DSPM will find data you did not know existed, in places you did not know it was stored. The finding is fast. The remediation is not.

A DSPM product connects to your stores, scans what is in them, classifies it and maps who can reach it. The first scan typically returns thousands of findings within days — and every one of them needs an owner, a decision and a change made by someone who has other work.

The check before you shortlist: ask where your sensitive data is. If the answer is a guess, the first deliverable of any product here is the map — and the second, larger project is doing something about what the map shows.

Already decided — What this page decides

What it can actually scancloud object storage, databases, SaaS, on-premises shares — coverage varies enormously and on-premises is the usual gap
Whether it can act or only reportthe difference between a finding and a fix, and where the headcount goes
What it costsmetered on stores and scanned volume rather than users — which changes the shape of the bill entirely

Still yours to weigh

Nobody can answer where personal data isyou need discovery before anything else
A public bucket held customer recordsyou need DSPM, not CSPM — see the boundary below
DPDP readiness started with no data mapthe DPDP section below is yours
What this covers

Discovery is the first deliverable, and the map is not the project.

Data security posture management finds data at rest, decides what it is, and maps who can reach it. It is the answer to the question almost no organisation can answer unaided — where is our sensitive data — and it is the prerequisite for writing any credible DLP policy or rights-management rule.

The fifteen products below differ most in what they can physically scan. Cloud-native tools are agentless and fast and stop at the cloud boundary. Hybrid platforms reach on-premises file shares and cost more to deploy. Two are modules of platforms carded elsewhere — Wiz in cloud security, Rubrik in backup, where the scan runs over a copy production never notices.

The row to get exactly right

What it can actually scan. Cloud object storage is universal; managed databases are common; SaaS varies; on-premises file shares are the usual gap. Estates whose sensitive data lives on shares and whose business case assumed coverage discover the mismatch after signature. Ask for the specific store list, not the category.

Often confused withDLP & Insider Risk — acting on what you find·Encryption & Rights — protecting what you find·Cloud & Workload Security — CSPM, which is a different job

All three Data Security & Privacy guides

Boundary — the terms this buyer confuses

Four terms, resolved

These are adjacent controls at different points in the data’s life, not tiers. A product that classifies perfectly may block nothing, and a product that secures the cloud account may know nothing about what is inside it.

DSPM vs CSPM

Are you securing the cloud account, or what is inside it?

DSPM vs DLP

Do you need to find data at rest, or stop it moving?

Discovery vs classification

Finding the file, or deciding what it is?

Classification vs cataloguing

Is the audience security, or the data team?

The practical consequence: these four sit in sequence rather than in competition. Discover, classify, then decide whether the control you need watches the exit, governs the access, or travels with the file.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Six variables move the shortlist. Everything else is preference.

01

What it can scan

Cloud object storage, managed databases, SaaS applications, on-premises file shares, large unstructured estates. Coverage varies enormously and on-premises is where business cases break.

02

Agentless or connector-based

Agentless is fastest to first finding. Connector catalogues decide coverage — confirm your specific stores are on the list before signature.

03

Access-path depth

Reporting permissions is not the same as computing effective access through nested groups, inherited rights and share links. This is Varonis's differentiator and where several cloud-first tools are visibly thinner.

04

Remediation or reporting

Acting on a finding, raising a workflow, or producing a report. The further right you sit, the more headcount the programme needs.

05

Indian data-type accuracy

PAN, Aadhaar, GSTIN. Undocumented across every vendor here — prove it in a proof of concept, because a US-tuned classifier returns nothing useful in an Indian estate.

06

Scanning cost

Metered on stores or scanned volume rather than headcount, so a small team with large object stores can cost more than a large workforce.

The narrowing instrument · the reasoning is the product

Narrow 15 products to your shortlist

Pick what has to be scanned and what has to happen to a finding. Products drop out with the reason stated, never silently.

What it has to do with what it finds

How it deploys

What it has to scan

India

Indian data-type classification and India residency are annotated, never used to eliminate: where a vendor has not documented them, the product is flagged for you to prove rather than ruled out.

