Present the Siberson platform — your way, in any meeting
Siberson is a data-centric security company helping regulated enterprises discover, classify, protect and monitor their most sensitive data across endpoint, cloud and hybrid environments.
This full-screen experience goes beyond the classic slide deck: jump between products, open use cases and technical detail on demand, search any feature, and close with clear next steps.
Siberson — Data-centric Security for Regulated Enterprises
Siberson is a data-centric security company from Türkiye. We help regulated enterprises discover, classify, protect and monitor their most sensitive data across endpoint, cloud and hybrid environments — with sovereign, on-premises deployment as a first-class option.
One platform, four capabilitiesData discovery, classification, DLP and file integrity monitoring built to work as one lifecycle.
Certified management systemsISO 27001, 27701, 20000-1, 9001, 10002 and 45001 certified; certificates available on request.
Regulated-market focusFinance, public sector, defense, telecom, energy and healthcare — with Turkish and international PII coverage.
Deployment sovereigntyOn-premises, SaaS or hybrid — including offline and isolated environments.
A Türkiye-based data-security vendor: enterprise references from finance to defense, a nationwide partner network, and a product family mapped one-to-one to regulatory frameworks.
+Enterprise CustomersFrom finance to defense
+Protected EndpointsAcross the installed base
+Global PartnersDistributor and integrator network
%+Satisfaction RateCustomer satisfaction
Microsoft ISV PartnerVeriket is listed on the Microsoft commercial marketplace
You Can Only Protect the Data You Can See and Understand
Most data-security programs fail at the first step: nobody knows exactly where sensitive data lives. Siberson's approach builds control on top of visibility and context — find it, label it, then enforce policy that understands what the data actually is.
DiscoverFind sensitive dataDatabases, file shares, endpoints and cloud — structured and unstructured.
ClassifyGive it contextPersistent labels and metadata that travel with the file.
ProtectEnforce policyChannel controls driven by classification — fewer false positives.
MonitorProve integrityTamper-evident monitoring of critical files and configurations.
The same controls generate the evidence compliance teams need. Siberson products support control implementation and evidence for KVKK, GDPR, ISO 27001, PCI DSS, NIS2, HIPAA, SOX and BDDK requirements.
KVKKGDPRISO 27001PCI DSSNIS2HIPAASOXBDDK
Solution Portfolio
Four Products, One Data-security Lifecycle
Each product solves a distinct problem — and they are designed to work together, sharing classification context across the platform.
Veriket Data Discovery
Scan structured and unstructured systems to locate sensitive data, score risk and remediate it in place.
Veriket Data Classification
Automatically identify, label and classify sensitive files at scale — the context layer of the platform.
Verikor DLP
Monitor, control and block sensitive data flows across endpoint, network and cloud channels.
Verifim FIM
Real-time file integrity monitoring with tamper-resistant logs on Windows, Linux and Pardus.
Veriket Data Classification — Label It Once, Protect It Everywhere
Veriket classifies documents, files and emails with manual, policy-based and AI-assisted methods, embedding persistent metadata that stays with the file — so every downstream control, including DLP, knows exactly what it is handling.
Every classification styleUser-driven, policy/content-based and AI-assisted classification with pre-send email labeling.
Visible + invisible labelsHeaders, footers and watermarks for people; persistent metadata for systems.
Screen watermarkingDeters screenshots and phone photos by marking the screen itself.
Beyond MicrosoftOffice, Microsoft 365, Outlook and OWA — plus Google Workspace and Zimbra.
Veriket Data Classification — management console
Technical detail — how classification works
Persistent metadata: each file carries its label and a GUID in metadata, so policies survive renaming, copying and format changes.
Content intelligence: OCR reads text inside images and scanned PDFs; fingerprinting tracks derived content.
Protection actions: masking and encryption (RMS-aware and RMS-less, with automatic encryption options).
Deployment: on-premises or SaaS, with multi-tenant architecture; editions Go, Pro and Enterprise (per user/year).
Every downstream control — DLP, discovery, audit — is only as good as its understanding of the data. These are the five problems classification solves at the root.
Data you can't seeUnlabeled files carry no signal; nobody knows what is sensitive until it is too late.
DLP needs contextPattern-only DLP guesses; label-driven DLP knows. Classification is what makes DLP precise instead of noisy.
Regulation demands itKVKK, GDPR and ISO 27001 all expect data to be classified and handled by sensitivity.
AI raises the stakesGenAI tools consume whatever users feed them — unlabeled data cannot be protected at that boundary.
Manual-only labelling failsPeople forget and mislabel; policy and AI assistance keep classification consistent at scale.
Where enterprise data usually sits
ClassifiedDiscovered, unlabeledDark data — invisible
Discovered & classified — protectable todayDiscovered but unlabeled — no context for DLPDark data — cannot be protected at all
Illustrative distribution used to frame the discussion — not a measurement of your organization. Veriket Data Discovery produces the real figures for your estate.
Veriket Data Classification · Product Architecture
Seven Classifiers, One Platform
Veriket is not a single add-in — it is a family of classifier modules that meet data wherever it is created, all reporting into one management console with one policy model.
Data Classification
Office ClassifierLabels inside Word, Excel and PowerPoint as documents are created and edited.
File ClassifierClassifies every file type on servers and shares — including bulk, folder-level operations.
Mobile ClassifierExtends the same labels and policy to mobile platforms.
CAD ClassifierLabels technical drawings — AutoCAD and engineering formats.
Desktop ClassifierAutomatic classification at creation, copy and download on the endpoint.
SharePoint ClassifierCovers SharePoint and OneDrive repositories at rest.
Email ClassifierOutlook and OWA labeling before send, with attachment content scanning.
Veriket Data Classification · Value
What This Buys the Business
Lower leak riskData leaves less often, and never unnoticed.
More effective DLPLabels sharpen every downstream security control.
Lower storage costKnowing what data is lets you govern and prune it.
User awarenessEmployees engage with data protection instead of bypassing it.
Regulatory alignmentSupports KVKK, ISO 27001 and PCI DSS classification requirements.
Violation reportingDetailed logging turns incidents into reportable evidence.
Veriket Data Classification · Compliance
Regulations Don't Ask If — They Ask How
Classification is not a nice-to-have: KVKK, GDPR and ISO 27001 all expect data to be known, labelled and protected — and sector rules from banking and capital-markets regulators ask for it explicitly. Veriket produces the evidence auditors ask for: label, log and report.
KVKK
Art. 4Art. 6Art. 7Art. 12
The two-axis label makes personal and special-category data visible; the retention parameter feeds erasure processes; label-driven DLP is documented evidence of the technical measures Art. 12 requires.
GDPR
Art. 5Art. 25Art. 30Art. 32
Consent, transfer and retention metadata document privacy by design; inventory output feeds Art. 30 records of processing; label-driven controls support Art. 32 security of processing.
ISO 27001:2022
A.5.12A.5.13A.8.12
Meets A.5.12 (classification of information) and A.5.13 (labelling) directly — and A.8.12 (data leakage prevention) through label-triggered actions.
NIST CSF 2.0
IdentifyProtectDetect
The data inventory feeds Identify, label-driven protection feeds Protect, and event logs feed Detect — traceable evidence at audit time.
Audit day: which file, which label, who, when, under which policy — one report.
Veriket Data Classification · Taxonomy
A Label Model People Actually Understand
What matters is not how many labels you have — it is that they are consistent, understandable and actionable across the organization. A typical four-level scheme, and what each level implies for sharing:
LV 01
PublicInformation whose external sharing poses no concern — public documents, press releases, brochures.
Sharing: free
LV 02
InternalLimited to employees — process documents, operational reports, internal correspondence.
Top SecretStrategic, critical or highly sensitive — security architectures, critical infrastructure documents.
