Contract
Updated on 9/3/2026
Enterprise data catalog and governance platform
$40/hr
Redwood City, CA, USA
Hybrid
Two days on-site per week (Tuesday and Thursday); local candidates only and no relocation is offered.
Bachelor's
See people who can refer or advise you
Alation provides an enterprise data catalog and data governance platform that helps organizations find, understand, trust, and collaborate on data across large environments. The product inventories data assets into a searchable catalog with metadata, lineage, and governance features, delivered via a subscription plus professional services, training, and support. It stands out by combining a widely adopted data catalog with governance capabilities and services to reduce data silos and improve data-driven decisions, backed by ROI evidence. Its goal is to help organizations manage data more effectively, improve data quality, enable trust and collaboration, and drive better decision-making and operational efficiency through a scalable catalog and governance platform.
Company Size
501-1,000
Company Stage
Series E
Total Funding
$315M
Headquarters
Redwood City, California
Founded
2012
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health and wellness package
Vacation and time off
401(k), performing bonus, and company equity
Promote from within; lunch and learns
Commuter benefit program, company outings, happy hours, certain meals provided
Why a Data Catalog breach is Different - and why you can't just rotate your way out of it. By Dan Moore, Sr. Director, CIAM Strategy & Identity Standards, FusionAuth [ Join Cybersecurity Insiders] September 2, 2026 Alation, a data catalog provider, recently disclosed a breach - and it's worth being precise about what that means. While the scope of the Alation incident hasn't yet been disclosed, a data catalog breach gives attackers a guided tour of how an organization "thinks" and where the valuables are hidden. After a breach like this, the bad guys now know how you classify what's sensitive, who can access it, and how it all connects. This stolen knowledge remains valuable for years because of data gravity and enterprise architecture persistence. It's difficult to remediate, because you can't simply change passwords or rotate tokens. What a Data Catalog Actually Stores A data catalog is basically an inventory of your data assets - tables, schemas, pipelines, APIs - with enough metadata attached that someone can find what exists and understand what it means without hunting down the person who built it three years ago. Companies build things that reflect their organization, so a catalog doesn't just reveal system structures, it reveals organizational and employment ones too. A data catalog is like a reconnaissance gift for hackers. Schema metadata tells attackers where the sensitive fields (ssn, phone number, api_key) are before they touch a database. Lineage graphs map how data moves between systems, giving attackers clues about potential lateral movement paths, and access control docs, if available, tell them which service accounts to target. Catalogs are usually less access-controlled than the data they describe, because discoverability is the whole point - that's a design constraint, not a misconfiguration. With catalog metadata in hand, an attacker turns a random walk into a directed search. They already know what's valuable and where it lives - now they just have to solve for the path. Practically speaking, this means they can target the named service accounts, probe tables with stale quality checks nobody's watching, and use lineage to find weaker upstream systems feeding the same sensitive data with fewer controls. Why "Data Gravity" Makes This Different Data gravity is why the architectural knowledge exposed in a data catalog remains valuable for years. At enterprise scale, data is difficult to move, and applications, integrations, pipelines, and business processes accumulate around it. Over time that makes the architecture surrounding the data difficult to change too. That persistence is what matters after a breach. You can change a password or revoke a token in minutes, but you can't simply redesign your data architecture because an attacker learned how it works. Moving critical data, restructuring pipelines, and changing the applications and processes that depend on it can take months or years. The result is that much of what an attacker learns from a data catalog can remain useful long after the initial breach. Why Remediation Looks Nothing Like a Typical Breach Response The damage is informational, not transactional - you can rotate credentials after a database breach, but you can't un-expose your architecture. The knowledge persists in the attacker's head, and the attack it enables is future-dated, possibly months out. There's no clean remediation process, mostly damage limitation: audit catalog access logs, rotate exposed credentials, and tighten ACLs immediately; add monitoring and review service-account permissions over the following weeks; then spend months deciding what metadata actually needs to be in the catalog versus what's just convenient. You're raising the cost of the attacker's next step, not undoing the recon. Part of the problem is that organizations don't guard catalogs the way they guard production databases. MFA is inconsistent, reads often aren't logged at all, and metadata rarely gets the same least-privilege controls as the