{"kind":"atlas-fold-public-documentation-research","notice":"Provisional editorial anchored assessments in tenths (0.0–5.0), not hands-on effectiveness or purchasing recommendations. Fractional scores include shared rubric criteria and credited source evidence. Unknown scores remain null. Compare only within the same segment, cohort and rubric version.","methodology":"https://atlasofsecurity.com/landscape/explore/methodology/","segment":{"slug":"data-security","name":"Data protection & posture","short":"DLP / DSPM"},"reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"dspm-discovery-posture","name":"Discovery, classification, and access posture","scope":"Comparable discovery, classification, and data-security posture (DSPM/access-posture) offerings. Microsoft Purview is assessed on classifiers, sensitivity labeling as classification, and Data Security Posture Management only. This cohort does not compare enterprise DLP suites or equate cloud DSPM with channel DLP enforcement. Forcepoint, Proofpoint, Symantec, Netskope, and Zscaler DLP are excluded as peers."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented operating safeguards for running discovery and posture: connector or collector permissions, tenant isolation, encryption of metadata, operator roles, and operational limits. Not vendor age, uptime, or claimed reliability.","question":"How completely do public docs describe safeguards operators use to run discovery and posture without treating marketing claims as proof of reliability?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.","1: A concrete basic operating safeguard is documented for the evaluated edition.","2: License or permission prerequisites and a basic administrator role for the console are documented.","3: A connector or collector permission model plus encryption in transit or tenant isolation for metadata is documented.","4: Operational safeguards such as admin-unit scoping, operator audit, inactivity handling, or in-network collectors that do not persist customer content are documented.","5: An end-to-end operating program is documented, including residency choice, tenant incident notification, reversible remediations, and shared-responsibility operator controls."],"refinements":[{"base":4,"criteria":[{"id":"residency-choice","label":"Customer choice of tenant data residency","weight":2},{"id":"tenant-incident-notification","label":"Notification of security incidents affecting the customer tenant","weight":2},{"id":"reversible-remediation","label":"Documented reversal of posture remediation actions","weight":3},{"id":"shared-responsibility-controls","label":"Named customer operating controls in a shared-responsibility program","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Ordinal evidence of shipped workflows against a contemporary shared cohort baseline. Stage 3 means supported baseline workflows, not novelty or superiority. Higher stages require concrete generally available differences supported by comparative primary evidence. Discovery, classification, sensitivity/access/exposure correlation, data-owner context, posture prioritization, and owner-routed or automated remediation are contemporary DSPM baseline capabilities. Access graphs, risk scores, AI labels and remediation queues alone do not establish differentiation.","question":"Which current baseline workflows are supported, and is any concrete shipped difference from that shared baseline established?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a shipped workflow within the scoped cohort. Missing evidence is unknown, never zero.","1: One basic in-scope workflow is confirmed shipped; no broader stage is established.","2: Several baseline components are confirmed shipped, but an integrated contemporary baseline workflow is not established.","3: An integrated contemporary baseline workflow is supported by primary evidence; this stage makes no differentiation or novelty claim.","4: Stage 3 plus one concrete generally available operator workflow difference beyond the shared contemporary baseline, supported by comparative primary evidence.","5: Stage 4 plus multiple complementary generally available workflow differences beyond that baseline, with their boundaries and prerequisites established."]},{"id":"breadth","name":"Capability breadth","description":"Documented discovery, classification, and access-posture coverage across store classes in this cohort. Channel DLP, DAM, and encryption suites are adjacent and not treated as extra DSPM breadth.","question":"Across which documented store classes can operators discover, classify, and assess access or exposure?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an in-scope assessment capability. Missing evidence is unknown, never zero.","1: A bounded in-scope capability is documented for one environment or workflow.","2: Discovery and classification cover one environment class, such as Microsoft 365 or one cloud object store.","3: Discovery plus access or exposure analysis cover more than one store class (files and SaaS, or cloud and database).","4: Documented coverage spans structured and unstructured data across cloud or SaaS plus on-premises or IaaS classes.","5: Generally available modules are documented for IaaS, SaaS, on-premises, databases, and AI-connected stores without relying on preview connectors."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented connectors and handoffs that feed discovery or posture: stores, labels, tickets, APIs, and named partners. A logo wall without configuration detail is weaker evidence than a named integration.","question":"Which store, label, identity, or automation integrations are documented for discovery and posture operators?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an integration or supported data handoff. Missing evidence is unknown, never zero.","1: A concrete native connector or supported manual integration is documented.","2: A small set of third-party store connectors is named.","3: Multi-cloud or SaaS connectors plus at least one labeling, ticketing, or identity handoff are documented.","4: A documented API or partner list names SIEM, SOAR, or peer DSPM or label platforms with specific products.","5: A public connector or partner matrix covers stores, identity, labeling, and automation with operator configuration detail."]},{"id":"governance","name":"Governance & control","description":"Documented administrative and policy controls for classification and posture: roles, scoped admin, owner approval, exceptions, and audit of remediations. Not compliance certifications as a substitute for product controls.","question":"What administrative and policy controls are documented for who may classify, view, and change access posture?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an administrative or policy control. Missing evidence is unknown, never zero.","1: A specific administrative control is documented for the scoped workflow.","2: Role-based access to the posture console is documented.","3: Least-privilege roles plus policy objects for classification or access remediation are documented.","4: Segmented administration, operator audit of remediations, and reversible or owner-approved actions are documented.","5: Policy governance includes residency, exception or risk-acceptance, evidence retention, and delegated administration across business owners."]},{"id":"operations","name":"Operator enablement","description":"Documented tooling that lets a practitioner set up, review, and act on discovery and posture: setup tasks, dashboards, explorers, owner queues, known issues, and training. Not staffing-savings claims.","question":"What published operator paths exist to set up, review, and act on discovery and posture findings?