Every data store. Every schema. Continuously.
PostQKey runs agentless discovery on 40+ cloud data stores. No agents to deploy. No data leaves your environment. Schema snapshots updated on a configurable schedule.
Four steps from connection to inventory.
Connect via read-only credentials
Provide an OAuth token, IAM role ARN, or service account. PostQKey uses read-only permissions only. Nothing is written to your environment. You can revoke access in the same UI where you granted it.
Enumerate stores and schemas
PostQKey lists all available buckets, tables, schemas, and file shares in your connected account. For warehouses: full schema traversal including future grants and inherited schemas. For object stores: scan by prefix and extension (CSV, JSON, Parquet, PDF, XLSX). New stores added to the account after the initial scan are picked up automatically on the next scheduled run.
Sample and analyze
PostQKey samples up to 1,000 rows per table (configurable). Object stores: samples up to 500 objects per bucket, selects by extension (CSV, JSON, Parquet, PDF, XLSX). No sampled data is stored server-side.
Build the structured inventory
Results are assembled into a structured inventory record per data store: type, region, owner, schema snapshot, last_modified, estimated row count, classification results, and exposure score. Updated on your chosen schedule.
What the inventory includes for every data store.
| Field | Description | Example |
|---|---|---|
data_store_id |
Unique internal identifier | ds-sf-prod-001 |
type |
Connector type | snowflake / s3 / salesforce |
region |
Cloud region or datacenter | us-east-1 |
owner |
Mapped IAM account or org unit | [email protected] |
schema_snapshot |
Current table/column structure | JSON schema object |
estimated_rows |
Approximate row count | 4,200,000 |
pii_detected |
Whether PII was found | true |
classification_confidence |
Highest confidence score across fields | 0.94 |
exposure_score |
Composite risk score (0-100) | 82 |
Start with one connector. See results in under 24 hours.
Read-only access. No agents. No data stored beyond metadata.