All outcomes
    Outcome

    Protect our most sensitive data

    Find it, classify it, encrypt it, stop it leaving.

    "I need to know where our crown-jewel data lives and lock it down."

    Categories that solve this

    Pick the angle you care most about, or scroll for the full vendor list.

    All 449 tools for this outcome

    Armis logo
    Armis
    IoT Security

    Armis provides agentless IoT security for unmanaged and hard-to-agent devices across enterprise, healthcare, industrial, and critical infrastructure environments. Its Centrix platform uses passive network sensing to discover connected assets, identify device type and behavior, and flag risk from unsupported operating systems, weak configurations, and suspicious communications. In this category, Armis is best suited for organizations that need visibility into IoT, OT, IIoT, and medical devices without installing agents or actively scanning devices that may be fragile or unavailable for software deployment. Adjacent exposure-management features exist, but the IoT security value centers on discovery, monitoring, and response for connected devices.

    Agentless OT and IoT asset discovery+10
    Claroty logo
    Claroty
    OT & ICS Security

    Claroty positions its platform for cyber-physical systems and IoT/IIoT security, with deployment options in the cloud as xDome or on-premises as Continuous Threat Detection (CTD). In the IoT Security scope, it focuses on discovering connected devices, profiling their communications and firmware, detecting anomalies, and supporting exposure analysis for industrial and other mission-critical environments. It is best suited for organizations that need passive visibility into unmanaged or fragile devices on operational networks, including manufacturing, utilities, healthcare, and other infrastructure operators. Adjacent modules such as secure remote access exist, but the core IoT Security value is asset discovery, monitoring, and threat detection.

    Discover and profile connected devices+11
    Evervault logo
    Evervault
    Encryption & Key Management

    Evervault is a developer-focused encryption and data de-identification platform used to protect sensitive fields while keeping applications able to process data without exposing plaintext. In the Encryption & Key Management category, it centers on application-level encryption, tokenization, and key handling built around its Evervault Encryption Engine (E3) running in an AWS Nitro Enclave. It is best suited for teams handling payments, cardholder data, and other regulated records that need encryption patterns embedded into application workflows rather than managed as a standalone vault. Adjacent functions such as secure enclaves and payment-specific tooling exist, but the core value here is encrypting data in transit and at rest with vendor-managed cryptographic operations.

    Store keys while data stays encrypted+9
    Forescout logo
    Forescout
    IoT Security

    Forescout’s IoT Security offering is an agentless device visibility and control platform for unmanaged IoT, OT, and IoMT environments. It identifies devices as they connect, classifies them by type and function, detects weak or factory-default credentials, monitors communications for anomalous behavior, and automates policy actions such as segmentation, quarantine, and least-privilege network access. The product is best suited for enterprises that need passive discovery and enforcement across mixed IT/OT networks, including healthcare, manufacturing, building automation, and critical infrastructure. Forescout also offers adjacent OT and network access control capabilities, but the IoT Security scope centers on device visibility, classification, and containment.

    Real-time device visibility+11
    Fortaegis Technologies logo
    Fortaegis Technologies
    Encryption & Key Management

    Fortaegis Technologies appears to be a deep-tech semiconductor vendor rather than a conventional software key-management provider, with its security model built into silicon. In the encryption and key management scope, it emphasizes hardware-based authentication, elimination of stored or exchanged cryptographic keys, and quantum-safe mutual authentication for device and system trust. Its stated use cases include secure cloud-to-edge networks, autonomous systems, telecom, energy, and defense environments where key exposure and performance overhead are concerns. Buyers evaluating it in this category would likely be teams seeking hardware-rooted trust primitives rather than a standard enterprise KMS.

    Hardware-based authenticationPublic-key replacement+9
    HashiCorp Vault logo
    HashiCorp Vault
    Encryption & Key Management

    HashiCorp Vault is a secrets and cryptographic key management system used to store, distribute, rotate, and control access to encryption keys, certificates, tokens, and other sensitive material. In the Encryption & Key Management scope, Vault’s key management secrets engine centralizes lifecycle control while still interfacing with external KMS providers, and its encryption-as-a-service functions let applications encrypt data without exposing keys. It is typically chosen by teams operating mixed cloud and on-prem environments that need policy-controlled key handling, auditability, and integration with existing identity systems. Enterprise features are available through Vault Enterprise and HCP Vault Dedicated.

    Lifecycle management for cryptographic keys+10
    Island logo
    Island
    Browser & Web Isolation

    Island provides the Island Enterprise Browser, a Chromium-based browser that replaces or coexists with standard browsers to isolate corporate web activity. It executes all web traffic natively on the endpoint, blocking malicious JavaScript across APIs like WebRTC and WebGL, and enables mitigations including Arbitrary Code Guard, Control Flow Enforcement, and Control Flow Guard. Unlike remote browser isolation, it avoids video streaming latency by rendering directly in-browser. Features include conditional access controls based on identity, device, network, and location; DLP for copy/paste, screenshots, print, and downloads; and app boundaries to prevent data leakage. Best for enterprises seeking zero-trust browser security without VPNs or RBI infrastructure.

