Head-to-head · updated 13 September 2026

DataShield vs Telmai: is the table behaving, or is the data safe to hand an agent?

Telmai watches data as it lands. Point it at a lake or lakehouse and it builds ML baselines per column, then flags anomalies, schema changes and drift before the dashboard breaks. On Google Cloud it runs inside your own account and reads the same Iceberg catalog as BigQuery, with no copies leaving. Their own post cites ZoomInfo at over a billion data points a day, with no sampling. GigaOm made them a Leader in 2023 and again in 2024. They hold SOC 2 Type 2. We do not, and we say so on this page.

We do a different job. DataShield does not monitor your pipelines. We profile and score the datasets an agent is about to read, name what sits in each column, then keep proof of what the agent did next. Every dataset gets a 20-section profile and a weighted trust score per domain. Our classification is deterministic: same data, same config, same verdict, stamped so you can re-run it and diff it. Datasets are tokenized at ingest; agents query tokenized data over MCP; detokenization is a privileged, audited operation. Here is the honest split, rows Telmai wins included.

DataShield vs Telmai at a glanceEight questions regulated buyers ask us. Scored from each vendor's public material. DataShield vs Telmai at a glance Eight questions regulated buyers ask us. Scored from each vendor's public material. DataShield Telmai Tamper-evident audit chain you can verify Authority re-checked on every governed tool call Break-glass access for agents Erasure that keeps the audit chain valid PII and PHI classification on every column Anomaly detection on tables and pipelines Incident triage and alert routing SOC 2 Type 2 today shipped partial / roadmap not offered Sources at the bottom of this page.

The short version

Pick DataShield when

  • Someone will ask you to prove an agent's access log was not edited. An auditor, a regulator, or Article 12 of the EU AI Act. Our chain answers with math, not a policy PDF. Run the verifier.
  • You need to pull an agent's authority mid-session and have the very next tool call fail. Not the next token refresh. The next call.
  • You need to know which columns hold PII or PHI, with a verdict you can re-derive next quarter and get the same answer.
  • The data plane, the policy engine and the evidence all have to run on your own hardware, on keys you hold. And you would like a price before the call.

Pick Telmai when

  • The pain is a broken pipeline, not a nosy agent. You want to hear about a bad load at 3am, and we send nobody a page at 3am.
  • Your data lives in a lakehouse on Iceberg or Delta, at a scale where sampling is a lie. That is the ground they built on.
  • You want incident triage, routing and plain-language diagnosis in the product, run by their named agent suite.
  • Procurement wants SOC 2 Type 2 on the vendor list this quarter. They have it. We are not there yet.

Bottom line: Telmai tells you the table is behaving. We tell you what is in the table, score it, and prove what the agent did with it. Most teams who buy us already own a monitoring tool, and we would rather they kept it.

Feature by feature

The Telmai cells describe what their site and blog say as of the date above. If we have got something wrong, email support@myorg.ai and we will fix it, with credit.

