Data security platforms for Google Cloud
Check Cloud Storage, BigQuery and Cloud SQL separately. A BigQuery metadata connector does not establish content classification. Confirm supported regions, engines and scan permissions.
Select environment headings to prioritize coverage.
What the marks mean
- Full
- Documented support within the scope stated in the platform notes.
- Partial
- Documented support with a material limitation or integration requirement.
- None
- Evidence establishes no support.
- Unconfirmed
- The reviewed sources do not establish support. This is a research gap.
A mark does not establish every capability in every store. Microsoft 365 does not include Azure infrastructure. Warehouses groups Snowflake and Databricks. On-prem covers file shares. Coverage methodology
Select environment headings to prioritize coverage. All columns and platforms stay visible unless you apply a filter.
| Platform | Pricing | ||||||
|---|---|---|---|---|---|---|---|
| ◐ | ● | ● | ● | ● | ◐ | Not published | |
Netskope documents store-specific discovery and classification across cloud, SaaS and file shares. SaaS support requires the relevant feature. Check the metadata sent to the application and the classification scope for each store. [1] Full profileCompare with…
Ask in the evaluationWhich SaaS connectors and classification types are included in the proposed license? | |||||||
| ◐ | ◐ | ◐ | ● | ● | ◐ | Not published | |
BigID supports metadata-only, sampled and full-content scans across files, databases and cloud stores. Its Snowflake integration also applies native tagging and masking. Compare scan settings and the proposed product entitlement. [1] [3] Full profileCompare with…
Ask in the evaluationShow how sampled and full scans classify the same representative dataset. | |||||||
| ◐ | ◐ | ◐ | ? | ? | ◐ | Not published | |
Cloudflare combines HTTP traffic inspection with API-based scans of stored content through CASB. Its documented CASB scan scope is publicly accessible files, with file-type and size limits. [1] [2] Full profileCompare with…
Ask in the evaluationTest whether your private, internally shared and public files are included in the proposed scan. | |||||||
| ? | ? | ◐ | ◐ | ? | ? | Not published | |
comforte protects data fields through tokenization and encryption. Its BigQuery integration replaces sensitive values with tokens while retaining formats for analytics. Verify who can reverse that protection. [2] Full profileCompare with…
Ask in the evaluationTest joins, analytics and application behavior with tokenized values. | |||||||
| ● | ● | ◐ | ● | ◐ | ◐ | Not published | |
Concentric AI uses content context to classify data and identify excessive access. Its Microsoft 365 workflow connects discovery with permission and sharing remediation. [2] Full profileCompare with…
Ask in the evaluationUse your own business documents to test classification without preassigned labels. | |||||||
| ◐ | ◐ | ◐ | ◐ | ◐ | ◐ | Not published | |
DataSunrise combines database monitoring with discovery across databases, object stores and selected collaboration tools. Discovery, masking and blocking have different deployment paths. Confirm feature support for each source. [1] [2] [4] Full profileCompare with… | |||||||
| ● | ◐ | ◐ | ? | ◐ | ◐ | Not published | |
Egnyte Secure & Govern scans connected content sources for sensitive data and access issues. Microsoft sources need permissions management configured to expose permission risks. Windows file servers use an agent. [1] [2] Full profileCompare with…
Ask in the evaluationConfirm that the source is connected for governance rather than migration only. | |||||||
| ? | ◐ | ◐ | ? | ? | ? | Usage-based | |
Discovery produces data profiles, while inspection identifies individual sensitive values. Supported stores differ between these functions, so specify whether the evaluation needs a risk profile or a content scan. [1] Full profileCompare with…
Ask in the evaluationDoes each required store need data profiles, individual inspection findings or both? Demonstrate the selected output. | |||||||
| ? | ◐ | ◐ | ◐ | ? | ? | Not published | |
Guardium spans discovery, classification and data detection and response across multiple products. Verify the component, collection method and license behind each promised control. [1] Full profileCompare with…
Ask in the evaluationWhich Guardium products and licenses are required for the proposed stores? | |||||||
| ? | ◐ | ◐ | ● | ? | ? | Not published | |
Immuta manages access policies in supported analytics platforms. Enforcement differs by integration, so a Snowflake masking policy should not be assumed to work identically in BigQuery or S3. [1] Full profileCompare with…
Ask in the evaluationShow masking and row filtering through every query path used by your applications. | |||||||
| ◐ | ◐ | ◐ | ◐ | ◐ | ◐ | Per user + usage | |
Purview combines Microsoft 365 DLP with endpoint, browser and data-governance capabilities. Coverage, prerequisites and billing differ by workload. A Data Map connector is not evidence of DLP enforcement. [1] [2] [3] Full profileCompare with…
Ask in the evaluationFor each required control, identify the workload, licensed plan and enforcement component. Demonstrate the action on that workload. | |||||||
