Head-to-head · updated 13 September 2026
DataShield vs TIBCO EBX: who governs the golden record once an agent is the one reading it?
EBX has been doing master data management for longer than most data teams have existed. It now trades as ON EBX, with offices in Fort Lauderdale and Paris, and it claims 26 years of the work. The pitch is model-driven MDM. You define the model, and the platform hands you the screens, the workflows, the hierarchies, the reference data and the golden records. PostNL, Panera Bread and Rabobank are named customers. That is a real product with real scars, and we are not going to pretend otherwise.
We come at the same job from the agent end. DataShield Ontology does entity resolution too, and we publish the method: Fellegi-Sunter probabilistic linkage, Jaro-Winkler and Double Metaphone comparators, LSH blocking, EM-trained parameters, five survivorship strategies. What differs is the ring around it. Datasets are tokenized at ingest; agents query tokenized data over MCP; detokenization is a privileged, audited operation. Every governed tool call is checked against the agent's authority before it runs, and the decision is sealed into a hash chain you can verify without trusting us. Here is the honest split, rows EBX wins included.
The short version
Pick DataShield when
- Agents, not just stewards, are about to read your golden records. Ours sit behind masked views, MCP tool tokens and a per-call authority check. How Auth does it.
- Someone will ask you to prove the match trail was not edited later. An examiner, an auditor, or Article 12 of the EU AI Act. Our chain answers with math. Run the verifier.
- You want the matching method written down, not described as configurable. We name ours: Fellegi-Sunter linkage, EM-trained m and u values, and a Population Stability Index check on every promoted match config. See Ontology.
- You would like a price before you book a call. Ours is published.
Pick TIBCO EBX when
- You need real multi-domain modelling. Customer, product, location and assets in one model, with cross-domain relationships and hierarchies that do not duplicate. EBX was built for that shape of problem and we were not.
- Reference data management is the actual job. Codes, classifications, standards, controlled updates and approval chains across dozens of systems. This is EBX home turf, and Rabobank is their proof of it.
- Business users must own the data day to day. EBX ships them screens, review workflows and stewardship roles out of the box. We ship MCP tools and a stewardship queue, which is a different kind of gift.
- A system from 2009 still runs the business and it speaks SOAP or JMS. EBX lists both, plus a Java extension point. We do REST and MCP, and that is the whole list.
Bottom line: EBX models and governs master data for people, and does it well. DataShield builds the golden record and then governs who may read it when the reader is an agent. If your MDM programme is a multi-year multi-domain rollout, buy EBX. If agents are querying customer data this quarter, the proof problem bites first.
Feature by feature
Competitor cells describe what ON EBX's public site says as of the date above. If we have mischaracterised something, email support@myorg.ai and we will correct it, credited.
| What matters | DataShield | TIBCO EBX | Edge |
|---|---|---|---|
| Multi-domain modelling | An open entity-type vocabulary with per-type matching modes, a People/Places/Things business category, parent-scoped hierarchies and validation rules that gate golden publication. It is real, and it is not a modelling studio a business analyst will drive on their own. | The core of the product and the reason people buy it. Model-driven data structures, cross-domain relationships and hierarchies, without prepackaged schemas. | ◇ |
| Reference data management | Curated reference datasets and a business glossary materialized from entity types. Useful, narrower than a dedicated RDM tool. | A named capability with its own use case: standardized datasets, controlled updates and approvals, cross-system consistency, definitions and classifications. | ◇ |
| Matching and survivorship | Fellegi-Sunter probabilistic record linkage with Jaro-Winkler, Levenshtein, Soundex and Double Metaphone comparators, LSH blocking, EM-trained parameters, five survivorship strategies, and Population Stability Index drift monitoring on promoted configs. An absolute-identifier tier routes identifier conflicts to review instead of merging blind. | "Smart match and merge": configurable match, merge and survivorship rules with transparent match results for stewardship. No linkage model, comparator set, training method or drift check is named publicly. | ◆ |
| Audit evidence | SHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained. Verification returns clean, attested damage, or tampered, and names the break. Try the verifier. | Audit trails and lifecycle tracking, plus lineage and traceability. We found no cryptographic tamper-evidence claim in their material. | ◆ |
