Head-to-head · updated 13 September 2026

DataShield vs Estuary: the rows land in a second, but who governs them after that?

Estuary Flow is a real-time data movement platform, and a good one. Log-based CDC, streaming and batch in the same system. They claim sub-100ms latency, 200-plus connectors, three petabytes moved a month, and 5,500 users. Their own hero says it plainly: "Streaming, log-based CDC, and batch in one platform." Their pricing page prints a rate you can do arithmetic with. We like that.

We are not an ELT tool. We have no CDC, no replication slots, no connector catalogue to match theirs. DataShield picks the problem up where the pipeline drops it off. Datasets are tokenized at ingest; agents query tokenized data over MCP; detokenization is a privileged, audited operation. Fields get classified against 129 PII, PHI, financial and secret classes. Every governed tool call is checked against the agent's current authority before it runs, and the decision is sealed into a hash chain you can verify yourself. Here is the honest split, rows they win included.

DataShield vs Estuary at a glanceEight questions regulated buyers ask us. Scored from each vendor's public material. DataShield vs Estuary at a glance Eight questions regulated buyers ask us. Scored from each vendor's public material. DataShield Estuary Sub-second CDC out of a database log Breadth of managed connectors SOC 2 Type II today Field-level PII and PHI classification Tokenization before an agent reads a row Authority re-checked on every tool call Tamper-evident audit chain Rates published before a sales call shipped partial / roadmap not offered Sources at the bottom of this page.

The short version

Pick DataShield when

  • Agents are already reading the data your pipeline delivers, and nobody can say which columns each one may touch.
  • You need to pull an agent's authority mid-job and have the very next tool call fail. Not the next token refresh. The next call.
  • Someone will ask you to prove an access log was not edited. An examiner, an auditor, or Article 12 of the EU AI Act. Run the verifier and see what the answer looks like.
  • The data plane, the policy decisions and the evidence all have to run on your own hardware, on keys you hold.

Pick Estuary when

  • You need rows out of a Postgres write-ahead log and into Snowflake in under a second. That is their whole craft and we do none of it.
  • Connector breadth decides the deal. 200-plus managed connectors is years of work we have not done.
  • Your procurement team wants a SOC 2 Type II report on the desk this quarter. They have one. We do not.
  • You are paying Fivetran by monthly active rows and the bill keeps surprising you. Their $0.50 per GB rate card is a real answer to that.

Bottom line: Estuary moves the data. We govern it once it has landed. Almost nobody has to choose, and most teams who buy us already run a pipeline tool of some kind.

Feature by feature

Competitor cells describe what Estuary's public site and blog say as of the date above. If we have mischaracterised something, email support@myorg.ai and we will correct it, credited.

