on screen for the user, nonsense to OCR engines and AI vision models when extracted as an image.

Healthcare· Financial Services· Government· Education

Remote Browser Isolation

TR7 ZeroLeak
AI-Era ProtectionData Leakage Prevention

Run the protected app inside a fully isolated session on the platform — the user sees only the rendered pixels. No HTML, no JavaScript, no cookies on the endpoint.

Healthcare· Financial Services· Government

Text Cipher

TR7 ZeroLeak
AI-Era ProtectionData Leakage Prevention

Letters on the page are silently swapped with visually-similar siblings; the area around the cursor reveals the originals. The human reads naturally — an AI fed a screenshot reads different words.

Healthcare· Financial Services· Government

Forensic Watermark

TR7 ZeroLeak
AI-Era ProtectionData Leakage Prevention

A visible per-user watermark plus an invisible trace ID embedded into the pixels — when a screenshot leaks, the source can be identified even after cropping, scaling, or being photographed.

Healthcare· Financial Services· Government

Browser Context Isolation

TR7 ZeroLeak
AI-Era ProtectionData Leakage Prevention

Every user session runs in its own isolated browser context — no shared cookies, storage, or process state — with a strict domain allowlist and rendering-level anti-automation defences built in.

Financial Services· Government

Session Recording & Audit

TR7 ZeroLeak
Data Leakage Prevention

Event-driven screenshots at consequential moments, continuous FFmpeg video, word-level keystroke buffer and clipboard logging — every session reconstructable for compliance and investigation.

Financial Services· Government

IP Masking and Normalization

TR7 ADC
Application Delivery & AccelerationPCI DSS ComplianceHIPAA ComplianceData Leakage Prevention

Mask IP for log privacy, reconstruct the correct client IP across proxy chains.

Financial Services· Healthcare· Government

Response Body Modification

TR7 ADCTR7 WAAP
Application Delivery & AccelerationWeb Application & API ProtectionData Leakage Prevention

Mask, replace or inject HTML into response content — without changing a line of backend code.

Healthcare· Financial Services

Cookie Encryption Rule

TR7 ADCTR7 WAAP
Application Delivery & AccelerationWeb Application & API ProtectionData Leakage Prevention

Hide cookie values from the client — protect session integrity without touching backend code.

Financial Services· Healthcare

FTP Security Proxy

TR7 WAAP
Web Application & API ProtectionData Leakage PreventionModernize Legacy Apps

Manage FTP not as an open port, but as a command-by-command controlled secure file transfer session.

Financial Services· Government· Healthcare

Sensitive Data Masking

TR7 WAAPTR7 ADC
API SecurityPCI DSS ComplianceHIPAA ComplianceData Leakage Prevention

Mask sensitive data at platform level before it reaches the user or the logs.

Healthcare· Financial Services· Government

Common questions

How is this different from a classical DLP product?
Classical DLP (Forcepoint, Microsoft Purview and similar) installs endpoint agents that watch files, USB ports and print queues — useful for desktop knowledge work. TR7's approach is the opposite end of the data path: we sit inside the WAAP in front of the web application, so sensitive data does not even reach the user's device in a form they can exfiltrate. Both approaches can coexist; they address different vectors.
Does this replace TR7 WAAP, or sit on top of it?
It sits on top. TR7 WAAP is the foundation — OWASP coverage, bot management, DDoS, API security, content-aware rules. For services that handle sensitive data, the extra layers — endpoint gating, ZeroLeak isolation, anti-OCR, forensic watermark — engage on top of the WAAP profile. Non-sensitive services keep the standard WAAP profile without extra cost or latency.
What does ZeroLeak do that the WAAP alone does not?
The WAAP inspects request and response payloads. ZeroLeak renders the application server-side, so the user's browser only sees the rendered output — not the DOM, not the source, not the raw API response. An attacker who somehow lands on the page through stolen credentials or a supply-chain compromise still has nothing to scrape or exfiltrate. The attack surface on the client side collapses.
What is anti-OCR rendering?
Modern attackers screenshot the rendered page and run AI-based OCR to extract the text. Anti-OCR rendering shapes the output so automated OCR pipelines struggle to reliably recover the underlying text — while a human user looking at the page sees normal, readable content. It is a specific defense against the AI era of screen-grab exfiltration.
How does forensic watermark help when data has already leaked?
Watermark is the trace. Every rendered page carries an embedded marker — visible or steganographic — tied to a specific session, user and timestamp. When a leaked screenshot, printed page or copied frame surfaces outside the application, the watermark identifies which session and which user produced it. Accountability replaces guesswork during the investigation.
What endpoint signals are used for access decisions?
TR7's endpoint security layer surfaces device-trust signals: whether the device is known and managed, its current security posture, and its compliance state. For a sensitive service, the access decision incorporates that signal before the application receives the request. Unknown or out-of-compliance endpoints can be blocked, challenged, or routed to a restricted experience per policy.
Do these layers run on every application?
No. The layers engage where the service is marked sensitive. A public marketing page, a static asset endpoint or a low-sensitivity portal runs on the standard WAAP profile without the extra latency or licensing of isolation. Sensitive admin panels, customer-data dashboards and regulated services pick up the additional protections.

A next-generation WAAP, for the services that actually need it

Request a live demo of TR7's data leakage prevention. We will walk through a sensitive admin panel: endpoint check, ZeroLeak isolation, anti-OCR rendering and forensic watermark — all running on the same platform as your WAAP.