DATAGUARD/by SidianProduct overview · June 2026
Product overview · Sidian Technologies

Decision-making for data
on the move.

Why every regulated organization needs provable data handling, and how we win them.

Here for the technical how-it-works? Jump to the deep dive →

DATAGUARD/Product overview02 / 18
Our mission

A law-grounded data policy.
Enforced automatically.

A law-grounded data policy, configured to how a firm's teams actually work, then enforced automatically on every internal access and external share, so each move is defensible.

Who it's built for

Regulated organizations responsible for protecting sensitive data, and accountable for proving how they handle it.

DATAGUARD/Product overview03 / 18
The blind spot

Everyone guarded the front door.
The leak walks out the back.

For two decades, security spend has gone to keeping hackers out of storage: firewalls, EDR, encryption. That problem is largely handled. The exposure almost no one built for is on the inside: a regulated org's own people accessing data they shouldn't, and sensitive data leaving the building in everyday sharing and public reporting.

Guarded

The front door

Hackers breaking in

Perimeter, endpoint, encryption. Real and necessary, and largely solved by your storage provider.

Wide open

The back door

Your own people

Over-permissioned to everything, and over-sharing in reports, productions, and public disclosures. Nobody is watching this door.

It's enterprise liability run on consumer-grade controls. Regulated organizations hold sensitive data, are forced to share it, and are accountable for protecting it, yet most still run on two things that don't hold: broad internal access, and a manual judgment call on every share, with no record of either.

01

Inside: everyone sees everything

Staff are over-permissioned to entire client and patient files, “controlled” by broad access plus a signed NDA and a lot of trust.

02

Outside: every share is a guess

Each share is a manual judgment call under deadline, the moment for the wrong attachment, un-redacted PII, or a privileged doc to the other side.

03

And no record of either

When a client, regulator, or auditor asks who saw what, the honest answer today is “we're not sure.”

Most data leaks aren't break-ins. They're an authorized person seeing, or sending, something they shouldn't. No firewall is watching that door.

DATAGUARD/Product overview04 / 18
When it goes wrong

Three ways the leak happens,
and what it triggers.

The insider look

A staffer opens records they have no business reason to see: a neighbor's chart, a celebrity's file, an ex's account.

Triggers

HIPAA minimum-necessary breach · OCR penalties up to $2.19M/yr · mandatory notice.

The public report with hidden PII

A report or open-records release is published with data still underneath: hidden spreadsheet columns, black-box redactions over live text, metadata, tracked changes.

Triggers

Mass exposure · GDPR fines up to €20M or 4% of global turnover · representative action.

The wrong recipient

A file goes to the wrong insurer, the wrong client's document is attached to a production, or autocomplete sends data to an outsider.

Triggers

Regulatory action · privilege waived · client lost.

CCPA / CPRA · United States

No single federal privacy law; California's CCPA/CPRA sets the US benchmark. Regulator fines $2,663 per violation ($7,988 if intentional or involving minors). After a breach, consumers can sue for $100–$750 each, per incident, across every record exposed. About 20 states now mirror it.

GDPR · European Union

Two tiers: up to €10M or 2% of global annual turnover for lesser breaches; up to €20M or 4% for breaching core principles or data-subject rights, whichever is higher. Affected individuals can also claim compensation under Article 82.

PIPEDA · Canada

Up to CAD $100,000 per violation for failing to report a breach or keep records; a public OPC investigation; Federal Court damages. (Quebec's Law 25 reaches CAD $25M or 4% of global revenue.)

DATAGUARD/Product overview05 / 18
The cost of doing nothing

Inaction isn't free.
It compounds.

$10.22M
Average U.S. data breach
IBM 2025
$17.4M
Avg annual insider-risk cost per org
Ponemon 2025
55%
Of insider incidents are negligence or mistakes
Ponemon 2025

Regulators pile on

HIPAA up to $2.19M/yr per violation type; GDPR up to €20M or 4% of global annual turnover, whichever is higher.

The quiet costs

Failed vendor security reviews and lost deals; cyber-insurance premiums rising, or claims denied, when basic controls and records are missing.

An enterprise absorbs a $10M hit. A mid-market regulated org often can't. One mishandled share can be existential. And with no record of what happened, there's no defense to mount.

Sources: IBM Cost of a Data Breach 2025 · Ponemon Cost of Insider Risks 2025 · HHS & CPPA 2025 penalty schedules.

DATAGUARD/Product overview06 / 18
The pain

The daily trade-off
they're stuck with.

Move too slow

Everything routes through one paranoid partner. The firm becomes the bottleneck and the work drags.

Move too fast

Just send it and hope. One slip, one over-share, one wrong recipient, and the exposure is done.

Today the only dials are slower or riskier, and a firm is forced to pick one every day. Both are bad, and neither is a control. That's the gap.

