Home DSPM
Data Security Posture Management

DSPM Data Security Posture

Know where every sensitive record lives, before a regulator asks.

DSPM continuously discovers and maps sensitive data across structured, unstructured, cloud and on-prem repositories, then risk-scores every finding in real time - giving you a live picture of your data security posture across Application, Cloud, DMS, Database, Drive and Email sources.

Agentless Discovery
AI-Powered Classification
Exposure Scoring
Compliance Tagging
Docs Scanned 13,081
Detection Rate 85.2%
See It In Action

Full visibility into every data source

The DSPM dashboard tracks total vs. processed records and PII found across Application, Cloud, DMS, Database, Drive and Email sources - in real time.

DSPM dashboard screenshot
Core Capabilities

What DSPM Does

Multi-Source Scanning

Scans SQL, NAS, Cloud, O365, Email and more to locate sensitive payloads wherever they live.

Smart Classification

AI-driven classification and deduplication identify PII and PHI with high precision.

Exposure Scoring

Every finding is risk-scored so teams can prioritize the highest-impact issues first.

Compliance Tagging

Findings are automatically tagged against DPDP, GDPR and HIPAA requirements.

Under the Hood

What Powers DSPM

The configurable engines and masters that keep detection accurate and compliance current.

Obliq Low-Code Platform No Redeployment

The document, file type and compliance masters all run on Obliq, our own Low-Code platform - configure changes directly and they go live instantly, with no redeployment required.

Rule Engine Configurable

Configure rules for documents based on entities like name, number and more - so the right rules fire automatically the moment a document is scanned.

Scanning Engine AI-Powered

Scans every document, detects all entities within it, and identifies the document type - Aadhaar, PAN and more - with high precision.

Document Type Management Extensible

Add new document types directly as they're introduced - by the government or otherwise - and configure them straight into the rule and scanning engines.

File & Field Type Management

The same flexibility extends to file types and field types, letting you onboard new data structures without engineering effort.

Compliance Master

A central library of regulations - UIDAI, RBI, SEBI, MORTH, PDPL and more - configurable directly into the rule engine for compliance-aware scanning and reporting.

Document Training

Train the detection model directly on new or evolving document formats, continuously improving identification accuracy.

Deduplication Cross-Source

Automatically detect duplicate documents uploaded across any source, so the same record doesn't get scanned, stored or reported multiple times.

Data Discovery

Data Discovery Modules

Comprehensive AI-powered scanning across all your enterprise data sources to identify, classify, and secure PII, PHI, and PCI in real-time.

80+
PII Fields Detected
25+
Compliance Guidelines
5
Discovery Modules
20+
File Types Supported

1. NAS Drive Scan

Scan files across NAS and shared drives with configurable paths, rules, schedules, and access control handling. Ideal for discovering sensitive files across distributed file systems.

Supported Drive Types

Network: SMB/CIFS shares, NFS mounts, FTP/SFTP servers
Local: NTFS, FAT32 file systems

Key Features

  • Folder Path Input - Set root folder to start
  • Recursive Scanning - Traverses subdirectories
  • File Type Detection - Docs, spreadsheets, PDFs, images
  • Content Analysis - OCR and text extraction
  • PII Matching - Aadhaar, PAN, Name, DOB, etc.
  • Live Progress - Real-time progress and ETA
  • Metadata Extraction - Properties, dates, access logs
  • Network Share Support - Mapped drives, UNC paths
Access Requirements
  • Read permissions on directories
  • Network access to shared drives
  • Service account with privileges
User Knowledge
  • File system hierarchy
  • Network drive mappings
  • Permissions and security

2. Database Scan

Analyze structured data across tables and columns for sensitive content like Aadhaar, SSNs, and emails. Supports schema retrieval, selective scanning and compliance tagging.

Supported Databases

Microsoft SQL Server, Oracle Database, PostgreSQL

Comprehensive Support

  • Credential Management - Validate before scanning
  • Schema Retrieval - Tables and columns
  • Selective Scanning - Targeted or full schema
  • Live Progress - Percent, counts, ETA
  • Structured Results - Interactive table
  • PII Detection - PII highlights with tags
Database Access
  • Read-only user credentials
  • SELECT on target schemas/tables
  • Network connectivity
  • Drivers (JDBC/ODBC) available
Required Knowledge
  • Basic DB administration
  • SQL and table relationships
  • Indexing concepts
  • Data sensitivity awareness

3. Email Scan

Deep scanning of email bodies, attachments, and archives with format-aware parsing and configurable scope. Supports Microsoft and Google email platforms.

Supported Email Platforms

Microsoft: Outlook.com, Office 365 • Google: Gmail

Email System Integration

  • Content - Body, subject, signatures
  • Attachments - Docs, images, archives
  • Metadata - Sender, recipient, timestamps
  • Threading - Conversation context
  • Archive - PST, OST, MBOX formats
  • Monitoring - Continuous scanning
OAuth Requirements
  • Azure AD registration
  • Mail.Read permissions
  • Admin consent for org-wide
  • MFA support
Compliance Considerations
  • Legal hold & eDiscovery
  • Retention requirements
  • Privacy impact assessments
  • Employee notification

4. Cloud Storage

Secure API-based scanning for major cloud platforms with scan boundaries, provider-specific security handling, and scalable processing.

Supported Cloud Platforms

AWS S3 • Azure Blob/Files • Google Cloud Storage/Drive

Platform Features

  • Multi-Cloud - Unified scanning interface
  • API Integration - Native connections
  • Buckets/Containers - Object analysis
  • Metadata - Properties, tags, ACLs
  • Versioning - Historical versions scan
  • Sharing - Public/private assessment
API Credentials
  • Service keys or OAuth tokens
  • Read permissions
  • Rate limiting & quotas
  • Secure secret storage
Skills Required
  • Cloud admin basics
  • API key management
  • Storage structures
  • Network security & firewalls

5. DMS - Document Management System

Integrate with DMS to scan documents, metadata, and versions. Supports classification, permissions, and detection of sensitive data across enterprise platforms.

Supported DMS Products

Digi-Drive • Alfresco • OpenText Documentum • IBM FileNet • M-Files

Platform Features

  • Libraries - Repository scanning
  • Metadata - Custom fields, tags
  • Version History - Track changes
  • Workflows - Approvals & lifecycle
  • Permissions - Rights & security groups
  • Content Types - Template classification
Content Analysis
  • Indexing & search
  • Metadata fields
  • Version tracking
  • Workflow alignment
System Requirements
  • DMS admin access
  • API docs & endpoints
  • Taxonomy knowledge
  • Permission model awareness
PII Detection

PII Fields Detection Capabilities

Comprehensive detection of 50+ sensitive data fields across multiple categories with AI-powered classification.

Identity Information

AadhaarPANPassportDriving LicenseVoter IDNameFirst NameMiddle NameLast Name

Personal Details

Date of BirthGenderPlace of BirthNationalityReligious DetailsCaste DetailsEducation DetailsEmergency Contact

Contact Information

EmailMobile NumberAddressSocial Handles

Digital Identity

UsernamePasswordIP AddressDevice IDLocation (GPS)

Biometric Data

Face RecognitionFingerprintIris ScanBlood Group

Financial Information

Account NumberIFSCCard NumberBankCVVExpiryUPI IDTxn IDAmountTxn DateEMI Amount

Tax & Investment

Tax DetailsGSTPortfolioInsurance PolicyPremiumClaim Number

Healthcare Information

DiagnosisMedical HistoryPrescriptionsLab ReportsDoctorAllergiesTreatment PlanSurgeryDischargeImmunizationMental HealthRisk ScoreDevice SerialInsurance Card
File Formats

Supported File Types

Comprehensive file format support for thorough data discovery across your entire organization.

Video & Audio

.mp4, .avi, .mov, .wmv, .mkv, .webm, .mp3, .wav, .ogg

Image Files

.jpg, .jpeg, .png, .tif, .tiff

Text Files

.txt, .log, .csv, .json, .xml, .md, .config, .ini, .env, .py, .raw

Documents

.pdf and other document formats

Compliance

Compliance Guidelines Coverage

Supporting 10 Indian regulations plus key global standards (GDPR, DPDP & HIPAA).