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a supported operator action or guidance path. Missing evidence is unknown, never zero.","1: A concrete operator action and its basic use are documented.","2: A getting-started or setup path is published.","3: Dashboards, reports, or recommended actions are documented for operators.","4: Guided workflows, activity or asset explorers, and owner or analyst queues are documented.","5: An operator kit includes setup tasks, known-issue notes, health or scan status, exportable evidence, and public runbooks or training."]}],"assessments":[{"vendor":"microsoft-purview","cohort":"dspm-discovery-posture","edition":"Microsoft Purview Information Protection classifiers and current Data Security Posture Management (not classic DSPM, not DLP-suite comparison)","asOf":"2026-09-21","status":"research-preview","summary":"Purview documents SITs, trainable classifiers, labels, and current DSPM objectives that correlate Microsoft 365 posture with partner-fed non-Microsoft stores. This assessment covers classification and DSPM only; DLP, Insider Risk, and encryption are adjacent and not scored as peers.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Learn docs list supporting licenses, Purview permissions, Copilot and Fabric prerequisites, and administrative-unit scoping that hides other units from restricted admins. Inactive tenants pause Microsoft 365 DSPM refresh after 60 days and resume on return. That matches documented operational safeguards (anchor 4). Shared-responsibility residency and tenant incident notification for DSPM itself are not documented here, so not anchor 5. The Data Security Posture Agent is preview and is not used as a safeguard.","sourceIds":["s2","s3"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support native sensitivity, oversharing and data-posture investigation within current DSPM, excluding adjacent DLP-policy creation, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s2"]},"breadth":{"score":3,"confidence":"medium","rationale":"Classifiers and DSPM cover Microsoft 365 discovery, labels, and access or oversharing assessments, and docs name Azure, Fabric, and partner-fed SaaS or IaaS such as GCP, Snowflake, and Databricks. Asset explorer currently lists Microsoft locations as Microsoft 365 only, with non-Microsoft locations depending on partner integrations. That is more than one store class (anchor 3), not independently verified native IaaS plus on-prem plus AI-store GA coverage (not 4 or 5).","sourceIds":["s1","s2","s4"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"DSPM consolidates signals from labels and other Purview solutions and names partner integrations with Varonis, Cyera, BigID, and OneTrust for non-Microsoft risk insights. That is a specific peer-DSPM and label partner list (anchor 4). Sentinel data lake setup for partners is described as preview and is not counted. A full operator connector matrix is not published here (not anchor 5).","sourceIds":["s2"]},"governance":{"score":4,"confidence":"medium","rationale":"Classification and DSPM use Purview role groups and least-privilege roles; administrative units restrict reports, explorers, and policies; unrestricted admins are required to create one-click policies. RBAC for AI content and audited agent actions are documented. That is segmented administration with constrained policy creation (anchor 4). Tenant residency and owner risk-acceptance workflows for DSPM findings are not documented on these pages (not anchor 5).","sourceIds":["s3","s4"]},"operations":{"score":4,"confidence":"medium","rationale":"The Purview portal walkthrough documents setup tasks, Posture and Objectives pages, asset explorer, activity explorer (including known display issues), reports, and remediation-action policies. Operators get guided outcome workflows plus known-issue notes (anchor 4). Exportable evidence and a complete public runbook kit beyond Learn articles are not verified (not anchor 5).","sourceIds":["s2","s3"]}},"constraints":["Edition scoped to Information Protection classifiers/labels and current DSPM; DLP, Insider Risk Management, Information Barriers, Privileged Access Management, and Customer Key or Double Key Encryption are adjacent and not compared as DLP-suite peers.","Prerequisite: supporting Purview license, supported region, and Purview permissions; Copilot, Fabric, Edge, and Entra-registered AI apps have additional documented prerequisites.","Microsoft locations in asset explorer currently include Microsoft 365 only; GCP, Snowflake, Databricks and similar stores depend on partner integrations.","Data Security Posture Agent and Sentinel data lake partner setup are preview; they are not treated as GA.","Classic DSPM and DSPM for AI remain available but are not the evaluated edition.","Classification and posture coverage by workload is license-dependent and unverified in a lab.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"s1","title":"Microsoft Purview data security solutions","url":"https://learn.microsoft.com/en-us/purview/purview-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Learn about Microsoft Purview Data Security Posture Management (DSPM)","url":"https://learn.microsoft.com/en-us/purview/data-security-posture-management-learn-about","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Considerations for deploying Microsoft Purview Data Security Posture Management","url":"https://learn.microsoft.com/en-us/purview/data-security-posture-management-considerations","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Classifiers overview","url":"https://learn.microsoft.com/en-us/purview/data-classification-overview","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Microsoft Purview Data Security","company":"Microsoft","profileUrl":"/landscape/vendors/microsoft-purview/"},{"vendor":"varonis","cohort":"dspm-discovery-posture","edition":"Varonis Data Security Platform DSPM (discovery, classification, access intelligence)","asOf":"2026-09-21","status":"research-preview","summary":"Varonis documents classification plus an access graph that includes nested groups and sharing links, with automated permission cleanup on supported stores. Public trust docs describe in-network collectors and metadata-only cloud storage. Channel DLP enforcement is an integration, not this cohort's comparison.","dimensions":{"maturity":{"score":4.7,"confidence":"medium","rationale":"Anchor 4 remains supported by in-network collection, metadata encryption and tenant isolation. The platform trust documentation additionally establishes tenant-location choice, tenant incident notification and customer operating responsibilities. These earn 0.7 under the shared rubric. Reversal procedures for posture remediations are not established, leaving 0.3 uncredited; backup restoration is not treated as reversing a permissions change.","sourceIds":["s3"],"refinement":{"base":4,"evidence":[{"criterion":"residency-choice","rationale":"Customers select tenant geolocation at onboarding; the documentation identifies that choice as a customer responsibility.","sourceIds":["s3"]},{"criterion":"tenant-incident-notification","rationale":"The tenant-security FAQ commits to notifying customers of incidents affecting their tenants.","sourceIds":["s3"]},{"criterion":"shared-responsibility-controls","rationale":"Customer responsibilities include federation, account deactivation, collector patching and monitoring, least-privilege application roles, and secure data-source secrets.","sourceIds":["s3"]}]}},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support sensitivity/access correlation and permissions-remediation workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s1","s2"]},"breadth":{"score":4,"confidence":"low","rationale":"Product pages document structured databases and warehouses, unstructured files and buckets, and semi-structured SaaS and email, plus on-prem file storage, IaaS, and named coverage for Microsoft 365, AWS, Azure, Google Cloud, Salesforce, Box, Snowflake, Databricks, and Windows file shares. That spans structured and unstructured across cloud or SaaS plus on-prem or IaaS (anchor 4). Per-connector GA depth and AI-store modules are not verified from public coverage tiles (not anchor 5).","sourceIds":["s1","s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Varonis documents Microsoft Purview Information Protection labeling and downstream DLP handoff, plus a web API for SIEM, SOAR, and data warehouses using API keys. Coverage pages name many stores. That is a named label platform plus SIEM/SOAR API (anchor 4). A public operator matrix with configuration steps for each integration is not in the reviewed pages (not anchor 5).","sourceIds":["s1","s2","s3"]},"governance":{"score":3,"confidence":"medium","rationale":"Customer-facing API permissions document departmental RBAC and least-privilege roles; classification guidance documents configurable policy objects and label enforcement. These support stage 3. The earlier stage-4 rationale established segmentation but not an operator audit of posture remediations together with reversal or owner approval. Provider-internal change approvals and backup restoration do not fill those customer-workflow requirements. This is a baseline research correction, not a product regression.","sourceIds":["s2","s3"]},"operations":{"score":null,"confidence":"low","rationale":"The cited product pages describe dashboards and recommended actions, but this evidence set does not verify the public setup path required by earlier cumulative stages. Operator enablement remains unknown; documentation access is not treated as product quality.","sourceIds":["s1","s2"]}},"constraints":["Evaluated as DSPM/discovery/access-intelligence; Varonis DLP policy enforcement is described as a Microsoft Purview integration and is not a DLP-suite comparison.","On-premises collectors are a customer-operated prerequisite; customers must patch, restrict access, and encrypt collector disks per the shared-responsibility list.","Optional File Analysis and AI Monitoring (Copilot, AgentForce, ChatGPT Enterprise) are separate roles or data sources; AI prompt retention is documented as 180 days when enabled.","Coverage logos are not a verified connector inventory; per-store permission completeness is unverified.","MDDR is a managed service overlay and is not scored as product posture.","Classification accuracy percentages are vendor claims and are not scored.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"s1","title":"Varonis Data Security Posture Management (DSPM)","url":"https://www.varonis.com/platform/dspm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Varonis Data Discovery and Classification","url":"https://www.varonis.com/platform/data-discovery-and-classification","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Varonis Security Standards and Practices","url":"https://www.varonis.com/trust/security","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Varonis Data Security Platform","company":"Varonis","profileUrl":"/landscape/vendors/varonis/"},{"vendor":"cyera","cohort":"dspm-discovery-posture","edition":"Cyera DSPM (agentless discovery, classification, exposure, and posture remediation)","asOf":"2026-09-21","status":"research-preview","summary":"Cyera documents agentless DSPM with AI-native classification, exposure scoring, and owner-routed or security-led remediation. Omni DLP and Cyera Identity after the Oasis closing are separate modules and are not treated as DSPM completeness. Identity integration evidence remains limited to the acquisition notice.","dimensions":{"maturity":{"score":null,"confidence":"low","rationale":"The cited pages describe in-place processing and logged owner actions. They do not verify the collector permission model and metadata safeguards required by the cumulative stage rubric. These safeguards are unknown, not absent.","sourceIds":["s1","s3"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support sensitivity/access context with data-owner remediation queues, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s1","s3","s4"]},"breadth":{"score":4,"confidence":"low","rationale":"DSPM and platform pages document agentless coverage of cloud, SaaS, DBaaS, and on-prem stores, with named examples including AWS, Azure, Google Cloud, Snowflake, Databricks, and Salesforce, and structured plus unstructured classification. That matches structured/unstructured across cloud or SaaS plus on-prem or IaaS (anchor 4). Email, network, and endpoint tiles on the platform page are adjacent to Omni DLP and are not counted as DSPM breadth. Per-connector GA depth is unverified (not anchor 5).","sourceIds":["s1","s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Existing multicloud/SaaS, ticketing and labeling handoffs remain supported. The official integration catalog explicitly labels Splunk and automation partners as DSPM integrations and describes their data handoffs, meeting stage 4. Omni DLP-only entries are excluded. The catalog does not supply the complete operator configuration matrix needed for stage 5.","sourceIds":["s1","s3","s5"]},"governance":{"score":null,"confidence":"low","rationale":"The source describes owner responses, risk acceptance and logged remediation. Console RBAC and least-privilege administration required by earlier cumulative stages were not verified; beta owner authentication is excluded. Governance remains unknown.","sourceIds":["s3"]},"operations":{"score":null,"confidence":"low","rationale":"The cited pages describe scan status and owner queues, but the earlier setup-path stage and its operator prerequisites were not verified from this evidence set. Operator enablement remains unknown; certification availability alone does not fill that gap.","sourceIds":["s1","s3"]}},"constraints":["Cohort is Cyera DSPM only. Omni DLP, Agent Guardian, Access Trail, and DataWatcher managed services are separate and are not DLP-suite or managed-service comparisons.","Oasis Security acquisition completed 3 September 2026; Cyera Identity is described as the going-forward identity pillar. Acquisition does not verify every identity integration as GA in DSPM.","Owner-portal OTP and SSO authentication are documented as beta.","In-place versus SaaS deployment, sampling versus full scans, and per-store API permissions are unverified.","Customer outcome metrics (precision, petabytes, issue counts) are not scored.","Email, network, and endpoint coverage on the platform page is not treated as DSPM breadth.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"s1","title":"Cyera Data Security Posture Management","url":"https://www.cyera.com/platform/dspm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Cyera platform overview","url":"https://www.cyera.com/platform","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Cyera Remediation Center and remediation paths","url":"https://www.cyera.com/blog/data-security-remediation-is-a-collaboration-problem-cyera-is-designed-for-it","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Cyera completes acquisition of Oasis Security","url":"https://www.cyera.com/press-releases/cyera-completes-acquisition-of-oasis-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Cyera integration catalog with DSPM module labels","url":"https://www.cyera.com/integrations","accessedAt":"2026-09-21","kind":"product"}],"name":"Cyera Data Security","company":"Cyera","profileUrl":"/landscape/vendors/cyera/"},{"vendor":"bigid","cohort":"dspm-discovery-posture","edition":"BigID discovery, classification, and DSPM (access-posture and delegated remediation)","asOf":"2026-09-21","status":"research-preview","summary":"BigID documents discovery and classification