The trouble with a locked door is that it encourages a comforting assumption: everything worth stealing must be behind it. Manmeet Singh and Adrian Booth started Dataguise in Fremont in 2007 with a less comforting idea. The dangerous material might already have been copied into a test database, tucked into a file share, or carried away by an employee on a flash drive. A stronger door would not tell you where the material had gone.
So Dataguise began with a question that sounds almost embarrassingly basic: where is the sensitive data? Its software crawled enterprise repositories, recognized personal and regulated information, and presented a map. Then it did something useful with the answer - masking fields, encrypting values, checking access, and watching for suspicious activity. The company was selling security, but the first product was really visibility.
A copy of the truth becomes a liability
The early products had refreshingly literal names. dgdiscover searched networks and databases for sensitive fields. dgmasker replaced the identifying values so production-shaped data could be used in development, testing, and analytics without dragging real people along with it. In 2009, Dataguise said customers included Amgen, Facebook, John Muir Hospital, and the University of California, Berkeley.
The problem was mundane and therefore enormous. Large organizations clone production databases constantly. A team wants realistic records for quality assurance; another wants a representative dataset for analysis. Every copy multiplies the places where a name, Social Security number, diagnosis, or card number can escape. Masking preserved the format and relationships that software expected while removing the identity a thief wanted.
“We first discover the data and tell you where it’s located on the network.”Manmeet Singh, co-founder
That sequence became the durable Dataguise playbook. Do not begin with the lock. Begin with the inventory. A policy can then classify what it finds as PII, payment data, or health information and choose the response: mask it, encrypt it, restrict it, monitor it, or delete it.
The first wall was not technical. It was financial.
Singh and Booth initially used their own money. Then customers asked the product to work across Oracle, DB2, Teradata, SQL Server, and the long tail of enterprise storage. Connector breadth was not a feature the founders could fake with a clever demo. Each system brought its own structure, permissions, and peculiarities. Singh later described the moment plainly: the company had “hit a wall.”
Dataguise raised roughly $3.2 million in 2011 from Herb Madan and other friends-and-family backers. In September 2013, it closed a $13 million Series B led by Toba Capital, with additional money from the investment arm of an unnamed electronics conglomerate. The budget was intended for sales, marketing, channels, support, and DgSecure development. The acquisition price seven years later was never disclosed.
The 2013 Series B bought runway for global distribution and a broader DgSecure platform. It did not buy the 2020 acquisition - that price remains private.
Hadoop made the map bigger
The timing placed Dataguise directly in the Hadoop boom. Businesses were pouring information into vast clusters built on Cloudera, Hortonworks, and MapR. The enthusiasm for collecting data ran ahead of the discipline for governing it. DgSecure scanned those environments, identified sensitive elements, and applied policy-based masking or encryption without demanding that customers write a custom protection application.
Partnerships mattered because enterprise data rarely lives in one vendor’s neat universe. Dataguise certified integrations across Hadoop distributions and worked with Teradata, Thales, cloud platforms, and key-management systems. Its pitch widened from “database masking” to one view of structured, semi-structured, and unstructured information, on premises and in public cloud.
The dashboard is the most revealing artifact of the company’s thinking. It did not merely count protected records. It showed exposed, monitored, and unscanned assets together. That last category is the corporate-security equivalent of writing “we do not know” in a board report. It is also more honest than a green checkmark.
The makeover changed the destination
By early 2020, Dataguise planned to refresh its brand for a final funding round. The design firm Mitosis audited the market and explored the SaaS product. It found enough challenges that the assignment changed. Instead of dressing the company to raise another round, the team positioned it to attract an acquirer. Less than nine months after the engagement began, PKWARE announced the purchase on November 10.
This was not a random roll-up. PKWARE descended from the ZIP file and had decades of experience compressing and encrypting information. Dataguise knew how to find and classify the sensitive pieces scattered across modern systems. One company owned the lock; the other knew which drawers to open. The combined proposition could move from discovery to remediation without handing the customer from one console to another.
Founded around insider risk and sensitive-data visibility.
dgdiscover and dgmasker join finding with de-identification.
A $13 million Series B funds the DgSecure expansion.
Continuous monitoring and a governance dashboard arrive.
PKWARE acquires Dataguise for an undisclosed sum.
The technology becomes part of PK Protect.
A product survives its logo
Dataguise no longer operates as a standalone brand. Its LinkedIn page points to PKWARE, and the old product family has been consolidated into PK Protect. Yet the original logic remains visible. The current platform discovers and classifies data across endpoints, cloud systems, Microsoft 365, databases, data lakes, and mainframes, then applies encryption, masking, redaction, quarantine, deletion, and audit policies.
The buyers are the teams whose mistakes become reportable events: banks, healthcare providers, retailers, government agencies, and other regulated enterprises. PKWARE said the combined company served more than 1,000 customers globally after the deal. The business is enterprise software - licensed or subscription access, partner-led integrations, and sales cycles built around compliance, risk, and infrastructure complexity.
Its alternatives are not only named rivals such as IBM Guardium, Imperva, Informatica, Protegrity, or Voltage. The real competitor is fragmentation: one tool that finds records, another that masks a database, a third that encrypts files, and a spreadsheet attempting to prove it all happened. Dataguise’s distinction was to shorten the distance between evidence and action.
What another team can copy
- Measure unknown coverage. “Unscanned” is a decision-making metric, not an embarrassment to hide.
- Sequence the work: discover, classify, protect, then monitor. Encryption without inventory leaves blind spots.
- Preserve usefulness when masking. Testers need realistic formats and relationships, not real identities.
- Integrate where data already lives. The method weakens when connector coverage is shallow or policies cannot trigger remediation.
- Know when the financing story has become a strategic-fit story. Dataguise changed its 2020 objective when the audit changed the evidence.
There is a limit to the lesson. Dataguise’s approach made the most sense for organizations with sprawling repositories, regulated information, and enough operational maturity to define classification and access policies. A small company with one well-contained database may not need an enterprise discovery platform. A large company that cannot agree on ownership will discover plenty and remediate little. The software can expose ambiguity; it cannot chair the meeting that resolves it.
Still, the company’s central observation has aged well. Every new cloud bucket, collaboration suite, analytics pipeline, and AI assistant increases the number of places sensitive data can travel. The perimeter keeps moving. The first practical question remains the one Dataguise asked in 2007: before you promise the data is safe, can you show where it is?