Alternatives to Brainwave GRC
Compare Brainwave GRC alternatives for your business or organization using the curated list below. SourceForge ranks the best alternatives to Brainwave GRC in 2026. Compare features, ratings, user reviews, pricing, and more from Brainwave GRC competitors and alternatives in order to make an informed decision for your business.
-
1
Josys
Josys
Josys is a modern AI-native identity security and governance platform. Enterprise AI adoption has made identity the fastest-growing attack surface — and the hardest to govern. Josys discovers, governs, and secures every identity - human, machine, and AI agent - across every application in the enterprise. Built on policy-led governance, Josys lets security and IT teams define access policies once and enforce them autonomously: risk is surfaced, access is controlled, and identity threats are remediated in real time, without manual oversight. Trusted by over 1,000 organizations and MSPs worldwide, Josys turns identity from the fastest-growing attack surface into an autonomously governed advantage. For more information, visit josys.com. -
2
SailPoint
SailPoint Technologies
You can’t do business without technology and you can’t securely access technology without identity security. In today’s era of “work from anywhere”, managing and governing access for every digital identity is critical to the protection of your business and the data that it runs on. Only SailPoint Identity Security can help you enable your business and manage the cyber risk associated with the explosion of technology access in the cloud enterprise – ensuring each worker has the right access to do their job – no more, no less. Gain unmatched visibility and intelligence while automating and accelerating the management of all user identities, entitlements, systems, data and cloud services. Automate, manage and govern access in real-time, with AI-enhanced visibility and controls. Enable business to run with speed, security and scale in a cloud-critical, threat-intensive world. -
3
IRI Voracity
IRI, The CoSort Company
Voracity is the only high-performance, all-in-one data management platform accelerating AND consolidating the key activities of data discovery, integration, migration, governance, and analytics. Voracity helps you control your data in every stage of the lifecycle, and extract maximum value from it. Only in Voracity can you: 1) CLASSIFY, profile and diagram enterprise data sources 2) Speed or LEAVE legacy sort and ETL tools 3) MIGRATE data to modernize and WRANGLE data to analyze 4) FIND PII everywhere and consistently MASK it for referential integrity 5) Score re-ID risk and ANONYMIZE quasi-identifiers 6) Create and manage DB subsets or intelligently synthesize TEST data 7) Package, protect and provision BIG data 8) Validate, scrub, enrich and unify data to improve its QUALITY 9) Manage metadata and MASTER data. Use Voracity to comply with data privacy laws, de-muck and govern the data lake, improve the reliability of your analytics, and create safe, smart test data -
4
SecurEnds
SecurEnds
SecurEnds cloud software enables the world’s most forward-thinking companies to automate: User Access Reviews, Access Certifications, Entitlement Audits, Access Requests, and Identity Analytics. Load employee data from a Human Resources Management System (e.g., ADP, Workday, Ultipro, Paycom) using built-in SecurEnds connectors or files. Use built-in connectors and flex connectors to pull identities across enterprise applications (e.g., Active Directory, Salesforce, Oracle), databases (e.g., SQL Server, MySQL, PostreSQL), and cloud applications (e.g., AWS, Azure, Jira). Perform user access reviews by role or attribute as frequently as needed. Application owners can use delta campaigns to track any changes since the last campaign. Send remediation tickets directly to application owners to perform access updates. Auditors can also be granted access to review dashboards and remediations. -
5
Kelltron IAM Suite
Kelltron
Kelltron’s IAM Suite is an AI-powered identity security platform that unifies Identity & Access Management (IAM), Privileged Access Management (PAM), and Data Governance (DGM) into one seamless solution. It enables secure user provisioning, Single Sign-On (SSO) to 4,000+ apps, adaptive Multi-Factor Authentication (MFA), and role-based access control. PAM features include just-in-time access, session monitoring, and credential vaulting to safeguard privileged accounts. The DGM module helps discover, classify, and enforce data access policies for compliance with GDPR, ISO 27001, and more. Designed for hybrid IT environments, Kelltron offers cloud, on-prem, and multi-tenant deployment. AI-driven automation reduces manual workload by flagging anomalies, suggesting least-privilege access, and generating real-time risk insights. With 24/7 support and a 6-month free trial, Kelltron empowers businesses and MSPs to scale securely with full visibility and control. -
6
QoreAudit
Coginov
Take full control of your information assets with the QoreAudit solution. QoreAudit is a powerful tool that provides your organization with a complete view of your information inventories. You will now be able to effectively manage the information you create, acquire, and distribute at any time. QoreAudit conducts a thorough inventory of all your information and data, including, but not limited to, documents, emails, web content, etc. QoreAudit then provides the most relevant information you need to make informed decisions in your organization. QoreAudit accurately identifies high-risk or high-value information in your documents regardless of the physical location of your information assets. QoreAudit analyzes, contextualizes, classifies, and categorizes information to create a complete picture of your information inventory. QoreAudit provides a dynamic dashboard that identifies duplicate documents and files (approx. 14% on average). -
7
Bravura Identity
Bravura Security
Bravura Identity is an integrated solution for managing identities, groups and security entitlements across systems and applications. It ensures that users are granted access quickly, that entitlements are appropriate to business need and that access is revoked once no longer needed. Users have too many login IDs. A typical user in a large organization may sign into 10 to 20 internal systems. This complexity creates real business problems. Bravura Identity manages the lifecycles of identities, accounts, groups and entitlements. It includes automation to grant and revoke access, after detecting changes on systems of record. A web portal for access requests, profile updates and certification. Full lifecycle management for groups and roles on target systems. A workflow manager to invite people to approve requests, review access or complete tasks. Policy enforcement related to SoD, RBAC, risk scores, privacy protection and more. Reports, dashboards and analytics. -
8
PingDataGovernance
Ping Identity
Digital transactions and data are exploding, but authorization logic is scattered across your enterprise. Updating, auditing and managing that logic can be tedious or even impossible. PingDataGovernance provides centralized authorization policies that can evaluate identity attributes, entitlements, consents, the requesting app or other contextual information to authorize critical actions and the retrieval of high-value data. You’ll have the agility to react instantly without sacrificing security or regulatory compliance. Anyone can update policies in minutes with a simple drag-and-drop UI. And you can choose which teams it’s most appropriate to give access to so they can manage policies—or any portion of them. Unlike traditional role-based access control (RBAC), dynamic authorization assembles key contextual data attributes and evaluates the validity of access requests in real time. This lets you centrally enforce policies to comply with regulatory requirements. -
9
Netwrix Access Analyzer
Netwrix
Netwrix Access Analyzer is a data protection solution designed to provide visibility and control over sensitive data across IT environments. It helps organizations discover and classify sensitive information across on-premises and cloud systems. The platform identifies access risks and highlights excessive or outdated permissions. It enables organizations to enforce least-privilege access to reduce the risk of data breaches. Netwrix Access Analyzer also automates governance processes to minimize manual effort. The solution supports compliance by generating audit-ready reports quickly. It provides insights into user activity and access patterns across multiple data sources. Overall, it helps organizations strengthen data security and maintain better control over their information.Starting Price: $10.00/one-time/user -
10
Tenable One Cloud Exposure CIEM
Tenable
Tenable One Cloud Exposure CIEM is a cloud infrastructure entitlement management solution designed to help organizations reduce identity and access risks in public cloud environments. The platform helps security teams identify and remove exposures caused by overly permissive access, excessive permissions, risky identities, and unmanaged entitlements. As part of Tenable’s unified CNAPP, it supports cloud adoption while helping organizations achieve least privilege at scale. Tenable One Cloud Exposure CIEM provides capabilities for access management, entitlement orchestration, risk assessment, automated remediation, just-in-time access, threat exposure, and compliance maintenance. The solution helps teams understand which identities and permissions create the greatest risk to cloud infrastructure. Tenable One Cloud Exposure CIEM is built to help organizations secure cloud environments by reducing identity-based attack paths and improving control over cloud entitlements. -
11
LinuxGuard
LinuxGuard
LinuxGuard is a Linux-native Identity & Access Management platform that maps every identity, privilege path, and access relationship across Linux fleets in real time, surfacing risks that SIEM and EDR tools miss. It inventories every user, group, SSH key, sudo rule, PAM config, and service account, mapping multi-hop escalation routes to root. Each account receives a 0-100 risk score. Non-Human Identities are classified with ownership mapping. The platform generates MITRE ATT&CK-mapped findings, detects configuration drift against approved baselines, and analyzes SELinux policy continuously. Automated response locks accounts, disables SSH keys, and revokes sudo, gated by approval thresholds with auto-rollback. Compliance scoring covers NIS2, DORA, SOC 2, CIS, NIST, PCI-DSS, ISO 27001, and HIPAA with exportable evidence packs. An eBPF agent delivers 1.2-second change detection. Integrates with Splunk, Jira, Slack, and Microsoft Teams. -
12
Visual Identity Suite
Core Security (Fortra)
As part of the Core Security Identity Governance and Administration portfolio of solutions, previously offered by Courion, Visual Identity Suite (VIS) empowers organizations to see user privileges and access certifications in a whole new way, leveraging an intelligent, visual-first approach. By providing an easy-to-use graphical interface, you can see common user entitlements and quickly identify outliers to make informed decisions about who has access to what. VIS enables you to visualize what access looks like in your business, so you can intelligently mitigate identity risk and manage identity chaos within your organization. Mitigating identity risk in your organization requires intelligent and visible identity governance across all of your environments. This means leveraging a visual-first approach for the creation and management of roles and access reviews, combined with intelligence-enabled context, to simplify your identity governance and administration processes. -
13
Kriptos
Kriptos
