Your customer data sits in mail, shares, laptops and SaaS. One rule should follow it everywhere — Symantec DLP finds and stops sensitive data on endpoints, shares, databases, mail, web and cloud apps — matching your real records, documents and even text inside images, from servers you run.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Symantec DLP — DLP Core and the DLP Cloud bundle. The rest of the Broadcom line:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
DLP inspects content as it moves or rests, and applies a rule when sensitive data is about to leave.
What consolidation actually replaces, dimension by dimension.
| Dimension | Keyword filters and hope | Symantec DLP |
|---|---|---|
| Finding sensitive files | Someone remembers where they saved them | Discover scans shares and databases |
| Telling a real record apart | Any number with the right digits | EDM checks rows from your own tables |
| Scans and screenshots | Invisible to text rules | Image recognition reads the text |
| Outgoing mail and uploads | Logged after the event, if at all | Network Prevent applies the policy |
| Repeat offenders | Noticed after they resign | ICA scores behaviour across incidents |
| What it is NOT | — | A published price, an Indian cloud region, or a quick project |
The cheapest test is a monitor-only pilot: one endpoint group, one mail policy, and a count of how many alerts were real.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
An agent on each managed endpoint finds sensitive files on local disks and can stop one leaving the device; Broadcom’s current agent line is 25.1, with 16.x still patched.
Network Monitor watches outbound traffic for policy matches, while Network Prevent for Email and Network Prevent for Web act on outgoing mail and uploads that break a rule.
Discover scans file shares and databases to show where sensitive records have collected, Protect acts on what it finds, and a separate DSPM module adds posture reporting.
DLP Cloud packages a Cloud Detection Service, detection for Cloud SWG traffic, CloudSOC CASB for SaaS and IaaS, and DLP for Office 365 email and Gmail.
Core components on your own servers — endpoint, network and storage — with DLP Cloud adding detection for SaaS and cloud mail.
Symantec DLP inspects content wherever it moves or rests, and applies your rule before it leaves.
Exact Data Match indexes rows from a customer or staff database, so a hit means a genuine record rather than any number of the right shape.
Indexed Document Matching learns contracts, designs or source files you nominate, then flags copies of them wherever they surface later.
Described Content Matching uses keywords, patterns and file-type checks for sensitive content when no database or master document exists to index.
Sensitive Image Recognition applies optical character recognition to scans and screenshots, so an image cannot slip past rules written for text.
Endpoint Discover inventories sensitive files on the device and Endpoint Prevent blocks a policy breach before the file leaves the machine.
Network Prevent for Email and for Web inspect outbound messages and uploads and apply the policy, while Network Monitor records the rest.
Network Discover crawls file shares and databases for sensitive records, and Network Protect acts on the files that should not sit there.
The cloud bundle adds CloudSOC CASB for SaaS and IaaS, a Cloud Detection Service, and DLP for Office 365 email and for Gmail.
Information Centric Analytics, listed in DLP Core, applies user and entity behaviour analytics so repeated incidents by one person stand out.
Policies can monitor or block sensitive data sent to generative AI apps, a control Broadcom demonstrated for DLP Cloud back in 2023.
Symantec’s Data Security Posture Management module reports where sensitive data lives and how exposed it is, beside the Discover scans.
Incidents can be remediated through ServiceNow, and Broadcom names integrations with Google, Microsoft and Seclore rights management.
A 2026 podcast on how DLP got here, a 2023 release tour, and DLP Cloud controls for generative AI apps.
A 2026 conversation with Matt Jones of Broadcom’s Enterprise Security Group on how DLP got here.
A September 2023 look at release changes; check each one against the current 25.1 line.
How DLP Cloud handled data bound for generative AI apps, as shown in mid-2023.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Pattern rules alone flag anything shaped like a card number. Exact Data Match indexes rows from your real customer or staff tables, and Indexed Document Matching learns the documents you nominate. Sensitive Image Recognition reads text in scans and screenshots, so a photographed form is inspected too.
Broadcom lists endpoints, file shares, databases, web, email and cloud apps as covered. DLP Core handles the first five; the DLP Cloud bundle reaches SaaS through CloudSOC CASB and adds Office 365 email and Gmail. One supplier means one definition of sensitive to keep in step.
DLP Core is software you run, so policies and incident records can sit in your own Indian data centre. That is a deployment model, not a certification, but it is the fair framing against DPDP and RBI expectations. Broadcom lists offices in Bangalore, Hyderabad and Pune; Westcon-Comstor distributes.
There is no public price, and a licensing consultancy reports perpetual licences have given way to subscriptions. No Indian region is documented for DLP Cloud. CVE-2026-3991, a March 2026 endpoint flaw, needed patches across 25.1 and 16.x. Symantec CBX, announced that month, is not a product to buy yet.
Name the record sets, document types and image forms that matter, and the channels each one leaves through today.
Build EDM indexes from the customer master and IDM indexes from key documents, so the first policies fire on real data.
Put endpoint agents on a pilot group and switch on Network Monitor; log incidents without blocking and count false positives.
Point Discover at file shares and databases, review where sensitive data has piled up, and decide what to move or lock.
Move the highest-confidence mail or endpoint policy to block, add ICA scoring, and only then price DLP Cloud for SaaS.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Indexing our customer master for EDM cut the noise sharply; regex on its own flagged every long invoice number as a card.”
“The first Discover scan found salary sheets on a finance share nobody had opened in years. That paid for the pilot.”
“Image recognition caught scanned onboarding forms going out as attachments, which our old text rules never saw.”
“Keeping the servers in our own data centre suited the auditors, but moving between major lines needs a real test window.”
“The quote took three partner calls, and the cloud pieces arrived as a separate bundle we had not budgeted for.”
“Six months in monitor mode before email went to block. Budget for policy work, not just for installing agents.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the data loss prevention market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only through partners; core and cloud bundles priced apart.
The grid nobody publishes — where the DLP can run and keep content, India included, vs how many exits it watches, device to cloud.
Six places covered; Core on your servers, no Indian cloud region listed.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Forcepoint DLP, Microsoft Purview, Trellix DLP Endpoint, Netskope Data Protection and Zscaler Data Protection — on deployment, channels, detection, price, India and exit.
| Dimension | Symantec DLP | Forcepoint DLP | Microsoft Purview | Trellix DLP Endpoint | Netskope Data Protection | Zscaler Data Protection |
|---|---|---|---|---|---|---|
| What it is | Classic enterprise DLP | Unified enterprise DLP | Labels inside M365 | Endpoint DLP on ePO | Module of Netskope One | Zscaler platform module |
| Deployment | Your servers + cloud | On-prem, cloud, hybrid | Microsoft’s cloud | ePO on-prem or SaaS | SaaS only | SaaS only |
| Channels covered | Device to SaaS | Device to cloud | Strongest in M365 | Device exits only | Web, SaaS and mail | Traffic in its path |
| Detection methods | EDM, IDM, DCM, OCR | Classifiers + prints | Auto-labels need E5 | Rules, visual labels | Instance-aware ML | AI/ML plus EDM |
| Insider risk | ICA in DLP Core | RAP add-on | Separate solution | No behaviour engine | Some signal | Some signal |
| AI apps and DSPM | GenAI controls + DSPM | DSPM beside DLP | Not assessed here | AI-chat exits blocked | SkopeAI + DSPM | DSPM and SSPM in |
| Integrations | Seclore and ServiceNow | Forcepoint’s own stack | Native to M365 | ePolicy Orchestrator | Netskope One engine | Zero Trust Exchange |
| Pricing model | Quoted subscription | Per user per year | Per user per month | Per endpoint | Per user, in platform | Per user, bundled |
| Published entry price | Not published | About $52/user/yr | $12/user/mo over E3 | ~$46/endpoint/yr est. | Not published | Not published |
| Included vs add-on | Core vs Cloud bundle | RAP costs extra | E3 manual, E5 auto | Endpoint only | Inside the platform | May already be licensed |
| India data location | Core on-prem in India | Not documented | India ADR geography | Not documented | Eight Indian DCs | Indian DCs; ask |
| Buying and support in India | Partner-led | Through partners | With your M365 licences | Through partners | Bengaluru engineering | Large India presence |
| Lock-in and exit | Indexes stay behind | Tuning is the asset | Tied to the M365 tenant | Tied to ePO | Tied to Netskope One | Tied to the platform |
| Best fit | Symantec estates | Cross-platform suites | Microsoft 365 shops | ePO estates | Netskope SASE estates | Zscaler SASE estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Symantec DLP is one of 20 DLP & insider risk products TechBag carries. The DLP & Insider Risk guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users covered by DLP; analyst-hour cost). Estimates model security-team time spent triaging alerts, chasing false positives and searching shares by hand at an assumed 1.5 hours per user a year, with 70% of it removed by indexed detection and tuned policies. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Broadcom prints no Symantec DLP price, and its product pages send buyers to a partner or a contact form. DLP Core and the DLP Cloud bundle are quoted separately, and a licensing consultancy reports subscription terms with bundle minimums. TechBag scopes the channels first, then quotes every component in INR with GST.
Best for on-premises control
Best for a broader rollout
Best for SaaS and cloud mail
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which exits matter most — endpoint, email, web, file shares, databases or SaaS — and does the quote cover each?
Is DLP Cloud needed now, or can CASB and cloud detection wait until the on-premises policies are tuned?
Is there a clean customer or staff table for EDM, and a set of master documents worth indexing with IDM?
Has a proof of concept shown detection of PAN, Aadhaar and GSTIN in your own records, rather than assumed it?
Will incidents stay on your servers, and if DLP Cloud is added, where will Broadcom process that content?
Are endpoints on 25.1 MP1 or a patched 16.x build that closes CVE-2026-3991, the March 2026 agent flaw?
Is Information Centric Analytics in scope, and who will act on its user risk scores every week?
Does the quote name each component, the user count, the term and any minimum? Ask for INR with GST.
Model the cost of manual incident triage first, or let a TechBag advisor scope a monitor-mode pilot built on EDM indexes from your own data.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.