Head-to-head · updated 13 September 2026

DataShield vs Dremio: your agents can query everything, but can you prove what they read?

Dremio calls itself "The Agentic Lakehouse" and, under the branding, it is a very good SQL engine. It reads Apache Iceberg tables that live in your own object storage. It federates across lakes, warehouses and operational sources with no forced ETL. Reflections make slow queries fast. Maersk runs 1.6 million queries a day on it. Dremio helped build Iceberg and Polaris, and that credibility is earned, not bought.

We are not a query engine and we will not pretend to be. DataShield is the governed data plane for the datasets agents actually touch. Fields get classified against 129 PII, PHI, financial and secret classes. Datasets are tokenized at ingest; agents query tokenized data over MCP; detokenization is a privileged, audited operation. Every governed tool call is re-checked against the agent's current authority before it runs, and the decision is sealed into a hash chain you can verify yourself. Most teams who talk to us keep their lakehouse. Below is the honest split, Dremio's wins included.

DataShield vs Dremio at a glanceEight questions regulated buyers ask us. Scored from each vendor's public material. DataShield vs Dremio at a glance Eight questions regulated buyers ask us. Scored from each vendor's public material. DataShield Dremio Tamper-evident audit chain you can verify Authority re-checked on every governed tool call Break-glass access for agents Field-level PII and PHI classification Tokenized values, not just filtered rows Iceberg-native query engine at petabyte scale Semantic layer and query acceleration Named references and enterprise scale shipped partial / roadmap not offered Sources at the bottom of this page.

The short version

Pick DataShield when

  • Someone will ask you to prove an agent's access log was not edited. An examiner, an auditor, or Article 12 of the EU AI Act. Our chain answers with math. Run the verifier.
  • You need to pull an agent's authority mid-session and have the very next tool call fail. Not the next token refresh.
  • The agent should read a token, not a real medical record number. Classification and tokenization happen before the model ever sees a value.
  • The whole stack has to run on your own infrastructure, on keys you hold, and you would like a price before you book a call.

Pick Dremio when

  • You have petabytes in Iceberg and you need them queried fast. That is the job Dremio was built for and it is not one we do at all.
  • You want to skip the ETL. Federated SQL across lake, warehouse and operational sources, with Reflections doing the acceleration, is a real engineering win.
  • You care about open table formats. Dremio co-founded Apache Polaris, pushed Iceberg V3 with deletion vectors and row-level lineage, and has an engineer on the ASF board.
  • You are an SAP shop. SAP announced it is buying Dremio in May 2026 to feed Business Data Cloud, so the roadmap is about to point straight at you.

Bottom line: Dremio makes your data queryable. We make the regulated slice of it safe for an agent to query, and we keep proof of what happened. Those are different jobs, and a lot of buyers need both.

Feature by feature

Competitor cells describe what Dremio's public site, blog and press releases say as of the date above. If we have mischaracterised something, email support@myorg.ai and we will correct it, credited.

What mattersDataShieldDremioEdge
Query engine and lakehouseNot our job. Ontology ingests, catalogs and transforms datasets, and runs DuckDB over Parquet for analytics on masked golden views. That is a dataset platform, not a federated engine over your lake.The core product, and it is strong. Iceberg-native SQL, federation without forced ETL, Reflections for acceleration, Iceberg V3 with deletion vectors and clustering.
Audit evidenceSHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained. Verification returns clean, attested damage, or tampered, and names the break: insertion, deletion or truncation. Try the verifier.Lineage tracking of which sources an agent touched and which policies applied. Useful. We found no published tamper-evidence over that record.
Agent authorizationEvery governed tool call passes a scope ceiling, a consented-tool allowlist, an authority tier, and a fresh revocation check before dispatch. It fails closed.Agents inherit the user's identity and their RBAC and FGAC. Their words: if you cannot see a column in the UI, the agent cannot see it over MCP. Good design. It is still one decision, made at grant time.
Break-glassScoped, time-boxed emergency access for agents. Admin plus IP allowlist plus step-up, auto-revoking, and it cannot be quietly removed from the log.Not described in their public material.
GDPR erasureCrypto-shred of per-subject key material, plus ISO 27560 signed consent receipts. The audit chain still verifies after the subject is gone.Iceberg V3 row-level lineage helps you find and rewrite rows. The erasure mechanism, and what it does to historic logs, is not described.
TokenizationDeterministic, join-preserving, vault-reversible tokens at ingest, plus quasi-identifier generalization (dates to year, decade or age band; ZIPs to 3 or 4 digits; partial phones, SSNs and emails) with a measured cardinality-reduction score per column. Detokenization is privileged and logged.Row and column filtering by policy. Tokenization is not vocabulary Dremio uses. The agent sees real values it is permitted to see.
PII and PHI classification129 field classes covering PII, PHI, financial data and secrets, including all 18 HIPAA Safe Harbor identifiers and eight non-US national ID formats. Regex plus checksum validation (Luhn, NPI, Verhoeff, ABA, IBAN, GTIN) plus column-name lexicons and anti-pattern suppressors. No model, so verdicts are reproducible from a config digest. Shipped recently, and we say so.Auto-generated wikis and labels for governance, and a semantic layer that carries business context. That is metadata description, not field-level sensitive-data classification with severity and a regulation reference.
Semantic layerA business glossary materialized from entity types, typed lineage traversal with per-hop access gating, and a 29-command stewardship workflow. Narrower than theirs, and aimed at governance rather than BI modelling.The AI Semantic Layer is a real asset, pitched as a living encyclopedia for the business so agents ask better questions. Years of modelling work behind it.
MCP and agentsNative MCP across Ontology, Auth, Corpus and Lighthouse: more than 200 tools. Tool tokens carry scope ceilings, per-call metering is attributed to the agent, and RFC 8693 delegation enforces a scope ceiling on behalf-of calls.A hosted MCP server, GA on Dremio Cloud since November 2025, with OAuth 2.0, query and pattern-analysis tools, semantic resources and guided prompts. Shipping and in customers' hands, which counts.
DeploymentSelf-hosted in your own cloud or data center, or a dedicated single-tenant server we operate. Docker images for Auth, Ontology, Corpus and Lighthouse, with a signed deploy manifest Guardian verifies. Ed25519 audit-signing keys can live in your KMS or HSM. HMAC tokenization keys sit in your environment today, not in a KMS.Dremio Cloud is AWS only, with Azure listed as coming soon. Dremio Enterprise is self-managed on Kubernetes, on-prem or any cloud. There is also a free Community Edition for a local machine or server.
Maturity signalsAuth, Guardian and Lighthouse are live in production (Guardian and Lighthouse since April 2026). SOC 2 not yet certified, and we say so. Small team, design-partner terms include source escrow.Founded 2015, roughly $385M raised, thousands of customers, Amazon and Shell and Maersk on the logo wall, and an ASF board seat. Being acquired by SAP, which cuts both ways.
PricingPublished model, scoped instant quote, no sales wall.Half published. Dremio Cloud is $0.20 per DCU with a $400 trial credit for 30 days. Dremio Enterprise, the self-managed tier, is quote only.

◆ DataShield leads◇ Dremio leads◈ comparable

Dremio claims are drawn from dremio.com, its pricing page, its MCP server blog post and its own press releases, last checked 13 September 2026. We link them below rather than work from memory.

Three things you get here that you won't get from a lakehouse engine

Proof that survives an audit

Lineage tells you what an agent read. It does not tell you the record was never edited. Ours is a hash chain with signed checkpoints, and the verifier names what broke rather than just saying something did. That is the property EU AI Act Article 12 and HIPAA §164.312(b) reviewers ask about. Try it in your browser, no signup.

Authority that can change mid-flight

An analyst quits on a Friday. Their agent is 20 minutes into a 40-minute job, running under their inherited permissions. With DataShield the next governed tool call is re-checked against current authority and fails closed. Inheritance alone waits for the next token. How Auth does it.

A token instead of a real value

Permissions decide whether an agent sees a column. Tokenization decides what is in it. Our tokens are deterministic and join-preserving, so analysis still works, and reversal is a privileged vault operation with its own log line. What Ontology does at ingest.

Where Dremio is genuinely stronger

Start with the engineering. Dremio has been at Iceberg since before it was fashionable, co-founded Apache Polaris, pushed Iceberg V3 support into its cloud in April 2026 with deletion vectors and row-level lineage, and has an engineer on the Apache Software Foundation board. That is not a marketing posture, it is a decade of committer work. The scale numbers are public and specific: Maersk at 1.6 million queries a day, RWE at 400,000. Their MCP server has been hosted for Cloud customers since November 2025, with OAuth 2.0 and inherited access controls, which is a sane design and it shipped before ours did on that surface. And SAP's May 2026 acquisition gives them a distribution channel we will never match.

Here is the push-back, and it is narrow on purpose. Dremio's agent answer is inheritance: the agent borrows the human's permissions, and Dremio logs the lineage. That is the right default and it solves the easy half. It does not classify which columns hold protected health information. It does not replace a value with a token before a model reads it. It does not re-check authority on the call that is running right now. And the record it leaves is a log, which means the answer to "prove this was not altered" is a policy document rather than a signature. Gartner expects most unauthorized agent transactions through 2028 to be internal policy violations rather than attacks. Inherited permissions plus an editable log is the weakest possible answer to that case. It is also the case regulated buyers get asked about first.

Questions worth asking both of us

These are the questions we would want answered if we were the ones buying. Ask them on every call, ours included.

Can you cryptographically prove an audit log entry wasn't deleted?

DataShield: yes. Each record commits to the one before it, checkpoints are Ed25519-signed and chained, and verification tells deletion apart from truncation and from tampering. Try it on a sample chain at /verify. Dremio: their MCP post describes full lineage tracking of sources, transformations and policies. We found no tamper-evidence mechanism over it. Ask them whether that lineage record is append-only and whether anyone outside Dremio can check it.

What happens to a revoked agent mid-session?

DataShield re-checks authority on every governed tool call, so revocation lands on the next call. Dremio says agents inherit user identity and access controls automatically, and that OAuth tokens flow through credential vending to each source. That is clean at grant time. Ask how long a token stays valid after you disable the human, and whether a query already in flight is stopped.

How does GDPR erasure interact with the audit trail?

DataShield crypto-shreds the per-subject key material, which makes every ciphertext for that subject unreadable at once, and issues an ISO 27560 consent receipt. Actor identities in the chain are HMAC-committed, so the evidence still verifies. Dremio ships Iceberg V3 row-level lineage, which helps you locate and rewrite rows. What happens to the query history and lineage record is not described. Ask for the mechanism, not the workflow.

Is DataShield a lakehouse? Do we drop Dremio?

No, and probably not. We do not query your Iceberg tables, we have no Reflections, and we will lose any benchmark you care to run. Ontology is a dataset platform: ingest, catalog, classify, tokenize, resolve entities, snapshot, serve to agents over MCP. Keep the lakehouse for analytics at scale. Put the datasets agents touch, the ones with names and diagnoses in them, under us.

SAP is buying Dremio. Does that matter?

It is a fair thing to weigh, and it is not a rumour: Dremio announced it on 4 May 2026, terms undisclosed, expected to close in Q3 2026. If you are an SAP shop this is good news, because the roadmap is about to serve you. If you are not, ask for a written roadmap and pricing commitment for the next 24 months, and ask what happens to Dremio Cloud as an independent product. Acquisitions change packaging before they change code.

Does DataShield have SOC 2?

Not yet, and we will not imply otherwise. Auth is live with a public threat model and a verifier anyone can run. Guardian and Lighthouse have been in production since April 2026. We could not find a published SOC 2, HIPAA or ISO certification for Dremio either, so ask us both the same question and ask for the report. Our details are on the security page.

Other head-to-heads

Same market

DataShield vs Microsoft Fabric

DataShield vs Microsoft Fabric: Fabric is the SaaS data platform for Microsoft estates. DataShield adds.

Same market

DataShield vs Starburst

DataShield vs Starburst: Starburst federates SQL across your estate and grounds AIDA in it. DataShield.

Same market

DataShield vs Snowflake

DataShield vs Snowflake: Snowflake wins scale, Cortex agents and ecosystem. DataShield adds self-hosting,.

All

Every comparison

One honest scorecard per vendor.

See both mechanisms run in your browser: break a live audit chain, revoke an agent mid-session, then decide what your lakehouse still owes you. Demo Center access is free with a work email.

Get free Demo Center access

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →