Data watch   Cloud discovery / sensitive data / Atlassian GuardCompany file   Borneo / founded 2019 / joined Atlassian 2025Data watch   Cloud discovery / sensitive data / Atlassian GuardCompany file   Borneo / founded 2019 / joined Atlassian 2025

Company profile / Data security

Borneo Went Looking for the Data Nobody Knew They Had

Most companies can tell you where their servers are. Ask where their sensitive data has wandered, and the room gets quieter. Borneo built a business around that silence - then Atlassian bought the team.

The odd thing about modern data is how good companies are at creating it, and how vague they can become when asked where it ended up. A customer record begins in a database. A fragment appears in a support ticket. An export lands in a shared drive. A developer copies a sample into a test environment. Each step seems reasonable; together they make an inventory that no one quite owns. Borneo, founded in 2019 by Prithvi Rai, made that inventory its business.

The short version

  • Borneo built software to discover, classify and help fix sensitive-data exposure across cloud, SaaS and other systems.
  • Its named customers include Robinhood, Grab, Angel One and Circles.life.
  • A $15.5 million Series A in 2021 preceded a 2024 move into Kafka streams and a 2025 acquisition by Atlassian.

Rai and his colleagues came from the sort of companies where a spreadsheet has never been a credible map of the data estate: Facebook, Uber and Yahoo. Their question was practical. What would a security team have to see before it could tell whether private information was exposed? Borneo's answer paired automated discovery with classification, monitoring and remediation. The point was to shorten the distance between finding a problem and assigning someone to solve it.

A map that keeps changing

A conventional audit can tell a team what was present on Tuesday. It is less helpful on Friday, after a new data pipeline, SaaS integration and batch export have appeared. Borneo described its approach as privacy observability: continually inspect the landscape, recognize sensitive information, and compare what is happening with a baseline. The product used machine learning and contextual analysis to identify information such as personal details, payment data, health records and credentials across structured and unstructured sources.

That breadth matters because private information seldom respects the neat boxes on an architecture diagram. A database may have a clear owner and a retention policy; a document, chat attachment or copied export may not. Borneo's agentless connectors and private deployment options were aimed at large organizations that needed coverage without introducing another operational project at every source. Its materials also described surface, audit and deeper forensic scans, giving teams different levels of inspection for different questions.

Borneo compliance dashboard showing a summary of data security and privacy activity
Figure 01 / Product viewThe dashboard has an unglamorous ambition: make a moving data estate legible to the people paid to worry about it.

The last box is the difficult one. A classifier that merely produces a longer queue of alerts has only rearranged the work. Borneo's commercial pitch stressed automated or guided remediation: notify the owner, change access, anonymize a field, encrypt what must remain, and show the result in a compliance view. Those are different actions, and a real organization still has to decide which one is appropriate. But the sequence gives a team something more useful than a colored risk score.

“Every company is also now a data company.”Prithvi Rai, announcing Borneo's 2021 funding

A stream is a particularly bad place to lose track

In August 2024, Borneo announced an integration with Confluent Kafka Stream Catalog. It was a precise demonstration of the company's idea. Kafka carries data between systems; the interesting information may be moving rather than resting in a database. Borneo said its integration could scan streams for sensitive fields, feed those classifications into the catalog and support end-to-end encryption. The claim is narrower than a promise to secure every stream. It is also more useful: put a label on sensitive data at a point where another system can act on it.

That expansion distinguished Borneo's pitch from a simple inventory tool. The company competed in the broader data security posture management market, where vendors such as BigID and Varonis also promise discovery, classification and remediation. Borneo emphasized a practitioner-built platform, real-time monitoring, private deployment and the ability to follow data in motion. In a crowded category, the meaningful test is whether those differences reduce the time between exposure and repair for a particular customer.

$15.5mSeries A raised in 2021
2025Year Borneo joined Atlassian

The money came before the stream integration. In September 2021, Borneo raised a $15.5 million Series A led by Vulcan Capital, with Prosus Ventures, Lytical Ventures and existing backer Wavemaker Partners participating. Contemporary reporting put its cumulative equity funding at about $18 million. There is no public price list for the platform; the sales model was enterprise software shaped around the customer's data sources, deployment and security requirements. A published Factorial case study also documents privacy-program and external DPO support, an example of services alongside the software.

Who buys a better question?

Borneo publicly named Robinhood, Grab, Angel One and Circles.life among companies that trusted its platform. The list spans finance, transport and communications, but the shared problem is less an industry than an operating condition: many systems, many copies and little tolerance for a sensitive field being left somewhere it should not be. For such teams, the first useful output is a trustworthy map. The second is a prioritized repair list with an owner.

There is a lesson here that travels beyond security software. If a company wants to know what its data policy really means, it can begin with one concrete question: where did a particular type of private information go this week? Map the sources, check who can reach them, inspect the exceptions, then assign each fix. Repeat after the next integration ships. The method is less glamorous than writing a new policy and more likely to reveal where the policy stops working.

It has limits. Discovery depends on what a product can connect to and what it has permission to inspect. Classification can misread context, especially in messy documents. Encryption may be the right answer in a stream and the wrong answer in a workflow that needs the data in plain text. No vendor can make those choices without the customer's owners, controls and review process. Borneo's own strongest idea was to make such choices visible and actionable, not to pretend they would disappear.

The exit was a change of venue

In 2025, Rai announced that Borneo had joined Atlassian. Later, in an Atlassian Guard discussion, an Atlassian team member said Borneo's engineers were helping with scanning and detection features. That is a more concrete account of the acquisition than the usual language about synergies. Atlassian has work items, documents, attachments and customers who need to know when sensitive information appears in the wrong place. Borneo had spent years building machinery to answer precisely that kind of question.

The marriage also changes the scale of the problem. An independent Borneo could scan across a customer's dispersed estate and offer a broad security view. Inside Atlassian, its team's work can become part of a familiar product workflow: find sensitive content, alert the right person, create an action, and track what happened. Whether that becomes a seamless experience is a product question for Atlassian. The logic behind the deal, however, is easy to see. The modern office has become a prolific publisher of data. Someone has to keep the index.