One platform for data discovery, classification, and exposure management.
PostQKey connects to your cloud data estate and builds a living inventory of every sensitive asset, its classification, who can access it, and where it is exposed.
Find every data store. Including the ones your team forgot.
PostQKey uses agentless connectors with read-only API access to crawl your cloud data estate. No agents to deploy. No data leaves your environment.
- Complete inventory: data store type, owner, creation date, last accessed
- Estimated row counts and schema snapshots
- Configurable scan schedule: continuous or on-demand
- Read-only by design, minimum necessary permissions
AI that reads context, not just column names.
PostQKey samples actual field values and applies classification models trained on PII, PHI, financial, and confidential patterns. Column name matching alone is too brittle: it misses obfuscated names and catches false positives on generic names. PostQKey reads the content. It catches "email in a column named user_ref" and correctly ignores "a column named customer_flag that contains 0 and 1." Every finding comes with a confidence score and a sample path, so your team can confirm before acting.
- Field-level classification with confidence scores
- PII, PHI, financial, confidential categories
- Custom classification labels (Professional plan)
- Configurable sample size per table
Map every path to sensitive data.
PostQKey queries AWS IAM policies, Snowflake role hierarchies, Salesforce permission sets, and Google Workspace sharing, then builds a graph of who (user, role, or service account) has an effective path to sensitive data. Effective access, not just explicit grants: the Snowflake role that inherited SELECT on your PII schema three role-hops away from SYSADMIN is in the graph too.
- AWS IAM users, roles, and policies
- Snowflake role hierarchies and grants
- Google Workspace and Salesforce sharing rules
- Path traversal for inherited permissions
From inventory to posture: where are you exposed?
Exposure scoring combines classification sensitivity, access breadth, encryption state, and public reachability. The result is a prioritized remediation queue your team can actually work through.
- Composite exposure score per asset
- CRITICAL / HIGH / MEDIUM / LOW severity tiers
- Actionable remediation guidance per finding
- Re-scan verification after remediation
40+ connectors. Built for where data actually lives.
S3, Azure Blob, Google Cloud Storage
Snowflake, BigQuery, Redshift, Databricks
Salesforce, Slack, Google Drive, OneDrive, SharePoint, Notion, Confluence, Teams
PostgreSQL, MySQL, MongoDB, MS SQL Server, Oracle, DynamoDB
Connect your first store in 15 minutes.
Read-only access, no agents, no data stored. Posture baseline in under 24 hours.