as the inventory for DSPM, access governance, privacy, and AI-data workflows, with policy-driven access remediation and owner delegation. Public product pages are marketing-dense; connector depth, encryption, and tenant isolation were not verified. Cloud DLP is adjacent, not this cohort.","dimensions":{"maturity":{"score":null,"confidence":"low","rationale":"The cited pages establish posture dashboards and remediation cases, but do not verify the permission prerequisites and administrator role required by stage 2 or the collector safeguards required by later stages. A dashboard is not evidence of those controls; the operating-safeguard assessment remains unknown.","sourceIds":["s1"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support discovery, classification, access context and delegated remediation, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s1","s2"]},"breadth":{"score":4,"confidence":"low","rationale":"Discovery and DSPM pages document structured, unstructured, and semi-structured sources across cloud, SaaS, on-prem, hybrid, data lakes, and AI-connected data, including PII, PHI, PCI, secrets, and IP. That is structured and unstructured across cloud or SaaS plus on-prem (anchor 4). A public GA connector inventory for IaaS, databases, and AI stores was not verified (not anchor 5).","sourceIds":["s1","s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Discovery/posture sources establish multicloud and SaaS coverage with labeling/remediation handoffs. The DSPM integration overview names Microsoft Purview, Splunk and ServiceNow and describes an API-first integration model, meeting the named-partner requirement at stage 4. This does not verify installation procedures, per-connector permissions or the complete matrix required for stage 5.","sourceIds":["s1","s2","s3"]},"governance":{"score":null,"confidence":"low","rationale":"The cited pages describe ownership and delegated remediation but do not verify console RBAC, least-privilege roles and segmented administration required by the cumulative rubric. Revoke, redact and delete actions have no verified rollback here and are not described as reversible. Governance remains unknown.","sourceIds":["s1"]},"operations":{"score":null,"confidence":"low","rationale":"Product pages describe dashboards and remediation cases, but the public setup path and operator runbooks required by the cumulative rubric were not verified. Operator enablement remains unknown rather than inferred from marketing pages.","sourceIds":["s1","s2"]}},"constraints":["Assessment is discovery, classification, and DSPM/access-posture. Listed cloud DLP, privacy automation, and catalog enrichment are adjacent modules, not DLP-suite comparison.","Connector coverage, scan completeness, and sampling versus full reads are unverified.","Tenant isolation, encryption, and console RBAC were not found on the public product pages reviewed.","Agentic remediation GA versus preview is not independently confirmed.","Classification accuracy rankings and analyst-firm placements are not scored.","Destructive actions (delete, redact) need an explicit lab check before use.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"s1","title":"BigID Data Security Posture Management","url":"https://bigid.com/data-security-posture-management/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"BigID Data Discovery and Classification","url":"https://bigid.com/discovery-classification/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"BigID DSPM and Microsoft Purview integration overview","url":"https://home.bigid.com/dspm-purview-demo","accessedAt":"2026-09-21","kind":"product"}],"name":"BigID","company":"BigID","profileUrl":"/landscape/vendors/bigid/"}],"scenarios":[{"id":"lean-team","name":"Small security team","description":"A small team needs inventory and exposure reduction on a few cloud or SaaS stores without staffing a DLP operations desk. Prioritize operator enablement and posture remediation that owners can complete. Do not treat a DSPM finding as proof that uploads are blocked.","priorities":["operations","maturity"],"questions":["Which connectors are licensed and actually scanning the lab stores?","Can one reversible access change be applied and verified at the repository?","Who reviews false positives without exposing document contents unnecessarily?"]},{"id":"microsoft-centered","name":"Microsoft 365-centered classification and posture","description":"The estate is mostly Microsoft 365 with optional partner-fed cloud stores. Compare Purview DSPM and labels with Varonis or Cyera only as discovery/posture overlays, not as Exchange or endpoint DLP replacements.","priorities":["ecosystem","governance"],"questions":["Does a sensitivity label only classify, or does a separate service enforce sharing?","Which non-Microsoft stores require a partner integration rather than native Purview scanning?","Are one-click DSPM policies allowed for restricted administrative units?"]},{"id":"hybrid-multicloud","name":"Hybrid file, SaaS, and IaaS posture","description":"Operators need structured and unstructured inventory across on-prem files or databases and cloud object or SaaS stores. Compare access-graph or owner-remediation workflows. Exclude SSE or endpoint DLP channel coverage from this scenario.","priorities":["breadth","innovation"],"questions":["Does the connector return nested groups, sharing links, and effective access, or only ACLs?","Is scanning agentless API, in-network collector, or both, and where does content reside during classification?","Which remediation is native to the store versus a ticket to another tool?"]},{"id":"shared-security-privacy","name":"Shared security and privacy inventory","description":"Security and privacy teams want one classified inventory for exposure reduction and data-rights workflows. BigID documents that overlap; others may label only. Still not a DLP or DAM comparison.","priorities":["governance","operations"],"questions":["Can classification errors be corrected without deleting the underlying record?","Which actions are exposure reduction versus retention or deletion?","What evidence export exists for an access review?"]}],"researchNotes":["First edition dated 2026-09-21; no historical assessments are available.","The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.","Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.","Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.","Contemporary cohort baseline: Discovery, classification, sensitivity/access/exposure correlation, data-owner context, posture prioritization, and owner-routed or automated remediation are contemporary DSPM baseline capabilities. Access graphs, risk scores, AI labels and remediation queues alone do not establish differentiation.","Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.","Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.","Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.","Rubric 1.1 divides the new maturity anchor 5 requirements into residency choice (two tenths), tenant incident notification (two), reversible remediation (three), and shared-responsibility operator controls (three). Reversibility and ongoing customer control receive the larger shares because they directly govern safe operation; these are shared editorial weights, not measured performance. Purview receives no extra credit from adjacent services or preview agents. Cyera and BigID operating safeguards remain unknown. Documented baseline innovation stays tied at 3.0.","All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged."],"history":{"segment":"data-security","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"data-security","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"dspm-discovery-posture","name":"Discovery, classification, and access posture","scope":"Comparable discovery, classification, and data-security posture (DSPM/access-posture) offerings. Microsoft Purview is assessed on classifiers, sensitivity labeling as classification, and Data Security Posture Management only. This cohort does not compare enterprise DLP suites or equate cloud DSPM with channel DLP enforcement. Forcepoint, Proofpoint, Symantec, Netskope, and Zscaler DLP are excluded as peers."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented operating safeguards for running discovery and posture: connector or collector permissions, tenant isolation, encryption of metadata, operator roles, and operational limits. Not vendor age, uptime, or claimed reliability.","question":"How completely do public docs describe safeguards operators use to run discovery and posture without treating marketing claims as proof of reliability?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.","1: A concrete basic operating safeguard is documented for the evaluated edition.","2: License or permission prerequisites and a basic administrator role for the console are documented.","3: A connector or collector permission model plus encryption in transit or tenant isolation for metadata is documented.","4: Operational safeguards such as admin-unit scoping, operator audit, inactivity handling, or in-network collectors that do not persist customer content are documented.","5: An end-to-end operating program is documented, including residency choice, tenant incident notification, reversible remediations, and shared-responsibility operator controls."],"refinements":[{"base":4,"criteria":[{"id":"residency-choice","label":"Customer choice of tenant data residency","weight":2},{"id":"tenant-incident-notification","label":"Notification of security incidents affecting the customer tenant","weight":2},{"id":"reversible-remediation","label":"Documented reversal of posture remediation actions","weight":3},{"id":"shared-responsibility-controls","label":"Named customer operating controls in a shared-responsibility program","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Ordinal evidence of shipped workflows against a contemporary shared cohort baseline. Stage 3 means supported baseline workflows, not novelty or superiority. Higher stages require concrete generally available differences supported by comparative primary evidence. Discovery, classification, sensitivity/access/exposure correlation, data-owner context, posture prioritization, and owner-routed or automated remediation are contemporary DSPM baseline capabilities. Access graphs, risk scores, AI labels and remediation queues alone do not establish differentiation.","question":"Which current baseline workflows are supported, and is any concrete shipped difference from that shared baseline established?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a shipped workflow within the scoped cohort. Missing evidence is unknown, never zero.","1: One basic in-scope workflow is confirmed shipped; no broader stage is established.","2: Several baseline components are confirmed shipped, but an integrated contemporary baseline workflow is not established.","3: An integrated contemporary baseline workflow is supported by primary evidence; this stage makes no differentiation or novelty claim.","4: Stage 3 plus one concrete generally available operator workflow difference beyond the shared contemporary baseline, supported by comparative primary evidence.","5: Stage 4 plus multiple complementary generally available workflow differences beyond that baseline, with their boundaries and prerequisites established."]},{"id":"breadth","name":"Capability breadth","description":"Documented discovery, classification, and access-posture coverage across store classes in this cohort. Channel DLP, DAM, and encryption suites are adjacent and not treated as extra DSPM breadth.","question":"Across which documented store classes can operators discover, classify, and assess access or exposure?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an in-scope assessment capability. Missing evidence is unknown, never zero.","1: A bounded in-scope capability is documented for one environment or workflow.","2: Discovery and classification cover one environment class, such as Microsoft 365 or one cloud object store.","3: Discovery plus access or exposure analysis cover more than one store class (files and SaaS, or cloud and database).","4: Documented coverage spans structured and unstructured data across cloud or SaaS plus on-premises or IaaS classes.","5: Generally available modules are documented for IaaS, SaaS, on-premises, databases, and AI-connected stores without relying on preview connectors."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented connectors and handoffs that feed discovery or posture: stores, labels, tickets, APIs, and named partners. A logo wall without configuration detail is weaker evidence than a named integration.","question":"Which store, label, identity, or automation integrations are documented for discovery and posture operators?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an integration or supported data handoff. Missing evidence is unknown, never zero.","1: A concrete native connector or supported manual integration is documented.","2: A small set of third-party store connectors is named.","3: Multi-cloud or SaaS connectors plus at least one labeling, ticketing, or identity handoff are documented.","4: A documented API or partner list names SIEM, SOAR, or peer DSPM or label platforms with specific products.","5: A public connector or partner matrix covers stores, identity, labeling, and automation with operator configuration detail."]},{"id":"governance","name":"Governance & control","description":"Documented administrative and policy controls for classification and posture: roles, scoped admin, owner approval, exceptions, and audit of remediations. Not compliance certifications as a substitute for product controls.","question":"What administrative and policy controls are documented for who may classify, view, and change access posture?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an administrative or policy control. Missing evidence is unknown, never zero.","1: A specific administrative control is documented for the scoped workflow.","2: Role-based access to the posture console is documented.","3: Least-privilege roles plus policy objects for classification or access remediation are documented.","4: Segmented administration, operator audit of remediations, and reversible or owner-approved actions are documented.","5: Policy governance includes residency, exception or risk-acceptance, evidence retention, and delegated administration across business owners."]},{"id":"operations","name":"Operator enablement","description":"Documented tooling that lets a practitioner set up, review, and act on discovery and posture: setup tasks, dashboards, explorers, owner queues, known issues, and training. Not staffing-savings claims.","question":"What published operator paths exist to set up, review, and act on discovery and posture findings?","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a supported operator action or guidance path. Missing evidence is unknown, never zero.","1: A concrete operator action and its basic use are documented.","2: A getting-started or setup path is published.","3: Dashboards, reports, or recommended actions are documented for operators.","4: Guided workflows, activity or asset explorers, and owner or analyst queues are documented.","5: An operator kit includes setup tasks, known-issue notes, health or scan status, exportable evidence, and public runbooks or training."]}],"assessments":[{"vendor":"microsoft-purview","cohort":"dspm-discovery-posture","edition":"Microsoft Purview Information Protection classifiers and current Data Security Posture Management (not classic DSPM, not DLP-suite comparison)","asOf":"2026-09-21","status":"research-preview","summary":"Purview documents SITs, trainable classifiers, labels, and current DSPM objectives that correlate Microsoft 365 posture with partner-fed non-Microsoft stores. This assessment covers classification and DSPM only; DLP, Insider Risk, and encryption are adjacent and not scored as peers.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Learn docs list supporting licenses, Purview permissions, Copilot and Fabric prerequisites, and administrative-unit scoping that hides other units from restricted admins. Inactive tenants pause Microsoft 365 DSPM refresh after 60 days and resume on return. That matches documented operational safeguards (anchor 4). Shared-responsibility residency and tenant incident notification for DSPM itself are not documented here, so not anchor 5. The Data Security Posture Agent is preview and is not used as a safeguard.","sourceIds":["s2","s3"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support native sensitivity, oversharing and data-posture investigation within current DSPM, excluding adjacent DLP-policy creation, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s2"]},"breadth":{"score":3,"confidence":"medium","rationale":"Classifiers and DSPM cover Microsoft 365 discovery, labels, and access or oversharing assessments, and docs name Azure, Fabric, and partner-fed SaaS or IaaS such as GCP, Snowflake, and Databricks. Asset explorer currently lists Microsoft locations as Microsoft 365 only, with non-Microsoft locations depending on partner integrations. That is more than one store class (anchor 3), not independently verified native IaaS plus on-prem plus AI-store GA coverage (not 4 or 5).","sourceIds":["s1","s2","s4"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"DSPM consolidates signals from labels and other Purview solutions and names partner integrations with Varonis, Cyera, BigID, and OneTrust for non-Microsoft risk insights. That is a specific peer-DSPM and label partner list (anchor 4). Sentinel data lake setup for partners is described as preview and is not counted. A full operator connector matrix is not published here (not anchor 5).","sourceIds":["s2"]},"governance":{"score":4,"confidence":"medium","rationale":"Classification and DSPM use Purview role groups and least-privilege roles; administrative units restrict reports, explorers, and policies; unrestricted admins are required to create one-click policies. RBAC for AI content and audited agent actions are documented. That is segmented administration with constrained policy creation (anchor 4). Tenant residency and owner risk-acceptance workflows for DSPM findings are not documented on these pages (not anchor 5).","sourceIds":["s3","s4"]},"operations":{"score":4,"confidence":"medium","rationale":"The Purview portal walkthrough documents setup tasks, Posture and Objectives pages, asset explorer, activity explorer (including known display issues), reports, and remediation-action policies. Operators get guided outcome workflows plus known-issue notes (anchor 4). Exportable evidence and a complete public runbook kit beyond Learn articles are not verified (not anchor 5).","sourceIds":["s2","s3"]}},"constraints":["Edition scoped to Information Protection classifiers/labels and current DSPM; DLP, Insider Risk Management, Information Barriers, Privileged Access Management, and Customer Key or Double Key Encryption are adjacent and not compared as DLP-suite peers.","Prerequisite: supporting Purview license, supported region, and Purview permissions; Copilot, Fabric, Edge, and Entra-registered AI apps have additional documented prerequisites.","Microsoft locations in asset explorer currently include Microsoft 365 only; GCP, Snowflake, Databricks and similar stores depend on partner integrations.","Data Security Posture Agent and Sentinel data lake partner setup are preview; they are not treated as GA.","Classic DSPM and DSPM for AI remain available but are not the evaluated edition.","Classification and posture coverage by workload is license-dependent and unverified in a lab.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"s1","title":"Microsoft Purview data security solutions","url":"https://learn.microsoft.com/en-us/purview/purview-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Learn about Microsoft Purview Data Security Posture Management (DSPM)","url":"https://learn.microsoft.com/en-us/purview/data-security-posture-management-learn-about","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Considerations for deploying Microsoft Purview Data Security Posture Management","url":"https://learn.microsoft.com/en-us/purview/data-security-posture-management-considerations","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Classifiers overview","url":"https://learn.microsoft.com/en-us/purview/data-classification-overview","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"varonis","cohort":"dspm-discovery-posture","edition":"Varonis Data Security Platform DSPM (discovery, classification, access intelligence)","asOf":"2026-09-21","status":"research-preview","summary":"Varonis documents classification plus an access graph that includes nested groups and sharing links, with automated permission cleanup on supported stores. Public trust docs describe in-network collectors and metadata-only cloud storage. Channel DLP enforcement is an integration, not this cohort's comparison.","dimensions":{"maturity":{"score":4.7,"confidence":"medium","rationale":"Anchor 4 remains supported by in-network collection, metadata encryption and tenant isolation. The platform trust documentation additionally establishes tenant-location choice, tenant incident notification and customer operating responsibilities. These earn 0.7 under the shared rubric. Reversal procedures for posture remediations are not established, leaving 0.3 uncredited; backup restoration is not treated as reversing a permissions change.","sourceIds":["s3"],"refinement":{"base":4,"evidence":[{"criterion":"residency-choice","rationale":"Customers select tenant geolocation at onboarding; the documentation identifies that choice as a customer responsibility.","sourceIds":["s3"]},{"criterion":"tenant-incident-notification","rationale":"The tenant-security FAQ commits to notifying customers of incidents affecting their tenants.","sourceIds":["s3"]},{"criterion":"shared-responsibility-controls","rationale":"Customer responsibilities include federation, account deactivation, collector patching and monitoring, least-privilege application roles, and secure data-source secrets.","sourceIds":["s3"]}]}},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support sensitivity/access correlation and permissions-remediation workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s1","s2"]},"breadth":{"score":4,"confidence":"low","rationale":"Product pages document structured databases and warehouses, unstructured files and buckets, and semi-structured SaaS and email, plus on-prem file storage, IaaS, and named coverage for Microsoft 365, AWS, Azure, Google Cloud, Salesforce, Box, Snowflake, Databricks, and Windows file shares. That spans structured and unstructured across cloud or SaaS plus on-prem or IaaS (anchor 4). Per-connector GA depth and AI-store modules are not verified from public coverage tiles (not anchor 5).","sourceIds":["s1","s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Varonis documents Microsoft Purview Information Protection labeling and downstream DLP handoff, plus a web API for SIEM, SOAR, and data warehouses using API keys. Coverage pages name many stores. That is a named label platform plus SIEM/SOAR API (anchor 4). A public operator matrix with configuration steps for each integration is not in the