Head-to-head · updated 13 September 2026
DataShield vs Secoda: who can prove what the AI data assistant actually read?
Secoda calls itself "The AI platform for data and analytics," and the product backs the phrase up. Connect your warehouse and BI tools and you get a clean data catalog, column and table lineage, a glossary, and a chat box that answers questions for people who will never write SQL. They ship Agents that run those chats on a schedule. They ship an MCP server so Claude or Cursor can read the catalog. Atlassian bought them in December 2025 to feed Rovo. It is a good product with a very large company behind it now.
We are not a prettier version of that. DataShield is the layer under the answers. Ontology scans and classifies the data itself against 129 PII, PHI, financial and secret classes. Datasets are tokenized at ingest; agents query tokenized data over MCP; detokenization is a privileged, audited operation. Auth checks an agent's authority on every governed tool call, and seals each decision into a hash chain you can verify without trusting us. Below is the honest split, and Secoda wins several rows.
The short version
Pick DataShield when
- Someone will ask you to prove what an agent read, and prove the log was not edited. An examiner, an auditor, or Article 12 of the EU AI Act. Our chain answers with math. Run the verifier.
- You need to pull an agent's authority mid-session and have the very next tool call fail. Not the next token refresh.
- The columns themselves need work: classified, tokenized, generalized. Labels in a catalog are not enough for your privacy review. See what Ontology does.
- Self-hosting is not a phase you are passing through. You want the catalog, the policy engine and the evidence on your own metal, and you want to see a price first.
Pick Secoda when
- Your estate is wide and mixed. Their connector list covers the modern stack; ours covers PostgreSQL and not much else yet.
- Business users are the audience. Secoda AI answers questions all day for people who do not want a catalog at all, and the reviews say it does it well.
- You already run Jira and Confluence, and the Rovo path is where your company is going anyway. That cross-sell is real money saved.
- You want observability too: monitors, quality scores, query monitoring, data CI/CD. We do not ship any of that.
Bottom line: Secoda tells your people what the data means. DataShield decides what an agent may do with it and keeps proof of the decision. Plenty of teams will run both, and that is a fine answer.
Feature by feature
Competitor cells describe what Secoda's public site and docs say as of the date above. If we have mischaracterised something, email support@myorg.ai and we will correct it, credited.
| What matters | DataShield | Secoda | Edge |
|---|---|---|---|
| Catalog and connector breadth | We register a provider over a live connection, scan it, and profile assets and columns in place. No rows leave the source. That is PostgreSQL today. Snowflake, BigQuery, Databricks, S3 and Salesforce are declared and not built. | The core of the product, and broad. Warehouses, BI tools, transformation tools, plus a Chrome extension that puts context where people work. | ◇ |
| Lineage | Typed lineage you traverse as edges, with access gating at every hop. It is derived from the pipelines that own the data, not a stored column graph. Honest limit: it is narrower than theirs. | End to end, column and table level, and a headline feature since their Series A. Better than ours. | ◇ |
| PII and PHI classification | 129 field classes covering PII, PHI, financial data and secrets, including all 18 HIPAA Safe Harbor identifiers. Regex plus checksum validation (Luhn, NPI, Verhoeff, ABA, IBAN), column-name lexicons and anti-pattern suppressors. No model, so verdicts are reproducible from a config digest. It shipped this month, and we say so. | PII scanning is listed as a Premium plan feature. Their 2023 launch described an assistant that tags personal data for documentation. We found no published class list or method. | ◆ |
| Tokenization and generalization | Deterministic, join-preserving, vault-reversible tokens at ingest, plus quasi-identifier generalization (dates to year, decade or age band; ZIPs to 3 or 4 digits; partial phones, SSNs and emails) with a measured cardinality-reduction score per column. Masking and generalization are switches you turn on, not defaults. | Not vocabulary they use. A catalog labels columns; it does not transform them. | ◆ |
| Sample values in the catalog | Default policy is omit. No column value is copied into the catalogue. Storing plaintext samples needs an explicit acknowledgement and writes an audit row. | Not described in their public docs. Worth asking, since a catalog that previews values is a copy of your sensitive data in a second place. | ◆ |
| Audit evidence | SHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained. The verdict is three-valued: clean, attested damage, or tampered. Verification names the failure. Try the verifier. | Audit logging and SIEM log export on Enterprise. We found no cryptographic tamper evidence in their material. | ◆ |
