Data Governance Plane · Privacy & Compliance

Securiti

Platform for data security, privacy and governance across clouds and SaaS applications. Veeam acquired Securiti in December 2025, and its releases now read Veeam's Securiti AI.

Overview

Securiti positions itself as a command platform for data and AI, built on a knowledge graph that supplies common intelligence to security, governance and privacy disciplines alike.

Its organising idea is a unified controls framework. Rather than being a privacy tool that grew, it was designed as one controls layer on which each discipline runs its own workflows.

Ownership changed and this is the most dating fact about it: Veeam acquired Securiti in December 2025, its releases now read as Veeam's Securiti AI, and its founder now leads product for Veeam.

Its clearest differentiator is that it goes beyond governing AI into helping you build it: data vectorisation and ingestion, curation and sanitisation for training, safe copilots and context-aware firewalls for language models.

Neither of its main rivals publishes a product for building enterprise AI systems, so this is a genuine category difference rather than a marketing gloss.

Those firewalls operate at prompt, retrieval and response level, which is enforcement in the inference path rather than only at the data store.

Its identity correlation equivalent is a people data graph, linking personal data to the individual it belongs to across structured and unstructured sources, with a natural-language interface for querying relationships.

Regulatory coverage is the longest published here by some distance, spanning Europe, the United States, Asia Pacific, the Americas and the Gulf, plus AI-specific frameworks, under a claim of auditing once to comply with many.

It publishes two capabilities its rivals do not: breach impact analysis with automated notification, and an agent commander that can undo actions an AI agent has already taken.

Deployment is unusually flexible for this category, offering both managed service and running inside your own network, with the published rationale that scanning next to the data avoids export cost and leakage risk.

Key features and capabilities

The same headings are used for every privacy & compliance entry, so two tools can be read side by side.

Finding personal data
  • Discovers, classifies and labels hundreds of sensitive elements at petabyte scale
  • Detects both shadow and native data assets across AWS, Azure, Google Cloud and Oracle Cloud
  • Classification combines machine learning, pattern matching and contextual analysis
  • Coverage spans structured, unstructured, SaaS, self-managed and streaming data flows
  • A people data graph links personal data to the individual, queryable through a conversational interface
Consent and subject rights
  • Subject requests run in four stages, intake with identity verification, discovery, fulfilment and secure delivery
  • Discovery uses the people data graph to link personal information to the requester in real time
  • Robotic automation creates and orchestrates fulfilment tasks across data sources
  • A workbench gives a single view of all request activity with dynamic audit logs
  • Cookie consent is Google-certified with support for consent mode and the advertising framework, plus separate mobile consent
Regulations covered
  • The longest published list here, covering Europe, the United States, Asia Pacific, the Americas and the Gulf
  • European coverage includes GDPR, the EU AI Act, DORA, the Data Act, the Data Governance Act and NIS2
  • United States coverage spans CCPA and a dozen state laws, plus HIPAA, GLBA and COPPA
  • AI frameworks including the NIST AI risk framework, ISO 42001 and the OWASP top ten for language models
  • A published claim of auditing once to comply with many, automating more than twenty standards
Risk assessment and reporting
  • Assessment automation covering records of processing, privacy and data protection impact assessments
  • AI risk assessment evaluating models for toxicity, bias, efficiency and copyright
  • A vendor risk module that invites and evaluates third-party privacy risk
  • Breach impact analysis and management, automating notification to individuals and regulators
  • A single assessment repository with dashboards for regulators, boards and internal stakeholders
Controls and remediation
  • Data minimisation identifies redundant, obsolete and trivial data and can quarantine it
  • Retention enforcement through automated detection of data held beyond policy
  • Access intelligence monitors use and enforces least-privilege controls
  • Context-aware firewalls for language models, acting at prompt, retrieval and response level
  • An agent commander that can undo actions an AI agent has already taken, unique among these three
Integrations
  • More than a thousand pre-built connectors claimed, with over 150 named individually in the directory
  • Clouds, warehouses and databases including Snowflake, Databricks, BigQuery, Redshift, Teradata and SAP HANA
  • SaaS coverage including Salesforce, HubSpot, Zendesk, Slack, ServiceNow, Stripe and Shopify
  • Named identity providers including Okta, Auth0, LDAP and Active Directory, which its rivals do not publish
  • REST APIs for scanning and metadata extraction, plus low-code workflows
Where it runs and what it costs
  • Both managed service and running inside your own network, with the rationale published
  • Scanning within your own network avoids data leakage risk and data export costs
  • The managed service runs on AWS and Google Cloud across multiple availability zones, with cross-region backup
  • Certifications include SOC 2 Type II, ISO 27001 and ISO 27701; underlying cloud certifications are not its own
  • Priced by module, procured per use case; a specific region list is not published

Pricing

Price on requestQuote only; free privacy centre trial

Quote-only, and unusually sparse: the pricing page carries a single substantive sentence, that you procure modules based on the use cases you need, plus a request for a personalised quote. No prices, currency, tiers or trial length appear anywhere. A free trial of its privacy centre is published, covering cookie preferences, individual requests, a preference centre, do-not-sell handling and privacy notices, though its duration is not stated. Its self-service purchasing domain no longer resolves, so do not assume a self-serve path exists.

Vendor pricing page →

Demos and videos

About Securiti, part of Veeam

Securiti was founded by Rehan Jalil and is based in San Jose; its own machine-readable summary gives 2019 as the founding year, though the about pages omit it. Veeam acquired the company in December 2025, making it no longer independent, and Jalil now leads products and technology at Veeam; the first integrated product shipped in February 2026. It had raised more than $150m before the acquisition, including a $75m Series C in October 2022 led by Owl Rock, with strategic investment from Capital One, Citi, Cisco and Workday. Its product has been renamed four times in six years, so older names circulate widely.

Founded 2019 · San Jose, California · securiti.ai

Other privacy & compliance tools

BigID

Data Governance Plane · Privacy & Compliance

Data discovery and classification for privacy, security and governance.

  • Commercial

OneTrust

Data Governance Plane · Privacy & Compliance

Privacy, consent and data governance platform for regulatory compliance programmes.

  • Commercial

Drafted with AI assistance and checked against the vendor’s own documentation.