EDR monitors system activity, such as running processes, network connections, and security alerts. It does not track personal browsing habits, private files, or non-work-related activity. When a security alert is triggered, EDR captures info on metadata (such as hashes or ‘fingerprints’ of files) related to the security event, not entire files. Full file collection is rare, reviewed by at least two Information Security analysts, and occurs only when flagged by known signatures associated with malicious activity. See our Data Collection Summary.