| ? | ◐ | ◐ | ◐ | ? | ◐ | Not published | |
PK Protect Data Store Manager discovers and masks sensitive data across databases, cloud repositories and packaged apps. Confirm which protection method is available for each store and whether it changes source data or a derived copy. [1] Full profileCompare with…
Ask in the evaluationDoes protection modify production values, create masked copies or enforce at query time? | |||||||
| ? | ◐ | ◐ | ◐ | ? | ? | Not published | |
Palo Alto Networks documents DSPM in Prisma Cloud and the newer Cortex Cloud documentation. Confirm the product edition, migration path and regional availability before using a feature list in procurement. [1] [2] [3] Full profileCompare with…
Ask in the evaluationIdentify the exact product, edition and DSPM entitlement in the contract. | |||||||
| ◐ | ◐ | ◐ | ◐ | ? | ◐ | Not published | |
Proofpoint DSPM discovers sensitive data and supports data-access analysis. Its Snowflake documentation describes different scan deployments, so require the architecture for the version being quoted. [1] [2] Full profileCompare with…
Ask in the evaluationIs the proposed Snowflake scanner a native app or a sidecar in your AWS account? | |||||||
| ? | ◐ | ◐ | ● | ? | ? | Not published | |
Protegrity applies field-level tokenization, encryption and masking through protectors integrated with data platforms. Evaluate the protector and runtime for each store because policy enforcement depends on the integration path. [1] [2] Full profileCompare with…
Ask in the evaluationWhich runtimes and clients can access unprotected values? | |||||||
| ? | ◐ | ◐ | ● | ? | ? | Not published | |
Satori governs access to databases and warehouses through proxy or native API integrations. Choose the integration mode per store, then test policy coverage for users who connect directly. [2] Full profileCompare with…
Ask in the evaluationWhich stores use a proxy and which use native policy APIs? | |||||||
| ? | ◐ | ◐ | ◐ | ? | ? | Not published | |
SecuPi combines data classification with fine-grained access policies and de-identification. Its coverage list spans applications, databases and cloud stores, but the enforcement method must be confirmed for each interface. [1] Full profileCompare with…
Ask in the evaluationWhich enforcement component is needed for each data access path? | |||||||
| ◐ | ? | ◐ | ◐ | ? | ? | Not published | |
Securiti combines sensitive-data discovery with privacy workflows and access governance. Its Snowflake integration supports native access controls, row filtering and dynamic masking. [1] [2] Full profileCompare with…
Ask in the evaluationSeparate data-security controls from privacy request automation in the quote. | |||||||
| ◐ | ◐ | ◐ | ◐ | ◐ | ◐ | Not published | |
DataGuard combines classification with identity, permission and activity analysis. Symmetry describes deployment within the customer environment, including the interface. Request a store-level support matrix before treating broad cloud claims as complete coverage. [1] Full profileCompare with…
Ask in the evaluationWhich connectors enumerate effective permissions and which only classify content? | |||||||
| ◐ | ◐ | ◐ | ? | ● | ◐ | Not published | |
CipherTrust combines data discovery with separately configured encryption and key-management components. Cloud key support does not establish content scanning or access governance for the same service. [1] [2] Full profileCompare with…
Ask in the evaluationMap each store to discovery, encryption and key-management components and quote them separately. | |||||||
| ● | ● | ◐ | ● | ● | ◐ | Not published | |
Varonis combines content classification, effective-permission analysis and activity monitoring. Its Microsoft 365 controls include removing risky shared links and excessive access. [2] Full profileCompare with…
Ask in the evaluationFor every connector, identify where file content is processed, which metadata leaves the environment and whether File Analysis or AI Monitoring changes retention. | |||||||
| ? | ◐ | ◐ | ◐ | ? | ? | Not published | |
Wiz links sensitive-data findings to cloud identity and infrastructure risks. Its DSPM and entitlement analysis can help investigate who can reach sensitive data alongside the surrounding cloud configuration. [1] Full profileCompare with…
Ask in the evaluationShow the difference between a user with permission and a user who actually accessed the data. | |||||||
| ? | ◐ | ◐ | ◐ | ? | ? | Not published | |
Zscaler documents different scan methods by store, including APIs, snapshots, exports and sampled queries. A supported connector does not establish that every row or object is inspected. [1] Full profileCompare with…
Ask in the evaluationWhat sampling rate and exclusions apply to each store? | |||||||
| ? | ? | ? | ● | ? | ? | Not published | |
ALTR applies access policies, masking and tokenization to connected databases. Snowflake enforcement and classification can take different processing paths, so check which data leaves the account. [2] Full profileCompare with…
Ask in the evaluationWhich protection types require an external call, and where will classification run? | |||||||
| ? | ◐ | ? | ? | ? | ? | Usage-based | |
Macie discovers sensitive data in Amazon S3. Storage classes, file formats and object eligibility limit what it can inspect. Database exports to S3 do not constitute a native database integration. [1] Full profileCompare with…
Ask in the evaluationShow which objects were inspected, skipped or excluded, grouped by format, storage class and access failure. | |||||||
| ? | ◐ | ? | ? | ? | ? | Not published | |
Bedrock combines data classification with entitlement analysis in its Metadata Lake. Adaptive scanning selects representative samples from similar objects. Check the sampling policy and what metadata reaches the service. [2] Full profileCompare with…
Ask in the evaluationHow are representative samples chosen and what could be missed? | |||||||
| ? | ◐ | ? | ? | ? | ? | Not published | |
Falcon Data Security for Cloud combines agentless discovery with runtime monitoring of sensitive data flows. Runtime visibility uses eBPF in the Falcon sensor. Request a store-level matrix before treating broad cloud coverage as complete. [1] [2] Full profileCompare with…
Ask in the evaluationList the exact cloud storage and database engines inspected at rest. | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
Cyberhaven combines endpoint and cloud discovery with data lineage and DLP. Its DSPM adds origin and movement context to classification and flags excessive repository permissions. [1] Full profileCompare with…
Ask in the evaluationSeparate stored-content scanning from observing a user download or upload in each required application. | |||||||
| ● | ◐ | ? | ● | ● | ◐ | Custom quote | |
Cyera DSPM combines content classification with identity, access and exposure context, including access revocation and remediation workflows. This profile covers DSPM. Cyera prices DLP as a separate plan. [1] [8] Full profileCompare with…
Ask in the evaluationDraw the SaaS or Outpost data flow for each required store, including metadata, samples, regions and any local connector. | |||||||
| ? | ◐ | ? | ● | ? | ? | Not published | |
DataMasque runs configurable masking jobs against supported databases. Its documented run_data_discovery task inspects schema metadata for likely sensitive columns. That task should not be mistaken for content classification. [2] Full profileCompare with…
Ask in the evaluationSeparate metadata discovery from any licensed content-discovery feature in the proposed workflow. | |||||||
| ◐ | ◐ | ? | ● | ? | ◐ | Not published | |
Forcepoint DSPM discovers and classifies data, while streaming integrations support activity monitoring. Its Microsoft 365 labeling integration writes classification results to Purview sensitivity labels. [2] [3] Full profileCompare with…
Ask in the evaluationQuote DSPM, activity monitoring and DLP enforcement separately. | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
FortiDLP combines endpoint controls with SaaS integrations. Browser activity controls and stored-content connectors have different visibility. Check which path protects each app and whether the needed feature is in the proposed tier. [1] [2] Full profileCompare with…
Ask in the evaluationWhich controls use an endpoint agent and which inspect content through an app connector? | |||||||
| ? | ? | ? | ? | ● | ? | Not published | |
Fortra DLP is the current name for Digital Guardian. Endpoint agents, network appliances and discovery components cover different data paths. The discovery documentation explicitly covers local and network shares. [1] [2] Full profileCompare with…
Ask in the evaluationWhich components are needed for endpoint, network and stored-data coverage? | |||||||
| ◐ | ◐ | ? | ? | ● | ◐ | Not published | |
GTB documents repository discovery alongside endpoint and network DLP. SharePoint Online and S3 have separate setup guides. Confirm discovery-server placement and the permissions required for each cloud connection. [2] [3] [4] Full profileCompare with…
Ask in the evaluationWhich requested Graph permissions are necessary for the selected remediation actions? | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
Metomic combines SaaS content discovery and remediation with controls for AI requests. Evaluate app connectors and the MCP gateway separately because they inspect different paths to sensitive data. [1] Full profileCompare with…
Ask in the evaluationWhich controls inspect stored app content and which require traffic through the MCP gateway? | |||||||
| ◐ | ? | ? | ? | ● | ◐ | Not published | |
Netwrix Data Classification scans file shares, Microsoft 365 and selected SaaS sources. Netwrix Auditor can use its classifications in audit reports. Confirm the licensed products together. [2] Full profileCompare with…
Ask in the evaluationList the exact product editions needed for classification, audit and access remediation. | |||||||
| ◐ | ◐ | ? | ? | ? | ◐ | Not published | |
Nightfall offers native SaaS integrations and a developer scanning API. Custom API workflows require integration work, so distinguish them from ready-made connectors when comparing coverage. [1] Full profileCompare with…
Ask in the evaluationWhich integrations need elevated app permissions or a specific app subscription? | |||||||
