Discovery that nothing downstream
can afford to let go stale.
Every connected store is scanned and classified continuously — 200+ built-in patterns across 20+ categories, plus your own. That classification is not a report you file. It is the input to how vulnerabilities get ranked, how compliance evidence gets assembled, and how file changes get attributed. A standalone discovery tool hands you a spreadsheet. This one is load-bearing.
An inventory is only fresh
if something depends on it
A discovery tool that only produces a document has no feedback loop — nobody notices when it rots. Three things here break visibly if the classification is wrong, which is exactly why it stays right.
It ranks your vulnerabilities
A CVE on an instance holding classified cardholder data outranks the identical CVE on a dev copy. Same CVSS score, different position in your queue — because the scanner already knows what the data is. A scanner licensed per asset cannot know this. It was never told.
Vulnerability ManagementIt assembles your compliance evidence
"Show every access to personal data in the last 90 days" is only answerable if something has already decided which columns hold personal data. Classification is what turns an audit trail into evidence, across all 57 mapped frameworks.
ComplianceIt attributes your file changes
A modified datafile is a fact. A modified datafile holding restricted PHI, changed by this session running this statement, is a finding. Classification is the difference between the two.
File Activity MonitorThe case for not buying
a dedicated discovery tool
| A purpose-built discovery tool | Discovery inside the platform | |
|---|---|---|
| Inventory freshness | Rescanned on a schedule, drifting in between | Continuous, on stores already connected |
| Onboarding a new data store | New scan target, new credentials, new ticket | Already connected for auditing — nothing to onboard |
| What consumes the output | A CSV, and whoever remembers to read it | Vulnerability ranking, compliance evidence, file attribution |
| Cost of scanning everything | Per-asset licence, so you scan what the budget covers | No marginal cost, so teams scan the whole estate |
What it looks for,
out of the box
- Personally identifiable information
- Payment card data (PAN, CVV, expiry)
- Protected health information
- Financial account and transaction data
- Government and national identifiers
- Credentials, keys, and tokens
- Contact and location data
- Employee and HR records
- Custom patterns you define
Classification findings are themselves forwardable events, so your SIEM can alert on "sensitive data appeared somewhere it has never been before" — not just on access to where you already knew it lived. Full pattern reference in theclassification docs.
You cannot protect
what you have not found
Cost
No separate discovery licence and no per-asset scan fee. Classification runs on stores the collector already reads, so scanning the whole estate costs the same as scanning a corner of it.
Ease of use
Nothing to onboard. The data stores are already connected, the patterns ship built in, and a new store is classified the day it is added — no scheduling ticket, no separate credential set.
Runs local
Classification happens inside your network and sensitive values are masked before anything egresses. Air-gapped estates get the same data map with no internet path.
AI beyond pattern matching
Regular expressions find a card number. Vector embeddings and semantic analysis find the column nobody labelled, the free-text field holding diagnoses, and the export that quietly contains both.
Cited by 55 of the 57 frameworks
we map
Each one below has at least one cited requirement whose evidence this capability produces. Follow any framework through to see the exact articles and why.
Find out what you're actually holding
Enter your business email and we'll classify a representative slice of your estate, then walk you through the data map — including the stores nobody expected to be in scope.