Platform

One platform for data discovery, classification, and exposure management.

PostQKey connects to your cloud data estate and builds a living inventory of every sensitive asset, its classification, who can access it, and where it is exposed.

Find every data store. Including the ones your team forgot.

PostQKey uses agentless connectors with read-only API access to crawl your cloud data estate. No agents to deploy. No data leaves your environment.

  • Complete inventory: data store type, owner, creation date, last accessed
  • Estimated row counts and schema snapshots
  • Configurable scan schedule: continuous or on-demand
  • Read-only by design, minimum necessary permissions
See Discovery deep-dive

AI that reads context, not just column names.

PostQKey samples actual field values and applies classification models trained on PII, PHI, financial, and confidential patterns. Column name matching alone is too brittle: it misses obfuscated names and catches false positives on generic names. PostQKey reads the content. It catches "email in a column named user_ref" and correctly ignores "a column named customer_flag that contains 0 and 1." Every finding comes with a confidence score and a sample path, so your team can confirm before acting.

  • Field-level classification with confidence scores
  • PII, PHI, financial, confidential categories
  • Custom classification labels (Professional plan)
  • Configurable sample size per table

Map every path to sensitive data.

PostQKey queries AWS IAM policies, Snowflake role hierarchies, Salesforce permission sets, and Google Workspace sharing, then builds a graph of who (user, role, or service account) has an effective path to sensitive data. Effective access, not just explicit grants: the Snowflake role that inherited SELECT on your PII schema three role-hops away from SYSADMIN is in the graph too.

  • AWS IAM users, roles, and policies
  • Snowflake role hierarchies and grants
  • Google Workspace and Salesforce sharing rules
  • Path traversal for inherited permissions
See Access Graph deep-dive

From inventory to posture: where are you exposed?

Exposure scoring combines classification sensitivity, access breadth, encryption state, and public reachability. The result is a prioritized remediation queue your team can actually work through.

  • Composite exposure score per asset
  • CRITICAL / HIGH / MEDIUM / LOW severity tiers
  • Actionable remediation guidance per finding
  • Re-scan verification after remediation
See Exposure Map deep-dive

40+ connectors. Built for where data actually lives.

Cloud Storage 3 connectors

S3, Azure Blob, Google Cloud Storage

Data Warehouses 4 connectors

Snowflake, BigQuery, Redshift, Databricks

SaaS Applications 8 connectors

Salesforce, Slack, Google Drive, OneDrive, SharePoint, Notion, Confluence, Teams

Databases 6 connectors

PostgreSQL, MySQL, MongoDB, MS SQL Server, Oracle, DynamoDB

Connect your first store in 15 minutes.

Read-only access, no agents, no data stored. Posture baseline in under 24 hours.