What mattersDataShieldEstuaryEdge
Real-time data movementNone. We ingest files, watch S3, Azure Blob, GCS, SFTP and SMB subtrees for new objects, and register a live PostgreSQL source as a catalog provider. There is no change data capture and no streaming runtime here.The product. Log-based CDC, streaming and batch in one pipeline model, with a claimed sub-100ms latency and a runtime they rebuilt in August 2026.
Connector breadthNarrow on purpose. PostgreSQL is the one catalog provider with working scan, profile and extract handlers. Snowflake, BigQuery, Databricks, S3, Kafka and Salesforce are declared on the roadmap with no handler yet, and we say so in the config file.More than 200 managed connectors across databases, warehouses, apps and cloud services.
Field classification129 built-in classes covering PII, PHI, financial data and secrets, including all 18 HIPAA Safe Harbor identifiers. Regex plus checksum validation (Luhn, NPI, Verhoeff, ABA, IBAN, GTIN), column-name lexicons and anti-pattern suppressors. No model, so verdicts are reproducible from a config digest.Not part of the product. Their compliance guide says sensitive fields "can be excluded or transformed before reaching downstream systems," which is a transform you write, not a classifier that finds them.
Tokenization and data handlingDeterministic, join-preserving, vault-reversible tokens applied at ingest, plus quasi-identifier generalization (dates to year, decade or age band; ZIPs to 3 or 4 digits; partial phones, SSNs and emails) with a measured cardinality-reduction score per column. Detokenization is privileged and every lookup is audited.Encryption in transit and at rest, with customer-managed KMS keys, and SOPS-encrypted connector credentials. Tokenization is not vocabulary they use.
Audit evidenceSHA-256 hash chain over the record stream with Ed25519-signed checkpoints that are themselves chained. Verification returns clean, attested damage, or tampered, and names the break. Try the verifier.Audit logs over configuration updates, replays and backfills, plus a History Mode that keeps every event. That is pipeline change history. We found no cryptographic tamper evidence.
Agent authorizationEvery governed tool call passes a scope ceiling, a consented-tool allowlist, an authority tier and a fresh revocation check before dispatch. It fails closed.Role-based access control with namespace prefixes and read, write and admin capabilities, plus SSO at the Enterprise tier. That governs who edits pipelines, not what an agent reads from a row.
Break-glassScoped, time-boxed emergency access, admin and IP-allowlist gated, with step-up. It auto-revokes and cannot be quietly removed from the log.Not described in their public material.
GDPR erasureCrypto-shred of per-subject key material, plus ISO 27560 consent receipts. Actor identities in the chain are HMAC-committed, so the audit still verifies after the subject is gone.They state adherence to GDPR, CCPA and CPRA, and BYOC for regional processing rules. The erasure mechanism itself is not described.
MCP and agentsMore than 200 MCP tools across Ontology, Auth, Corpus and Lighthouse. Agents query the governed data itself under tool tokens with scope ceilings, and each call is metered and attributed to the agent.Agent Skills: markdown instruction packs that teach Claude Code, Codex or Gemini CLI how to build a pipeline. Clever, and genuinely useful. It is an authoring surface for engineers, not a runtime the agent reads data through.
DeploymentSelf-hosted in your own cloud or data center, or a dedicated single-tenant server we operate. Docker images ship for Auth, Ontology, Corpus and Lighthouse, and Guardian verifies a signed deploy manifest. Ed25519 audit-signing keys can live in your KMS or HSM. HMAC tokenization keys sit in your environment or derive from your machine key, not in a KMS.Three first-class modes: public SaaS in EU and US regions, a network-isolated private deployment, and bring-your-own-cloud. PrivateLink and Google Service Connect at the Enterprise tier. This is one of the better hosting stories in their category.
Compliance certificationsDesign citations only. HIPAA §164.312(b) and §164.514(b), GDPR Art. 17 and Art. 25, ISO 27560, RFC 8785. SOC 2 is not certified and we will not imply it is.SOC 2 Type II, with stated adherence to HIPAA, GDPR, CCPA and CPRA, and BYOC plus a BAA as the HIPAA route.
Maturity signalsAuth, Guardian and Lighthouse are live in production (Guardian and Lighthouse since April 2026). Small team, source escrow in design-partner terms, SOC 2 not yet certified.Founded 2019. 5,500 users, three petabytes moved a month, a 99.9% uptime SLA, and named customers including Glossier, Xometry and Together AI.
PricingPublished model and a scoped instant quote, no sales wall.Published too: a free 10 GB tier, then $0.50 per GB and $100 per connector for the first six, $50 after that. Enterprise is quote-only.

◆ DataShield leads◇ Estuary leads◈ comparable

Estuary claims are drawn from estuary.dev, its pricing page and its blog, last checked 13 September 2026. We link them below rather than work from memory.

Three things you get here that you won't get from a data movement platform

The pipeline knows the schema. It doesn't know the risk.

A CDC stream will happily carry a column of medical record numbers into your warehouse. It has no opinion about that. We label fields against 129 classes, including every HIPAA Safe Harbor identifier, using regex, checksums and column-name evidence. No model, so the same column gets the same verdict next month. How the catalog works.

Authority that can change mid-flight

An analyst leaves on a Friday. Their agent is 20 minutes into a 40-minute job. With DataShield the next governed tool call is re-checked against current authority and fails closed. Pipeline RBAC will not help you here, because it governs the pipeline, not the read. How Auth does it.

An erasure you can defend

GDPR says delete. Your auditor says keep the log. Crypto-shred settles it: the subject's key material is destroyed, the data goes unreadable, and the chain still verifies. See the diagram.

Where Estuary is genuinely stronger

They are better at their job than we would be. Log-based CDC is hard, and the parts that hurt are the parts nobody demos: replication slot bloat, multi-day backfills running while production keeps writing, schema drift landing in a warehouse at 3am. Estuary writes about all three in public, which is usually the sign of a team that has been paged for them. The May 2026 pricing post picking apart Fivetran's monthly-active-rows meter is the kind of thing a vendor only publishes when the arithmetic is on its side. And their hosting ladder is real: public SaaS, a network-isolated private deployment, and bring-your-own-cloud, with a SOC 2 Type II report behind it. We have self-hosting and honesty, which is not the same as a report.

Here is the push-back. Their compliance guide describes audit logs over configuration updates, replays and backfills. That is a record of what the pipeline did. It is not a record of what a person or an agent did with a row after the pipeline delivered it, and those are the entries an examiner asks for. The same gap shows up in their access control: RBAC with namespace prefixes decides who can edit a capture. It does not decide whether the support agent may read the unmasked phone number in it. Freshness is a real problem and they solved it. Governance of the landed data is a different problem, and it is ours.

Questions worth asking both of us

These are the questions we would want answered if we were the ones buying. Ask them on every call, ours included.

Can you cryptographically prove an audit log entry wasn't deleted?

DataShield: yes. Each record commits to the one before it, checkpoints are signed and chained, and the verifier tells deletion apart from truncation and from tampering. Try it against a sample chain at /verify. Estuary: their public material describes audit logs over configuration updates, replays and backfills, and a History Mode that retains every event. We found no tamper-evidence mechanism. Ask them what stops a privileged user editing that history.

What happens to a revoked agent mid-session?

DataShield re-checks authority on every governed tool call, so a revocation lands on the next call rather than the next token refresh. Estuary has RBAC and SSO at the Enterprise tier, which covers pipeline operators. We could not find anything about revoking an agent's read access in flight, because that is not really what their access model is for. Ask both of us how long a compromised credential keeps working.

How does GDPR erasure interact with the audit trail?

DataShield crypto-shreds per-subject key material and issues an ISO 27560 consent receipt. Actor identities in the chain are HMAC-committed, so the evidence still verifies once the subject is gone. Estuary states GDPR, CCPA and CPRA adherence and offers BYOC for regional processing rules. The mechanism for an actual erasure request across a replicated stream is not spelled out. Ask for the mechanism, not the certification.

Is DataShield a CDC or ELT tool? Do we drop Estuary?

No, and no. We have no change data capture, no replication slots and no streaming runtime. If you need rows out of a database log in under a second, buy Estuary or something like it. Run us on the datasets agents actually query, where the obligation is classification, tokenization, authorization and evidence. The two sit end to end quite happily.

Estuary ships Agent Skills. Isn't that the same idea as your MCP surface?

Different layer, and it took me a minute to see it. Their Agent Skills, launched in July 2026, are markdown instruction packs that let Claude Code or Gemini CLI stand up a pipeline for you. The agent is the engineer's assistant. Our MCP surface is where an agent reads the governed data itself, so every call carries a tool token with a scope ceiling, gets authorized before dispatch, and lands in the audit chain. One helps you build the pipe. The other decides what may come out of it.

Does DataShield have SOC 2?

Not yet, and we will not imply otherwise. Estuary does, and if that gates your purchase then this is a short conversation. What we offer instead is a published threat model, a verifier anyone can run, and source escrow in design-partner terms so a small vendor is not a single point of failure. Auth, Guardian and Lighthouse are live in production, Guardian and Lighthouse since April 2026. More on the security page.

Other head-to-heads

Same market

DataShield vs Onehouse

DataShield vs Onehouse: Onehouse runs an open lakehouse in your own cloud. DataShield adds agent.

Same market

DataShield vs Y42

DataShield vs Y42: Y42 runs turnkey data orchestration into BigQuery and Snowflake. DataShield governs the.

Same market

DataShield vs Starburst

DataShield vs Starburst: Starburst federates SQL across your estate and grounds AIDA in it. DataShield.

All

Every comparison

One honest scorecard per vendor.

See both mechanisms run in your browser: break a live audit chain, revoke an agent mid-session, then decide what your pipeline still owes you. Demo Center access is free with a work email.

Get free Demo Center access

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →