Head-to-head · updated 13 September 2026

DataShield vs Privitar: where do you go now that Privitar is gone?

Start with the honest part. You can't buy Privitar. Informatica bought it in June 2023. The old site now redirects to theirs, and the tech lives inside IDMC as "Data Governance, Access & Privacy." Salesforce then bought Informatica. That deal closed on 18 November 2025. Privitar was a good product. Its de-identification work was real, and plenty of banks still run it.

So this page is about the job, not the logo. You came here for policy-driven de-identification. You did not come here to buy a data platform. Here is what we do instead. Datasets are tokenized at ingest, agents query tokenized data over MCP, and detokenization is a privileged, audited operation. Below is the row by row, including the rows they win.

DataShield vs Privitar (now Informatica) at a glanceEight questions regulated buyers ask us. Scored from each vendor's public documentation. DataShield vs Privitar (now Informatica) at a glance Eight questions regulated buyers ask us. Scored from each vendor's public documentation. DataShield Privitar / Informatica Still sold as a standalone product Quasi-identifier generalization named as shipped Tamper-evident audit chain you can verify Authority re-checked on every tool call Break-glass access for agents Runs on your own infrastructure Pricing you can see before a call Breadth of data platform around it shipped partial / roadmap not offered Sources at the bottom of this page.

The short version

Pick DataShield when

  • You wanted the de-identification tool, not the data platform that now contains it. We ship PII and PHI classification across 129 field classes and quasi-identifier generalization as named features you can point at. See the Ontology surface.
  • You need tokens that are reversible under policy, not one-way masking. Ours are deterministic and join-preserving, so your analytics still work. Detokenization is a privileged, audited operation.
  • An examiner will one day ask you to prove the access log wasn't edited. Our chain answers that with math. Run the verifier.
  • The control plane has to run inside your own network. IDMC has no self-hosted control plane. We do.

Pick Informatica when

  • You're consolidating vendors and want catalog, quality, MDM, integration, and privacy on one contract. That is a real strategy and we can't serve it.
  • You already run Informatica. The module is a line item on a renewal, not a new procurement. That's a large, boring advantage.
  • You need 50,000-plus source connectors and decades of ETL lineage. We're a dataset and governance layer, not an integration suite.
  • You're a Salesforce shop chasing the Agentforce roadmap, and being owned by Salesforce reads as a feature rather than a risk.

Bottom line: if you want the Privitar job done, buy a tool that still names the mechanism. If you want the big platform, buy the platform. Just don't pretend the privacy module is why.

Feature by feature

Their cells describe what the vendor's public site and docs say as of the date above. If we got something wrong, email support@myorg.ai and we'll fix it, credited.

What mattersDataShieldPrivitar / InformaticaEdge
Does the product still existYes, sold and priced on its own.Not as Privitar. The brand is retired and the site redirects. Capability sits inside IDMC's Data Governance, Access & Privacy.
De-identification mechanismPII and PHI classification against 129 field classes, plus quasi-identifier generalization (dates to year, decade or age band; ZIPs to 3 or 4 digits; partial phones, SSNs and emails) with a measured cardinality-reduction score per column, named and shipped in Ontology.Privitar's heritage here was strong. On the current pages the only named mechanism is role-based access control and dynamic data masking down to rows and columns. We found no k-anonymity wording.
TokenizationDeterministic, join-preserving, vault-reversible tokens applied at ingest. Detokenization is a privileged, logged operation.Masking and policy-based access are described. We found no public tokenization mechanism detail for the current module. Ask them.
Audit evidenceSHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained. Verification names the failure: tampering, insertion, deletion, or truncation. Public verifier.Governance reporting and policy audit within IDMC. No published cryptographic tamper evidence that we could find.
Agent authorizationEvery governed tool call passes a scope ceiling, an authority tier, and a revocation re-check before dispatch. Revocation lands mid-session.Policy-based access control over data. The agent story is preparing trusted data for agents, not authorizing a specific tool call.
Break-glassScoped, time-boxed emergency access for agents that auto-revokes and can't be quietly deleted from the log.Not described in public docs.
GDPR erasureCrypto-shred of per-subject key material plus ISO 27560 consent receipts. The audit chain stays verifiable after erasure.GDPR, CCPA, and HIPAA compliance support is claimed at the platform level. The erasure mechanism isn't spelled out.
MCP and agentsNative MCP endpoints on Auth, Ontology, and Lighthouse. MCP tool tokens with scope ceilings, and per-call metering attributed to the agent.MCP is named on the homepage, in a webinar: "Equip AI agents with trusted data using MCP." That's data prep for other people's agents.
DeploymentSelf-hosted in your own cloud or data center, or on a dedicated single-tenant server we operate. Your keys.IDMC is SaaS. On-prem systems connect through a Secure Agent that calls back to the cloud. No self-hosted control plane found.
Platform breadthDataset platform, identity control plane, fleet and host daemons. No ETL suite. Our MDM is narrower than theirs but specific: Fellegi-Sunter probabilistic record linkage, Jaro-Winkler, Levenshtein, Soundex and Double Metaphone comparators, LSH blocking, EM-trained parameters, five survivorship strategies and drift monitoring on every promoted match config.Catalog, integration, data quality, MDM, API management, marketplace, governance. Connectors to more than 50,000 sources.
Maturity signalsAuth, Guardian and Lighthouse are live in production (Guardian and Lighthouse since April 2026). SOC 2 not yet certified, and we say so.Founded 1993. Public company until Salesforce closed its $8B purchase on 18 November 2025. Thousands of enterprise customers.
PricingPublished model, scoped instant quote, no sales wall.Consumption pricing in Informatica Processing Units. No published rate. You need a sales cycle to see a number.

◆ DataShield leads◇ Privitar / Informatica leads◈ comparable

Informatica claims are drawn from informatica.com and public records, last checked 13 September 2026. We link them below rather than paraphrase from memory.

Three things you get here that you won't get from a data management platform

Proof that survives an audit

A log that can be edited in silence proves nothing. Ours is a hash chain with signed checkpoints. The verifier tells you what went wrong, not just that something did. That is the property EU AI Act Article 12 and HIPAA §164.312(b) reviewers care about. Try it in your browser, no signup.

Authority that can change mid-flight

An analyst quits on a Friday. Their agent is still grinding through a 40 minute job. Here, the next governed tool call gets checked against current rights. It fails closed. Row level masking will not save you, because the agent still holds a live session. How Auth does it.

An erasure you can defend

GDPR says delete. Your auditor says keep the log. Crypto-shred settles it. We destroy the subject's key material, the data turns to noise, and the chain still verifies. See the diagram.

Where Privitar and Informatica are genuinely stronger

Privitar earned its name. It brought real privacy work to banks and health systems at a time when most vendors offered a regex and a shrug. The k-anonymity engine, the risk scores, the idea that hiding a name is a policy choice and not a script: that was good thinking. We build on the same ideas. Informatica is a 1993 company with connectors into more or less everything. If you want one vendor for pipelines, quality, MDM, catalog, and rules, we are not that vendor and will not pretend to be.

Here is the push-back. When a small product gets absorbed, the mechanism words go first. That is what we found. The hero on their privacy page now reads "Deliver trusted outcomes with AI-powered data governance." The only method named is role based access with dynamic masking. Trusted outcomes is not a mechanism. So ask for a screen share. Ask to see the k-anonymity settings, the risk score, and the re-identification report, on your own data. If they show you, great. If the demo turns into a platform tour, you have your answer.

Questions worth asking both of us

These are the questions we'd want answered if we were buying. Ask them on every vendor call, including ours.

Can I still buy Privitar?

No. Informatica bought Privitar in June 2023. The old site now returns a permanent redirect to theirs. The tech ships inside IDMC under Data Governance, Access & Privacy. Live Privitar deployments are still supported. If you are searching for a Privitar alternative, you probably want two things: policy-driven de-identification, and tokens you can reverse under policy. That is the part we do.

Do you have k-anonymity, like Privitar did?

Not k-anonymity, and we won't claim a k we don't compute. Ontology ships PII and PHI classification against 129 field classes, plus quasi-identifier generalization (dates to year, decade or age band; ZIPs to 3 or 4 digits; partial phones, SSNs and emails) with a measured cardinality-reduction score per column. We pair that with tokens that are deterministic, join-preserving, and vault-reversible. So a masked dataset still joins across sources. On their current public pages we could not find k-anonymity named at all. Ask them if the old engine is still a distinct feature, or just masking rules now.

Can you cryptographically prove an audit log entry wasn't deleted?

DataShield: yes. Each record commits to the one before it. Checkpoints are signed and chained. The check tells deletion apart from truncation and from tampering. Run it against a sample chain at /verify. Informatica: they report on policy, but we found no published tamper-proof mechanism. Ask them to show one.

What happens to a revoked agent mid-session?

We re-check rights on every governed tool call. So a pulled agent stops at the next call. Their controls sit at the data layer, as policy based access and masking. That is a different question. We found no mention of agent tiers or mid-session cut-off. Ask how long a stolen agent keeps working after you pull its access.

How does GDPR erasure interact with the audit trail?

We crypto-shred the subject's key material and issue an ISO 27560 consent receipt. Actor names in the chain are HMAC-committed. So the evidence still verifies after the subject is gone. They claim GDPR, CCPA, and HIPAA support at the platform level, but the erasure method is not public. Ask whether erasing a subject breaks the log.

Does it matter that Salesforce owns Informatica now?

It might. Salesforce closed its $8 billion purchase on 18 November 2025. The homepage now reads "Informatica from Salesforce." If you run a mixed stack, ask how the roadmap gets set when Agentforce wants something your stack does not. We are small and free of all that. It cuts both ways: no parent steering us, and no parent balance sheet either.

Does DataShield have SOC 2?

Not yet, and we will not imply otherwise. Auth is live a public threat model and a verifier anyone can run. Guardian and Lighthouse have been in production since April 2026. Design partner terms include source escrow, so a small vendor is not a single point of failure. Details on the security page.

Other head-to-heads

Direct

DataShield vs Immuta

Policy-based access control versus evidence you can verify.

Direct

DataShield vs Protegrity

Enterprise tokenization at scale versus agent-scoped governance.

Direct

DataShield vs Okera

Another privacy point product absorbed into a platform.

All

Every comparison

One honest scorecard per vendor.

See both parts run in your browser. Generalize a dataset, break a live audit chain, then decide. Demo Center access is free with a work email.

Get free Demo Center access

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →