Cyera
Compare with…Cyera DSPM combines content classification with identity, access and exposure context, including access revocation and remediation workflows. This profile covers DSPM. Cyera prices DLP as a separate plan. [1] [8]
Discovery & classification and Access governance [1]
Updated 12 sources
Store and control evidence
Read each documented action together with its limits.
Restrict file sharing in Microsoft 365
Cyera documents revoking public and organization-wide access in SharePoint and OneDrive, including files accessed through Teams. [9]
The documented actions change access and record an audit trail. Test inherited permissions and rollback separately from any requirement to block content in transit. [9]
Find sensitive data in S3
Cyera documents detecting exposed sensitive files in S3 and removing public access. [10]
The release describes exposure remediation. Require the supported file types, scan exclusions and sampling settings for the discovery evaluation. [10]
Classify Snowflake data
Cyera documents column-level discovery of sensitive Snowflake data and identification of overexposed columns. [11]
Require the scan scope, sampling settings and connector permissions for the proposed deployment. The release establishes column discovery but does not provide a complete connector setup or exclusion matrix. [11]
Mask sensitive columns in Snowflake
Cyera documents an Apply Snowflake Tag action that links a sensitive column to a native Snowflake dynamic masking policy. [11]
Snowflake tag-based masking requires Enterprise Edition or higher and a policy matching the column data type. Confirm the Cyera entitlement, write permissions and existing tag-policy setup. Test results with authorized and unauthorized query roles. [11] [12]
Data coverage
Read the scope beside each mark. Support for an environment does not establish every capability in every store.
- Microsoft 365
- Full
Releases document Exchange discovery and classification alongside native public and organization-wide sharing remediation for SharePoint, OneDrive and Teams. [4] [5]
- AWS
- Partial
The S3 release documents sensitive-file exposure detection and public-access removal. Confirm the scan and control matrix for other AWS stores. [5] [10]
- Google Cloud
- Unconfirmed
- Snowflake and Databricks
- Full
Snowflake scanning is documented separately from the findings-export integration. Databricks Unity Catalog scanning is listed in the integration catalog. [2] [3]
- On-prem shares
- Full
Identity analysis maps Active Directory access to sensitive files on SMB shares, NetApp and Dell PowerScale. Confirm the connector and remediation scope. [5]
- SaaS apps
- Partial
Releases document discovery and classification for Salesforce files and ServiceNow ITSM records. The Slack integration sends alerts and is not evidence of Slack content scanning. [5]
Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed
Deployment and cost
How it runs
Cyera offers SaaS and Outpost deployment models. Its implementation FAQ places Outpost scanning inside the customer account. [6] [7]
- Processing boundary
- The FAQ describes metadata flowing to the Data Insights SaaS service in both models. Confirm the metadata fields, samples and regions in the proposed architecture.
- On-prem connection
- The on-prem product page offers both connector-based and connectorless deployments in SaaS or Outpost environments. Confirm the mode for each required store.
- Scan completeness
- The FAQ describes clustering similar objects to classify data without scanning every object. Test which sensitive examples are missed and how exclusions are reported.
Pricing
Cyera requests a custom quote and describes separate DSPM and DLP plans. [8]
- Optional products
- Data Subject Request Automation and DataWatcher are described as optional add-ons.
- Quote requirements
- The reviewed pricing page does not state rates or a billing unit. Require the included stores, usage assumptions, add-ons and renewal terms in the quote.
Operating workload is not published in the reviewed sources.
Questions for the vendor
- Draw the SaaS or Outpost data flow for each required store, including metadata, samples, regions and any local connector.
- Test seeded sensitive examples, unusual file types and low-frequency data. Show how clustering, scan exclusions and missed objects appear in the results.
- Demonstrate access revocation with approval, audit history and rollback. Identify the licensed plan and permissions required for each action.