| Agent authorization | Every governed tool call passes a scope ceiling, a consented-tool allowlist, an authority tier and a revocation re-check before dispatch. The call fails closed. | Permissions, roles and access control for users and services. Agents are not mentioned anywhere on their site. | ◆ |
| Break-glass | Scoped, time-boxed emergency access for agents, admin and step-up gated, auto-revoking, and it cannot be quietly removed from the log. | Not described in their public material. | ◆ |
| GDPR erasure | Crypto-shred: deleting the subject key destroys every ciphertext for that subject at once, with an ISO 27560 consent receipt at grant and withdrawal. The audit chain still verifies afterwards. | Lifecycle control, versioning and retirement of records. The erasure mechanism is administrative deletion as far as their docs describe it. | ◆ |
| Tokenization and masking | Deterministic, join-preserving, vault-reversible tokens applied at ingest, plus quasi-identifier generalization (dates to year, decade or age band; ZIPs to 3 or 4 digits; partial phones, SSNs and emails) with a measured cardinality-reduction score per column. Masked golden views mask unconditionally. Matching runs on real source values, so a tokenized-at-rest match field makes the run refuse rather than mega-merge. | Not vocabulary they use. Data protection is expressed as permissions and validation. | ◆ |
| MCP and agents | More than 200 MCP tools across Ontology, Auth, Corpus and Lighthouse, with MCP tool tokens carrying scope ceilings and per-call metering attributed to the agent. The MDM tool alone dispatches 99 commands. | REST, SOAP/WSDL, JMS, file import and export, and Java extensibility. No MCP server, and no agent surface we could find. | ◆ |
| AI features | No copilot. We do not proxy your LLM traffic. We do gate every value that leaves a governed dataset for a prompt, and a PHI dataset refuses an endpoint without a BAA. | An embedded AI Assistant for record-level steward tasks, plus AI-assisted enrichment with human oversight. Their AI story is about feeding models better data, which is a fair and different bet. | ◈ |
| Deployment | Self-hosted in your own cloud or data center, or a dedicated single-tenant server we operate. Docker images ship for Auth, Ontology, Corpus and Lighthouse, and a signed deploy manifest is verified by Guardian. Ed25519 audit-signing keys can live in your KMS or HSM; HMAC tokenization keys sit in your environment today, not in a KMS. | On-premises, hybrid, and cloud-supported. The 2022 TIBCO Cloud EBX SaaS branding has not carried over to the new site. | ◈ |
| Maturity signals | Auth, Guardian and Lighthouse are live in production (Guardian and Lighthouse since April 2026). SOC 2 not yet certified, and we say so. | 26 years of MDM behind them, named customers in logistics, food service and banking, and a support organisation with two offices. Long enterprise track record. | ◇ |
| Pricing | Published model, scoped instant quote, no sales wall. | Quote only. No price, no trial, no free tier. The demo request on every page is a Google Form. | ◆ |
◆ DataShield leads◇ TIBCO EBX leads◈ comparable
ON EBX claims are drawn from onebx.com and docs.onebx.com, last checked 13 September 2026. We link them below rather than work from memory.
Three things you get here that you won't get from an MDM suite
A match you can argue with
"Configurable rules" is not a method. Ours is Fellegi-Sunter linkage: each field comparison carries an m and a u probability, the weights add up, and the score is a probability you can inspect. The parameters are trained with EM, not guessed. When a promoted config drifts, a Population Stability Index check says so. See how Ontology does MDM.
Proof that survives an audit
A merge log that can be silently edited proves nothing about the merge. Ours is a hash chain with signed checkpoints, and verification tells you what broke, not just that something did. That is the property EU AI Act Article 12 and HIPAA §164.312(b) reviewers care about. Try it in your browser, no signup.
Authority that can change mid-flight
A supplier analyst leaves on a Friday. Their agent is 20 minutes into a 40-minute reconciliation across your golden supplier records. With DataShield the next governed tool call is re-checked against current authority and fails closed. A workflow engine notices on Monday. How Auth does it.
Where TIBCO EBX is genuinely stronger
We would rather you heard this from us. EBX is model-driven in a way we are not, and that matters more than it sounds. You describe customer, product, location and asset in one model, with the relationships and hierarchies between them, and the platform generates the editing screens, the validation, the approval workflow and the lifecycle. A data steward in the finance office can then run it without asking an engineer for anything. Reference data is a first-class product there, not a side effect, which is why a bank like Rabobank uses them for exactly that. They carry 26 years of implementations, three published customer stories, and a legacy integration surface we cannot match: SOAP, JMS, Excel import, Java extension points. If your estate still talks in those verbs, that is not nostalgia, it is a requirement.
