A security officer had a confession for Karthik Krishnan. If an audit arrived that day, he said, he would probably be fined. He did not know where the company's most important data lived, let alone who could read it. This was not a small shop with a messy filing cabinet. It was an enterprise with the sort of digital estate that makes an inventory sound less like paperwork than archaeology.
Krishnan and his future cofounders, Madhu Shashanka and Shankar Subramaniam, took the question to at least 30 security professionals. They heard variations of the same answer: millions of files, spread across cloud services and local servers, with little idea which documents deserved the strongest protection. Concentric AI was founded in 2018 to make that question answerable.
- It reads the context of enterprise files to identify sensitive material and risky access.
- A Baron Capital deployment scanned six million files and flagged about 300 business-sensitive files with permission problems.
- The company expanded into AI-use controls after acquiring Swift Security and Acante in 2025.
- Its software is sold to enterprises; pricing depends on data scanned and, for Semantic DLP, user count.
A very large haystack, a very specific needle
Traditional data security tools can be excellent at finding patterns: a credit-card number, a social-security number, a familiar label. But some of the most valuable company information has no tidy signature. A draft acquisition plan may contain no regulated number at all. A piece of source code may look like ordinary text to a scanner trained only to hunt for personal data. The difference between the two requires a sense of what the document is about.
Concentric AI's core product, Semantic Intelligence, uses machine learning to group and classify data by context. It connects to cloud repositories by API and to on-premises systems through a virtual proxy. It then maps sensitivity against permissions, location, and sharing. A security team can see a business-critical document in the wrong folder, an old file accessible to too many people, or a label that understates what the content reveals. The team can change permissions, apply labels, or route work into its existing tools.
The Baron Capital case makes the abstract language unusually concrete. According to Concentric AI's customer account, the investment firm's security team set up the platform in one day. It scanned six million files on local Windows servers, grouped them into 200 themes, and surfaced roughly 100 business-sensitive files with incorrect group permissions plus another 200 with inappropriate user-level permissions. That is the useful compression: six million objects became a few hundred decisions.
The case study says the high-risk set was around 0.05% of business-sensitive documents. It also says the work saved hundreds of staff hours a month. Those are customer-reported outcomes, and the exact results depend on a company's repository and permission habits. Still, the lesson travels well: before buying a new rule book, find out whether the existing one describes the files people actually have.

The files learned to travel
A file with excessive permissions was always a problem. Generative AI made the path from careless access to careless disclosure shorter. An employee could paste a confidential paragraph into a public tool, or an approved assistant could retrieve a document that should never have been broadly shared. The original Concentric question - what is this file, and who may use it? - suddenly sat inside an AI rollout.
Jennison Associates offers a second version of the story. The investment manager temporarily blocked generative AI tools while it searched for a safer approach. Its case study says Concentric AI was initially brought in for classification and labeling, then used to monitor data flows and support approval workflows for uploads. Jennison's CISO, Paul Pak, put the goal plainly: employees should be able to use the benefits of generative AI without exposing the firm's data.
“If you don’t know what you have, you can’t monitor or protect it.”Karthik Krishnan, cofounder and CEO
Concentric AI widened its product line in July 2025 by buying Swift Security and Acante. Swift's technology added monitoring of public AI applications and the ability to mask or block sensitive uploads. Acante added controls over data used to train AI and machine-learning models, including redaction, replacement, masking, and encryption. The resulting pitch spans data at rest, in motion, and in use. It is a broader promise than a scanner, and it brings a broader implementation job with it.

What the company actually sells
The product family has two main pieces. Semantic Intelligence discovers and classifies data, checks access and risk, and supports remediation across cloud and on-premises systems. Semantic DLP is delivered as a browser extension for AI applications: it can observe prompts and responses and apply controls when users try to share sensitive material. The company also offers managed and advisory support, an acknowledgment that an alert has little value until someone owns the fix.
The commercial units are unusually clear even without a public price list. Concentric AI says it prices Semantic Intelligence by the amount of data scanned and Semantic DLP by the number of users. That means an enterprise evaluating it should start with two counts: the size of the estate it wants inspected and the number of people whose AI interactions need controls. A pilot on a representative repository is more revealing than a slide full of detection claims.
Its customers are security, privacy, and compliance teams in industries where sensitive records multiply: finance, healthcare, technology, manufacturing, education, and government. Public customer stories name Baron Capital, Jennison Associates, Cadence, Oceaneering, and others. Concentric AI reported that it tripled its customer count in 2024 and managed hundreds of petabytes of customer data. It has not made an exact customer total public, so that growth is best read as the company's own account of momentum.
The market has too many initials
Buyers will encounter DSPM, DLP, access governance, insider-risk tools, and AI security in adjacent sales conversations. Microsoft Purview, Varonis, Cyera, and BigID are among the kinds of alternatives a team might consider, depending on whether its immediate problem is labeling, permissions, cloud exposure, or data leaving through applications. Concentric AI's distinction is its insistence that the same contextual understanding of data should inform each task. It does not remove the need to choose policies or decide which risks merit action.
The company has kept extending that premise. In 2025 it announced integrations with Wiz, GitHub, and Salesforce. In 2026 it added an Anthropic Compliance API integration for Claude activity and a vision feature for finding documents such as passports and driver's licenses by visual signature, where text recognition can be unreliable. It also signed Sektor to distribute in Australia and New Zealand. The direction is consistent: more places to look, more ways data moves, and more signals to judge what matters.
The approach has a boundary that matters in practice. A repository must be connected before the platform can inspect it, and someone still has to decide whether a flagged permission is genuinely excessive. A team without repository access or a clear owner for remediation may gain a sharper map of risk without reducing it.
Concentric AI has raised more than $67 million, including a $45 million Series B in 2024. Capital helps a company cover more formats, repositories, and channels. It cannot decide whether a particular spreadsheet should be open to an entire department. That decision still belongs to the organization. The software's case is that the people making it should finally have the right file in front of them.