| Agent authorization | Every governed tool call passes a scope ceiling, a consented-tool allowlist, an authority tier, and a revocation re-check before dispatch. It fails closed. Delegation is RFC 8693 token exchange with an enforced scope ceiling. | Their MCP server inherits the authenticated user's workspace permissions and RBAC. That is a sensible floor. It is not a per-call decision point you can point an auditor at. | ◆ |
| Break-glass | Scoped, time-boxed emergency access for agents, admin and step-up gated, IP allowlisted, fully audited. It auto-revokes. | Not described in their public material. | ◆ |
| GDPR erasure | Crypto-shred of per-subject key material, plus ISO 27560 consent receipts. Actor identities in the chain are HMAC-committed, so the evidence still verifies after the subject is gone. | Policies and access request workflow. The erasure mechanism is not described. | ◆ |
| MCP and agents | More than 200 MCP tools across Ontology, Auth, Corpus and Lighthouse. Auth issues MCP tool tokens with scope ceilings, and meters every call with the agent attributed. | A live MCP server since August 2025 for Claude, Cursor and VS Code, serving search, docs, lineage and glossary, and able to run SQL on your connected warehouse. Plus scheduled Agents: saved AI chats that run on a cadence with a run history. | ◈ |
| Observability and quality | Profiling and anomaly checks on datasets we hold. No monitors, no quality score, no query monitoring, no data CI/CD. | All four ship. This is a real product area for them and a blank on our roadmap. | ◇ |
| Deployment | Self-hosted in your own cloud or data center, or a dedicated single-tenant server we operate. Docker images for Auth, Ontology, Corpus and Lighthouse, with a signed deploy manifest Guardian verifies. Ed25519 audit-signing keys can live in your KMS or HSM. HMAC tokenization keys sit in your environment today, not in a KMS. | SaaS first. Self-hosting is documented and real (ECS Terraform, EKS, GKE, Helm, Docker Compose) but gated to the Enterprise plan. Their acquisition post says infrastructure will gradually migrate to Atlassian's Cloud Platform. | ◈ |
| Maturity signals | Live in production, with Guardian and Lighthouse since April 2026. SOC 2 not yet certified, and we will not imply otherwise. Small team, source escrow on design-partner terms. | Founded 2021, Y Combinator, about $16.3M raised, SOC 2, a long logo wall, strong G2 ratings, and now owned by Atlassian. | ◇ |
| Pricing | Published model and a scoped instant quote, no sales wall. | Core, Premium and Enterprise, all listed as contact sales. Third-party sites still quote an older $99 Starter tier; Secoda's own page publishes no numbers today. | ◆ |
◆ DataShield leads◇ Secoda leads◈ comparable
Secoda claims are drawn from secoda.co, docs.secoda.co and Secoda's own blog posts, last checked 13 September 2026. We link them below rather than work from memory.
Three things you get here that you won't get from a data catalog
Proof that survives an audit
A log that can be quietly edited proves nothing. Ours is a hash chain with signed checkpoints, and the verifier tells you what broke: tampering, insertion, deletion, or truncation. That is the property EU AI Act Article 12 and HIPAA §164.312(b) reviewers care about. Try it in your browser, no signup.
Authority that can change mid-flight
An analyst resigns on a Friday. Their agent is 20 minutes into a 40-minute job. With DataShield the next governed tool call is re-checked against current authority and fails closed. A catalog with RBAC will let that job finish, then log it neatly. How Auth does it.
Work done on the column, not the label
Tagging a column email is documentation. Turning it into a token an agent can join on, and generalizing the birth date to a year, is control. We do the second, then record that we did. What Ontology ships.
Where Secoda is genuinely stronger
Their connector coverage is wider than ours and will stay that way. Their lineage is column level across a full stack; ours is typed edges over the pipelines we own, gated per hop, and narrower. The chat front door is the part we admire most. A business user asks a question in plain English and gets a trusted answer, and the ROI dashboard they shipped in 2025 exists because that keeps happening. They have SOC 2. We do not. They have Atlassian's balance sheet and a path into every Jira tenant on earth. We have a small team and a verifier you can run in a browser tab.
Here is the push-back, and it is one sentence long in their own acquisition post: infrastructure will gradually migrate to Atlassian's Cloud Platform. If you picked Secoda partly because you could run it yourself, ask what that migration means for your self-hosted install, and ask for it in writing. Then ask the second question. Their MCP server can execute SQL against your connected warehouse, scoped to the user's permissions. Permissions are the right floor and the wrong ceiling. They tell you a query was allowed at the time. They do not re-check authority on the next call, they do not fail closed when someone is revoked mid-job, and they do not hand you an artefact an examiner can verify independently. That layer is what we sell, and it sits under a catalog like theirs without complaint.
Questions worth asking both of us
These are the questions we would want answered if we were the ones buying. Ask them on every call, ours included.
Can you cryptographically prove an audit log entry wasn't deleted?
DataShield: yes. Each record commits to the one before it, checkpoints are signed and chained, and verification tells deletion apart from truncation and from tampering. Run it against a sample chain at /verify. Secoda: Enterprise plans include audit logging and SIEM export. We found no tamper-evidence mechanism in their public docs. Ask them to show one.
What happens to a revoked agent mid-session?
DataShield re-checks authority on every governed tool call, so revocation lands on the next call. Secoda's MCP server honours the authenticated user's workspace permissions and RBAC. We could not find a mid-session revocation mechanism in their docs. Ask how long a revoked agent keeps working, and whether the answer is measured in calls or in hours.
How does GDPR erasure interact with the audit trail?
DataShield crypto-shreds per-subject key material and issues an ISO 27560 consent receipt. Actor identities in the chain are HMAC-committed, so the evidence still verifies once the subject is gone. Secoda ships policies and access requests. What happens to the underlying data, and to the history, is not spelled out. Ask for the mechanism, not the workflow.
Is DataShield a Secoda alternative, or do we need both?
Depends what you are buying it for. If you want a catalog for the whole estate with an AI front door for business users, buy Secoda, because we cannot cover that estate yet. If your problem is that agents are reading regulated columns and nobody can prove what they saw, that is ours. A team that runs a warehouse on PostgreSQL and needs classification, tokenization and evidence in one self-hosted stack can reasonably run us alone. Most others will run both.
Secoda ships an MCP server too. What's different?
Theirs, live since August 2025, gives an AI assistant search, documentation, lineage, glossary, and the ability to run SQL against your connected warehouse under the user's permissions. That is a good design for a catalog. Ours is where the governed data is queried, so the tool token carries a scope ceiling, the call is authorized before dispatch, the agent is attributed and metered, and the decision is sealed into the chain. Different jobs. One gives an agent context. The other gives you an account of what it did.
Now that Atlassian owns Secoda, does that change the comparison?
It cuts both ways, and we will not pretend it is all bad news for them. They gained distribution, money and a roadmap inside Rovo. What changed for a regulated buyer is the hosting question. Their own post from 4 December 2025 says infrastructure will gradually migrate to Atlassian's Cloud Platform. If your data residency rule or your BAA depends on where the thing runs, get the self-hosted commitment in your contract. We are independent, we ship Docker images, and there is no second company whose cloud strategy sets ours.
Does DataShield have SOC 2?
Not yet, and Secoda does. That is a fair point against us and we are not going to talk around it. What we offer instead is a published threat model, a verifier anyone can run, and source escrow on design-partner terms so a small vendor is not a single point of failure. Details on the security page.
- Secoda's current positioning: "The AI platform for data and analytics," powered by "enterprise data governance and context across your entire data stack." — secoda.co, 13 Sep 2026
- Atlassian acquired Secoda to feed structured data into Rovo; the post states infrastructure will gradually migrate to Atlassian's Cloud Platform. — Secoda blog, 4 Dec 2025
- Independent coverage of the acquisition: a data catalog for Atlassian's Rovo AI. — TechTarget, 5 Dec 2025
- Secoda's MCP server lets Claude, Cursor and VS Code search the catalog, read lineage, glossary and documentation, and "execute SQL queries directly on your connected data warehouse," scoped to the authenticated user's permissions. — Secoda blog, 26 Aug 2025
- Agents launch: "Scheduled Secoda AI chats that run automatically on a cadence, with a complete run history saved in the Chat interface," plus AI Automation blocks and an Impact dashboard. — Secoda blog, 16 Sep 2025
- Pricing lists Core, Premium and Enterprise as contact sales; PII scanning sits on Premium and self-hosted deployment on Enterprise. — secoda.co/pricing, 13 Sep 2026
- Self-hosted Secoda ships as container images via an AWS ECS Terraform module, automated EKS and GKE deployments, a generic Helm chart, or Docker Compose for trials. — docs.secoda.co, 13 Sep 2026
Other head-to-heads
DataShield vs Atlan
Active metadata for humans, versus authority for agents.
CatalogDataShield vs Alation
The enterprise catalog, and the evidence layer it doesn't ship.
Open sourceDataShield vs OpenMetadata
Free to run, but who pays for the audit trail?
AllEvery comparison
One honest scorecard per vendor.
See both mechanisms run in your browser: break a live audit chain, revoke an agent mid-session, then decide what your catalog still owes you. Demo Center access is free with a work email.
Get free Demo Center accessYou've seen the proof
Ready for a number? Scope your deployment and we'll price it against your own economics.
Get your quote →