Here is the push-back. Their whole AI story points upstream. Better structured data, richer context, an assistant that helps a steward finish a record. All good, and none of it answers the question a 2026 risk committee actually asks: an agent read the golden customer record at 03:12, under whose authority, and can you prove that line was not edited afterwards? ON EBX publishes audit trails and lineage. It does not publish tamper-evidence, per-call authorization, mid-session revocation, or a crypto-erase that leaves the audit history standing. Those are the four things we built first, because we started from the agent and worked backwards, and they started from the model and worked forwards. Both are defensible. Only one of them has a verifier you can run yourself.
Questions worth asking both of us
These are the questions we would want answered if we were the ones buying. Ask them on every call, ours included.
Can you cryptographically prove an audit log entry wasn't deleted?
DataShield: yes. Each record commits to the one before it, checkpoints are Ed25519-signed and chained, and verification tells deletion apart from truncation and from tampering. Run it against a sample chain at /verify. ON EBX: their platform page lists "audit trails and lifecycle tracking" and lineage. We found no tamper-evidence mechanism described. Ask them to show one.
What happens to a revoked agent mid-session?
DataShield re-checks authority on every governed tool call, so revocation lands on the next call, not the next token refresh. ON EBX describes roles, permissions and access control for its data services. Agents are not in their vocabulary at all, so there is nothing to compare. Ask how long a compromised service account keeps reading golden records after you pull its access.
How does GDPR erasure interact with the audit trail?
DataShield crypto-shreds the subject key, which destroys every ciphertext for that subject at once, and issues an ISO 27560 consent receipt. Actor identities in the chain are HMAC-committed, so the evidence still verifies once the subject is gone. ON EBX offers versioning, lifecycle control and retirement. That reads as administrative deletion. Ask for the mechanism, not the workflow, and ask what the audit history looks like afterwards.
We're evaluating a TIBCO EBX alternative for mid-market MDM. What do we lose?
The modelling studio, mainly. You lose the generated business-user screens and the multi-domain model that a non-engineer can evolve. You also lose a deep reference data product and a very long reference list. You gain a named matching method, golden records exposed to agents behind masked views, a published price and a verifier. If your programme is customer or supplier records in one quarter, self-hosted, that trade is usually worth it. If it is a five-domain rollout with a steering committee, it is not.
ON EBX has an AI Assistant. Isn't that the same thing?
No, and they do not claim it is. Their card describes generative AI help for a human finishing record-level tasks, with validation workflows around it. That is a copilot for a steward. Our question is the reverse: an autonomous agent, with no human in the loop, asks for 4,000 golden records over MCP. What checks it, what does it get back, and what is written down. A copilot does not answer that, and an assistant that makes stewards faster is still a good thing to own.
Does DataShield have SOC 2?
Not yet, and we will not imply otherwise. Auth is live with a public threat model and a verifier anyone can run. Guardian and Lighthouse have been in production since April 2026. Design-partner terms include source escrow, so a small vendor is not a single point of failure. Details on the security page.
- ON EBX's current positioning: "Turn enterprise data into trusted context for AI and business", a "model-driven, multi-domain platform" for master, reference and metadata. — onebx.com, 13 Sep 2026
- Match story, verbatim: "Smart match and merge: identify duplicates and maintain golden records using configurable match, merge, and survivorship rules, with transparent match results for data stewardship." — onebx.com/platform, 13 Sep 2026
- Integration surface is REST, SOAP/WSDL, JMS messaging, CSV/XML/Excel files and Java extensibility. No MCP server or agent tooling is listed. — onebx.com/platform, 13 Sep 2026
- AI capability, verbatim: "AI Assistant capability: Generative AI assistance embedded in EBX to help users complete record-level tasks." Deployment is on-premises, hybrid and cloud-supported. — onebx.com/platform, 13 Sep 2026
- "26+ years of master data management expertise", with governance framed as validation rules, permissions, audit trails and lifecycle tracking. — onebx.com/why-on-ebx, 13 Sep 2026
- Named customers: PostNL (30-40% reduction in MDM technology costs), Panera Bread, and Rabobank for centralized reference data. — onebx.com/resources, 13 Sep 2026
Other head-to-heads
See both mechanisms run in your browser: break a live audit chain, revoke an agent mid-session, then decide what your MDM platform still owes you. Demo Center access is free with a work email.
Get free Demo Center accessYou've seen the proof
Ready for a number? Scope your deployment and we'll price it against your own economics.
Get your quote →