reviewed pages (not anchor 5).","sourceIds":["s1","s2","s3"]},"governance":{"score":3,"confidence":"medium","rationale":"Customer-facing API permissions document departmental RBAC and least-privilege roles; classification guidance documents configurable policy objects and label enforcement. These support stage 3. The earlier stage-4 rationale established segmentation but not an operator audit of posture remediations together with reversal or owner approval. Provider-internal change approvals and backup restoration do not fill those customer-workflow requirements. This is a baseline research correction, not a product regression.","sourceIds":["s2","s3"]},"operations":{"score":null,"confidence":"low","rationale":"The cited product pages describe dashboards and recommended actions, but this evidence set does not verify the public setup path required by earlier cumulative stages. Operator enablement remains unknown; documentation access is not treated as product quality.","sourceIds":["s1","s2"]}},"constraints":["Evaluated as DSPM/discovery/access-intelligence; Varonis DLP policy enforcement is described as a Microsoft Purview integration and is not a DLP-suite comparison.","On-premises collectors are a customer-operated prerequisite; customers must patch, restrict access, and encrypt collector disks per the shared-responsibility list.","Optional File Analysis and AI Monitoring (Copilot, AgentForce, ChatGPT Enterprise) are separate roles or data sources; AI prompt retention is documented as 180 days when enabled.","Coverage logos are not a verified connector inventory; per-store permission completeness is unverified.","MDDR is a managed service overlay and is not scored as product posture.","Classification accuracy percentages are vendor claims and are not scored.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"s1","title":"Varonis Data Security Posture Management (DSPM)","url":"https://www.varonis.com/platform/dspm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Varonis Data Discovery and Classification","url":"https://www.varonis.com/platform/data-discovery-and-classification","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Varonis Security Standards and Practices","url":"https://www.varonis.com/trust/security","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"cyera","cohort":"dspm-discovery-posture","edition":"Cyera DSPM (agentless discovery, classification, exposure, and posture remediation)","asOf":"2026-09-21","status":"research-preview","summary":"Cyera documents agentless DSPM with AI-native classification, exposure scoring, and owner-routed or security-led remediation. Omni DLP and Cyera Identity after the Oasis closing are separate modules and are not treated as DSPM completeness. Identity integration evidence remains limited to the acquisition notice.","dimensions":{"maturity":{"score":null,"confidence":"low","rationale":"The cited pages describe in-place processing and logged owner actions. They do not verify the collector permission model and metadata safeguards required by the cumulative stage rubric. These safeguards are unknown, not absent.","sourceIds":["s1","s3"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support sensitivity/access context with data-owner remediation queues, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s1","s3","s4"]},"breadth":{"score":4,"confidence":"low","rationale":"DSPM and platform pages document agentless coverage of cloud, SaaS, DBaaS, and on-prem stores, with named examples including AWS, Azure, Google Cloud, Snowflake, Databricks, and Salesforce, and structured plus unstructured classification. That matches structured/unstructured across cloud or SaaS plus on-prem or IaaS (anchor 4). Email, network, and endpoint tiles on the platform page are adjacent to Omni DLP and are not counted as DSPM breadth. Per-connector GA depth is unverified (not anchor 5).","sourceIds":["s1","s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Existing multicloud/SaaS, ticketing and labeling handoffs remain supported. The official integration catalog explicitly labels Splunk and automation partners as DSPM integrations and describes their data handoffs, meeting stage 4. Omni DLP-only entries are excluded. The catalog does not supply the complete operator configuration matrix needed for stage 5.","sourceIds":["s1","s3","s5"]},"governance":{"score":null,"confidence":"low","rationale":"The source describes owner responses, risk acceptance and logged remediation. Console RBAC and least-privilege administration required by earlier cumulative stages were not verified; beta owner authentication is excluded. Governance remains unknown.","sourceIds":["s3"]},"operations":{"score":null,"confidence":"low","rationale":"The cited pages describe scan status and owner queues, but the earlier setup-path stage and its operator prerequisites were not verified from this evidence set. Operator enablement remains unknown; certification availability alone does not fill that gap.","sourceIds":["s1","s3"]}},"constraints":["Cohort is Cyera DSPM only. Omni DLP, Agent Guardian, Access Trail, and DataWatcher managed services are separate and are not DLP-suite or managed-service comparisons.","Oasis Security acquisition completed 3 September 2026; Cyera Identity is described as the going-forward identity pillar. Acquisition does not verify every identity integration as GA in DSPM.","Owner-portal OTP and SSO authentication are documented as beta.","In-place versus SaaS deployment, sampling versus full scans, and per-store API permissions are unverified.","Customer outcome metrics (precision, petabytes, issue counts) are not scored.","Email, network, and endpoint coverage on the platform page is not treated as DSPM breadth.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"s1","title":"Cyera Data Security Posture Management","url":"https://www.cyera.com/platform/dspm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Cyera platform overview","url":"https://www.cyera.com/platform","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Cyera Remediation Center and remediation paths","url":"https://www.cyera.com/blog/data-security-remediation-is-a-collaboration-problem-cyera-is-designed-for-it","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Cyera completes acquisition of Oasis Security","url":"https://www.cyera.com/press-releases/cyera-completes-acquisition-of-oasis-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Cyera integration catalog with DSPM module labels","url":"https://www.cyera.com/integrations","accessedAt":"2026-09-21","kind":"product"}]},{"vendor":"bigid","cohort":"dspm-discovery-posture","edition":"BigID discovery, classification, and DSPM (access-posture and delegated remediation)","asOf":"2026-09-21","status":"research-preview","summary":"BigID documents discovery and classification as the inventory for DSPM, access governance, privacy, and AI-data workflows, with policy-driven access remediation and owner delegation. Public product pages are marketing-dense; connector depth, encryption, and tenant isolation were not verified. Cloud DLP is adjacent, not this cohort.","dimensions":{"maturity":{"score":null,"confidence":"low","rationale":"The cited pages establish posture dashboards and remediation cases, but do not verify the permission prerequisites and administrator role required by stage 2 or the collector safeguards required by later stages. A dashboard is not evidence of those controls; the operating-safeguard assessment remains unknown.","sourceIds":["s1"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support discovery, classification, access context and delegated remediation, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s1","s2"]},"breadth":{"score":4,"confidence":"low","rationale":"Discovery and DSPM pages document structured, unstructured, and