DATAGUARD/Product overview07 / 18
Why now

The forcing functions
are arriving at once.

01

Regulators are mandating it

California's CCPA cyber-audit rule is live as of Jan 1, 2026: annual independent audits and executive certification to the agency.

02

Insider risk is mostly accidents

Insider-risk costs run into the tens of millions a year for large orgs, driven by negligence, not malice. Consistent enforcement is the fix.

03

AI is an ungoverned reader

Copilot and assistants inherit the over-permissioning and can surface anything to anyone. A brand-new, unsolved exposure.

04

Trust is becoming a gate

Buyers, insurers and partners increasingly ask for proof of data handling. Prove it and you win the deal; can't and you lose it.

DATAGUARD/Product overview08 / 18
The solution

One policy.
Enforced everywhere.

Every move on a firm's data (who sees it inside, what leaves, and to whom) is decided by one law-grounded policy, not a person's judgment in the moment. Define it once; it drives every access and every share, and stamps each decision with its basis.

Compiled from
HIPAAGDPRCCPASECState law

+ how your teams work: your roles, your data types, your sharing.

Your policy

One law-grounded rulebook

What it produces
EnforcementThe same rule, every move, every time.
EvidenceA recorded basis on every decision.
TrustProvable to the partners whose data you hold.
Data on the move, decided by the policy
A staffer opens a client filePer-role view logged
A report is publishedPII redacted logged
A file goes to an insurerScoped to recipient logged
Copilot reads a folderBlocked logged
The ideaThe policy is the driver. Write it once and it decides every move on your data. The proof comes free, as a byproduct of the decision.
Authored once
by you, with us

Enforced on every access and every share: every employee, every document, every day. No retraining, no human variance, no gaps when someone's rushing.

What that looks like in their tools
Everything leaving your firm
An email
A shared folder
An AI prompt
DataGuard checkpoint

Reads everything before it leaves. One screen, every channel.

Two outcomes
Clean work flows through, untouched.
Sensitive data is caught, redacted, and logged.
The ideaNot a wall that blocks work. One checkpoint that lets clean work pass and stops only what shouldn't leave.
01

Internal access

Per-role views inside the same document. Finance sees the numbers, legal sees the privileged work, nobody sees everything.

02

External sharing

Recipient-specific transforms. The same source goes out scoped to each recipient under the rule that governs them, decided and recorded.

03

Governance wrapper

A tamper-evident record of every decision and its basis. Who received or viewed what. Data residency kept intact.

What that one policy gives them

Defensible by record

If something slips, the firm produces the policy that governed the move and the recorded basis for every decision. A documented, enforced control is the difference between negligence and a footnote.

They hear it first

Over-exposure and anomalies surface to the firm in real time. It knows before its client, its regulator, or the press does, while it can still get ahead of it.

Transparency partners can verify

The firm holds their sensitive data. The policy is the artifact it shows them: exactly how it's handled, with proof it was. Trust stops being a promise and becomes something they can inspect.

DATAGUARD/Product overview09 / 18
How it works

We wrap the tools
they already use.

We don't replace the stack. We wrap it. A storage provider keeps attackers out; DataGuard governs the people it lets in, adding policy enforcement and evidence to the tools the firm already uses.

Keeps it fast: AI data discovery · contextual sharing rules.

Your stackwrapped, not replaced
DataGuard policy + evidence
Microsoft 365
Google
Clio
Email
Storage
AI tools
Storage provider
Keeps attackers out
DataGuard
Governs who you let in
AI data discovery · contextual rulesevery decision logged ✓
The how, for technical readers

This page is the why. Want to see how it works?

The technical overview walks the architecture, the exact path your data takes at the moment of access or share, and how the audit record builds itself. Seven diagrams, no marketing.

Open the technical overview
DATAGUARD/Product overview10 / 18
The payoff

The benefits of data
driven by policy.

One rulebook, enforced everywhere

Defined once, applied to every internal access and external share, not living in people's heads, scattered approvals, and an NDA.

Consistency at scale

The same rule, the same way, every time, across every employee and document. It removes the human variance that causes the slip.

Provable on demand

Every access and share carries a recorded basis. Asked “how do you handle data,” you show evidence, not a policy PDF.

Speed

Teams move at the speed of the policy, not a human review queue. Move fast and stay protected.

Smaller blast radius

Least-privilege by default shrinks what any one person, or any AI tool, can expose.

Adaptable

When a law changes, update the policy once and the whole org's behavior updates. You don't retrain everyone.

Trust becomes a sellable asset

Demonstrate posture to win business and pass vendor audits, the SOC 2 effect.

Most of this is downside protection. One payoff is pure upside: trust you can prove becomes trust you can sell. Pass the vendor security review, clear the insurer's checklist, win the deal the un-provable competitor loses. That's the SOC 2 effect, and it's the reason buyers fund this faster than they fund fear.

DATAGUARD/Product overview11 / 18
The category

A trust instrument,
not another tool.

SOC 2 turned “trust us, we're secure” into an independent, standard-based attestation, and a procurement gate. DataGuard does the equivalent for data handling.

The position

We make passing continuous and cheap, instead of a once-a-year scramble. Not the body that passes you.

We produce the evidence for standards regulators and clients already use:

CCPA cyber-auditSOC 2 · Privacy & ConfidentialityISO 27701HIPAA minimum-necessary
DATAGUARD/Product overview12 / 18
Where we fit & how we differ

We're not the firewall.
We're the insider layer no tool bundles.

Keeping hackers out (encryption, EDR, the perimeter) is the storage provider's job, and it's handled. The gap still wide open is the org's own people: employees accessing data they shouldn't, or sharing the wrong thing out. Most leaks are accidents, not attacks. DataGuard removes the avoidable ones, and makes the rest defensible.

Perimeter · your storage provider
Attacker blocked at the edge. Handled by encryption, EDR, the perimeter. Not our job.
DataGuard · the insider layer

Makes sure the people you let in aren't the breach when they access or share data.

Employees governedAI / Copilot governed
Where we sitYour provider holds the outer wall. DataGuard governs everyone already inside it.

Prevent the avoidable

Least-privilege means the wrong person, or the wrong AI, simply can't reach what they don't need.

Contain the rest

When something does slip, far less is exposed, because nobody was holding everything in the first place.

Prove all of it

Every access and every share carries a recorded basis, producible on demand.

Against the tools a firm already owns

Each tool owns part of the picture. No one bundles the part that falls between them.

Capability
Firewall / EDR
Identity
DLP
Rights mgmt
Posture
DataGuard
Keep external attackers out
·
·
·
·
·
Govern who can enter a system
·
·
·
Control files leaving the org
·
·
·
Find overexposed data & alert
·
·
·
Per-role views inside everyday live documents: no repo or special viewer required
·
·
·
·
Compliance-mapped, tamper-evident basis per decision
·
·
covers it partial· not its job

No single tool a firm already owns does per-role and per-recipient views, internal and external, with a compliance-grade record, in one place, on the tools they already use. That bundle is DataGuard.

Specialized tools do pieces of the bottom rows: EDRM (Seclore) for external control, ECM viewers (OpenText, IBM) for in-document redaction, eDiscovery (Relativity) for recorded redaction basis. None combine them across everyday documents, internal and external, with a compliance-grade record.

DATAGUARD/Product overview13 / 18
Who we're for

Regulated organizations
that hold sensitive data.

The profile
  • Operates in a regulated industry
  • Holds sensitive personal or client data
  • Must routinely share it to do business
  • Accountable to prove how it's protected
  • No enterprise privacy or GRC team

Sweet spot: on the hook for sensitive data, but without a OneTrust-scale program to prove it.

Healthcare & life sciences

PHI under HIPAA minimum-necessary.

Financial services & insurance

Customer data under SEC Reg S-P, GLBA & state law.

Legal & professional services

Privileged & client-confidential records.

Other regulated data holders

Government, education, accounting & more.

The beachhead

We land in law firms first, then fan out.

Of the four verticals, legal is the sharpest wedge: acute pain (privilege, redaction, discovery), a hard ROI story (manual redaction burns 80–120 paralegal hours/month at a typical 10-attorney firm), and reachable channels: bar associations, malpractice insurers, and Clio, where the whole market already lives. Win the playbook there, then reuse it in healthcare, financial services, and the rest, where the same profile holds.

Geography: US = sharper pain & real forcing functions (HIPAA, CCPA, SEC). Canada = softer urgency → sell on value & trust, not fear.

DATAGUARD/Product overview14 / 18
How we win them

We don't find them one by one.
We ride the rails they already trust.

The market is fragmented: thousands of small regulated firms, no central list, cost-sensitive, no dedicated buyer. Chasing them one-by-one with direct sales doesn't pencil. So we go through the institutions they already trust, and we make first value land in minutes, not a quarter.

Four channels to ride
01

Insurers

Malpractice and cyber carriers price the exact risk we reduce. We become a premium discount or a policy requirement, so they distribute us to lower their own loss ratio.

02

Industry bodies

Bar associations and trade groups carry the trust and the member list. An endorsement plus a member offer reaches the whole vertical at once.

03

Platforms they live in

Clio, EHRs, and practice-management suites are the daily workspace. We integrate where the documents already are, so adoption is a setting, not a migration.

04

MSPs & IT providers

The outsourced IT shops that already run these firms' stacks resell us into their book of regulated SMBs as a managed add-on.

Land

A channel introduces us with trust attached. The firm shows up warm, not cold-emailed.

Activate

Automated onboarding builds their policy for them and redacts a real document in minutes. Near-zero time-to-value, or they stall.