What mattersDataShieldTelmaiEdge
How data quality gets scoredA 20-section profile per dataset: completeness, field statistics, patterns, column semantics, relationship graph, quality metrics, business rules, lineage and compliance governance. On top sits a weighted trust score per entity type, domain and estate, with a per-axis breakdown and a trend, recomputed hourly. It is deterministic, so two runs on the same data agree."ML-driven and rule-based checks" over live tables, with baselines learned per column and user-defined expectations on top. Strong for drift. Harder to re-derive a score six months later.
Monitoring, incidents and source coverageWe have none of the monitoring half. No anomaly detector, no alerts on warehouse tables, no freshness SLAs, no incident queue. We do ship change and drift detection across dataset versions: a diff engine, a change classifier, schema evolution and a CDC log. On coverage we scan, profile and classify a live PostgreSQL source in place with no rows leaving it, plus file ingest and storage watching. PostgreSQL today, not your whole estate.The core of the product, and the best part. Anomaly detection, consistency checks, incident management, routing, and a named agent suite that diagnoses in plain language. Lake and lakehouse first: Iceberg, Delta and flat files through the Iceberg REST catalog, plus OneLake and Google Cloud.
PII and PHI classification129 field classes covering PII, PHI, financial data and secrets, with checksum validators, anti-pattern suppression and per-class confidence. Every verdict carries a config digest and a rule version, so you can re-run it and diff the result. The catalog also does source-system fingerprinting across 95 built-ins.We could not find sensitive-data classification in their public material. Their quality signals are about shape and behaviour, not about what the value means under HIPAA.
Audit evidenceA SHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained. Verification names the failure: tampering, insertion, deletion or truncation. Try the verifier.Data health KPIs published into the catalog, and quality history. We found no cryptographic tamper evidence over the log of who did what.
Agent authorizationEvery governed tool call passes a scope ceiling, an authority tier and a revocation re-check before dispatch. The call fails closed.Not their layer. Their agents read and explain data health. We found no per-call decision point on data access.
Break-glassScoped, time-boxed emergency access for agents. It revokes itself and cannot be quietly deleted from the log.Not described in their public material.
GDPR erasureCrypto-shred of per-subject key material plus ISO 27560 consent receipts. The audit chain still verifies after the subject is gone.Not described in their public material. Fair enough: a monitoring tool is rarely the system of record for a subject.
Tokenization and maskingDeterministic, join-preserving, vault-reversible tokens applied at ingest. Plus quasi-identifier generalization: dates to year, decade or age band, ZIPs to 3 or 4 digits, partial phones, SSNs and emails, with a measured cardinality-reduction score per column. Masking and generalization are switches you turn on, not defaults.Not part of the product. They validate data; they do not de-identify it.
MCP and agentsMore than 200 MCP tools across Ontology, Auth, Corpus and Lighthouse. Tool tokens carry a scope ceiling, calls are authorized before dispatch, and per-call metering is attributed to the agent.An MCP-compliant server that lets agents such as Claude, Bedrock or Vertex query validated data and quality metadata. Announced October 2025, with a waitlist CTA still next to the agent suite on their home page.
DeploymentSelf-hosted in your own cloud or data center, or a dedicated single-tenant server we operate. Docker images for Auth, Ontology, Corpus and Lighthouse. Ed25519 audit-signing keys can live in your KMS or HSM. HMAC tokenization keys sit in your environment today, not in a KMS, and we will not pretend otherwise.SaaS, plus a customer-account model on Google Cloud that their own post describes as zero-copy and running inside your own cloud account, reading your Iceberg catalog with no copies leaving your environment. Better than the SaaS-only story we expected.
Maturity and certificationLive in production, with Guardian and Lighthouse there since April 2026. SOC 2 not yet certified. Design-partner terms include source escrow.Founded 2021. SOC 2 Type 2, GigaOm Leader in 2023 and 2024, G2 badges in 2025, and named customers including Bill.com, PropertyGuru Group and Zip Co. Funding is not public.
PricingPublished model, scoped instant quote, no sales wall.Quote only. We found no pricing page at all on 13 September 2026.

◆ DataShield leads◇ Telmai leads◈ comparable

Telmai claims are drawn from telm.ai and the Telmai blog, last checked 13 September 2026. We link the posts below rather than work from memory.

Three things you get here that you won't get from a data observability platform

Proof that survives an audit

A log that can be quietly edited proves nothing. Ours is a hash chain with signed checkpoints, and the verifier tells you what broke, not just that something did. That is the property EU AI Act Article 12 and HIPAA §164.312(b) reviewers ask about. Try it in your browser, no signup.

Authority that can change mid-flight

An analyst leaves on a Friday. Their agent is 20 minutes into a 40-minute job. With DataShield the next governed tool call is re-checked and fails closed. A monitoring layer would file you a nice incident about it on Monday. How Auth does it.

A verdict you can re-run

Ask a model why it scored a column and you get a story. Ask our classifier and you get a config digest and a rule version. Run it again next quarter and the answer matches, or the diff tells you which rule changed. See the catalog.

Where Telmai is genuinely stronger

Let us be plain. Telmai does a job we do not do at all. They sit at the point where data lands and watch it, at volumes where sampling would be dishonest, and they do it on open formats through the Iceberg catalog your query engines already read. Their Google Cloud work runs in the customer's own account with no copies leaving, which is a better answer than most observability vendors give. They plug into Atlan, OneLake and Dataplex instead of asking you to rip anything out. GigaOm rated them a Leader two years running, they carry SOC 2 Type 2, and we carry neither. If a bad load is what keeps you up, buy them.

Here is the push-back. Their agent suite reads quality signals and explains them. It does not decide what an agent may do with the data, and health KPIs in a catalog are not evidence. Quality and sensitivity are also different questions. A column can pass every freshness and drift check while holding plaintext medical record numbers, and a baseline will never tell you that, because nothing about the shape of the data is off. One more thing worth asking on the call: an ML baseline is a moving judgment. When a regulator asks why a dataset was cleared for use in March, a learned threshold from March is a hard thing to reproduce. Ours is a config digest you can replay.

Questions worth asking both of us

These are the questions we would want answered if we were buying. Ask them on every call, ours included.

Can you cryptographically prove an audit log entry wasn't deleted?

DataShield: yes. Each record commits to the one before it, checkpoints are signed and chained, and verification tells deletion apart from truncation and from tampering. Run it on a sample chain at /verify. Telmai: their material covers data health KPIs and quality history, not tamper evidence over an access log. Ask them to show one if it exists.

What happens to a revoked agent mid-session?

DataShield re-checks authority on every governed tool call, so revocation lands on the next call, not the next refresh. Telmai's agents are about data health, and we found no access-revocation mechanism in their public docs. Ask how long a compromised agent keeps reading after you pull its access.

How does GDPR erasure interact with the audit trail?

DataShield crypto-shreds per-subject key material and issues an ISO 27560 consent receipt. Actor identities in the chain are HMAC-committed, so the evidence still verifies once the subject is gone. Telmai does not describe an erasure mechanism, which is reasonable for a monitoring tool. Ask both of us for the mechanism, not the workflow.

Does DataShield replace Telmai? Do we drop our data observability platform?

No. We have no anomaly detection, no monitors on warehouse tables, no freshness SLAs and no incident queue. If that is your problem, keep the tool that solves it. Run us on the governed datasets agents actually read, where the job is profiling, classification, authorization and evidence. Plenty of teams will sensibly run both.

ML baselines or deterministic checks: which is better?

It depends on the question. For "did this table just get weird", a learned baseline wins, and that is Telmai's ground. For "is this column a medical record number" and "can you show the same answer in six months", a learned score is the wrong tool. Ours is rule-based with checksum validation, stamped with a config digest and a rule version. There is no model in the path and nothing to drift.

Does DataShield have SOC 2?

Not yet, and we will not imply otherwise. Telmai has SOC 2 Type 2 and we do not. What we offer instead is a published threat model, a verifier anyone can run, and source escrow in design-partner terms, so a small vendor is not a single point of failure. Details on the security page.

Other head-to-heads

Same market

DataShield vs Datafold

DataShield vs Datafold: Datafold owns value-level data diff and AI migrations. We classify the sensitive.

Same market

DataShield vs Qualytics

DataShield vs Qualytics: Qualytics scores and monitors the data an AI system reads. DataShield decides.

Same market

DataShield vs Lightup

DataShield vs Lightup: Lightup monitors pipelines with zero-config anomaly detection. DataShield classifies,.

All

Every comparison

One honest scorecard per vendor.

See both mechanisms run in your browser: break a live audit chain, revoke an agent mid-session, then decide what your monitoring tool still owes you. Demo Center access is free with a work email.

Get free Demo Center access

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →