DataMasque
Compare with…DataMasque runs configurable masking jobs against supported databases. Its documented run_data_discovery task inspects schema metadata for likely sensitive columns. That task should not be mistaken for content classification. [2]
Discovery & classification [2]
Sources reviewed 2 sources
Data coverage
Read the scope beside each mark. Support for an environment does not establish every capability in every store.
- Microsoft 365
- Unconfirmed
- AWS
- Partial
Connections include RDS, Aurora, Redshift, DocumentDB and DynamoDB. The documented metadata-discovery task is unavailable for DynamoDB. [1] [2]
- Google Cloud
- Unconfirmed
- Snowflake and Databricks
- Full
Connections include Snowflake, Databricks SQL Warehouse and Databricks Lakebase. Check task and type limitations for each. [1]
- On-prem shares
- Unconfirmed
- SaaS apps
- Unconfirmed
Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed
Deployment and cost
How it runs
Rulesets execute ordered tasks against connected databases and can group work serially or in parallel. [2]
- Operational boundary
- Plan and test masking on a controlled data copy before changing production data.
Pricing and operating workload are not published in the reviewed sources.
Questions for the vendor
- Separate metadata discovery from any licensed content-discovery feature in the proposed workflow.
- Prove referential integrity after masking a representative copy of production data.
- Identify unsupported data types and keys before including a database in the masking run.