| ? | ? | ? | ◐ | ? | ? | Not published | |
OneTrust connects discovery and classification with privacy and access policies. Its Snowflake integration applies data tags and role-based masking. Confirm the current entitlement and enforcement workflow. [2] Full profileCompare with…
Ask in the evaluationShow the deployed version of the Snowflake integration and the permissions it requires. | |||||||
| ? | ? | ? | ? | ? | ? | Not published | |
Data Safe focuses on Oracle databases, including deployments outside Oracle Cloud. Discovery identifies sensitive columns. Its database scope should not be read as coverage of file shares or collaboration apps. [1] Full profileCompare with…
Ask in the evaluationCan each target database connect to the selected Data Safe region? | |||||||
| ? | ? | ? | ? | ? | ◐ | From $95/mo | |
Polymer classifies SaaS content and applies actions such as redaction, deletion and sharing restrictions. Remediation differs by app. Its Standard price is per user and per integration, which matters when connecting several apps. [1] [2] [3] Full profileCompare with…
Ask in the evaluationHow are active users counted across multiple integrations? | |||||||
| ? | ◐ | ? | ● | ? | ? | Not published | |
Privacera manages access policies and scans supported data platforms. Snowflake discovery supports offline and incremental scans, while its feature matrix excludes real-time scanning and lineage. [1] Full profileCompare with…
Ask in the evaluationTest policy enforcement on SELECT queries and document what happens on writes. | |||||||
| ◐ | ◐ | ? | ◐ | ? | ◐ | Not published | |
Rubrik DSPM combines classification with sensitive-data access analysis and suspicious-activity monitoring. Confirm whether each finding comes from a live source or protected data in the proposed configuration. [1] Full profileCompare with…
Ask in the evaluationMap live scanning, backup classification and their refresh intervals for every source. | |||||||
| ◐ | ? | ? | ? | ? | ◐ | From $72/user/yr | |
Safetica combines content classification, DLP and user-activity controls. Cloud-hosted and on-prem editions have different feature sets. The plan matrix distinguishes Microsoft 365 visibility from sharing policies, so check the required action. [3] Full profileCompare with…
Ask in the evaluationWhich policies can block an action versus report it after it happens? | |||||||
| ? | ◐ | ? | ? | ◐ | ◐ | Not published | |
Sentra classifies cloud data, analyzes sharing permissions and alerts on suspicious data activity. Its scanning architecture allows both customer-owned and Sentra-owned scanner accounts. [1] [2] Full profileCompare with…
Ask in the evaluationSpecify which account owns every scanner and where extracted samples and metadata are retained. | |||||||
| ◐ | ? | ? | ? | ? | ◐ | Not published | |
Skyhigh combines cloud access controls with content classification and DLP. API and proxy use cases need separate evaluation, especially when the requirement is to stop a download from an unmanaged device. [1] [2] Full profileCompare with…
Ask in the evaluationWhich controls scan stored content and which intercept activity? | |||||||
| ◐ | ◐ | ? | ? | ● | ◐ | Not published | |
Spirion uses scanning agents with a SaaS analytics platform. Differential scans skip unchanged files, but that feature has its own source restrictions. Confirm whether a scan covers all content or only changes. [2] [3] Full profileCompare with…
Ask in the evaluationWhich sources support differential scans and which require full rescans? | |||||||
| ◐ | ? | ? | ? | ● | ◐ | Not published | |
Symantec DLP spans endpoint, network, stored-data and cloud components. File-share discovery and cloud enforcement can require different products, so evaluate the licensed combination against the intended channels. [1] Full profileCompare with…
Ask in the evaluationWhich DLP Core, CloudSOC and cloud detection licenses are required? | |||||||
| ? | ◐ | ? | ◐ | ? | ? | Not published | |
Tenable combines sensitive-data classification with cloud exposure and identity findings. Its DSPM uses agentless API scans and provides guided remediation for risky configurations and permissions. [1] Full profileCompare with…
Ask in the evaluationConfirm DSPM entitlement and scan costs in the exact Tenable One package quoted. | |||||||
| ? | ? | ? | ? | ● | ? | Not published | |
Trellix separates endpoint, network and stored-data DLP. Discover inventories and classifies repository content. Confirm the required modules and current server support before using older deployment specifications. [1] [2] Full profileCompare with…
Ask in the evaluationWhich supported server versions and Discover components are required today? | |||||||
| ? | ◐ | ? | ● | ? | ? | Not published | |
TrustLogix monitors and enforces data-access policies in analytics platforms. It can use Alation classifications and catalog metadata as inputs, so confirm which discovery capabilities come from a separate product. [1] Full profileCompare with…
Ask in the evaluationShow enforcement when a user queries through an alternate client or service account. | |||||||
Confirm each capability in your specific data stores. Methodology