Data Security Posture Management · United Arab Emirates

Know where your sensitive data lives. Without any of it leaving your cloud.

In active development. Design-partner conversations open across UAE banking, government, and energy.

DSPM Test is being built to map every datastore in your estate, classify what is regulated, and show who can reach it — with the engine running inside your own trust boundary, so nothing sensitive has to leave it to be understood.

In-boundary by design · Read-only access · Built in the UAE

Engineering targets

The bar the first release is built to

Four numbers that shape every design decision — from how the scanner is deployed to what is permitted to cross your boundary at all.

0 bytes
Raw data or metadata crossing your boundary. A property of the architecture, not a clause in a contract.
< 15 min
From connecting a source to your first classified finding.
PDPL-first
Designed around UAE data-protection rules from the start, rather than retrofitted to them later.
2–3
Design-partner slots open for the first release.

The first release

Find the regulated data. Prove exactly where it sits.

Most breaches are not exotic. They are a forgotten copy of production data sitting somewhere with the wrong policy on it. The first release of DSPM Test is built to do one job completely — find that copy — without moving anything out of your environment.

Agentless discovery

Connect a source read-only and let it inventory the datastores you know about and the ones that never made it into the CMDB. No agents, no proxies, no copies.

Classification you can audit

Regulated personal data labelled at the column level. Every finding carries a sample and a confidence score, so your DPO can check the work instead of trusting it.

Execution inside your boundary

Scanning and classification run on your infrastructure. Only posture signals — findings, risk scores, policy violations — ever leave. Never raw data. Never metadata.

Connector roadmap

Where coverage lands first, and what follows. Design partners set the priority — if your estate runs on something further down the list, that is a conversation worth having early.

Landing with the first release

  • Amazon S3
  • Amazon RDS
  • Azure Blob Storage
  • PostgreSQL (self-managed)
  • Microsoft 365

Next wave

  • Snowflake
  • Databricks
  • BigQuery
  • Amazon Redshift
  • Oracle Database
  • Salesforce
  • Google Drive
  • SMB and NAS shares

How it's designed to work

Four steps, none of which copy your data out

01

Connect

A read-only role deployed by Terraform or CloudFormation. Nothing is installed on the hosts, and nothing dials out with your data.

02

Discover and classify

DSPM Test inventories your datastores, samples them where they sit, and builds a map of regulated data and who can reach it.

03

Prioritize

Exposure paths get correlated with sensitivity to produce a ranked register your engineers will actually work through.

04

Prove it

Posture signals leave your boundary as findings and evidence — the part a regulator or auditor needs, and nothing more.

After the first release

Where this goes next

Discovery and classification come first, but they are not the whole picture. Here is where the platform goes from there, sequenced by what design partners tell us hurts most.

Planned

Access intelligence

Resolve effective permissions across IAM roles, resource policies, and nested groups, so "who can actually read this table?" stops being a week of spreadsheet archaeology.

Planned

Data flow lineage

Follow sensitive data as it moves between production, analytics, and third-party pipelines — and catch the copy that landed somewhere it was never meant to.

Planned

Risk scoring over alert soup

Rank findings by sensitivity, exposure path, and blast radius, so a team gets the ten things that matter rather than ten thousand rows.

Planned

Evidence for your regulator

Control mapping for UAE PDPL, ADGM and DIFC data protection regulations, PCI DSS, and ISO 27001, exported as standing evidence instead of rebuilt each audit cycle.

Planned

Output engineers can use

API, Terraform provider, and webhook events, so posture work fits into pipelines that already exist rather than becoming another console someone has to remember to open.

Why DSPM Test

Built for regulated estates, not retrofitted for them

The scanner goes to your data

Most DSPM platforms route your metadata — sometimes your data — to the vendor's cloud to classify it. DSPM Test inverts that. The engine runs where the data already is, and only posture signals come back out.

Built in the UAE, for the UAE

A UAE-registered company, with infrastructure and IP in the same jurisdiction as the regulated data they serve. No cross-border transfer to justify to a regulator, because the architecture never creates one.

Regulation is the design brief

PDPL, ADGM, and DIFC obligations are the design brief here, not an enterprise tier bolted on to a product shaped for somewhere else. Banks, government entities, and energy companies get a tool that starts from their constraints.

Early enough to shape

The scope of the first release is still open. Come in as a design partner and your requirements move it, before the roadmap hardens. Behind it is a team that has worked inside banking, deep tech, and oil and gas data security.

Shape the first release around your estate

We're taking on a small number of design partners across UAE banking, government, and energy. You get direct access to the founders, real influence over what the first release does, and the first deployment inside your own environment. No procurement cycle, no pricing conversation — just the work.