All use cases
    Use case

    Data security posture (DSPM)

    Find sensitive data wherever it lives, then govern it.

    Why this fits, Data security posture management: discovery, classification and risk for data at rest.

    39 vendors for this

    Evervault logo
    Evervault
    Encryption & Key Management
    9 products

    Evervault is a developer-focused encryption and data de-identification platform used to protect sensitive fields while keeping applications able to process data without exposing plaintext. In the Encryption & Key Management category, it centers on application-level encryption, tokenization, and key handling built around its Evervault Encryption Engine (E3) running in an AWS Nitro Enclave. It is best suited for teams handling payments, cardholder data, and other regulated records that need encryption patterns embedded into application workflows rather than managed as a standalone vault. Adjacent functions such as secure enclaves and payment-specific tooling exist, but the core value here is encrypting data in transit and at rest with vendor-managed cryptographic operations.

    Store keys while data stays encryptedClient-side card encryption+8
    Netwrix logo
    Netwrix
    Identity Governance & Administration (IGA)
    8 products

    Netwrix provides a SaaS-based Identity Governance and Administration (IGA) platform, primarily through Netwrix Identity Manager (formerly Usercube), automating identity lifecycle management across hybrid IT environments. It handles provisioning, deprovisioning, access reviews, and policy enforcement for joiner-mover-leaver processes. The solution builds role catalogs mapping technical entitlements to business roles, detects toxic role combinations and Segregation of Duties (SoD) conflicts, and generates compliance reports. Best suited for mid-to-large enterprises needing scalable IGA for Active Directory, Azure AD, and multi-system access governance to enforce least privilege and support audits.

    Automate joiner mover leaver workflows+11
    Skyhigh Security CASB logo
    Skyhigh Security CASB
    CASB (Cloud Access Security Broker)
    8 products

    Skyhigh Security CASB is a cloud-based, multi-tenant Cloud Access Security Broker that deploys via forward and reverse proxy modes for real-time control over sanctioned and unsanctioned cloud services. It leverages the Cloud Registry for 50+ attribute risk assessments across 20,000+ services, enabling discovery, classification, and remediation. Key capabilities include DLP policy enforcement synced with endpoint DLP, machine learning-based UEBA for insider threat detection, malware analysis, configuration auditing against benchmarks with automated remediation, and contextual access controls. Best suited for enterprises needing comprehensive visibility and governance across hybrid cloud environments with SharePoint integration.

    Discover unsanctioned cloud services+11
    Ubiq Security logo
    Ubiq Security
    Encryption & Key Management
    2 products

    Ubiq Security is an identity-driven encryption and key management platform focused on client-side protection of sensitive data before it reaches storage or downstream services. It provides application-level encryption, tokenization, and masking with integrated master key lifecycle management, so teams do not need to operate a separate KMS or HSM for common deployments. The product is aimed at engineering, security, and compliance teams that need to bind data access to IAM policies and enforce policy-controlled cryptography across applications, databases, data warehouses, API gateways, and cloud workloads. It is best suited to organizations that want data-level control rather than storage-layer encryption alone.

    Integrated key management with secure storage+11