Data security platforms for access governance
Ask each platform to show effective access and the reason it is granted. Test an inherited permission, external link and service account. Separate visibility from enforcement and verify rollback.
Access governance
These platforms have documented access governance. Confirm that capability in each required store. Environment marks do not establish that combination.
Select environment headings to prioritize coverage.
What the marks mean
- Full
- Documented support within the scope stated in the platform notes.
- Partial
- Documented support with a material limitation or integration requirement.
- None
- Evidence establishes no support.
- Unconfirmed
- The reviewed sources do not establish support. This is a research gap.
A mark does not establish every capability in every store. Microsoft 365 does not include Azure infrastructure. Warehouses groups Snowflake and Databricks. On-prem covers file shares. Coverage methodology
Select environment headings to prioritize coverage. All columns and platforms stay visible unless you apply a filter.
| Platform | Pricing | ||||||
|---|---|---|---|---|---|---|---|
| ? | ? | ? | ● | ? | ? | Not published | |
ALTR applies access policies, masking and tokenization to connected databases. Snowflake enforcement and classification can take different processing paths, so check which data leaves the account. [2] Full profileCompare with…Ask in the evaluationWhich protection types require an external call, and where will classification run? | |||||||
| ? | ◐ | ? | ? | ? | ? | Not published | |
Bedrock combines data classification with entitlement analysis in its Metadata Lake. Adaptive scanning selects representative samples from similar objects. Check the sampling policy and what metadata reaches the service. [2] Full profileCompare with…Ask in the evaluationHow are representative samples chosen and what could be missed? | |||||||
| ◐ | ◐ | ◐ | ● | ● | ◐ | Not published | |
BigID supports metadata-only, sampled and full-content scans across files, databases and cloud stores. Its Snowflake integration also applies native tagging and masking. Compare scan settings and the proposed product entitlement. [1] [3] Full profileCompare with…Ask in the evaluationShow how sampled and full scans classify the same representative dataset. | |||||||
| ● | ● | ◐ | ● | ◐ | ◐ | Not published | |
Concentric AI uses content context to classify data and identify excessive access. Its Microsoft 365 workflow connects discovery with permission and sharing remediation. [2] Full profileCompare with…Ask in the evaluationUse your own business documents to test classification without preassigned labels. | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
Cyberhaven combines endpoint and cloud discovery with data lineage and DLP. Its DSPM adds origin and movement context to classification and flags excessive repository permissions. [1] Full profileCompare with…Ask in the evaluationSeparate stored-content scanning from observing a user download or upload in each required application. | |||||||
| ● | ◐ | ? | ● | ● | ◐ | Custom quote | |
Cyera DSPM combines content classification with identity, access and exposure context, including access revocation and remediation workflows. This profile covers DSPM. Cyera prices DLP as a separate plan. [1] [8] Full profileCompare with…Ask in the evaluationDraw the SaaS or Outpost data flow for each required store, including metadata, samples, regions and any local connector. | |||||||
| ● | ◐ | ◐ | ? | ◐ | ◐ | Not published | |
Egnyte Secure & Govern scans connected content sources for sensitive data and access issues. Microsoft sources need permissions management configured to expose permission risks. Windows file servers use an agent. [1] [2] Full profileCompare with…Ask in the evaluationConfirm that the source is connected for governance rather than migration only. | |||||||
| ? | ◐ | ◐ | ● | ? | ? | Not published | |
Immuta manages access policies in supported analytics platforms. Enforcement differs by integration, so a Snowflake masking policy should not be assumed to work identically in BigQuery or S3. [1] Full profileCompare with…Ask in the evaluationShow masking and row filtering through every query path used by your applications. | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
Metomic combines SaaS content discovery and remediation with controls for AI requests. Evaluate app connectors and the MCP gateway separately because they inspect different paths to sensitive data. [1] Full profileCompare with…Ask in the evaluationWhich controls inspect stored app content and which require traffic through the MCP gateway? | |||||||
| ? | ? | ? | ◐ | ? | ? | Not published | |
OneTrust connects discovery and classification with privacy and access policies. Its Snowflake integration applies data tags and role-based masking. Confirm the current entitlement and enforcement workflow. [2] Full profileCompare with…Ask in the evaluationShow the deployed version of the Snowflake integration and the permissions it requires. | |||||||
| ? | ? | ? | ? | ? | ◐ | From $95/mo | |
Polymer classifies SaaS content and applies actions such as redaction, deletion and sharing restrictions. Remediation differs by app. Its Standard price is per user and per integration, which matters when connecting several apps. [1] [2] [3] Full profileCompare with…Ask in the evaluationHow are active users counted across multiple integrations? | |||||||