Expand

Start a seat or a team, grow into more users, more data sources, and the audit-log tiers as trust compounds.

Distribution is the bet. Whoever owns the trusted channel into these firms owns the category.

DATAGUARD/Product overview15 / 18
Pricing & model

Per-seat SaaS.
Priced to start small.

Simple per-user subscription, three tiers, one free month. Low enough to start without a procurement cycle, structured to grow with usage and controls.

Base
$39/ user / mo

Small teams getting started: 500 docs/mo, up to 3 policies, automatic redaction.

Most popular
Pro
$74/ user / mo

Growing firms: 2,500 docs/mo, role controls, up to 15 policies, 90-day audit log.

Unlimited
$249/ user / mo

Org-wide: unlimited docs & policies, 1-year audit log, priority support.

Frictionless land

Free for 30 days, no credit card, live in under a week. The free month does the selling; near-zero time-to-value drives conversion.

Expansion built in

Document volume, role controls, and audit-log retention all step up by tier, so accounts grow as their reliance does.

Room to customize

Hybrid tiers, custom policies, and volume pricing on request for channel deals and larger organizations.

A Pro seat is $74/month. Manual redaction alone burns 80–120 paralegal hours/month at a typical 10-attorney firm. The math closes itself, before counting a single avoided breach.

USD / user / mo. Full tier detail on the sales offering →

DATAGUARD/Product overview16 / 18
The objection you'll hear most

“But my team signed NDAs.”
A promise is not a control.

The objection

“My employees are bound by NDAs, so them accessing internal and client data is already covered.”

Fair, and keep the NDA. But an NDA deters misuse after the fact, through a lawsuit. It never decides who can see what, it doesn't stop the accident, and it isn't access governance a regulator will accept.

A remedy, not a control

An NDA acts after the damage, in court. It prevents nothing in the moment data leaves, and by then privilege is waived and the breach-notice clock is already running.

Regulators require technical limits

HIPAA minimum-necessary, GDPR data-minimisation and Article 32, SOC 2 CC6, and ISO 27001 all demand enforced least-privilege you can prove. A signature on file is not access governance.

Accidents ignore contracts

Most leaks are mistakes: wrong recipient, hidden column, fat-finger autocomplete. You can't sue your way out of an accident your own team caused.

AI never signed one

Copilot and ChatGPT inherit a user's over-permissioning and can surface anything to anyone. An NDA binds a person, not an assistant.

What an NDA does not satisfy
HIPAA minimum-necessaryGDPR Art. 5 · 25 · 32SOC 2 · CC6 accessISO 27001 access control

Keep the NDA. DataGuard is what makes it real: it decides who can see what, redacts the rest, and produces the access record the NDA never could.

More you'll hear, answered

We already have DLP, or Microsoft Purview.

DLP and Purview classify, then block or alert, usually at the perimeter and usually noisy. They don't produce a per-role view inside a live document or a per-recipient version of a share. DataGuard redacts in place at the moment of sharing and keeps the record. Keep your DLP. This governs the access and the share it waves through.

Won't this slow my team down?

It's a checkpoint, not a gate. Clean work flows through untouched; only sensitive content is redacted in place, automatically, inside the tools they already use. No review queue, no new app. The real slowdown is routing everything through one cautious partner.

We're too small to be a target.

You're not being targeted, you're leaking by accident. Small teams hold the same client data and the same duties, with less margin to absorb a hit. Regulators don't scale fines to your size, and buyers and insurers increasingly gate deals on proof, whatever your headcount.

DATAGUARD/Product overview17 / 18
The honest risks

What has to be true
for this to work.

Regulated buyers move slowly

Risk

Cost-sensitive, tech-averse, no dedicated buyer.

Our answer

The motion answers this (see §How we win them): automated onboarding builds the policy for them. Residual risk: if time-to-value isn't near-zero, they stall, so activation speed is the metric we defend.

They're hard to reach one by one

Risk

Fragmented market, no central list. Direct sales won't scale.

Our answer

We go through trusted channels, not outbound (see §How we win them). Residual risk: channel deals are slow to sign and concentrate dependence on a few partners.

The tech isn't the risk. The core mechanic exists today. Winning the channel is. This is an execution bet, not a research one.

DATAGUARD/Product overview18 / 18
What we're aligning on

Enforcement automatic.
Proof a byproduct.

Regulated organizations are accountable for data they can't currently prove they protect. We make enforcement automatic and the proof a byproduct.

01

Commit to the law-grounded, productized positioning: policy that builds and enforces itself.

02

Land law firms as the beachhead, then fan out to the other regulated verticals that share the profile.

03

Reach them through insurers, industry associations, and the tools they already use.

04

Sell urgency in the US; sell value and trust in Canada.

DataGuard

Decision-making for data on the move.