Plaid
Plaid Company Overview
Plaid is a data network that powers the tools millions of people rely on to live a healthier financial life. Plaid works with thousands of companies like Venmo, SoFi, and Betterment, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid's network covers more than 12,000 financial institutions across the US, Canada, UK and Europe. Headquartered in San Francisco, the company was founded in 2013 by Zach Perret and William Hockey.
Focused on democratizing financial services through technology, Plaid builds beautiful consumer experiences, developer-friendly infrastructure, and intelligent tools that give everyone the ability to create amazing products that solve big problems.
Challenges
Security that scales with cloud speed
Plaid's infrastructure is 100% AWS-native and Mac-native, and built to move fast. Before Cyberhaven, the security team had almost no visibility into how sensitive data moved across that environment. As David Seidman, Head of Platform Security at Plaid, put it: "You could just straight up download all the data and exfiltrate it and nobody would really notice anything."
Insider threat that is not hypothetical
Having led security at Microsoft, Robinhood, and now Plaid, Seidman has seen the same pattern repeat at every company. "At every single job since then, insider threat is just rampant," he said. "If you think you have no insider threat at your business, you're either a one-person shop or you're wrong." Plaid wanted broad-spectrum detection: not a tool built around one type of threat, but visibility into all of them, including the ones the team had not yet anticipated.
Legacy tools that could not keep up
When Plaid ran an RFP and evaluated legacy data loss prevention (DLP) vendors, most were eliminated in the first round. "Their Mac support was generally unusable," Seidman said. Others detected threats reasonably well but lacked feature depth, or covered a wide feature set with poor detection quality. None offered both.
Impact
Transformed visibility
Plaid gained a real-time picture of how sensitive data moves across systems, users, and endpoints, replacing a near-total blind spot.
A credible deterrent
Knowing that Cyberhaven would catch attempted exfiltration changed behavior across the company, not just the security team's response to it.
Investigations reduced from hours to minutes
Cyberhaven's Data Lineage capability let Plaid trace a document's full history almost instantly, turning what used to be manual forensic work into an immediate, evidence-backed answer.
Room to move faster elsewhere
Because endpoint exfiltration is covered, Plaid has been able to take a more developer-friendly posture on some other security decisions rather than defaulting to the most conservative option.
Overview
Plaid's security team evaluated Cyberhaven twice: first at Robinhood, where Seidman used the platform before joining Plaid, and then in a formal RFP and proof-of-concept process at Plaid itself. Legacy DLP vendors were disqualified early over weak Mac support, including the absence of copy-paste detection, a gap Seidman called out specifically. Vendors closer to Cyberhaven in capability were missing detection depth or feature completeness. "Cyberhaven was the most complete offering," Seidman said. "Every other platform we tried had gaps."
“Cyberhaven created a transformational difference. We now have really substantial visibility.”
Unlocking Full Control and Rapidly Ruling Out Insider Risk
Cyberhaven gave Plaid a credible deterrent against data exfiltration. Where sensitive data leaving the company once went undetected, it now surfaces immediately, and the team can act on it. "It's a transformational difference," Seidman said. "We now have really substantial visibility."
The message to the organization is direct: whether the risk is an insider or accidental data misuse, "we will catch you."
Data Lineage: closing the gap endpoint detection and response (EDR) tools leave open
Seidman pointed to Data Lineage as the capability that changes how his team investigates. Endpoint detection and response (EDR) tools can search for a specific file name or hash, but they cannot confirm the full picture once a file has been renamed, copied, or moved. "Without the data lineage feature, even though you can use an EDR tool to look for a file name or a hash, you're never really sure that you got the whole thing," he said. "That's exactly what data lineage gets you."
That difference matters most during a leak investigation, which Seidman described as one of the hardest questions a security team can be asked to answer. With Data Lineage, Plaid can reconstruct where a document has been seen and how it moved, often in minutes.
Hero moment: ruling out a breach in minutes, not days
That capability was put to the test during an external leak inquiry, when a party outside Plaid raised a concern that a Plaid document may have been exposed and asked Plaid to investigate.
"We were very quickly able to use Cyberhaven to determine that this document had not appeared on any of our computers," Seidman said. Data Lineage showed the document's full history within Plaid's environment, which ruled out the internal exposure the team was being asked about.
"We could basically just immediately say there was no [leak on our side]. We can see that this document was not on our computers."
— David Seidman, Head of Platform Security, Plaid
What could have consumed days of manual forensic work, cross-referencing file access logs, endpoint history, and records by hand, was resolved with a few minutes of investigation. "Within literally minutes and almost no effort, we were able to rule out a leak from our side," Seidman said.
A mitigating control, not just a detection tool
Cyberhaven's visibility has also changed how Plaid weighs other security tradeoffs. When the team debates whether to tighten access to a sensitive data table or add more granular permissions, they can factor in that a download to a work laptop would already be visible. "It's let us be a little bit less conservative in some of our other security choices," Seidman said. "You might be able to delay doing something for a few months, or take a slightly more developer-friendly posture, because you know that you would catch a data exfiltration via Cyberhaven, most of the time."
Why This Matters Beyond Plaid
Seidman's view is that this category of tool belongs at every company handling sensitive data, not just financial services.
"I think that a Cyberhaven-area tool like this should be deployed at every company of this size. Everyone should have Cyberhaven or equivalent, the same way that everyone has EDR."
— David Seidman, Head of Platform Security, Plaid
He also pointed to a shift in how the DLP category itself is perceived. Legacy DLP earned a reputation for false positives and heavy overhead, and many security leaders remain hesitant because of it. Seidman's experience across three companies has been different: "A lot of folks are hesitant around the DLP category because historically, legacy DLP was garbage. But modern DLP is just like night and day different. It actually works."
His advice to another fintech facing the same insider risk and cloud visibility challenges: "Anyone who is seriously doing an evaluation of this area really ought to be looking at Cyberhaven."

.avif)
.avif)
