The most revealing number in Ohalo's history is not 950 million, the file count the company says its software has secured. It is 19. In a 2020 evaluation with Britain's Health and Safety Executive, Data X-Ray automatically anonymised a sample of accident reports. Of 743 records containing sensitive text, 724 were adequately anonymised. Nineteen still held enough information to pose a significant breach risk.
That is a 97 percent reduction, which sounds excellent in a pitch deck and insufficient in a privacy office. The final dataset could not be called fully anonymised. Some names were caught in one sentence and missed in another. Health-and-safety language was new to the software. Context, as usual, was the expensive part.
Here is why the episode matters. Ohalo did not merely count the miss and move on. HSE data scientists reviewed false positives and unredacted details, supplied examples and updated the models. The test added context-specific anonymisation and better entity association. Automation became a loop with domain experts, not a trapdoor through which responsibility disappeared.
A metal detector for the shared drive
Founded in 2017 by CEO Kyle DuPont and CTO Alistair Jones, London-headquartered Ohalo sells enterprise software for unstructured data: documents, emails, scans, images and the miscellany living in SharePoint, file shares, cloud buckets and legacy repositories. Its flagship platform, Data X-Ray, connects to those systems, inventories the files, examines their content and permissions, classifies what it finds and helps teams act on it.
The sequence is practical. Discover the estate. Annotate sensitive passages and technical metadata. Categorize contracts, invoices or regulatory correspondence. Extract useful fields. Protect, redact, archive or delete what policy requires. Monitor the result. The output can flow into products an enterprise already owns, including Collibra catalogs, Microsoft Purview controls, Thales security tooling and Virtru's file-level encryption.
This makes Ohalo less a replacement for the governance stack than a content-intelligence layer underneath it. A traditional catalog may know that a file exists and who owns the folder. Data X-Ray tries to understand whether the file is a contract, whether it contains personal information, whether an open sharing link exposes it and which policy should follow. It combines regular expressions and dictionaries with OCR, named-entity recognition, machine learning and large language models. The mix matters because a passport number behaves like a pattern; an ambiguous legal document behaves like language.
An inventory is useful. Context makes it governable. Automated, reviewed action is where the economic value appears.
The buyer has a deadline and a headache
Ohalo's natural customers are not small teams shopping for a clever search bar. They are privacy, security, legal, records, data and AI leaders inside large regulated organizations. The trigger is usually unpleasant: a divestiture, a data-subject request, a retention deadline, a cloud migration, an audit or a generative-AI project that suddenly wants access to years of documents.
One company-described case involved a global financial institution separating an $8 billion business. Regulators required the bank to identify sensitive correspondence across more than 19 million files within two months. The alternative was a projected army of more than 300 consultants. Ohalo says Data X-Ray classified the initial set, expanded across as many as 330 million files and saved $22 million. The customer is unnamed, so those figures deserve the label they carry: company-reported. The operational idea is still clear. Rules made for the emergency could be reused for normal retention, audit and privacy work.
“The compliance issue merged with security. We realized the core issue wasn't just regulatory, it was that companies didn't understand their data.”Kyle DuPont, co-founder and CEO
The named proof is Suncor Energy. Its estate contained about 110 million files across multiple sources and several petabytes. Ohalo and Suncor ran workshops with security, privacy, data custodians and other stakeholders before automating discovery and classification in OpenText Livelink. The case study says the broader program was expected to save millions through disposition, lower storage, automated privacy work and reduced software costs. The workshops are the unflashy clue: classification policy is partly software and partly an argument among humans about what the business means.
What it cost - and what changed
Ohalo does not publish current list pricing. The cleanest public cost marker is the 2019 Safetytech Accelerator challenge, which provided a three-month pilot worth £25,000 in research time. Ohalo put a Data X-Ray server inside HSE's environment and worked against RIDDOR accident reports. A later account says the project processed 600,000 records in 1.4 days with 99 percent accuracy, compared with an estimated 12.5 years of manual work.
The smaller formal evaluation supplies the caveat: even a large reduction in risk leaves residual risk. Complete anonymisation was not expected in every case. Contracts, access controls, reviewer checks and other safeguards still mattered. This is the condition under which Ohalo's approach works best - the scanner reduces an impossible review problem to a manageable exception queue, and accountable people decide what happens next.
What failed first
Context-specific names and entity relationships. The fix was not a universal accuracy slogan. HSE reviewers marked false positives and misses, added training examples and improved the next pass. If nobody can review the exceptions, the loop breaks.
What changed Ohalo's framing was broader than one pilot. DuPont has described compliance and security converging around a more basic problem: companies do not understand their own data. Generative AI sharpened that problem. A retrieval system can expose an over-permissioned document faster than a human ever could. Ohalo consequently moved beyond its early GDPR-scanning wedge toward data access governance, AI readiness and attribute-based controls. In DuPont's formulation, the new perimeter is the identity and the data that identity can access.
The playbook worth stealing
Pick expensive disorder
Ohalo chose workflows where manual review takes years, deadlines are real and an error has regulatory consequences.
Start inside the boundary
Agentless, container-based and self-hosted options reduce resistance in hybrid, on-premise and air-gapped environments.
Sell the correction loop
Let customer experts mark mistakes and turn edge cases into classifiers. Trust grows from visible control, not mystery.
Join the existing stack
Send intelligence into catalogs and security tools already budgeted. A useful missing layer beats a rip-and-replace crusade.
Ohalo's business model follows the enterprise problem: demo-led software contracts, negotiated deployments, implementation support, custom connectors and partner distribution. YFM Equity Partners and existing investors put $3.5 million of growth capital into the company in 2024 to support international expansion. Ohalo operates from London with offices in Atlanta and Calgary, and publicly names HSE, Suncor, the UK Home Office, Wood and Costain among its customers or working relationships.
The competitive field is crowded. BigID, Varonis, Securiti, Cyera, Concentric AI, Spirion and native Microsoft capabilities approach discovery, data-security posture, classification or privacy from adjacent positions. Ohalo's distinction is the combination: unstructured content rather than database-first governance; deployment into awkward secure environments; custom connectors; contextual classification; and a route from detection to redaction, retention or access enforcement.
That integration strategy is also a sales strategy. Catalog vendors and security platforms already have executive sponsors, procurement history and trained users. Ohalo can arrive as the specialist that fills their blind spot instead of asking a bank to discard years of work. Its partner program gives consultants and resellers another service to deliver, while custom connectors make difficult legacy systems a feature of the engagement rather than a reason to postpone it. The tradeoff is dependence on long enterprise buying cycles and careful implementation. A product that touches permissions, retention and deletion cannot rely on a five-minute self-serve onboarding trick.
When the X-ray is unnecessary
Do not copy this model merely because every pitch now contains “AI readiness.” It is a poor fit when the corpus is small, ordinary search already finds the relevant material, the organization cannot express a policy, or nobody has authority to remediate what the system flags. Sophisticated classification can produce an exquisite map of a fire that no team is empowered to extinguish.
It also does not remove the need for controls outside the model. Ohalo and Virtru, for example, include a dry-run mode before mass encryption. That is a telling feature. Automated action at enterprise scale can create its own disaster if classification, identity attributes or recovery procedures are wrong. Preview, sample, review and stage the rollout. The faster the machine, the more valuable the brake.
Ohalo fits a market moving from periodic compliance exercises toward continuous knowledge of file content and access. Its product can reduce search and review work, prepare safer corpora for AI, improve migrations and attach governance context to documents. But its best lesson is smaller and more portable: find a painful workflow, measure the miss honestly, give experts a way to correct it, and make the correction reusable. Nineteen risky records did more to explain the company than a perfect score ever could.