Know where sensitive data lives — and who can reach it.
Discovery, classification and access exposure, in one pipeline, across files and databases.
One pipeline, from a raw file or table to a fixed exposure.
What it does
Detection, classification and access mapping, running as one pipeline over files and databases alike.
Built-in detectors
Aadhaar, PAN and card numbers validated for real, not just pattern-matched — plus email, phone and IP.
Custom rules
Regex, keyword dictionaries, boolean logic and YARA rules, layered on the built-ins for anything sector-specific.
OCR
Scanned images and image-only PDF pages get read too, so nothing sensitive hides behind a picture.
Multi-type findings
A single file can trip PII, PCI and HIPAA together — every match is reported, not just the first one found.
Live scan progress
Full sweeps, incremental scans and one-off scoped scans, with files-scanned and percent-complete streamed live.
Access mapping
See exactly which identities can reach a sensitive store, including stale accounts and permissions no one's using.
Guardrails
Policy checks run the moment a finding lands — alert, auto-remediate, or hold for an approver's sign-off.
Audit trail
Every data action and every admin action is logged, so an investigation never starts from a blank slate.
Inside the console
Where findings, access and policy come together.
Data Stores
Registered for discovery and classification.
| Name | Type | Status |
|---|---|---|
| analytics-lake | Filesystem | Active |
| prod-users-db | PostgreSQL | Active |
| finance-warehouse | Snowflake | Active |
| shared-drive | Filesystem | Scanning |
| legacy-oracle | Oracle | Active |
Data stores
One inventory, files and databases
Register a filesystem or a database once, and it stays in view — status, type and what it holds, all in the same list.
- Filesystem, warehouses and RDBMS side by side
- Status tracked per store
Access intelligence
See who can reach sensitive data
A live graph of identities and the stores they touch, so exposure is something you can see rather than infer from a spreadsheet.
- Identities and stores mapped as a graph
- Surfaces stale and unused access
Access Intelligence
Who can reach what, mapped automatically.
Guardrails
Evaluated in real time as findings come in.
Aadhaar + card number exposure
Critical finding
Stale access on sensitive folders
High finding
External sharing of PII
High finding
Guardrails
Policy checks that act, not just alert
Rules evaluate every finding as it lands, then either alert, remediate automatically, or hold for a named approver to sign off.
- Alert, auto-remediate, or wait for approval
- Evaluated as findings arrive
Sensitivity scale
Every finding resolves to one of five levels, consistently.
Critical
Regulated IDs together
High
Aadhaar or PAN alone
Medium
Email, phone in volume
Low
Weak or isolated signals
None
Nothing sensitive found
Coverage
File stores and the major databases, in one scan.
Files
Databases
Security
The compliance-critical rules are enforced by the platform, not left to convention.
- Native MFA for administrators
- Role-based access control throughout
- A separate gate just to view raw file contents
- Every data and admin action logged
- Alerts reach your SIEM over Syslog/CEF, webhook, or STIX/TAXII