Kriptos is an AI & Data Governance Platform for unstructured data. It automatically discovers, classifies, and labels sensitive and business-critical documents across endpoints, servers, and cloud storage. Unlike traditional security tools that only detect PII, Kriptos analyzes the 72% of enterprise documents that contain no PII but hold the most critical data — product roadmaps, financial models, board presentations, and trade secrets. The platform integrates as an AI intelligence layer that enriches existing DLP, CASB, SIEM, EDR, and IAM tools, adding context-aware risk scores and enabling access governance based on real business risk. Key capabilities include: automated data discovery, multi-AI classification, intelligent labeling, UEBA, insider threat management, compliance support (ISO 27001, GDPR, LOPDP), and secure AI adoption governance. Deploy in minutes with no infrastructure changes.Starting Price: Custom pricing — contact sales -
14
Steward
Steward
Steward is an end-to-end onboarding and Know Your Customer (KYC) platform built for an AI age that streamlines the entire verification process from identity capture through automated checks. The platform integrates a smooth digital workflow including document capture, face-match, liveness detection and identity verification, with AI-driven decisioning and risk-scoring that adapt in real time to changing regulations and threats. It supports multi-jurisdictional compliance, automates sanctions and watch-list screening, and triggers alerts and case management workflows when higher-risk scenarios emerge, helping firms scale due-diligence without manual-intensive review. The system features APIs and embeds easily into existing customer-facing journeys, reducing drop-off and improving conversion, while giving compliance teams a unified dashboard to monitor status, audit trails and risk metrics. -
15
Cross Identity
Cross Identity
Cross Identity is a converged Identity and Access Management (IAM) platform designed to eliminate the security and complexity risks caused by traditional IAM point solutions. It unifies Access Management, PAM, IGA, CIEM, ISPM, and ITDR into a single, purpose-built architecture with shared genetics. By removing stitched integrations and fragile connectors, Cross Identity dramatically reduces attack surface and operational failure points. The platform delivers advanced risk intelligence through its OneBrain™ and Warchief™ engines, providing real-time user, application, and entitlement risk scoring. Cross Identity enables organizations to strengthen their security posture from day one while simplifying implementation and long-term maintenance. It is built to meet modern threat vectors without introducing new system complexity or downtime. -
16
Linx Security
Linx Security
Linx Security is an AI-native identity security and governance platform designed to give organizations full visibility and control over the entire identity lifecycle. It enables teams to map, monitor, and manage all identities, including human and non-human, across applications, cloud environments, and on-prem systems, helping reduce blind spots and shrink the identity attack surface. It provides a unified system that connects identity, security, and IT operations, allowing them to manage access, enforce policies, and maintain compliance from a single place. Using AI-powered analytics, Linx continuously analyzes identity relationships, entitlements, and access patterns to detect risks, anomalies, and gaps such as dormant accounts, excessive privileges, weak authentication, or missing security controls. It includes features like identity security posture management, just-in-time access, and lifecycle automation, enabling organizations to replace standing privileges. -
17
Dymium
Dymium
Dymium is the real-time data governance layer that ensures AI agents, applications, and analytics only access the precise information they’re permitted to see. Powered by its Ghost Layer architecture, Dymium evaluates every request as it happens, enforcing identity-, role-, and context-aware policies instantly. Sensitive data never needs to be copied, staged, or broadly exposed—access is governed directly at the source through GhostDB, GhostAPI, and GhostMCP. This enables teams to work at inference speed without creating compliance or security risk. Every interaction is logged and auditable in real time, supporting GDPR, HIPAA, and AI Act requirements by default. With Dymium, organizations unlock more data safely while eliminating over-permissioning, data duplication, and operational bottlenecks. -
18
Unity Catalog
Databricks
Databricks Unity Catalog is the industry’s only unified and open governance solution for data and AI, built into the Databricks Data Intelligence Platform. With Unity Catalog, organizations can seamlessly govern both structured and unstructured data in any format, as well as machine learning models, notebooks, dashboards, and files across any cloud or platform. Data scientists, analysts, and engineers can securely discover, access, and collaborate on trusted data and AI assets across platforms, leveraging AI to boost productivity and unlock the full potential of the lakehouse environment. This unified and open approach to governance promotes interoperability and accelerates data and AI initiatives while simplifying regulatory compliance. Easily discover and classify both structured and unstructured data in any format, including machine learning models, notebooks, dashboards, and files across all cloud platforms. -
19
IRI Data Protector Suite
IRI, The CoSort Company
