Head-to-head · updated 13 September 2026

DataShield vs Microsoft Purview: who proves what the agent did?

Microsoft Purview is very good at the thing it is built for. Inside an Azure and Microsoft 365 tenant it maps the estate, labels the sensitive bits, runs DLP, and gives the compliance team Audit, eDiscovery and Records in one portal. Unified Catalog adds governance domains, data products, a live glossary, quality scores and OKRs. If your data lives in SharePoint and OneLake and your agents are Copilots, Purview is the default answer and it is a reasonable one. We are not going to pretend otherwise.

We are a smaller, narrower thing, and we run where you put us. Datasets are tokenized at ingest; agents query tokenized data over MCP; detokenization is a privileged, audited operation. Every governed tool call is re-checked against the agent's current authority before it runs. Every decision is sealed into a hash chain you can verify without trusting us or Microsoft. Below is the honest split, including the many rows Purview wins.

DataShield vs Microsoft Purview at a glanceEight questions regulated buyers ask us. Scored from each vendor's public docs. DataShield vs Microsoft Purview at a glance Eight questions regulated buyers ask us. Scored from each vendor's public docs. DataShield Purview Tamper-evident audit chain you can verify Authority re-checked on every governed tool call Break-glass access for agents Reversible tokenization at ingest Runs outside a Microsoft tenant Reach into Microsoft 365 and Copilot Catalog breadth: domains, products, quality, OKRs eDiscovery, records and DLP in one portal shipped partial / roadmap not offered Sources at the bottom of this page.

The short version

Pick DataShield when

  • Someone will ask you to prove an agent's log was not edited. Not search it. Prove it. Our chain answers with math. Run the verifier.
  • You need to pull an agent's authority mid-session and have the very next tool call fail closed.
  • The agents that matter are not Microsoft agents. Purview's own matrix marks Claude Enterprise and ChatGPT Enterprise agents as unsupported for both information protection and compliance management.
  • The policy engine, the vault and the evidence have to run on your own infrastructure, on keys you hold.

Pick Microsoft Purview when

  • Your data and your agents both live in the Microsoft tenant. Nothing third-party matches that reach into SharePoint, Exchange, Teams and Copilot.
  • The compliance office is buying. Audit, eDiscovery, Records Management, Communication Compliance and Compliance Manager are real products with real users.
  • You want a business-facing catalog: governance domains, data products, critical data elements, quality scores, OKRs and health controls. Ours is thinner and only covers PostgreSQL.
  • It is already on the bill. E5 money is spent money, and that argument wins a lot of meetings.

Bottom line: Purview governs the Microsoft estate. We govern the data an agent touches and keep proof of every decision, wherever that agent runs. Most of our buyers keep both, and the line between them is the tenant boundary.

Feature by feature

Competitor cells describe what Microsoft's public docs say as of the date above. If we have mischaracterised something, email support@myorg.ai and we will correct it, credited.