India Flag India Regulations (10/10 Active)

  • ✓🔒DPDP Act (Digital Personal Data Protection Act, 2023)
  • ✓🏦RBI Guidelines (Reserve Bank of India)
  • ✓📊SEBI Regulations (Securities and Exchange Board of India)
  • ✓🛡️IRDAI Regulations (Insurance Regulatory Authority)
  • ✓💻IT Act, 2000 & Amendments
  • ✓🏥DISHA (Digital Information Security in Healthcare Act)
  • ✓⚕️NDHM / ABDM (Ayushman Bharat Digital Mission)
  • ✓📡TRAI Regulations (Telecom Regulatory Authority)
  • ✓🚨CERT-In Guidelines (Computer Emergency Response Team)
  • ✓🆔UIDAI Compliance (Aadhaar)

🌍 Global Standards (3/10 Active)

  • ✓🇪🇺EU GDPR (General Data Protection Regulation)
  • ✓🔒DPDP (Digital Personal Data Protection Act)
  • ✓🏥HIPAA (Health Insurance Portability and Accountability Act)
  • ⏳💳PCI DSS (Payment Card Industry Data Security Standard)
  • ⏳📊SOX (Sarbanes-Oxley Act)
  • ⏳🏦GLBA (Gramm-Leach-Bliley Act)
  • ⏳📈SEBI Guidelines (Securities and Exchange Board of India)
  • ⏳🔒HITECH (Health Information Technology Act)
  • ⏳📡TRAI Regulations (Telecom Regulatory Authority)
  • ⏳🛡️ISO/IEC 27001 (Information Security Management)

Expansion planned for remaining 7 standards in next version

UAE Flag UAE Regulations (Coming Soon)

🔐 Data Protection & Privacy Laws

  • ⏳PDPL (Personal Data Protection Law - Federal Decree-Law No. 45 of 2021)
  • ⏳DIFC Data Protection Law (Law No. 5 of 2020)
  • ⏳ADGM Data Protection Regulations (Abu Dhabi Global Market)
  • ⏳Health ICT / Health Data Law (Health Information Privacy & Security)

🛡️ Cybersecurity & Compliance Standards

  • ⏳IAR (Information Assurance Regulation by TDRA)
  • ⏳Cybercrime Law (Federal Decree-Law No. 34 of 2021)
  • ⏳Cabinet Resolution No. 21 of 2013 (Data Security Framework)
  • ⏳DESC ISR (Dubai Electronic Security Center Information Security Regulation)
  • ⏳Central Bank Regulations / RPSCS (Payment & Card Schemes)

🚀 Expansion planned for UAE regulations in the next version

Implementation

Before You Begin: Requirements & Checklist

Essential requirements and preparation steps before implementation.

⚠️ System Prerequisites

⚙️ Technical Requirements

  • ✓Windows Server 2016+
  • ✓Minimum 8GB RAM, 16GB recommended
  • ✓100GB+ available storage space
  • ✓Network connectivity to target systems
  • ✓Administrative privileges on scanning systems

🎓 User Knowledge Requirements

  • ✓Basic understanding of data privacy regulations (GDPR, HIPAA)
  • ✓Familiarity with your organization's data architecture
  • ✓Knowledge of file system structures and permissions
  • ✓Understanding of database concepts and SQL basics
  • ✓Email system administration experience

✅ Getting Started Checklist

⚡ Before You Begin

  • ✓Conduct a data mapping exercise to identify all data sources
  • ✓Obtain necessary permissions and approvals from data owners
  • ✓Set up service accounts with appropriate access levels
  • ✓Configure network access and firewall rules

💡 Best Practices

  • ✓Start with a pilot scan on non-production systems
  • ✓Schedule scans during off-peak hours to minimize impact
  • ✓Implement proper logging and monitoring
  • ✓Establish data classification and handling procedures