Automated PII & PCI masking platform that transforms production databases into safe, realistic copies for development, testing, and analytics—without exposing sensitive customer data.
Production databases are goldmines for development and testing, but sharing them creates massive compliance and security risks.
Sharing real customer names, emails, SSNs, credit cards across teams exposes you to GDPR, HIPAA, and PCI-DSS violations with severe penalties.
Hand-coding SQL scripts to mask PII is error-prone, time-consuming, and breaks every time your schema changes.
Production data in dev environments means broader access, weaker controls, and higher breach risk, one leak can cost millions.
Teams wait weeks for sanitized test data, slowing releases and preventing realistic testing with production-quality datasets.
From database connection to obfuscated data in 7 simple steps—no manual scripting required.
Add source and destination database connections. DataShield validates connectivity and securely stores encrypted credentials.
Auto-detect PII and PCI fields across your entire schema. DataShield reflects tables, columns, relationships, and flags sensitive data.
Adjust auto-detected classifications. Override any field's classification or add custom sensitive columns as needed.
Select tables, set row limits, apply date filters, exclude columns. Choose realistic or masked mode. Save as reusable profile.
Run dry-run to preview exact row counts and validate your configuration before committing to the full obfuscation job.
Start the job and monitor real-time progress. DataShield processes data in parallel batches while preserving all foreign keys.
Compare source and obfuscated data side-by-side in browser. Verify results and hand off clean database to your team.
Built for production workloads with security, performance, and developer experience at the core.
No manual tagging. DataShield scans your schema and auto-detects sensitive fields with 85-90% confidence scores.
Choose between realistic or masked data based on your use case.
Foreign key relationships stay intact across your entire database—your data works just like production.
You decide exactly what gets obfuscated with surgical precision.
Preview exact row counts before committing to potentially hours-long jobs.
Track every discovery and obfuscation job with live telemetry.
Compare source and obfuscated data in browser—no database client needed.
Connect to virtually any relational database your organization uses.
Built with security as a first principle, not an afterthought.
From engineering to compliance, DataShield empowers teams to work with production-quality data safely.
Safe dev/test databases without production PII. Develop against realistic data that mirrors production volume and complexity.
Realistic test data matching production schema and volume. Run comprehensive tests without compliance risk.
Anonymized datasets for BI reporting and analysis. Explore production patterns without exposing customer identities.
Demonstrate PII/PCI controls for GDPR, HIPAA, PCI-DSS audits. Show auditors your non-production data is properly masked.
Connect to the databases your organization already uses—no migration required.
Two ways to use DataShield — choose what works best for your team.
Hosted by LagrangeDATA. Try DataShield with no setup required.
No credit card required
Note: Database must be publicly accessible
Try DataShield FreeDeployed in your environment. Your data never leaves your infrastructure.
Billed annually upfront
Discount: Our customers receive discounts off Year 1 in exchange for a case study and product feedback.
Multi-year discounts available. Contact us to discuss.
Everything you need to know about DataShield
No. DataShield only reads the schema (table and column names, data types, relationships) during discovery. During obfuscation, data is read from your source database and written directly to your destination database. No data passes through or is stored on DataShield's servers. On the Self-Hosted tier, everything runs entirely within your own infrastructure.
PostgreSQL, MySQL / MariaDB, Microsoft SQL Server, Oracle Database, and SQLite. AWS RDS IAM authentication is available for PostgreSQL and MySQL on the Self-Hosted tier.
No. The Cloud tier requires your database to be publicly accessible because DataShield's hosted servers need network access to connect. For private, VPC-hosted, or on-premise databases, the Self-Hosted tier is required.
The license covers one deployment (one organization). The annual fee provides access to the software, updates, and support for the license period. Run DataShield in your own environment with no usage-based metering and no dependency on vendor callbacks, under a standard annual license.
Your deployment continues to function. You will no longer receive software updates or priority support until the license is renewed.
Yes — contact us to discuss multi-year pricing.
Our customers receive discounts off Year 1 Pricing, in exchange for a case study and product feedback. Contact us to enquire.
Start masking production data in minutes. No credit card required for trial.