    Enterprise browser with native security controls+11
    ManageEngine PAM360 logo
    ManageEngine Endpoint DLP Plus
    Data Loss Prevention (DLP)

    ManageEngine Endpoint DLP Plus is an enterprise-grade endpoint data loss prevention solution that scans network endpoints to discover and classify structured and unstructured sensitive data using pre-defined or customizable templates. It monitors data-in-use, data-at-rest, and data-in-motion across endpoints via a centralized web console, enforcing policies to block unauthorized uploads to cloud storage, email transmissions to unpermitted addresses, and peripheral device access like USBs and printers. Designed for large organizations with distributed setups including WAN and mobile users, it supports GDPR compliance through incident management, user behavior analytics, and detailed audit reports. Best suited for enterprises needing comprehensive endpoint DLP in Windows environments.

    Discover and classify sensitive data+11
    Phosphorus logo
    Phosphorus
    IoT Security

    Phosphorus provides an agentless IoT security platform for connected cyber-physical devices, including IoT, OT, IIoT, and IoMT assets. In this category, it focuses on device discovery, posture assessment, and active remediation rather than passive monitoring alone. The platform is built for enterprises that need to inventory unmanaged devices, identify weak credentials, firmware and certificate issues, and enforce hardening actions across heterogeneous device types. It is best suited for security teams responsible for connected device risk in hospitals, industrial environments, and large enterprise networks.

    Uses agentless discovery over native device protocols to inventory connected IoT, OT, IIoT, and IoMT assets without deploying endpoint software or relying on active port scanning.
    QIZ Security logo
    QIZ Security
    Encryption & Key Management

    QIZ Security provides a cryptography management platform that helps organizations discover, prioritize and remediate cryptographic risk while preparing for the transition to post-quantum cryptography. The platform connects over APIs rather than agents or network probes, continuously mapping cryptographic assets and dependencies across cloud and on-premises infrastructure, applications, code, networks, and data in transit and at rest. It builds a knowledge graph of these assets against policy to reveal vulnerabilities such as outdated protocols and weak encryption, ranks risks by context and impact, and provides step by step remediation plans. It is aimed at CISOs, compliance teams and application owners in large enterprises that need crypto-agility, quantum readiness and cryptographic lifecycle governance across complex, multi-stakeholder environments.

    Cryptographic asset discovery+5
    Skyhigh Security CASB logo
    Skyhigh Security CASB
    CASB (Cloud Access Security Broker)

    Skyhigh Security CASB is a cloud-based, multi-tenant Cloud Access Security Broker that deploys via forward and reverse proxy modes for real-time control over sanctioned and unsanctioned cloud services. It leverages the Cloud Registry for 50+ attribute risk assessments across 20,000+ services, enabling discovery, classification, and remediation. Key capabilities include DLP policy enforcement synced with endpoint DLP, machine learning-based UEBA for insider threat detection, malware analysis, configuration auditing against benchmarks with automated remediation, and contextual access controls. Best suited for enterprises needing comprehensive visibility and governance across hybrid cloud environments with SharePoint integration.

    Discover unsanctioned cloud servicesApply cloud data loss prevention+10
    Talon Cyber Security logo
    Talon Cyber Security
    Browser & Web Isolation

    Talon Cyber Security, now part of Palo Alto Networks, built an enterprise browser product for securing SaaS and web access on managed and BYOD endpoints. In the Browser & Web Isolation category, it focuses on keeping work activity inside a controlled Chromium-based browser layer rather than relying on device trust. It is best suited for organizations with hybrid workforces that need browser hardening, data loss controls, and visibility into web activity without deploying a traditional VDI stack. Adjacent Palo Alto Networks SASE features exist, but Talon’s core browser capability is the relevant scope here.

    Chromium-based enterprise browser isolation for SaaS and web access, keeping work sessions inside a controlled browser layer instead of exposing the underlying endpoint to the full internet.
    TXOne Networks logo
    TXOne Networks
    OT & ICS Security

    TXOne Networks is an OT-native cybersecurity vendor focused on protecting industrial and IoT-connected environments such as factories, utilities, and medical/production sites. In the IoT Security scope, its portfolio centers on device and network protection for operational assets, including inspection of removable media, endpoint defense for legacy and modern OT systems, and inline network controls for industrial protocols. It is best suited for organizations that need to secure brownfield OT/IoT environments without disrupting operations. TXOne also sells adjacent OT security orchestration and threat intelligence components, but its IoT security value is primarily in asset, endpoint, and network protection.

    Zero-trust endpoint protectionInline industrial network prevention+10
    Ubiq Security logo
    Ubiq Security
    Encryption & Key Management

    Ubiq Security is an identity-driven encryption and key management platform focused on client-side protection of sensitive data before it reaches storage or downstream services. It provides application-level encryption, tokenization, and masking with integrated master key lifecycle management, so teams do not need to operate a separate KMS or HSM for common deployments. The product is aimed at engineering, security, and compliance teams that need to bind data access to IAM policies and enforce policy-controlled cryptography across applications, databases, data warehouses, API gateways, and cloud workloads. It is best suited to organizations that want data-level control rather than storage-layer encryption alone.

    Integrated key management with secure storage