ON-PREM · PII DISCOVERY

Know where sensitive data lives — without it ever leaving your environment

Instrata deploys as a container inside your own infrastructure to discover and classify PII across your databases — the data-layer foundation of the Instrata AI Control Plane, and every privacy and AI-governance workflow built on top of it.

Runs entirely inside your environment
Nothing scanned or classified ever leaves it
Low-confidence matches route to a human reviewer
instrata · discovery
SAMPLE DATA
ORACLE-CORE-01
Oracle
read-only
48 tables · 312 columns scanned
Zero rows or values left the container
Sample classifications
CUSTOMER_MASTER.EMAIL_ADDR
email
auto-accepted
ACCOUNT.NATL_ID_NUM
national_id
auto-accepted
SUPPORT_TICKETS.NOTES_TXT
— unmapped
needs review
Full sample report
Every column, tier, confidence score, and reviewer field
View report →
Built to guarantee:Zero network egressRuns inside your VPC or on-premRead-only connectionsEvery low-confidence match reviewed by a humanNo data retained after a scan
The problem

Nobody has a current map of where sensitive data actually lives

Across Oracle, SQL Server, MySQL, Postgres, and legacy systems that predate any API, sensitive data accumulates for years with no consistent record of where it is or how sensitive it is — and that gap blocks every downstream privacy, security, and AI-governance workflow that depends on it.

4+
Database engines a typical on-prem enterprise runs, each with its own schema conventions.
Years
Of legacy data accumulation with no consistent record of where sensitive fields live.
0
Bytes of scanned data or classification output that ever leave your environment.
How it works

From raw schema to a reviewed, canonical map

Everything runs inside a single container in your environment — nothing is sent out, and a human reviews anything the pipeline isn't confident about.

1
Container
Connects read-only
The container connects read-only to one data source at a time — no write access, ever.
2
Container
Enumerates the schema
Every table and column is catalogued, along with row counts and basic metadata.
3
Container
Samples values locally
A small sample of real values is pulled per column, entirely inside the container.
4
Container
Classifies in three stages
Name matching, then pattern matching, then a local model resolves anything ambiguous — no external API calls.
5
Reviewer
Routes low-confidence matches
Anything the pipeline isn't confident about is queued for a human reviewer instead of auto-accepted.
6
Output
Produces a canonical map
Every column maps to a canonical PII field and sensitivity tier — re-scans never overwrite a prior human decision.
Capabilities

Everything needed to trust the map it produces

01
Schema enumeration
Catalogs every table and column across the connected source, with row counts.
02
Local sampling
Pulls a small real-value sample per column without it ever leaving the container.
03
Three-stage classification
Name matching → pattern matching → local-model tiebreak for anything ambiguous.
04
Canonical PII schema
Every column maps to a small, consistent field set — email, phone, national ID, account number, date of birth, name, address.
05
Sensitivity tiers
Each canonical field carries a tier — pii, restricted, or confidential.
06
Human review queue
Low-confidence matches are queued for a reviewer, never auto-accepted.
07
CSV review round-trip
Reviewers export, annotate, and re-import decisions in their own tools.
08
Re-scan safe
Re-running a scan never overwrites a human reviewer’s prior decision.
09
Zero-egress container
No network egress required once the image is built — nothing leaves your environment.
10
Oracle today, more on the roadmap
SQL Server, MySQL, and Postgres connectors are next.
Where this sits — and where it's going

One container, four layers of the same problem

Instrata deploys as a container inside your own environment to discover and classify PII across your data — the foundation every other compliance and AI-governance workflow depends on. DLP enforcement, DSAR automation, and AI-governance readiness are the same platform, unlocked from that same container as you need them.

DSPMDiscover & classify PII across your dataDesign-partner pilot
DLPEnforce protection across the network in real timeNext
Privacy & GRCDSAR automation, audit trails, disclosure workflowsAlready free
AI GovernanceEU AI Act & consequential-decision complianceNext
Live today — the wedge Unlocked next, same container — no new vendor, no new deployment

Most of this category — BigID, Securiti, OneTrust — connects to your data from the cloud. Instrata runs inside your environment instead, so nothing you classify ever leaves it. For regulated, security-conscious teams, that's not a deployment detail — it's the reason they can say yes.

Sample report

See what a scan actually finds

A sample run against a mid-size Oracle schema — every column mapped to a canonical field, a confidence score, and a status. It's a static walkthrough of the real output shape, not live customer data.

01Schema enumerated
02Columns classified
03Low-confidence rows queued for review