| ? | ◐ | ? | ● | ? | ? | Not published | |
Privacera manages access policies and scans supported data platforms. Snowflake discovery supports offline and incremental scans, while its feature matrix excludes real-time scanning and lineage. [1] Full profileCompare with…Ask in the evaluationTest policy enforcement on SELECT queries and document what happens on writes. | |||||||
| ◐ | ◐ | ◐ | ◐ | ? | ◐ | Not published | |
Proofpoint DSPM discovers sensitive data and supports data-access analysis. Its Snowflake documentation describes different scan deployments, so require the architecture for the version being quoted. [1] [2] Full profileCompare with…Ask in the evaluationIs the proposed Snowflake scanner a native app or a sidecar in your AWS account? | |||||||
| ? | ◐ | ◐ | ● | ? | ? | Not published | |
Protegrity applies field-level tokenization, encryption and masking through protectors integrated with data platforms. Evaluate the protector and runtime for each store because policy enforcement depends on the integration path. [1] [2] Full profileCompare with…Ask in the evaluationWhich runtimes and clients can access unprotected values? | |||||||
| ◐ | ◐ | ? | ◐ | ? | ◐ | Not published | |
Rubrik DSPM combines classification with sensitive-data access analysis and suspicious-activity monitoring. Confirm whether each finding comes from a live source or protected data in the proposed configuration. [1] Full profileCompare with…Ask in the evaluationMap live scanning, backup classification and their refresh intervals for every source. | |||||||
| ? | ◐ | ◐ | ● | ? | ? | Not published | |
Satori governs access to databases and warehouses through proxy or native API integrations. Choose the integration mode per store, then test policy coverage for users who connect directly. [2] Full profileCompare with…Ask in the evaluationWhich stores use a proxy and which use native policy APIs? | |||||||
| ? | ◐ | ◐ | ◐ | ? | ? | Not published | |
SecuPi combines data classification with fine-grained access policies and de-identification. Its coverage list spans applications, databases and cloud stores, but the enforcement method must be confirmed for each interface. [1] Full profileCompare with…Ask in the evaluationWhich enforcement component is needed for each data access path? | |||||||
| ◐ | ? | ◐ | ◐ | ? | ? | Not published | |
Securiti combines sensitive-data discovery with privacy workflows and access governance. Its Snowflake integration supports native access controls, row filtering and dynamic masking. [1] [2] Full profileCompare with…Ask in the evaluationSeparate data-security controls from privacy request automation in the quote. | |||||||
| ? | ◐ | ? | ? | ◐ | ◐ | Not published | |
Sentra classifies cloud data, analyzes sharing permissions and alerts on suspicious data activity. Its scanning architecture allows both customer-owned and Sentra-owned scanner accounts. [1] [2] Full profileCompare with…Ask in the evaluationSpecify which account owns every scanner and where extracted samples and metadata are retained. | |||||||
| ◐ | ◐ | ◐ | ◐ | ◐ | ◐ | Not published | |
DataGuard combines classification with identity, permission and activity analysis. Symmetry describes deployment within the customer environment, including the interface. Request a store-level support matrix before treating broad cloud claims as complete coverage. [1] Full profileCompare with…Ask in the evaluationWhich connectors enumerate effective permissions and which only classify content? | |||||||
| ? | ◐ | ? | ◐ | ? | ? | Not published | |
Tenable combines sensitive-data classification with cloud exposure and identity findings. Its DSPM uses agentless API scans and provides guided remediation for risky configurations and permissions. [1] Full profileCompare with…Ask in the evaluationConfirm DSPM entitlement and scan costs in the exact Tenable One package quoted. | |||||||
| ? | ◐ | ? | ● | ? | ? | Not published | |
TrustLogix monitors and enforces data-access policies in analytics platforms. It can use Alation classifications and catalog metadata as inputs, so confirm which discovery capabilities come from a separate product. [1] Full profileCompare with…Ask in the evaluationShow enforcement when a user queries through an alternate client or service account. | |||||||
| ● | ● | ◐ | ● | ● | ◐ | Not published | |
Varonis combines content classification, effective-permission analysis and activity monitoring. Its Microsoft 365 controls include removing risky shared links and excessive access. [2] Full profileCompare with…Ask in the evaluationFor every connector, identify where file content is processed, which metadata leaves the environment and whether File Analysis or AI Monitoring changes retention. | |||||||
| ? | ◐ | ◐ | ◐ | ? | ? | Not published | |
Wiz links sensitive-data findings to cloud identity and infrastructure risks. Its DSPM and entitlement analysis can help investigate who can reach sensitive data alongside the surrounding cloud configuration. [1] Full profileCompare with…Ask in the evaluationShow the difference between a user with permission and a user who actually accessed the data. | |||||||
Confirm each capability in your specific data stores. Methodology