Data security platforms for data loss prevention
Test each required channel with the same content. Include browser, email, endpoint and API paths where relevant. Measure false positives, missed transfers and the work needed to investigate alerts.
Data loss prevention
These platforms have documented data loss prevention. Confirm that capability in each required store. Environment marks do not establish that combination.
Select environment headings to prioritize coverage.
What the marks mean
- Full
- Documented support within the scope stated in the platform notes.
- Partial
- Documented support with a material limitation or integration requirement.
- None
- Evidence establishes no support.
- Unconfirmed
- The reviewed sources do not establish support. This is a research gap.
A mark does not establish every capability in every store. Microsoft 365 does not include Azure infrastructure. Warehouses groups Snowflake and Databricks. On-prem covers file shares. Coverage methodology
Select environment headings to prioritize coverage. All columns and platforms stay visible unless you apply a filter.
| Platform | Pricing | ||||||
|---|---|---|---|---|---|---|---|
| ◐ | ◐ | ◐ | ? | ? | ◐ | Not published | |
Cloudflare combines HTTP traffic inspection with API-based scans of stored content through CASB. Its documented CASB scan scope is publicly accessible files, with file-type and size limits. [1] [2] Full profileCompare with…Ask in the evaluationTest whether your private, internally shared and public files are included in the proposed scan. | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
Cyberhaven combines endpoint and cloud discovery with data lineage and DLP. Its DSPM adds origin and movement context to classification and flags excessive repository permissions. [1] Full profileCompare with…Ask in the evaluationSeparate stored-content scanning from observing a user download or upload in each required application. | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
FortiDLP combines endpoint controls with SaaS integrations. Browser activity controls and stored-content connectors have different visibility. Check which path protects each app and whether the needed feature is in the proposed tier. [1] [2] Full profileCompare with…Ask in the evaluationWhich controls use an endpoint agent and which inspect content through an app connector? | |||||||
| ? | ? | ? | ? | ● | ? | Not published | |
Fortra DLP is the current name for Digital Guardian. Endpoint agents, network appliances and discovery components cover different data paths. The discovery documentation explicitly covers local and network shares. [1] [2] Full profileCompare with…Ask in the evaluationWhich components are needed for endpoint, network and stored-data coverage? | |||||||
| ◐ | ◐ | ? | ? | ● | ◐ | Not published | |
GTB documents repository discovery alongside endpoint and network DLP. SharePoint Online and S3 have separate setup guides. Confirm discovery-server placement and the permissions required for each cloud connection. [2] [3] [4] Full profileCompare with…Ask in the evaluationWhich requested Graph permissions are necessary for the selected remediation actions? | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
Metomic combines SaaS content discovery and remediation with controls for AI requests. Evaluate app connectors and the MCP gateway separately because they inspect different paths to sensitive data. [1] Full profileCompare with…Ask in the evaluationWhich controls inspect stored app content and which require traffic through the MCP gateway? | |||||||
| ◐ | ◐ | ◐ | ◐ | ◐ | ◐ | Per user + usage | |
Purview combines Microsoft 365 DLP with endpoint, browser and data-governance capabilities. Coverage, prerequisites and billing differ by workload. A Data Map connector is not evidence of DLP enforcement. [1] [2] [3] Full profileCompare with…Ask in the evaluationFor each required control, identify the workload, licensed plan and enforcement component. Demonstrate the action on that workload. | |||||||
| ◐ | ◐ | ? | ? | ? | ◐ | Not published | |
Nightfall offers native SaaS integrations and a developer scanning API. Custom API workflows require integration work, so distinguish them from ready-made connectors when comparing coverage. [1] Full profileCompare with…Ask in the evaluationWhich integrations need elevated app permissions or a specific app subscription? | |||||||
| ? | ? | ? | ? | ? | ◐ | From $95/mo | |
Polymer classifies SaaS content and applies actions such as redaction, deletion and sharing restrictions. Remediation differs by app. Its Standard price is per user and per integration, which matters when connecting several apps. [1] [2] [3] Full profileCompare with…Ask in the evaluationHow are active users counted across multiple integrations? | |||||||
| ◐ | ? | ? | ? | ? | ◐ | From $72/user/yr | |
Safetica combines content classification, DLP and user-activity controls. Cloud-hosted and on-prem editions have different feature sets. The plan matrix distinguishes Microsoft 365 visibility from sharing policies, so check the required action. [3] Full profileCompare with…Ask in the evaluationWhich policies can block an action versus report it after it happens? | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
Skyhigh combines cloud access controls with content classification and DLP. API and proxy use cases need separate evaluation, especially when the requirement is to stop a download from an unmanaged device. [1] [2] Full profileCompare with…Ask in the evaluationWhich controls scan stored content and which intercept activity? | |||||||
| ◐ | ? | ? | ? | ● | ◐ | Not published | |
Symantec DLP spans endpoint, network, stored-data and cloud components. File-share discovery and cloud enforcement can require different products, so evaluate the licensed combination against the intended channels. [1] Full profileCompare with…Ask in the evaluationWhich DLP Core, CloudSOC and cloud detection licenses are required? | |||||||
| ? | ? | ? | ? | ● | ? | Not published | |
Trellix separates endpoint, network and stored-data DLP. Discover inventories and classifies repository content. Confirm the required modules and current server support before using older deployment specifications. [1] [2] Full profileCompare with…Ask in the evaluationWhich supported server versions and Discover components are required today? | |||||||
Confirm each capability in your specific data stores. Methodology