Observability Plane · Data Observability

Sifflet

Data observability platform that combines monitoring, lineage and a data catalogue.

Overview

Sifflet positions itself as a control plane for data and AI, and argues its differentiation openly: detection is table stakes, so the value is in enriching an alert with lineage, downstream usage and ownership.

It covers freshness, volume, schema and distribution across pipelines and dashboards, delivered through monitor templates grouped into table health, metrics, field profiling, format validation and custom checks.

One thing it does better than any competitor here is tell you which checks are learned and which are fixed. Each template is labelled dynamic or static, so volume, freshness and distribution learn a threshold while schema change, uniqueness and referential integrity are rules.

Three named agents run the intelligent parts: Sentinel recommends monitors, Sage does root-cause analysis and Forge suggests fixes. All three work on metadata only, never raw rows, which matters for a security review.

Onboarding leans on Sentinel, which takes a new asset to a fully monitored one in a few clicks, recommending in under thirty seconds, in bulk across up to ten assets, and skipping monitors that already exist.

AI monitoring optimisation is the feature to know about. It watches how your monitors perform and proposes changes to schedule, window and sensitivity, reassessed every 24 hours, though only for the machine-learning templates.

Incident handling is properly built rather than a list of alerts: related failures group into one incident, severity is inherited, assignees can be individuals or whole teams, and every status change is logged for audit.

Deployment is the most flexible in this category. Software as a service by default, an agent in your own network for private sources, or genuine full self-hosting where no data is exchanged with Sifflet at all.

Pricing is by monitored assets across three tiers with no figures published, and note that hybrid and self-hosted deployment are enterprise-only.

Key features and capabilities

The same headings are used for every data observability entry, so two tools can be read side by side.

What it monitors
  • Table health covering volume, freshness, update time gaps, row-level duplicates and schema change
  • Metrics covering aggregated values, custom metrics against history, and divergence between two correlated metrics
  • Field profiling covering distribution change, duplicates, uniqueness, nulls, value lists, ranges and referential integrity
  • Format validation for email, phone, UUID and regular expressions, plus custom SQL and no-code conditions
  • No dedicated job or dashboard monitor template is listed, though a flow stopper can halt pipelines
How incidents are detected
  • Each monitor template is labelled dynamic or static, the clearest published split in this category
  • Volume, freshness, metrics and distribution learn thresholds; schema, uniqueness and value checks are rules
  • Sensitivity is the tuning control, defining how much variation counts as an anomaly, set per monitor
  • AI monitoring optimisation proposes schedule, window and sensitivity changes, reassessed every 24 hours
  • That optimisation applies only to machine-learning templates, not to custom SQL or fixed thresholds
Coverage and onboarding
  • Sentinel takes a new asset to fully monitored in a few clicks, recommending in under thirty seconds
  • Bulk mode handles up to ten assets at once, or every asset in a data product, skipping existing monitors
  • Sentinel uses metadata exclusively, including table importance, usage signals, schema and lineage
  • Monitors as code, a CLI and a Terraform provider for repeatable configuration at scale
  • The agent sends row samples for specific features, and those samples can be disabled
Triage and root cause
  • Related failures group automatically into a single incident based on grouping rules, to limit alert fatigue
  • Severity is inherited from the triggering monitors and shown in both list and detail views
  • Multiple assignees per incident, either individual users or whole teams
  • A status workflow from open through in progress to closed, with every transition logged for audit
  • Sage generates the incident overview and root cause from monitor metadata, asset relationships and dbt run logs
Lineage and impact
  • Field-level lineage alongside table-level, with declarative assets for anything not discoverable
  • Alerts are enriched with upstream lineage, recent schema changes and historical behaviour
  • Downstream BI coverage across Power BI, Tableau, Looker and QuickSight, with MicroStrategy and Qlik in beta
  • A browser extension surfaces data health directly on BI dashboards
  • How lineage is derived technically is not published
Integrations
  • Platforms including Snowflake, BigQuery, Databricks, Redshift, Synapse and Athena, plus databases via the agent
  • dbt Core and dbt Cloud, with GitHub and GitLab for code
  • Orchestrators including Airflow, managed Airflow, Cloud Composer, Databricks Workflows and Fivetran
  • Atlan in beta is the only external catalogue integration published
  • Alerting to email, Slack, Teams, Jira, ServiceNow, PagerDuty, Statuspage and Google Chat, plus a REST API and Terraform
Where it runs and what it costs
  • Software as a service by default, agentless for reachable sources, and available on Snowflake Marketplace
  • An agent for private networks, as a container on Kubernetes, ECS or a virtual machine, outbound HTTPS only
  • Full self-hosting on any compatible Kubernetes including on-premises, with no data exchanged with Sifflet
  • Private links on AWS and Azure, and single sign-on across the usual providers
  • Priced by monitored assets; hybrid and self-hosted deployment are enterprise-only

Pricing

Price on requestQuote only; three tiers by monitored assets

Three tiers, Entry, Growth and Enterprise, priced on monitored assets at up to 500, up to 1,000 and beyond, with no figures published and every route going to sales. All tiers include the core observability, catalogue, lineage, automated root-cause analysis and the agents; Enterprise adds pipeline monitoring, early agent access and the hybrid and self-hosted deployment options. Entry and Growth are available through self-serve marketplaces, and Snowflake credits can be used. A start-free option is advertised but no trial length is reliably published.

Vendor pricing page →

Demos and videos

About Sifflet

Sifflet was founded by Salma Bakouk, its chief executive, with Wissem Fathallah as chief product officer and Wajdi Fathallah as chief technology officer, and is based in Paris with operations across EMEA, the US and Asia Pacific; no founding year is published. It is private, having raised a $12.8m Series A in March 2023 led by EQT Ventures with Mangrove and Bessemer, and a further $18m in June 2025 from EQT and Mangrove plus Capmont Technology, at which point it reported tripling customers and revenue year on year. Its 2025 review published more than 5,000 users, naming Saint-Gobain, Carrefour, BBC Studios and Euronext.

Paris, France · siffletdata.com

Other data observability tools

Bigeye

Observability Plane · Data Observability

Data observability platform with automated monitoring and lineage-based root cause analysis.

  • Commercial

Elementary

Observability Plane · Data Observability

dbt-native data observability, with an open-source package and a cloud platform.

  • Open core

Monte Carlo

Observability Plane · Data Observability

Data observability platform that monitors freshness, volume, schema and quality across the data stack. Now trading as Monte Carlo AI, with montecarlodata.com redirecting, and extended to monitoring AI agents.

  • Commercial

Drafted with AI assistance and checked against the vendor’s own documentation.