The IRI Data Protector suite contains multiple data masking products which can be licensed standalone or in a discounted bundle to profile, classify, search, mask, and audit PII and other sensitive information in structured, semi-structured, and unstructured data sources. Apply their many masking functions consistently for referential integrity: IRI FieldShield® Structured Data Masking FieldShield classifies, finds, de-identifies, risk-scores, and audits PII in databases, flat files, JSON, etc. IRI DarkShield® Semi & Unstructured Data Masking DarkShield classifies, finds, and deletes PII in text, pdf, Parquet, C/BLOBs, MS documents, logs, NoSQL DBs, images, and faces. IRI CellShield® Excel® Data Masking CellShield finds, reports on, masks, and audits changes to PII in Excel columns and values LAN-wide or in the cloud. IRI Data Masking as a Service IRI DMaaS engineers in the US and abroad do the work of classifying, finding, masking, and risk-scoring PII for you. -
20
MetaPrivacy
MetaCompliance
The management of data protection processes, assets, and external parties has become much more important within modern organizations. Simply being able to identify what personal data is being processed within an organization is a significant challenge given legacy systems and the complexity of information stores. MetaPrivacy is a proven privacy lifecycle management system that provides the key automation to help organizations visualize and manage their data processing over time. The solution provides out-of-the-box functionality that allows customers to quickly obtain value without extended periods of consultancy and configuration. Identify, manage and mitigate risk through a risk register and task management module. Access GDPR policies and guidelines within the system and complete related assessments. Demonstrate GDPR and privacy compliance to your national regulatory body. -
21
BeyondTrust Pathfinder
BeyondTrust
BeyondTrust Pathfinder offers a comprehensive identity-centric security platform designed to protect enterprises from privilege-based attacks by delivering visibility, control, and governance across human and non-human identities, credentials, and access paths. At the core is the Pathfinder Platform, which dynamically maps paths to privilege across endpoints, servers, clouds, IdPs, SaaS, and databases, exposing hidden over-privileged accounts, orphaned identities, and attack vectors. Other key components include Identity Security Insights for unified detection and risk-based prioritization of identity threats, Password Safe to discover, vault, manage and audit privileged credentials and session activity, Privileged Remote Access for secure, rule-based access with full session monitoring, Entitle for automating cloud permissions and just-in-time access, Endpoint Privilege Management for enforcing least-privilege on endpoints with application control and file-integrity monitoring. -
22
Prosperoware CAM
Prosperoware
CAM fixes the challenges, mitigates the risks, and reduces the costs of using multiple collaboration systems, making it easier to provision, classify, protect, move and minimize data for project & relationship-based organizations. CAM streamlines the process of managing & governing data, making it accessible, secure and compliant. CAM minimizes the chaos of data spread across systems, making it easier for users to place documents in the right place and for risk management teams to understand context. Quickly provision Teams, Channels, workspaces, folders, & documents automatically or through a human workflow across systems. Apply rich metadata to help end users locate data & risk management teams to understand document context. Gain naming templates to create standardized naming for different groups and teams. Transform the way you protect your data. Manage internal & external users and groups across systems, assign relevant roles and permissions, & grant permissions or restrictions. -
23
Okera
Okera
Okera, the Universal Data Authorization company, helps modern, data-driven enterprises accelerate innovation, minimize data security risks, and demonstrate regulatory compliance. The Okera Dynamic Access Platform automatically enforces universal fine-grained access control policies. This allows employees, customers, and partners to use data responsibly, while protecting them from inappropriately accessing data that is confidential, personally identifiable, or regulated. Okera’s robust audit capabilities and data usage intelligence deliver the real-time and historical information that data security, compliance, and data delivery teams need to respond quickly to incidents, optimize processes, and analyze the performance of enterprise data initiatives. Okera began development in 2016 and now dynamically authorizes access to hundreds of petabytes of sensitive data for the world’s most demanding F100 companies and regulatory agencies. The company is headquartered in San Francisco. -
24
ManageEngine AD360
Zoho
AD360 is an integrated identity and access management (IAM) solution for managing user identities, governing access to resources, enforcing security, and ensuring compliance. From user provisioning, self-service password management, and Active Directory change monitoring, to single sign-on (SSO) for enterprise applications, AD360 helps you perform all your IAM tasks with a simple, easy-to-use interface. AD360 provides all these functionalities for Windows Active Directory, Exchange Servers, and Office 365. With AD360, you can just choose the modules you need and start addressing IAM challenges across on-premises, cloud, and hybrid environments from within a single console. Easily provision, modify, and deprovision accounts and mailboxes for multiple users at once across AD, Exchange servers, Office 365 services, and G Suite from a single console. Use customizable user creation templates and import data from CSV to bulk provision user accounts.Starting Price: $595.00 / year -
25
OvalEdge
OvalEdge
OvalEdge is a cost-effective data catalog designed for end-to-end data governance, privacy compliance, and fast, trustworthy analytics. OvalEdge crawls your organizations’ databases, BI platforms, ETL tools, and data lakes to create an easy-to-access, smart inventory of your data assets. Using OvalEdge, analysts can discover data and deliver powerful insights quickly. OvalEdge’s comprehensive functionality enables users to establish and improve data access, data literacy, and data quality.Starting Price: $1,300/month -
26
Systnaps
Systnaps
The regulatory context of data security is constantly evolving, it is essential to implement a flexible and responsive solution within its IS to meet the complex requirements related to regulations and laws. Classify and categorize regulatory data. Inventory your data and manage retention periods. Respond quickly to requests from your data subjects. Manage hold times and business requirements for all of your master processes through a single application. Management of rules related to retention periods. Regulatory compliance of an Information System (retention period). Classify and calculate the level of data vulnerability. Model your service-oriented objects in order to inventory your IS assets. -
27
Whistic
Whistic
The best way to assess, publish, and share vendor security information. Automate vendor assessments, share security documentation, and create trusted connections—all from the Whistic Vendor Security Network. Once companies start using Whistic, they can’t imagine how they managed vendor security assessments or responded to questionnaire requests before. Avoid the black box security reviews of the past by openly sharing vendor security requirements and publishing profiles. Focus on establishing trust rather than chasing down spreadsheets. Initiate assessments, assign inherent risk, engage vendors, calculate risk scores and trigger reassessments—automatically. In the fast-paced business environment we’re living in, no one has time for the slow, outdated security review processes of the past. Access the security posture of thousands of businesses immediately with Whistic. -
28
Microsoft Entra
Microsoft
Confidently enable smarter, real-time access decisions for all identities across hybrid, multicloud, and beyond. Safeguard your organization by protecting access to every app and every resource for every user. Effectively secure every identity including employees, customers, partners, apps, devices, and workloads across every environment. Discover and right-size permissions, manage access lifecycles, and ensure least privilege access for any identity. Keep your users productive with simple sign-in experiences, intelligent security, and unified administration. Safeguard your organization with the identity and access management solution that connects people to their apps, devices, and data. Discover, remediate, and monitor permission risks across your multicloud infrastructure with a cloud infrastructure entitlement management (CIEM) solution. Create, issue, and verify privacy-respecting decentralized identity credentials with an identity verification solution. -
29
Decube
Decube
Decube is a data management platform that helps organizations manage their data observability, data catalog, and data governance needs. It provides end-to-end visibility into data and ensures its accuracy, consistency, and trustworthiness. Decube's platform includes data observability, a data catalog, and data governance components that work together to provide a comprehensive solution. The data observability tools enable real-time monitoring and detection of data incidents, while the data catalog provides a centralized repository for data assets, making it easier to manage and govern data usage and access. The data governance tools provide robust access controls, audit reports, and data lineage tracking to demonstrate compliance with regulatory requirements. Decube's platform is customizable and scalable, making it easy for organizations to tailor it to meet their specific data management needs and manage data across different systems, data sources, and departments. -
30
DryvIQ
DryvIQ
Gain deep and robust insight into your unstructured enterprise data to gauge risk, mitigate threats and vulnerabilities, while enabling better business decisions. Classify, label and organize unstructured data at enterprise scale. Enable rapid, accurate and detailed identification of sensitive and high-risk files and provide deep insight via A.I. Enable continuous visibility across both new and existing unstructured data. Enforce policy, compliance and governance decisions without reliance upon manual input from users. Expose dark data while automatically classifying and organizing sensitive and other content groups at scale—so you can make intelligent decisions on where and how to migrate that data. The platform also enables both simple and advanced file transfers across virtually any cloud service, network file system or legacy ECM platform, at scale. -
31
Oasis Security
Oasis Security
Oasis Security provides the first enterprise platform purpose-built to secure the complete lifecycle of NHIs. Oasis continuously analyzes your environment to identify, classify and resolve security risks related to all Non-Human Identities. Auto-discovers all NHIs (Non-Human Identities). Oasis seamlessly connect with your environment and in minutes automatically creates a comprehensive inventory of all Non-Human Identities, providing a consolidated single pane of glass. Automatically assesses and ranks posture issues. The platform conducts automated assessments of the system's posture, meticulously evaluating its configuration and compliance. It then ranks posture issues based on their severity, allowing for a prioritized approach to addressing Non-Human Identity risks. Gives out-of-the-box remediation plans to shorten resolution. In addition to identifying issues, the platform goes a step further by offering pre-configured remediation plans. -
32
OpenText NetIQ Identity Governance
OpenText
Govern access to applications and data across your diverse enterprise landscape. Whether you choose to deploy on premises or via SaaS, you'll get the same full-featured capabilities that you expect from a modern identity governance solution. Discover who has access to critical applications and data on premises and in the cloud. With Identity Governance, you can collect and visualize identities and entitlements across your ecosystem. You'll know who has access to what, who approved that access, and why it was approved. Keep teams productive by providing accurate, timely access to applications and data across your diverse IT landscape. With Identity Governance, your IT team and application owners no longer need to manage entitlements in each application and platform. You'll have a user-friendly, self-service access request and approval system, backed by automated fulfillment for the most commonly used applications. -
33
exorbyte
exorbyte
Growing amounts of data, digital transformation and increasing compliance requirements call for intelligent technologies for the efficient use of all existing data. exorbyte offers you tailor-made Search & Match solutions that make all data available to humans and machines at lightning speed. Regardless of the structure, language, format and quality of the data. The master data search enables comprehensive, fuzzy searches in real time and millions of data records with just one search field. Error-tolerant, flexible across all fields, fully adjustable. The master data comparison offers the possibility of comparing whole or parts of data records with the master data. Without restrictions, regardless of errors, across databases. The master data recognition extracts identities from documents, letters or faxes and compares them with reference data. Fuzzy data matching and intelligent data extraction. -
34
minFraud
MaxMind
minFraud is a data return service that helps businesses prevent online fraud by providing risk scoring and risk data related to online transactions. Learn more about whether the minFraud service is right for your organization. The riskScore is generated in under half a second based on machine learning models and human review of network-wide fraud patterns. The data that feeds the riskScore consists of over 3 billion online transactions that the minFraud service screens annually for thousands of online businesses. When evaluating some types of online activity such as account logins, affiliate or incentivized traffic, or app installs, an IP address may be all you have. In these cases, the IP Risk Score allows you to check the IP risk to prevent bad activity. We recommend implementing our device tracking functionality to improve IP risk scoring. -
35
QoreUltima
Coginov
Manage the lifecycle of any type of content from start to finish, from creation to disposal or retention. QoreUltima™ allows you to manage both objects from the digital world (electronic documents, processes, etc.) and physical inventories (containers, files, archives, works of art, objects, people, etc.). More than fifty types of diversified inventories have been developed to allow you to fully manage your information assets. The heart of the solution is the flexibility of the platform allowing you a manage in a standardized way while being flexible on the capacity of the solution to adapt to your organizational particularities. The modular design streamlined for an easy (intuitive) user experience allows you to access features quickly. Six generations of software developed over a period of more than 25 years have led to QoreUltima, the most complete software with a set of intelligent features you need to manage your information effectively and efficiently. -
36
MetaCompliance Policy Management
MetaCompliance
MetaCompliance Advantage is a policy management software that enables organisations to automate and manage the key tasks associated with user awareness and engagement for information assurance, including risk assessment, the measurement of organisation wide IT security posture and policy management. From creation and management to publishing and delivery, cloud-based policy management software enables organisations to measure and demonstrate the continuing improvements in awareness, and highlight areas that require attention before they pose a risk to security and compliance. The magic of the MetaCompliance policy management software lies in its unique ability to obtain employee attestation of staff policies. This avoids the need for management to chase staff participation and sign up, saving huge amounts of time. The software will encourage the user to electronically sign the policy through levels of insistence determined by you. -
37
QueryPie
QueryPie
QueryPie is a centralized platform to manage scattered data sources and security policies all in one place. Put your company on the fast track to success without changing the existing data environment. Data governance is vital to today's data-driven world. Ensure you're on the right side of data governance standards while giving many users access to growing amounts of critical information. Establish data access policies by including key attributes such as IP address and access time. Privilege types can be created based on SQL commands classified as DML, DCL, and DDL to secure data analysis and editing. Manage details of SQL events at a glance and discover user behavior and potential security concerns by browsing logs based on permissions. All histories can be exported as a file and used for reporting purposes. -
38
Clarity Security
Clarity Security
Eliminate audit angst with 10-minute user access reviews, flexible provisioning/de-provisioning workflows, and audit-friendly reporting, all in one simple, scalable IGA platform. White-glove onboarding takes the burden of implementing a solution off of team members reducing the impact on other IT initiatives. Automated evidence collection into a downloadable ledger mitigates the need for wasted time gathering spreadsheets, screenshots, etc. Nested entitlements and Clarity Explorer provide insight into what’s giving users access and why they’re being granted that access. True role-based access control (RBAC) and automated workflows for full alignment with your organizational structure and needs. Unlike "traditional" manual methods, Clarity has everything you need to quickly upgrade your identity governance program and seamlessly adapt it as your organization grows. Fast reviews for certifying user access, entitlements, roles, application access, and more. -
39
Symmetry Business Intelligence
AMAG Technology
Symmetry Business Intelligence delivers critical information through data analysis to help identify the employees, contractors, and other identities that may pose the highest risk to the organization. Each person’s access history and patterns are analyzed and a risk score is assigned and updated over time. Anomalous behavior is flagged, helping identify potential threats, better control access, and prevent data theft. Identifying potentially risky behavior, allows earlier detection of potential threats, thereby mitigating risk and reducing the potential cost of an incident. Dashboards provide a real-time visual representation of the movement and trends of people. See a summary of the identities with the highest risk scores as well as the more detailed activity each hour of the week. Risk scores provide early insight into potential risks when a score rises. Scores are generated based on the reader's location, time of day, and a user’s access patterns. -
40
Syrix
Syrix
Syrix is an automated SaaS security platform built specifically for Microsoft 365 environments to help organizations continuously enforce security controls, reduce configuration risks, and maintain compliance. The platform automatically detects and remediates Microsoft 365 misconfigurations, governs privileged access, and monitors identity-related security risks without requiring agents or complex infrastructure changes. Syrix provides continuous enforcement of security policies across Microsoft Entra ID, Exchange Online, SharePoint, OneDrive, Teams, Power BI, and Microsoft Defender using native Microsoft APIs. The platform also includes identity and access governance tools that help organizations review privileged roles, manage guest accounts, enforce least-privilege access, and control risky OAuth permissions. Syrix maps security controls to compliance frameworks such as CIS, CISA SCuBA, NIST, ISO 27001, SOC 2, GDPR, and HIPAA.Starting Price: $5/month -
41
IBM InfoSphere® Information Governance Catalog is a web-based tool that allows you to explore, understand and analyze information. You can create, manage and share a common business language, document and enact policies and rules, and track data lineage. Combine with IBM Watson® Knowledge Catalog to leverage existing curated data sets and extend your on-premises Information Governance Catalog investment to the cloud. A knowledge catalog allows you to put collected metadata into the hands of knowledge workers so data science and analytics communities can get easy access to the best assets for their purpose while still adhering to enterprise governance requirements. Provides a common business language and vocabulary to enable a deeper understanding of all your data assets, structured, semi-structured and unstructured. Documents governance policies and enacts rules to help you define how information should be structured, stored, transformed and moved.
-
42
Core Security Access Assurance Suite
Core Security (Fortra)
As part of the Core Security Identity Governance and Administration portfolio of solutions, previously known as Courion, Access Assurance Suite is an intelligent identity and access management (IAM) software solution that enables organizations to deliver informed provisioning, meet ongoing regulatory compliance, and leverage actionable analytics for improved identity governance. Comprised of four industry-leading modules, our identity management software offers the most intelligent and efficient path to mitigating identity risk, and provides a complete solution for streamlining the provisioning process, reviewing access requests, managing compliance, and enforcing robust password management. A convenient web portal where end users can request access and managers can review, approve, or deny access. Using a shopping cart approach, Core Access delivers an efficient and user-friendly experience, replacing paper forms, emails, and tickets used to manage access. -
43
Catalog
Coalesce
Catalog from Coalesce (formerly CastorDoc) is a data catalog designed for mass adoption across the whole company. Have an overview of all your data environment. Search for data instantly thanks to our powerful search engine. Onboard to a new data infrastructure and access data in a breeze. Go beyond your traditional data catalog. Modern data teams now have numerous data sources, build one truth. With its delightful and automated documentation experience, Catalog makes it dead simple to trust data. Column-level, cross-system data lineage in minutes. Get a bird’s eye view of your data pipelines to build trust in your data. Troubleshoot data issues, perform impact analyses, comply with GDPR in one tool. Optimize performance, cost, compliance, and security for your data. Keep your data stack healthy with our automated infrastructure monitoring system.Starting Price: $699 per month -
44
Augment your cross-channel DLP with AI-powered classification. Proofpoint Intelligent Classification and Protection is an AI-powered approach to classifying your business-critical data. It recommends actions based on risk accelerating your enterprise DLP program. Our Intelligent Classification and Protection solution helps you understand your unstructured data in a fraction of the time required by legacy approaches. It categorizes a sample of your files using a pre-trained AI-model. And it does this across file repositories both in the cloud and on-premises. With our two-dimensional classification, you get the business context and confidentiality level you need to better protect your data in today’s hybrid world.
-
45
Theom
Theom
Theom is a cloud data security product that discovers and protects all data in cloud stores, APIs, and message queues. Like a bodyguard who closely follows and protects a high-value asset, Theom ensures controls follow the data regardless of how it is stored or accessed. Theom identifies PII, PHI, financial information, and trade secrets using agentless scanning and NLP classifiers, which support custom taxonomies. Theom discovers dark data, data that are never accessed, and shadow data, data whose security posture is different from the primary copy. Theom pinpoints confidential data, e.g., developer keys, in APIs and message queues. Theom estimates the financial value of data to help prioritize risks. Theom maps the relationships between data, access identities, and security attributes to uncover the risks to data. Theom shows how high-value data is accessed by identities (users and roles). Security attributes including user location, atypical access patterns, etc. -
46
Teleskope
Teleskope
Teleskope is a modern data protection platform designed to automate data security, privacy, and compliance at enterprise scale. It continuously discovers and catalogs data across cloud, SaaS, structured, and unstructured sources, classifying over 150 entity types such as PII, PHI, PCI, and secrets with high precision and high throughput. Once sensitive data is identified, Teleskope enables automated remediation, such as redaction, masking, encryption, deletion, and access correction, while integrating into developer workflows via its API-first model and supporting deployment as SaaS, managed, or self-hosted. The platform also builds prevention capabilities, embedding into SDLC pipelines to stop sensitive data from entering production systems, support safe AI adoption (without using unchecked sensitive data), handle data subject rights requests (DSARs), and map findings to regulatory standards (GDPR, CPRA, PCI-DSS, ISO, NIST, CIS). -
47
[GO] Onboarding
Geniusto
The customer acquisition ‘speed-dial’. Your complete onboarding solution for accelerated hyper-scale—with fully configurable KYC and KYB, customized risk-scoring, biometrics and integrations. Like the nervous system sending signals throughout your payment ecosystem, [GO] Connect seamlessly integrates core legacy, Geniusto and 3rd party technology. Easily ensure your business exceeds compliance in any territory with advanced identity verification, data processing and data analysis—to minimize abandonment and maximize revenue. Advanced intelligent customer screening makes compliance a rock-solid given, and advanced monitoring automates crime and money laundering prevention. Improve credit quality and acceptance rates ad make better onboarding decisions with lightning-fast, neutral risk assessments based on custom parameters. -
48
BalkanID
BalkanID
Leverage AI to automate discovery & risk prioritization of entitlement sprawl. Streamline access reviews & certifications across the public cloud and SaaS landscape. Connect all third-party integrations to the BalkanID dashboard. Integrations are supported for the most commonly used SaaS apps. Single pane of glass for coarse and fine-grained entitlements, as well as outliers across SaaS and public cloud environments. Simplify the access review and certification process across the SaaS and public cloud landscape. Leverage data science and machine learning to provide visibility into entitlement risks across SaaS and public cloud environments. Discovery and prioritization of entitlement risks. Discover, normalize and attribute entitlement taxonomy and associated data sets, to ensure that while an access review can be high-level there is still detailed data (permissions, roles, groups, etc.) to support certification actions. -
49
Core Access Insight
Fortra
Core Access Insight offers a continuous, comprehensive view and analysis of the relationship between identities, access rights, policies, and resources that occur across your entire environment. Our easy-to-use, easy-to-understand solution applies analytics to the big identity and access data in your organization, empowering you to identify identity-related access risks, and drive provisioning and governance controls to manage that risk within your business. With Access Insight, your governance system does more than just manage access. It provides access intelligence to analyze the identity and access data in your organization, using advanced analytics tools. This enables you to perform data mining, statistical analysis, and data visualization—drawing on specific governance policies, rules, and risk indicators to provide intelligence and valuable information for administrators, analysts, compliance officers, and incident responders. -
50
Access Auditor
Security Compliance Corp
Access Auditor automates user entitlement reviews and user access reviews. Access Auditor also alerts on changes in user access rights, and watches for separation of duties violations, and shows who has access to what. Users can be imported from any AD/LDAP, Database, or any REST API. Enterprise roles (RBAC) can be modeled and defined, allowing full RBAC reviews and provisioning. Access Manager leverages the same ease-of-use to automate the provisioning and management of user access rights. Any system with a database, LDAP, or REST API can be automatically managed via role based access controls. SCC’s powerful and simple approach to Identity Management enables a very rapid success at a low overall cost. With a 100% customer success rate, Access Auditor is the fastest and simplest solution available and can automate your user access reviews in under a week.