USB · web · external: full block
Levels, names and colors are fully configurable — this is the scheme most organizations start from, not a fixed product constraint.
Veriket Data Classification · Taxonomy
Two Axes, Not One
Veriket separates security sensitivity from personal-data sensitivity, because KVKK and GDPR obligations do not map neatly onto a single confidentiality ladder. A document can be “Internal” for security purposes and still carry special-category personal data.
KVKK · Personal dataConfidentiality levelSecret + special-category → strictest policy
Axis 1 — Classification level
Corporate confidentiality, driven by your information-security policy.
Public
Internal
Confidential
Top Secret
Axis 2 — Personal-data sensitivity (KVKK)
A separate level for personal data, plus the parameters the regulation actually asks about:
Personal-data level (sensitivity)
Personal-data types present
Explicit-consent status
Sharing permission
Retention period
Every one of these choices is written into the file's metadata, so DLP, SIEM and Discovery can all read and act on them.
Veriket Data Classification · Experience
The User Becomes Part of the Control
Classification changes behaviour, not just metadata. The moment of labelling is the moment a user notices what they are handling — which is why mis-sharing drops even before a single DLP rule fires.
01 · SEESees the sensitivityThe label and visual mark appear the moment the document is opened.
02 · SELECTSelects the right labelVeriket suggests from policy and content; the user confirms — conscious classification.
03 · SENDShares consciouslySensitivity awareness kicks in at send time, before the message leaves.
04 · RESULTMis-sharing decreasesHuman and system work in the same context — a sustainable control, not a fight.
Veriket Data Classification · Experience
The Guidance Menu
Rather than asking “pick a label”, Veriket presents a customisable guidance menu that collects everything the policy and the regulation need — in one dialog, at the moment of saving or sending.
Detected automaticallyMatching policy and detected content are shown to the user, so the suggestion is explainable.
Chosen by the userClassification level, personal-data level and types, consent, sharing permission and retention.
Veriket — Classify document
Detected policyHR · Payroll
Detected contentTCKN, IBAN
Classification levelConfidential
Personal-data levelSensitive
Personal-data typesIdentity · Financial
Explicit consentObtained
Sharing permissionInternal only
Retention period10 years
Schematic of the guidance-menu parameters — field set is configurable per organization.
Veriket Data Classification · Capabilities
Capabilities in Depth
From right-click labeling to AI auto-classification — every capability below is on the product page and in the documentation.
Manual & email classificationRight-click labeling in Office, PDF and files, and pre-send labeling in Outlook — from the Go edition.
Visual labels & metadataHeaders, footers, watermarks and persistent metadata (label + GUID) readable by DLP, SIEM and Discovery.
OCR & fingerprintingRead text inside images and scanned PDFs, and detect proprietary content by exact or partial match.
Automated protectionMasking, encryption (RMS-aware and RMS-less), auto-encryption on policy hits and Kryptos integration.
★ Screen watermarkDynamic on-screen watermark deters photo and screenshot exfiltration — a Siberson signature capability.
★ AI auto-classificationContent-aware AI suggests and applies labels automatically — Veriket's signature classification engine.
Veriket Data Classification · Coverage
When It Labels — and What It Can Read
The file lifecycleevery moment, every formatOn first installationAs users workIn bulkAt send timeWatermarks with exceptionsEncrypted files
On first installationAn initial estate-wide scan brings existing files into the scheme instead of starting from zero.
As users workAutomatic classification on file creation, copy and download — the label follows the moment of creation.
In bulkWhole folders classified in one operation for legacy shares and migrations.
At send timeOutlook labelling before the message leaves, with attachment content scanned too.
Watermarks with exceptionsDocument and screen watermarks, governed by detailed exception rules so they never disrupt the wrong workflow.
Encrypted filesAutomatic classification of encrypted files keeps protected content inside the scheme.
Word · Excel · PowerPointPDFUDFTXTLibreOffice · OpenOfficeAutoCADPhotoshopImages (OCR)Audio · VideoRAR · ZIP · 7z contentsEXE · BAT · DLL.msg e-mail
Veriket Data Classification · E-mail
E-mail Control, End to End
E-mail is where classification earns its keep. Veriket classifies messages by sensitivity, marks them visually and in metadata — then controls that labeled mail actually goes only where it should.
Right recipients onlyLabeled e-mail and attachments are checked so they reach only the intended recipients.
Attachments includedAttachment content is scanned — a clean message cannot smuggle a sensitive file.
Block or control the sendA file containing TCKN, payroll, credit-card or IBAN data is blocked or sent under control, per policy and KVKK.
Admin oversightSecurity admins monitor attempted violations, analyse the full audit log and report to management.
Veriket Data Classification · Policy Engine
Policies That Match How Your Organization Is Actually Shaped
A rule is rarely just “find this pattern”. Veriket lets you combine content, identity, location and time — so the same file can be treated differently depending on who holds it and where it lives.
What a rule can look at
ContentDictionary / keyword listsRegular expressionsUser nameDepartmentUser groupFile nameFolder nameFile directoryFile sizeFile creatorValidity time range
→
What the policy produces
Classification levelPersonal-data levelVisual labelPersistent metadataWatermarkMaskingEncryptionBlock the sendLog & report
Unlimited dictionariesBuild keyword lists per business domain — contract terms, project code names, product identifiers.
Regex where you need precisionStructured identifiers such as TCKN, VKN, IBAN and card numbers, matched exactly.
Ready-made templatesStart from the most commonly used policies, then save your own back into the template library.
Scope per policyEach policy can cover classification only, discovery only, or both — one console, two disciplines.
A well-behaved agentHard CPU ceiling, tunable communication, works offline, encrypted sync with the console.
Metadata hand-offLabels are written as persistent metadata that Verikor DLP, SIEM and Discovery read and act on.
Ecosystem integrationDesigned to feed DLP, enterprise rights management (ERM), CASB and next-generation firewalls with the same label.
Web service APIAutomate labelling and pull classification state into your own workflows.
Directory & identityAD-integrated policy targeting and authorization by user, group and department.
Recipient-awareAutomatic labelling based on the e-mail recipient's domain — internal and external treated differently.
Veriket Data Classification · Differentiation
What Sets Veriket Apart
Six differences that decide real projects — each one verifiable in a PoC.
Pardus and Zimbra includedThe same experience on local platforms global vendors don't cover — critical for public sector and defense.
The two-axis modelConfidentiality plus the KVKK personal-data axis in one dialog; compliance metadata lives with the label.
A true on-premises optionEvery component can run inside your network; content never leaves.
A Türkiye-based vendorProduct management and support are local; your needs enter the roadmap directly.
Open metadataLabels are written to standard metadata fields; DLP, ERM, CASB and other tools can read them — no vendor lock-in.
An end-to-end portfolioDiscovery + Classification + DLP from one vendor, speaking one policy language.
Veriket Data Classification · With DLP
One Rule, Four Different — Correct — Outcomes
This is the single most important slide for a security team. Without labels, DLP can only match patterns and every decision looks the same. With labels, the same policy produces a different, appropriate action at each sensitivity level.
Action taken per classification level and channel
Label
E-mail · external domain
E-mail · personal account
USB & removable
Web upload
Print
Public
Allow
Allow
Allow
Allow
Allow
Internal
Warn
Justify
Allow + log
Justify
Allow + log
Confidential
Justify
Block
Justify
Block
Warn
Top Secret
Block
Block + incident
Block + incident
Block + incident
Block
Illustrative policy matrix — every cell is configurable. Actions shown are the Verikor DLP action set: allow, warn, request justification, block, and raise an incident.
A Confidential-labeled document is e-mailed to a personal address — here is the whole story, end to end:
01 · BEFOREVeriket assigned the labelThe document was classified Confidential earlier; the label lives in its metadata.
02 · TRIGGERUser hits sendThe recipient is a personal e-mail account outside the organization.
03 · DECISIONPolicy evaluatesLabel: Confidential + channel: personal e-mail → the matrix says block.
04 · ACTIONSend is stoppedThe user is informed and pointed to the corporate channel instead.
05 · EVIDENCEIncident recordedA full audit trail is created for security review and compliance reporting.
Fewer false positivesPattern-only DLP blocks a lunch menu that happens to contain digits; label-driven DLP does not.
Correct blockingThe genuinely sensitive document is stopped even when its content does not match a regex.
Explainable to auditorsEvery decision references a label, a channel and a policy — not an opaque score.
Veriket Data Classification · Evidence
Protection You Can Prove
Auditors do not accept “we have a control” — they ask for evidence. Every classification action is logged in detail, and the console turns those logs into reports management and regulators can read.
Real screens, not mockups — from the user's first right-click to the admin console.
Veriket lives in the Word ribbon — labelling happens inside the documentTwo clicks in Explorer — right-click, classifyThe classification dialog — detected policy and content, level selectionThe sensitivity tab — personal-data types, consent, retention (KVKK/GDPR)One-step file encryption from the same menuAdmin dashboard — classification posture at a glance
Veriket Data Classification · FAQ
Frequently Asked, Answered
How does licensing work?
Veriket Data Classification is licensed per user; Veriket Data Discovery by scanned data volume (per terabyte). Editions (Go, Pro, Enterprise) set the module scope — see the editions slide.
How long does installation take?
Server components are typically installed within a single business day; agents are deployed centrally via SCCM, Intune or GPO. A typical PoC produces results in two weeks.
Does it affect performance?
The agent is resource-friendly: labelling runs locally and is designed not to introduce noticeable delay in daily office work.
What happens when the license expires?
Labels live in file metadata — independent of the product. When the license ends, new labelling and console management stop; existing labels, watermarks and logged evidence are not lost.
Does our content leave the network?
No. Classification analyses content in place; in an on-premises deployment every component stays inside your network.
Which Office versions are supported?
Microsoft Office 2010 and later, Microsoft 365, LibreOffice and OpenOffice. For e-mail: Outlook, OWA, Gmail / Google Workspace and Zimbra.
Can we bulk-label existing (legacy) files?
Yes — the post-install initial scan and folder-level bulk classification label historical data; for large stores it teams up with Veriket Data Discovery for prioritisation.
Can the label scheme be customised for us?
Yes — level names (TR/EN), colours, defaults, level locking and block-lower-level rules are defined in the console; multiple classification scopes are supported.
How flexible are the watermarks?
Per-format settings for Word, Excel, PowerPoint, PDF and e-mail. Dynamic fields such as [username], [date] and [classification]; headers/footers and screen watermarks included.
Are e-mail attachments controlled too?
Yes — attachments are checked against policy and can be labelled at send time; mandatory labelling is configured separately for external and internal sending.
Is there file encryption?
Yes — Veriket File Encryption from the right-click menu: password protection, adding users and optionally deleting the original.
Does it work with labels from other tools?
Yes — labels are written to open metadata fields, and the console can map other tools' metadata fields; DLP, ERM and CASB products can read the labels.
Is Pardus and Zimbra support built in?
Yes — the agent on Pardus desktops and e-mail classification on Zimbra are built in; both are in production use in public-sector and defense projects.
How does a PoC run?
A typical two-week PoC: scope and policy selection, agent rollout to a pilot group, labelling on sample data, and a joint review of the report output.
Veriket Data Discovery — Find Sensitive Data, Then Fix It in Place
Discovery scans structured databases and unstructured file shares, endpoints and cloud to locate sensitive data — with Turkish and international PII detection — then goes beyond reporting with in-place remediation and DSPM risk scoring.
Verikor DLP — Stop Sensitive Data from Leaving, on Every Channel
Verikor monitors, controls and blocks sensitive data flows across endpoint, network and cloud channels from a single agent — with context-aware policies driven by classification, which is what keeps false positives low.
Multi-channel from one agentEmail (Outlook), USB & removable media, print, web/HTTP(S) uploads, cloud sync, SMB shares — and GenAI tools.
Channel-specific actionsAllow, audit, warn, block, encrypt or require justification — per channel and per policy.
Offline OCR on the endpointContent inspection including OCR runs locally — no OCR server, and policies keep working offline.
250+ policy templatesPrebuilt detection for Turkish and international data types; SIEM integration with Splunk, QRadar, Sentinel and Elastic.
Verikor DLP — real-time block on the web channel
Technical detail — enforcement and editions
Context-aware engine: decisions combine content, classification labels, destination and user context.
Editions are cumulative: Go (endpoint DLP), Pro (web channel, offline OCR, fingerprinting, SIEM), Enterprise (multi-tenant + bundled Veriket Classification Pro), Complete (adds Veriket Enterprise + Data Discovery Go).
Resilient agent: tamper-protected, works offline, CPU/RAM throttled; Windows 8/10/11 and Windows Server 2012+.
Directory & audit: AD/LDAP integration; traceable incidents and audit evidence.
The products are not alternatives — each one makes the next more effective. Discovery tells you where sensitive data is, Classification tells every control what it is, and Verikor enforces how it may move. Verifim adds tamper-evident integrity monitoring around the most critical files.
Veriket DiscoveryFind & risk-scoreLocate sensitive data across DBs, shares, endpoints and cloud.
Veriket ClassificationLabel with contextPersistent metadata travels with every file.
Verikor DLPEnforce policyClassification-driven decisions on every channel.
Verifim FIMProve integrityTamper-resistant monitoring and audit evidence.
Classification-aware DLPPolicies act on labels, not just patterns — sharply fewer false positives than pattern-only DLP.
Bundled by designVerikor Enterprise includes Veriket Classification Pro; Verikor Complete adds Veriket Enterprise and Data Discovery Go.
One evidence trailDiscovery maps, labels, DLP incidents and integrity logs support the same audits.
Regulated enterprises keep full control: run everything on your own infrastructure, consume it as SaaS, or mix both. Multi-tenant management supports holdings and managed-service scenarios in the relevant editions.
On-premisesSovereign deployment on your infrastructure — including isolated and offline environments.
SaaSManaged consumption without owning the infrastructure; same policy model.
HybridConsole and connectors placed where your data-residency rules require.
Multi-tenantSeparate tenants under one management plane (Enterprise-level editions).
Technical detail — requirements & installation
Endpoints: Windows agents for Classification/DLP (Windows 8/10/11, Server 2012+); Linux and Pardus coverage for Classification and FIM.
Installation guides: step-by-step installation, database configuration and hardware sizing live in the documentation.
Every product ships with a public knowledge base — installation, configuration, administration and FAQ articles. Filter or search below; articles open in a new tab so your presentation stays where it is. Documentation is in English.
Enterprises and institutions across five sectors protect their sensitive data with Siberson; the full list is available on request.
Finance & Banking
Defense Industry
Public Sector
Telecom & Insurance
Energy & Services
Ecosystem
Partners, Marketplace and Channel
Siberson is a Microsoft ISV partner; Verikor DLP, Veriket Data Classification and Veriket Data Discovery are listed on the Microsoft commercial marketplace. Delivery and support run through an established partner ecosystem.
Microsoft ISV Partner — Siberson on the Microsoft commercial marketplace
The strongest close is a concrete next step. A typical path: a scoped proof of concept on your data and policies, a technical evaluation meeting, or a hands-on start with the free self-service tools.
Proof of conceptScoped to your channels, data types and success criteria — request via the contact page.
Technical meetingArchitecture, requirements and integration questions with Siberson engineers.
Free tools todayRun the vendor-neutral DLP Test or get a Data Risk Score before any commitment.
PartnershipMSSPs and resellers: multi-tenant management and a partner program built for the channel.