semi-structured sources across cloud, SaaS, on-prem, hybrid, data lakes, and AI-connected data, including PII, PHI, PCI, secrets, and IP. That is structured and unstructured across cloud or SaaS plus on-prem (anchor 4). A public GA connector inventory for IaaS, databases, and AI stores was not verified (not anchor 5).","sourceIds":["s1","s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Discovery/posture sources establish multicloud and SaaS coverage with labeling/remediation handoffs. The DSPM integration overview names Microsoft Purview, Splunk and ServiceNow and describes an API-first integration model, meeting the named-partner requirement at stage 4. This does not verify installation procedures, per-connector permissions or the complete matrix required for stage 5.","sourceIds":["s1","s2","s3"]},"governance":{"score":null,"confidence":"low","rationale":"The cited pages describe ownership and delegated remediation but do not verify console RBAC, least-privilege roles and segmented administration required by the cumulative rubric. Revoke, redact and delete actions have no verified rollback here and are not described as reversible. Governance remains unknown.","sourceIds":["s1"]},"operations":{"score":null,"confidence":"low","rationale":"Product pages describe dashboards and remediation cases, but the public setup path and operator runbooks required by the cumulative rubric were not verified. Operator enablement remains unknown rather than inferred from marketing pages.","sourceIds":["s1","s2"]}},"constraints":["Assessment is discovery, classification, and DSPM/access-posture. Listed cloud DLP, privacy automation, and catalog enrichment are adjacent modules, not DLP-suite comparison.","Connector coverage, scan completeness, and sampling versus full reads are unverified.","Tenant isolation, encryption, and console RBAC were not found on the public product pages reviewed.","Agentic remediation GA versus preview is not independently confirmed.","Classification accuracy rankings and analyst-firm placements are not scored.","Destructive actions (delete, redact) need an explicit lab check before use.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"s1","title":"BigID Data Security Posture Management","url":"https://bigid.com/data-security-posture-management/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"BigID Data Discovery and Classification","url":"https://bigid.com/discovery-classification/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"BigID DSPM and Microsoft Purview integration overview","url":"https://home.bigid.com/dspm-purview-demo","accessedAt":"2026-09-21","kind":"product"}]}],"scenarios":[{"id":"lean-team","name":"Small security team","description":"A small team needs inventory and exposure reduction on a few cloud or SaaS stores without staffing a DLP operations desk. Prioritize operator enablement and posture remediation that owners can complete. Do not treat a DSPM finding as proof that uploads are blocked.","priorities":["operations","maturity"],"questions":["Which connectors are licensed and actually scanning the lab stores?","Can one reversible access change be applied and verified at the repository?","Who reviews false positives without exposing document contents unnecessarily?"]},{"id":"microsoft-centered","name":"Microsoft 365-centered classification and posture","description":"The estate is mostly Microsoft 365 with optional partner-fed cloud stores. Compare Purview DSPM and labels with Varonis or Cyera only as discovery/posture overlays, not as Exchange or endpoint DLP replacements.","priorities":["ecosystem","governance"],"questions":["Does a sensitivity label only classify, or does a separate service enforce sharing?","Which non-Microsoft stores require a partner integration rather than native Purview scanning?","Are one-click DSPM policies allowed for restricted administrative units?"]},{"id":"hybrid-multicloud","name":"Hybrid file, SaaS, and IaaS posture","description":"Operators need structured and unstructured inventory across on-prem files or databases and cloud object or SaaS stores. Compare access-graph or owner-remediation workflows. Exclude SSE or endpoint DLP channel coverage from this scenario.","priorities":["breadth","innovation"],"questions":["Does the connector return nested groups, sharing links, and effective access, or only ACLs?","Is scanning agentless API, in-network collector, or both, and where does content reside during classification?","Which remediation is native to the store versus a ticket to another tool?"]},{"id":"shared-security-privacy","name":"Shared security and privacy inventory","description":"Security and privacy teams want one classified inventory for exposure reduction and data-rights workflows. BigID documents that overlap; others may label only. Still not a DLP or DAM comparison.","priorities":["governance","operations"],"questions":["Can classification errors be corrected without deleting the underlying record?","Which actions are exposure reduction versus retention or deletion?","What evidence export exists for an access review?"]}],"researchNotes":["First edition dated 2026-09-21; no historical assessments are available.","The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.","Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.","Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.","Contemporary cohort baseline: Discovery, classification, sensitivity/access/exposure correlation, data-owner context, posture prioritization, and owner-routed or automated remediation are contemporary DSPM baseline capabilities. Access graphs, risk scores, AI labels and remediation queues alone do not establish differentiation.","Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.","Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.","Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.","Rubric 1.1 divides the new maturity anchor 5 requirements into residency choice (two tenths), tenant incident notification (two), reversible remediation (three), and shared-responsibility operator controls (three). Reversibility and ongoing customer control receive the larger shares because they directly govern safe operation; these are shared editorial weights, not measured performance. Purview receives no extra credit from adjacent services or preview agents. Cyera and BigID operating safeguards remain unknown. Documented baseline innovation stays tied at 3.0.","All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged."]},"changes":[]}]},"unassessed":[{"slug":"veeam-securiti","name":"Securiti AI within Veeam","company":"Securiti AI","profileUrl":"/landscape/vendors/veeam-securiti/"},{"slug":"forcepoint-dlp","name":"Forcepoint DLP","company":"Forcepoint","profileUrl":"/landscape/vendors/forcepoint-dlp/"},{"slug":"proofpoint-dlp","name":"Proofpoint Enterprise DLP","company":"Proofpoint","profileUrl":"/landscape/vendors/proofpoint-dlp/"},{"slug":"symantec-dlp","name":"Symantec Data Loss Prevention","company":"Symantec Enterprise","profileUrl":"/landscape/vendors/symantec-dlp/"},{"slug":"netskope-dlp","name":"Netskope One DLP","company":"Netskope","profileUrl":"/landscape/vendors/netskope-dlp/"},{"slug":"zscaler-dlp","name":"Zscaler Data Loss Prevention","company":"Zscaler","profileUrl":"/landscape/vendors/zscaler-dlp/"},{"slug":"nightfall-ai","name":"Nightfall AI","company":"Nightfall AI","profileUrl":"/landscape/vendors/nightfall-ai/"},{"slug":"rubrik-dspm","name":"Rubrik Security Cloud DSPM","company":"Rubrik","profileUrl":"/landscape/vendors/rubrik-dspm/"},{"slug":"ibm-guardium","name":"IBM Guardium Data Security","company":"IBM","profileUrl":"/landscape/vendors/ibm-guardium/"},{"slug":"thales-imperva","name":"Thales Imperva Data Security Fabric","company":"Imperva","profileUrl":"/landscape/vendors/thales-imperva/"}]}