What mattersDataShieldMicrosoft PurviewEdge
Audit evidenceSHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained. Verification names the failure: tampering, insertion, deletion or truncation. Try the verifier.The unified audit log: searchable, exportable, and kept 180 days by default. Premium holds Entra, Exchange, OneDrive and SharePoint records a year; ten years needs a per-user add-on and is not retroactive. We found no cryptographic tamper evidence.
Agent authorizationEvery governed tool call passes a scope ceiling, an authority tier and a revocation re-check before dispatch. The call fails closed.Labels, DLP rules and audit capture around named apps. Per their docs, agents inherit the protections of their parent AI app. We found no per-call decision point for an agent.
Break-glassScoped, time-boxed emergency access for agents. It auto-revokes and cannot be quietly deleted from the log.Privileged Access Management exists for admin tasks. Nothing agent-shaped that we could find.
GDPR erasureCrypto-shred of per-subject key material plus ISO 27560 consent receipts. The audit chain still verifies afterwards.Retention policies, Data Lifecycle Management and eDiscovery-driven deletion. That is a workflow, not a cryptographic mechanism.
TokenizationDeterministic, join-preserving, vault-reversible tokens applied at ingest, plus quasi-identifier generalization (dates to year, decade or age band; ZIPs to 3 or 4 digits; partial phones, SSNs and emails) with a measured cardinality-reduction score per column. Detokenization is privileged and logged.Sensitivity labels and DLP decide who may read the value. The raw value stays where it is. Purview does not pseudonymize and reverse.
MCP and agentsMore than 200 MCP tools across Ontology, Auth, Corpus and Lighthouse. Auth issues MCP tool tokens with scope ceilings, and meters each call against the agent.No mention of MCP server support or MCP tool-call auditing anywhere in the Purview docs we read. Agent governance runs through Entra registration and the Copilot surfaces.
Non-Microsoft agentsAny MCP client, any IdP we federate to over SAML or OIDC. Nothing about the control plane assumes a vendor.Their own agent matrix marks Anthropic Claude (Enterprise) agents unsupported for both columns, and ChatGPT Enterprise agents unsupported except for classification and Insider Risk.
Catalog and discoveryWe scan, profile and classify a live PostgreSQL source in place, with no rows leaving it, against 129 field classes covering PII, PHI, financial data and secrets. There is a materialized glossary, typed lineage with per-hop access gating and a 29-command stewardship workflow. PostgreSQL today, not your whole estate.Data Map scans Azure sources plus S3, Redshift, BigQuery, Snowflake, Oracle, SAP and more. Unified Catalog adds governance domains, data products, critical data elements, quality rules and OKRs. Far broader than us.
Microsoft 365 reachNone. We do not see SharePoint, Exchange, Teams or Copilot prompts.Deep, and nobody else can match it. Prompts and responses land in the unified audit log with the labels of the files touched.
Compliance suiteConsent receipts, erasure mechanics, retention and a signed evidence ledger. No eDiscovery, no records management, no communication compliance.Audit, eDiscovery, Records Management, Data Lifecycle Management, Communication Compliance and Compliance Manager, with regulatory templates for AI rules.
DeploymentSelf-hosted in your own cloud or data center, or a dedicated single-tenant server we operate. Docker images for Auth, Ontology, Corpus and Lighthouse. Ed25519 audit-signing keys can live in your own KMS or HSM. HMAC tokenization keys sit in your environment today, not in a KMS.SaaS inside your Azure tenant. Non-Azure sources are scanned through a self-hosted integration runtime you install, but the control plane stays in Azure.
PricingPublished model, scoped instant quote, no sales wall.Consumption meters: Unified Catalog per governed asset per month, a governance processing unit worth 60 minutes of compute, Audit per 1,000 records ingested, and more. The public page shows the meters with the dollar figures blanked until you sign into the calculator.
Maturity signalsAuth, Guardian and Lighthouse are live in production (Guardian and Lighthouse since April 2026). SOC 2 not yet certified, and we say so.Microsoft. Every certification you can name, at platform level, and a reference list longer than our roadmap.

◆ DataShield leads◇ Microsoft Purview leads◈ comparable

Purview claims are drawn from learn.microsoft.com and the Azure pricing page, last checked 13 September 2026. We link them below rather than work from memory.

Three things you get here that you won't get from a platform catalog

Evidence, not a search box

The unified audit log is a good search box. It is not an artifact. An examiner who asks whether the March records were edited gets an export and your word for it. Ours is a hash chain with signed checkpoints, and the verifier says what broke, not just that something did. That is the property EU AI Act Article 12 and HIPAA §164.312(b) reviewers care about. Try it in your browser, no signup.

Authority that can change mid-flight

An analyst leaves on a Friday. Their agent is 20 minutes into a 40-minute job. With DataShield the next governed tool call is re-checked against current authority and fails closed. A token lifetime, by design, does not do that. How Auth does it.

The value is gone, not gated

A label decides who may read the name. Tokenizing at ingest means the name is not there to read. The token still joins across datasets, so your analysts keep working, and the raw value comes back only through a privileged, audited vault call. We wrote up the mechanism split in more detail here.

Where Microsoft Purview is genuinely stronger

Start with the obvious. Purview sees things we never will. Prompts and responses from Microsoft 365 Copilot land in the unified audit log with the sensitivity labels of the files that were touched, and no third party gets that without the same Graph and Entra access Microsoft has. Unified Catalog is a real catalog for real business users: governance domains, data products, critical data elements, glossary terms that carry policy, quality scores, OKRs and health controls. Our catalog covers PostgreSQL and nothing else. Their Data Map reaches S3, Redshift, BigQuery, Snowflake, Oracle and SAP. And the compliance suite around it, Audit and eDiscovery and Records, is a set of products people have run for years. One portal, one bill, one vendor.

Here is the push-back, and it is narrow on purpose. Two of Microsoft's own pages set the boundary. The agent matrix marks Anthropic Claude (Enterprise) agents as unsupported for both information protection and compliance management, and ChatGPT Enterprise agents as supported only for classification and Insider Risk. So the governance story covers Microsoft's agents well and other agents barely. Meanwhile the retention clock runs: 180 days by default, a year for a few workloads on Premium, ten years only with a per-user add-on that is not retroactive. Records from service principals and system events, which is what an agent generates, are fixed at one year and the doc says that period isn't configurable. If you need evidence beyond that, you export it and keep it yourself. Microsoft's own storage guidance puts it plainly: you are responsible for storing those logs persistently. That do-it-yourself step is our product.

Questions worth asking both of us

These are the questions we would want answered if we were the ones buying. Ask them on every call, ours included.

Can you cryptographically prove an audit log entry wasn't deleted?

DataShield: yes. Each record commits to the one before it, checkpoints are signed and chained, and verification tells deletion apart from truncation and from tampering. Run it against a sample chain at /verify. Purview: the docs describe search, export to CSV, and the Management Activity API. We found no tamper-evidence mechanism. Ask them to show one, then ask why the export path caps at 50,000 records per search on Standard.

What happens to a revoked agent mid-session?

DataShield re-checks authority on every governed tool call, so revocation lands on the next call. Purview is not the enforcement point here; Entra is, and Entra works on token lifetime and Conditional Access re-evaluation. Ask how long a compromised agent keeps working after you pull its access.

How does GDPR erasure interact with the audit trail?

DataShield crypto-shreds per-subject key material and issues an ISO 27560 consent receipt. Actor identities in the chain are HMAC-committed, so the evidence still verifies once the subject is gone. Purview offers retention policies, Data Lifecycle Management and eDiscovery deletion. Those are workflows over a copy of the data. Ask for the mechanism, not the workflow.

Does Purview support MCP, and does DataShield replace it?

No, and no. We read the Purview docs for AI and agents and found no MCP server, no MCP tool-call auditing and no protocol-level agent controls; governance flows from Entra registration and the Copilot surfaces. We ship more than 200 MCP tools across Ontology, Auth, Corpus and Lighthouse, with tool tokens that carry a scope ceiling. That does not make us a replacement. Keep Purview for the Microsoft estate. Run us for the datasets agents query and for the agents Purview marks unsupported.

We already pay for Purview in E5. Why add anything?

Often you shouldn't. If your agents are Copilots and your data is in the tenant, spend the E5 money and stop. The three cases where people call us anyway: an agent stack that isn't Microsoft, a retention rule longer than the audit clock, and a regulator who wants evidence rather than a search result. One more thing: the Purview meters are separate from the seat price, and the public pricing page shows the meters with the figures blanked until you sign in.

Does DataShield have SOC 2?

Not yet, and we will not imply otherwise. Auth is live with a public threat model and a verifier anyone can run. Guardian and Lighthouse have been in production since April 2026. Design-partner terms include source escrow, so a small vendor is not a single point of failure. Details on the security page.

Other head-to-heads

Same market

DataShield vs Amundsen

DataShield vs Amundsen: LF AI & Data archived Amundsen in September 2026. An honest self-hosted migration.

Same market

DataShield vs Unity Catalog

DataShield vs Unity Catalog: Unity Catalog wins unified governance inside Databricks. We add independent,.

Same market

DataShield vs DataHub

DataShield vs DataHub: DataHub wins on connectors, lineage and open-source catalog depth. DataShield adds.

All

Every comparison

One honest scorecard per vendor.

See both mechanisms run in your browser: break a live audit chain, revoke an agent mid-session, then decide what your tenant still owes you. Demo Center access is free with a work email.

Get free Demo Center access

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →