Incident detection today is based on protecting the conduit to protect the data inside. Lack of correlation between APIs and data has lead to high false positive rates that are inundating incident response teams. We present a new approach to data security incident detection and response that avoids correlation with the goal of maximizing the real incident to false positive ratio. This approach is particularly useful with APIs that feed RAG and fine tuning models in generative AI.