Legacy DLP has a well-earned reputation for drowning security teams in noise: pattern-match first, flag everything, let a human sort out what actually matters. Jazz, this year's winner of the CrowdStrike, AWS, and NVIDIA Startup Nest competition, is betting that inverting that order, investigate before anything surfaces, is the fix. The company just launched its DLP platform, powered by an AI investigator called Melody, as a native app on CrowdStrike's Falcon Foundry platform. I talked with Roi Vanunu, Director of Product Management at Jazz, about how Melody actually reasons, what happens when she's wrong, and why he thinks most of what gets called "agentic" in security right now doesn't deserve the word.
What Falcon knows versus what Melody understands
The partnership's framing is straightforward: Falcon's security context flows into Melody, and Melody layers business understanding on top of it. When a data protection signal fires, Melody opens an investigation across four dimensions, the data itself, the systems it touched, the person involved, and the business process it belongs to, without a fixed checklist order. "Like a good investigator, she pulls the threads the case requires," Vanunu said.
The two examples he gave make the distinction concrete. A salesperson exporting a large customer report at 11 p.m. looks alarming by volume and timing alone. But Melody has seen this workflow before: same report, same role, same point in the quarter, ahead of business reviews. Closed, documented, legitimate. Now the inverse: a small handful of files moved to a personal cloud account, trivial by volume. But the person resigned last week, the files belong to a roadmap they never worked on, and the destination has no relationship to their role. That one gets escalated with the full evidence chain attached. "Volume and pattern can't tell you which of those is which," Vanunu said. "Business context can."
Where the human still sits
Melody's output falls into two categories. When an investigation concludes the activity is legitimate, she closes it herself, every closure documented and auditable. That's the majority of what she sees. When something genuinely warrants attention, it surfaces to an analyst as a decision-ready finding: the investigation is complete, but the decision and response stay human. How much autonomy Melody gets is fully configurable by the customer. Vanunu compared the trust curve to onboarding a new analyst: "You review Melody's work early, you see the evidence holds up, you extend the leash." He was direct that this is a journey, not a launch-day claim: "Full autonomy is where security is heading, but it's earned case by case, not claimed on day one."
What "no new agent, no new console" actually requires
Jazz's simplicity pitch has real specificity behind it. Out of the box, Melody investigates using the data protection signals the Falcon sensor already collects, no new deployment, no new access beyond what a customer already granted Falcon. Customers who want visibility into surfaces outside Falcon's scope, prompt-level GenAI activity, desktop applications, shadow IT, personal cloud accounts, can add a separate, lightweight Jazz agent Vanunu said runs under 1% CPU. That's an explicit opt-in, not a hidden requirement, and Vanunu said most customers start agentless and add depth later.
Going from Startup Nest winner to shipping natively on Falcon in the same year is a fast timeline, and Vanunu was specific about what actually makes this different from a typical marketplace connector. "A marketplace connector ships data from one tool to another," he said. What Jazz built instead is an application running on Foundry, CrowdStrike's application platform, inside the Falcon console itself, reading Falcon's signals, reasoning over them, and writing findings back into the same records analysts already work in. He credited real joint engineering and direct sponsorship from CrowdStrike's leadership for compressing the timeline from Accelerator win to live platform integration into five months, and said more from the partnership is coming, to be announced as it ships rather than roadmapped in advance.
How wrong answers get corrected
Given DLP's history of false positives, I asked directly what happens when Melody misreads a situation. Vanunu's answer leaned on the same architecture that avoids the noise problem in the first place: since Melody investigates before anything surfaces, most of what she examines never reaches an analyst at all. When a customer disagrees with a verdict, every finding carries its full evidence chain, so the reasoning is visible and correctable. Fixing a misread doesn't require rewriting rules or adjusting thresholds. "You share the missing context in plain English, 'this team is allowed to work with that vendor,' and Melody remembers," he said. Each correction becomes part of what he called organizational memory, intended to prevent the same misread from recurring.
The skepticism test Vanunu applies to his own category
Asked what claim about agentic security investigation deserves the most scrutiny right now, Vanunu didn't point to a specific competitor. He pointed at the word itself. "Be skeptical any time 'agentic' describes what a product is instead of what it finishes," he said. "A lot of what wears the label today is a chat interface or a summarizer bolted onto the same old pipeline, it explains the alert queue faster, but a human still owns every outcome." He referenced Gartner's recent warnings to buyers about "agent washing" as a sign the industry itself is catching up to the problem.
His suggested test for evaluating any vendor's agentic claims, including Jazz's own: ask for a demonstration of a complete investigation, evidence gathered, verdict reached, a benign case closed without human involvement, along with the underlying evidence chain so the reasoning can actually be audited. "If the answer is a summary and a risk score, that's assistance, and assistance is fine, it's just not an investigator," he said. "Security teams should demand the demo, not the adjective."