BigID
Compare with…BigID supports metadata-only, sampled and full-content scans across files, databases and cloud stores. Its Snowflake integration also applies native tagging and masking. Compare scan settings and the proposed product entitlement. [1] [3]
Updated 5 sources
Store and control evidence
Read each documented action together with its limits.
Find sensitive data in S3
BigID lists classification of Amazon S3 data with bucket and prefix scope. [1]
Scan depth can use metadata, sampling or full content. Agree on the S3 scan mode and exclusions before comparing findings. [1]
Classify Snowflake data
BigID documents discovery and classification of sensitive Snowflake data with native tagging of classification results. [3]
Require the selected scan depth, supported object types and exclusions. BigID separately offers a DSPM Native App for discovery and classification and a Data Intelligence Platform private offer. Confirm which product the proposal includes. [3] [4]
Mask sensitive columns in Snowflake
BigID documents applying Snowflake-native dynamic masking policies based on tags and classification. [3]
Snowflake tag-based masking requires Enterprise Edition or higher and a policy matching the column data type. Require the BigID product entitlement and policy permissions. Do not assume the separately offered discovery Native App includes this enforcement. [3] [4] [5]
Data coverage
Read the scope beside each mark. Support for an environment does not establish every capability in every store.
- Microsoft 365
- Partial
Microsoft 365 is listed as a discovery source. Confirm permissions and sharing-link analysis for each workload. [1]
- AWS
- Partial
Amazon S3 discovery is documented. Confirm coverage for the AWS database services you use. [1]
- Google Cloud
- Partial
Google Cloud Storage and BigQuery discovery are listed. [1]
- Snowflake and Databricks
- Full
Snowflake and Databricks discovery are listed. Confirm which scan modes each connector supports. [1]
- On-prem shares
- Full
Discovery includes SMB, NFS, CIFS and NetApp file stores. [1]
- SaaS apps
- Partial
Named discovery sources include Google Workspace, Box and Dropbox. [1]
Deployment and cost
How it runs
Scanners run in containers in BigID cloud or customer infrastructure, depending on deployment. [2]
- Connectors
- REST API or Java connectors connect scanners to data stores.
- Network access
- Scanners and connectors need the documented network paths to the source.
Pricing and operating workload are not published in the reviewed sources.
Questions for the vendor
- Show how sampled and full scans classify the same representative dataset.
- Which scanner reads content, which fields leave it and who pays for compute?
- Demonstrate effective permissions and public-link discovery separately from classification.