Still in15/ 15
Varonis
PriceQuote

quoted per user or per data store; discovery and classification across Microsoft 365, cloud stores, databases and on-premises file shares, with effective-permission mapping and automated remediation

Estates whose real question is who can actually reach this — through every nested group, inherited permission and share link — and whose data lives partly on file shares that cloud-first tools do not scan.

The catch: The most complete answer here and priced accordingly; quote-only, and deployment is a programme rather than a connector. The breadth that makes it strong on file shares also makes it heavier than an agentless cloud scan.

Deepest access-path analysisScans on-prem sharesProgramme, not a connector
Open the intel page
Varonis

quoted within the Varonis platform; least-privilege enforcement over unstructured data — finding and removing excessive access rather than only reporting it

Estates that already know roughly where the data is and whose finding is that far too many people can reach it — the remediation half rather than the discovery half.

The catch: Governance over unstructured data specifically: it is not a cloud posture tool and not a DLP. Assumes the Varonis platform underneath.

Least-privilege enforcementUnstructured dataPlatform-dependent
Open the intel page
Varonis
PriceQuote

quoted within the Varonis platform; alerting and automated response on abnormal access to data at rest, rather than on a cloud configuration

Estates that have the map and now need a motion sensor on it — detecting the account that suddenly reads ten thousand files it has never touched.

The catch: Detection over data Varonis already classifies: it is the response half of a posture investment, not a standalone monitoring product.

Alerts on access, not configNeeds the map firstQuote
Open the intel page
Cyera
PriceQuote

quoted per environment or scanned volume; agentless AI-native discovery and classification across cloud object storage, managed databases and SaaS applications

Cloud-first estates that want an accurate map quickly without deploying anything — the fastest time-to-first-finding on this page.

The catch: Cloud-scoped: on-premises file shares are the usual gap, and buyers whose business case assumed them discover it after signature. Access-path analysis is present but shallower than Varonis.

Agentless, fast to valueCloud-scopedThinner on access paths
Open the intel page
Cyera

quoted within the Cyera platform; who can reach which classified data across cloud stores and SaaS, with entitlement analysis over the discovered map

Cyera estates whose next question after discovery is access — and who want that answered inside the platform that did the classification.

The catch: Cloud and SaaS scope, following the platform's coverage; on-premises shares are outside it. Assumes Cyera DSPM underneath.

Access over the Cyera mapCloud scopeAdd-on
Open the intel page
Securiti
PriceQuote

quoted within the Data Command Center; discovery, classification and posture across cloud, database, SaaS and on-premises sources through a connector catalogue

Estates whose driver is privacy operations as much as security — where the same map has to serve a DPDP or GDPR obligation and a security finding.

The catch: Connector-based, so coverage is a function of the catalogue: confirm your specific stores are supported before signature. Acquired by Veeam (about $1.725B, closed December 2025) and continuing under its own brand.

Privacy-operations depthConnector catalogueVeeam-owned
Open the intel page
Securiti

quoted within the Data Command Center; the discovery and cataloguing layer — what personal and sensitive data exists, where, and whose it is

Organisations at the very start of a privacy programme whose first deliverable is a defensible data map rather than an enforcement control.

The catch: Discovery and cataloguing rather than posture: it produces the inventory and does not analyse access paths or remediate. The right first step, not the whole answer.

The data mapNo access analysisReports only
Open the intel page
Securiti

quoted within the Data Command Center; consent records, data-principal request handling and privacy reporting built on the discovered map

Estates whose obligation is operational privacy — honouring data-principal requests and evidencing consent — rather than a security posture finding.

The catch: Privacy operations, not a security control: it does not block, encrypt or detect. It answers a regulator's question, not an attacker's.

Consent and DSR handlingNot a security controlPrivacy-first
Open the intel page
Securiti

quoted within the Data Command Center; policy, quality and lineage over the catalogued data estate for governance and analytics teams

Organisations where the data map has to serve analytics governance as well as security — one inventory, two audiences.

The catch: Governance tooling rather than a security control, and its audience is the data team rather than the security team. Buying it to satisfy a security finding answers a different question.

Governance and lineageData-team audienceNot a security control
Open the intel page
Forcepoint logo
Forcepoint DSPMForcepoint
PriceQuote

quoted within the Forcepoint data-security portfolio; discovery and classification that feed the same policy engine driving Forcepoint DLP

Estates buying discovery and enforcement together, where the classification that finds the data should be the one the DLP acts on.

The catch: The strongest case assumes Forcepoint DLP alongside it; as a standalone DSPM it is less specialised than the cloud-native tools. India residency is not documented.

Feeds Forcepoint DLPBuy-together caseLess specialised alone
Open the intel page
Forcepoint logo
Forcepoint DDRForcepoint
PriceQuote

quoted within the Forcepoint portfolio; detection and response on access to classified data at rest, rather than on cloud configuration drift

Forcepoint estates that want the posture map to raise alerts when someone actually touches what it found.

The catch: Detection over data Forcepoint classifies — it is the response half of a portfolio purchase rather than a standalone product.

Alerts on data accessPortfolio purchaseQuote
Open the intel page
Seclore
PriceQuote (INR)

quoted per environment in INR from the Mumbai-built vendor; discovery and classification that can hand off directly to Seclore's rights management for protection

Indian estates that want the discovery and the protection from one India-built vendor, with the remediation being protect-the-file rather than only report-the-finding.

The catch: Narrower connector coverage than the global platforms and documented deployments are Indian mid-market and BFSI. Indian data-type classification is not documented despite the India-built positioning — prove it.

India-built (Mumbai)Remediates by protectingNarrower connectors
Open the intel page
Wiz
PriceIn the platform

a module of the Wiz platform, licensed with the cloud security graph; data findings joined to the same graph that carries the misconfiguration and vulnerability context

Wiz estates that want to know whether the public bucket the CSPM found actually holds sensitive data — the finding and the consequence in one view.

The catch: Cloud-native only and a module, not a standalone product: no on-premises coverage at all, and the case assumes Wiz is already the cloud security platform.

On the Wiz graphCloud-onlyModule
Open the intel page
Rubrik logo
PriceIn the platform

a module of the Rubrik platform; classification run over data the backup already holds, so discovery does not touch production systems

Rubrik estates that want a data map without a second scan of production — the backup copy is already a complete, quiescent snapshot of everything.

The catch: Scope is whatever Rubrik backs up, which is a real constraint if some stores are not protected. Reporting-oriented: it finds and classifies rather than remediating.

Scans the backup copyNo production loadScope = what is backed up
Open the intel page
Seqrite logo
PriceQuote (INR)

quoted per endpoint or per user in INR; personal-data discovery across endpoints and shares with DPDP-shaped reporting, from the India-built vendor

Indian mid-market estates whose driver is DPDP readiness and whose data sits mostly on endpoints and file shares rather than cloud object storage.

The catch: Endpoint and share oriented: cloud object storage and managed database coverage is thin, and there is no access-path analysis. Reports rather than remediates.

India-built, INRDPDP-shaped reportingThin on cloud stores
Open the intel page
Why each constraint rules out what it doesShow the reasoning ↓

effective access pathsRules out Cyera DSPM, Securiti DSPM, Securiti Data Governance, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM, Wiz DSPM and Rubrik DSPM — reports permissions, but not effective access through nested groups and inherited rights; Securiti Data Discovery, Securiti Data Privacy Automation and Seqrite Data Privacy — no access analysis at all. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR and Cyera Data Access Governance.

acting on findingsRules out Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM and Wiz DSPM — raises a workflow or ticket; the change is made elsewhere; Securiti Data Discovery, Rubrik DSPM and Seqrite Data Privacy — reporting only. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Forcepoint DDR and Seclore DSPM.

data detection and responseRules out Varonis Data Access Governance, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM, Seclore DSPM, Wiz DSPM, Rubrik DSPM and Seqrite Data Privacy — posture only, no data detection and response. That leaves Varonis DSPM, Varonis DDR and Forcepoint DDR.

agentless deploymentRules out Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Forcepoint DSPM and Forcepoint DDR — hybrid deployment with components to install; Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Seclore DSPM, Rubrik DSPM and Seqrite Data Privacy — connector-based: coverage depends on the connector catalogue. That leaves Cyera DSPM, Cyera Data Access Governance and Wiz DSPM.

a standalone productRules out Wiz DSPM and Rubrik DSPM — sold inside a cloud-security or backup platform licence, not as a discovery product on its own. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM and Seqrite Data Privacy.

on-premises sharesRules out Cyera DSPM, Cyera Data Access Governance, Securiti Data Governance and Wiz DSPM — cloud-scoped: on-premises shares are not covered. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM, Rubrik DSPM and Seqrite Data Privacy.

managed databasesRules out Varonis Data Access Governance, Varonis DDR, Forcepoint DDR, Seclore DSPM, Rubrik DSPM and Seqrite Data Privacy — database contents are not a documented scan target. That leaves Varonis DSPM, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM and Wiz DSPM.

SaaS applicationsRules out Wiz DSPM — SaaS application data is not covered. That leaves Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM, Rubrik DSPM and Seqrite Data Privacy.

unstructured sharesRules out Varonis DDR, Cyera DSPM, Cyera Data Access Governance, Securiti DSPM, Securiti Data Privacy Automation, Securiti Data Governance, Forcepoint DSPM, Forcepoint DDR, Seclore DSPM, Wiz DSPM and Rubrik DSPM — not documented for large unstructured share estates. That leaves Varonis DSPM, Varonis Data Access Governance, Securiti Data Discovery and Seqrite Data Privacy.

DPDP reportingRules out Varonis DSPM, Varonis Data Access Governance, Varonis DDR, Cyera DSPM, Cyera Data Access Governance, Forcepoint DSPM, Forcepoint DDR, Wiz DSPM and Rubrik DSPM — no DPDP-specific reporting documented (the underlying discovery may still serve the obligation). That leaves Securiti DSPM, Securiti Data Discovery, Securiti Data Privacy Automation, Securiti Data Governance, Seclore DSPM and Seqrite Data Privacy.

Indian data typesRules nothing out on published terms. It flags Varonis DSPM — Indian data-type classification is not documented by the vendor, Varonis Data Access Governance — Indian data-type classification is not documented by the vendor, Varonis DDR — Indian data-type classification is not documented by the vendor, Cyera DSPM — Indian data-type classification is not documented by the vendor, Cyera Data Access Governance — Indian data-type classification is not documented by the vendor, Securiti DSPM — Indian data-type classification is not documented by the vendor, Securiti Data Discovery — Indian data-type classification is not documented by the vendor, Securiti Data Privacy Automation — Indian data-type classification is not documented by the vendor, Securiti Data Governance — Indian data-type classification is not documented by the vendor, Forcepoint DSPM — Indian data-type classification is not documented by the vendor, Forcepoint DDR — Indian data-type classification is not documented by the vendor, Seclore DSPM — Indian data-type classification is not documented by the vendor, Wiz DSPM — Indian data-type classification is not documented by the vendor, Rubrik DSPM — Indian data-type classification is not documented by the vendor and Seqrite Data Privacy — Indian data-type classification is not documented by the vendor — marked on the cards, not removed.

India residencyRules nothing out on published terms. It flags Varonis DSPM — India residency for the classification index is not documented, Varonis Data Access Governance — India residency for the classification index is not documented, Varonis DDR — India residency for the classification index is not documented, Cyera DSPM — India residency for the classification index is not documented, Cyera Data Access Governance — India residency for the classification index is not documented, Securiti DSPM — India residency for the classification index is not documented, Securiti Data Discovery — India residency for the classification index is not documented, Securiti Data Privacy Automation — India residency for the classification index is not documented, Securiti Data Governance — India residency for the classification index is not documented, Forcepoint DSPM — India residency for the classification index is not documented, Forcepoint DDR — India residency for the classification index is not documented, Wiz DSPM — India residency for the classification index is not documented and Rubrik DSPM — India residency for the classification index is not documented — marked on the cards, not removed.

On-premises is the usual gapCloud-native DSPM is fast and agentless because it scans cloud APIs. Estates whose sensitive data sits on file shares discover this after signature. Confirm on-premises coverage explicitly if the business case assumed it.

Two of these fifteen are modulesWiz and Rubrik sell DSPM inside their platforms. If you already run either, the discovery may be a licence change rather than a purchase — and Rubrik's runs over the backup copy, so production carries no scan load.

Classification accuracy on Indian records is unprovenNo DSPM vendor here documents PAN, Aadhaar or GSTIN support. We mark it per product rather than assume it, and never eliminate on it. Scan a representative sample of your own records during the proof of concept — an empty finding list is the usual symptom of a US-tuned classifier.

Finding is fast; remediation is notA scan returns thousands of findings in days. Every one needs an owner and a decision. Estates that treat the scan as the deliverable end up with a report nobody actions and a renewal nobody can justify.

Narrow to your situation

Eight situations, and what each one buys

If one of these is your sentence, the shortlist is short.

Most of our sensitive data is on file shares

Why: On-premises unstructured coverage is the dividing line here, and the cloud-native tools do not cross it.

The trade-off: Deployment is heavier than an agentless cloud scan — a programme rather than a connector.

Cloud-first, and we need a map this quarter

Why: Agentless discovery across cloud object storage, databases and SaaS with nothing to install.

The trade-off: On-premises shares are outside scope entirely; confirm that matches your estate before signature.

Too many people can reach the data we found

Why: Effective access-path analysis through nested groups and inherited permissions, plus least-privilege enforcement.

The trade-off: Both assume their platform underneath; this is the remediation half of a discovery investment.

The CSPM found a public bucket and nobody knows if it matters

Why: This is exactly the CSPM-to-DSPM handoff: configuration finding, data consequence.

The trade-off: Wiz DSPM is a module — the case assumes Wiz is already your cloud security platform.

We cannot put scan load on production

Why: Classification runs over the backup copy, which is a complete quiescent snapshot production never notices.

The trade-off: Scope is whatever Rubrik backs up. Stores outside the backup are outside the map.

DPDP readiness started and the data map does not exist

Why: All four document DPDP-shaped reporting, and personal-data discovery is the first practical step of any readiness programme.

The trade-off: Privacy automation is not a security control — read the DPDP section below before assuming one product covers both.

We have the map and want alerts when someone touches it

Why: Data detection and response alerts on access to classified data at rest, not on configuration drift.

The trade-off: Both are the response half of a posture investment and assume the classification is already there.

We are buying discovery and enforcement together

Why: The classification that finds the data is the one the enforcement acts on — one definition of sensitive, not two.

The trade-off: Ties you to one vendor across two routes; the specialists are deeper at each individual job.

What the law actually says

India’s Digital Personal Data Protection Act, 2023 was passed in August 2023. The DPDP Rules were notified on 13 November 2025, with phased commencement — most substantive obligations for data fiduciaries land around 13 May 2027. Penalties under the Act reach ₹250 crore for failure to take reasonable security safeguards.

What is stated, and what is implied. Rule 6 of the DPDP Rules, 2025 requires a data fiduciary to take reasonable security safeguards to prevent personal data breaches — and lists measures including encryption, obfuscation, masking, access control, and logs retained for a specified period. That is the provision. It does not name DSPM, DLP or any product category.

Everything beyond that is implication, and we label it as such. You cannot apply access control to personal data you cannot locate, and you cannot evidence masking or encryption of records you have never inventoried — so discovery becomes the practical first step of a readiness programme. That is a reasonable inference, not a statutory requirement, and any vendor telling you “DPDP mandates DSPM” is overstating what the instrument says.

What the law says

What actually helps. Four products here document DPDP-shaped reporting: Securiti Data Discovery, Securiti Data Privacy Automation, Seqrite Data Privacy and Seclore DSPM. Note the split — consent handling and data-principal request workflows are privacy operations, while classification and access control are security controls. One obligation, two different product shapes, and estates frequently buy one expecting both.

Sources: Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025 (notified 13 November 2025), Rule 6 on reasonable security safeguards. Commencement is phased — confirm the schedule applicable to your class of fiduciary with counsel. TechBag states the provision and labels inference as inference; we do not advise on legal obligation.

What breaks as you grow

What changes as the estate grows

DSPM is metered on stores and scanned volume, so scale here means data, not headcount.

1data stores

A handful of cloud stores

  • Agentless scanning is fast and cheap at this size
  • One person can action the findings
  • Wiz or Rubrik may already cover it

Put this in your PoC

Check whether an existing platform already includes DSPM.

2data stores

Cloud plus SaaS, tens of stores

  • Connector coverage becomes the deciding variable
  • Findings need a triage process, not one person
  • Classification accuracy starts to matter commercially

Put this in your PoC

Confirm your specific stores appear on the connector list.

3data stores

Hybrid, with on-premises shares

  • The cloud-native tools stop being candidates
  • Deployment becomes a programme
  • Access-path analysis earns its price

Put this in your PoC

Prove on-premises coverage in the proof of concept, not in the datasheet.

4data stores

Petabyte-scale unstructured

  • Scanning cost becomes a material line item
  • Incremental and targeted scanning matters more than raw speed
  • Remediation needs automation, not tickets

Put this in your PoC

Model the scanning bill on your actual volume before signature.

Where a vendor does not publish deployment scale evidence, this page says so rather than implying it.

The switching cost

Getting out

The map is easier to leave than the tuning behind it.

The inventory

Findings and classifications export to CSV or API almost everywhere

Exit costPortable

Classification tuning

Custom classifiers and thresholds are vendor-specific and are rebuilt

Exit costNot portable

Connector configuration

Each platform models stores differently; the connections are re-made

Exit costRebuilt

Remediation history

Who decided what about which finding — exportable, but rarely in a form the next tool ingests

Exit costPartly portable

The practical consequence: a second DSPM re-scans and re-classifies from scratch. Switching is cheaper than switching DLP, and still not free.

What it costs

What it costs

Metered on stores, environments or scanned volume — not per user, which changes the budgeting shape entirely.

01

Do you already own one?

Four checks, in the order most likely to return a yes.

Microsoft Purview
Already scanning, if your data is in Microsoft 365 E5 includes data classification and scanning across Microsoft 365. Its scope is the Microsoft estate — strong there, and not a map of your cloud object storage or file shares.
Your cloud security platform
Wiz sells DSPM on the same graph as its CSPM findings If Wiz is already deployed, the data half is a licence change rather than a new tool to run.
Your backup platform
Rubrik sells DSPM over the copy it already holds Discovery with no production scan load — scope is whatever is backed up.
Your DLP vendor
Forcepoint, Varonis and Seclore sell both halves Buying discovery from the vendor that will enforce means one definition of sensitive rather than two.

None of these is automatically right, and each covers a different slice. The Microsoft answer in particular is strong inside its own estate and silent outside it.

02

What the rest actually cost

Quote-led across the board, and the meter is the thing to negotiate.

Varonis, Cyera and Securiti are quoted per environment, per data store or on scanned volume — which is why an estate with 200 users and large object stores can cost more than one with 5,000 users and little data. Seclore and Seqrite quote in INR, both India-built, and are the two options here priced for the Indian mid-market rather than the global enterprise; Seclore additionally quotes per environment rather than per seat. Wiz and Rubrik carry no separate line where the platform is already licensed. Ask every vendor to model the bill against your actual store inventory and growth rate, because the meter and not the rate is what decides the number.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

Remediation headcount

Thousands of findings need owners and decisions. This is the line that decides whether the map becomes a fix.

Scanning costs on large stores

Cloud egress and compute for scanning petabyte-scale object storage is a real and separate bill.

Indian data-type proof of concept

Undocumented across every vendor. Budget the time to prove it against your own records.

Connector gaps

Stores outside the catalogue need custom work or stay unscanned — and unscanned stores are exactly where surprises live.

Before you commit

What goes wrong

Five ways this purchase goes wrong. Each is recoverable if caught before signature.

Findings nobody owns

The scan returns thousands of results in days and stops there. Without a named owner and a triage process, the map is a report and the renewal has no case behind it.

On-premises shares out of scope

The business case assumed them; the agentless tool cannot see them. This is the single most common mismatch in this category — confirm it explicitly.

Classification tuned for US data types

A classifier looking for social security numbers finds nothing useful in an Indian estate. Undocumented across every vendor here, so prove it with your own records.

Scanning costs nobody modelled

Volume-metered scanning on large object stores produces a bill that has nothing to do with headcount. Model it before signature.

Buying DSPM when the requirement was DLP

Or the reverse. One finds data at rest; the other stops it moving. The boundary section above resolves it in one question.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Data Security & Privacy map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content. · Last reviewed