Platform

One engine that finds regulated data and produces governed alternatives to it.

Four core capabilities share one detection engine, one policy layer, and one audit trail. Everything runs inside your environment.

01 · Discovery

PII discovery & classification

Connect PostgreSQL, MySQL, Snowflake, S3, and SharePoint. VestraData samples schemas, scores fields by name, value, and context, and returns field-level findings with confidence scores and row counts.

Adaptive sampling — no full table scans
Zero-shot classification for custom entity types
Structured and unstructured sources in one queue
Every action written to a tamper-evident audit log
02 · Anonymisation

In-place anonymisation

Apply masking and anonymisation where the data lives. Remove personal data from staging, analytics, and dev environments without rebuilding pipelines — and take those systems out of audit scope.

Consistent surrogates across tables and time
Automatic schema-change detection
Direct import to PostgreSQL, MySQL, SQL Server, Oracle
Built against the ICO's anonymisation guidance
03 · Test data

Production-like test data

Extract referentially intact subsets and generate statistically faithful synthetic datasets for engineering, QA, and ML pipelines. Distribution, correlation, and null rates match production.

Foreign-key-preserving extraction
Differential-privacy mode for GDPR/HIPAA exports
Scheduled refreshes — no manual rebuild cycle
Exports: Parquet, S3, Delta Lake, direct DB import
04 · Audit

Audit evidence

Every finding, decision, and transformation across the platform writes to a hash-chained, immutable record — evidence generated as a by-product of doing the work.

GDPR Art. 30 records from scan findings
Hash-chained records — tampering breaks the chain
Maps to DSPT, PCI-DSS 4.0, HIPAA §164
Exportable as a regulator-ready evidence package
Beyond the core

Extended capabilities

These build on the same engine. They matter for specific environments — document-heavy firms, platform builders, and teams governing AI tool usage — and are secondary to the core discovery and anonymisation workflow.

Data airlock

Watch repositories — SharePoint, Drive, S3, SFTP drops — for new documents. When sensitive content is found, a governed clean copy is produced ahead of time.

  • Event-driven: triggers on file arrival
  • Clean copies staged in a governed location
  • Replaces last-minute manual review

SDK & API

Embed the detection and anonymisation engine directly into your own pipeline or product. REST API with an OpenAPI 3.1 spec, typed clients for Python, Node.js, Java, and .NET.

  • Event-driven scanning with webhook callbacks
  • Multi-tenant isolation for platform builders
  • Same audit trail as the standalone deployment

VestraShield — companion browser tool

A browser extension that intercepts prompts and file uploads before they reach external AI tools, replacing sensitive values with consistent surrogates. Currently available to evaluation customers alongside the platform.

  • Browser-level — no endpoint agent required
  • Policy actions: transform, block, warn, or audit-only
  • Shares entity definitions with your VestraData deployment

See it against your own data.

The technical review connects to one real source in your environment and runs this entire workflow live, in 45 minutes.