sensitive data it describes. The catalog gets treated as internal tooling rather than a sensitive system in its own right - even though security investment should follow data sensitivity, not the label on the system. The Worst-Case, Compound Attack The worst-case version of this is a stolen catalog combined with a separate access breach down the line. This attack becomes compounded with catalog knowledge sitting dormant until an attacker gets a credential through phishing or a leak. Instead of wandering and tripping alarms, they go straight to the highest-value tables, via the least-monitored path, timed to when they know monitoring runs. That precision and speed is what makes it dangerous. An attacker with catalog knowledge looks like a legitimate user who knows exactly what they're doing. Detection tools flag unusual behavior, but if hackers know the architecture, their behavior is less likely to be unusual. What CISOs Should Do Now The one non-negotiable control before a catalog goes into production is audit logging on reads. You need to know who accessed catalog metadata, what they accessed, and when. Without that forensic trail, you can't determine what an attacker learned or which systems, identities, and data they may target next. You're flying blind. That visibility also tells security teams where additional controls are needed, including MFA, tighter ACLs, and stronger monitoring. Read logging is available in many catalog platforms, so organizations should ensure it's actually enabled. If your company is an Alation customer, contact your support team for guidance now. For more on attackers using information repositories like data catalogs, see MITRE ATT&CK technique T1213. Dan Moore is the senior director of CIAM strategy and identity standards at FusionAuth, where he drives B2C product direction and serves as a primary spokesperson on authentication, developer identity, and the emerging challenge of securing AI agents. With over 25 years of software engineering experience - including stints as a CTO, AWS certification instructor, and engineering manager - he is a regular speaker at identity and security conferences and a sought-after podcast guest on authentication and developer security. He is the author of Letters to a New Developer (Apress) and a contributor to 97 Things Every Cloud Engineer Should Know (O'Reilly).
Alation confirms cyberattack following days-long investigation into customer disruptions. Enterprise data and artificial intelligence firm Alation confirmed Thursday that it had suffered a cyberattack, days after customers experienced a service disruption tied to the same incident. Alation said it detected unauthorized activity within one of its systems and has launched an investigation into the matter. The company has not disclosed how the attackers gained access, what specifically triggered the breach, or whether customer data was accessed or removed from its systems. "Alation recently identified an isolated incident involving unauthorized activity in one of its systems," the company said in a statement provided through external representative Stephen Russell. "We are conducting a thorough investigation of what occurred and we will provide additional information as appropriate." The company has not disclosed the number of customers affected by the breach, nor has it said whether it notified customers directly or issued instructions on protective measures they should take in response. Alation builds software that enterprise clients use to locate files and data through natural-language search. The company has broadened its offerings in recent years to include artificial intelligence capabilities aimed at converting large volumes of unorganized data into usable formats. More than 500 companies worldwide rely on its products, according to the company, including roughly half of the 1,000 largest firms in the United States by revenue. The confirmation follows a separate incident reported Tuesday, when Alation said some customers experienced reduced service availability. The company stated the disruption was addressed within an hour of being identified. Alation's infrastructure runs largely on Amazon Web Services. Whether any data was removed from company systems during the breach remains undetermined. The disclosure adds Alation to a growing list of technology firms handling large volumes of corporate data that have reported security incidents in recent weeks, as attackers increasingly focus on companies that store sensitive information on behalf of business clients. Earlier this month, multiple companies disclosed data theft connected to a breach at European shipping firm Ceva Logistics. Financial institutions and private equity firms have also reportedly been targeted by hackers in recent weeks.
Alation confirms cyberattack after days of vague 'incident' language. August 20, 2026 When a company that handles sensitive corporate data for hundreds of the world's largest businesses gets hit by a cyberattack, you'd expect some transparency. What Alation offered instead was a carefully worded statement and a lot of silence. According to TechCrunch, Alation confirmed the cyberattack on Thursday, days after quietly flagging an unspecified "incident" that caused "degraded availability" for some customers on Tuesday. That earlier disruption was reportedly resolved within an hour. But what actually happened? The company isn't saying. No root cause. No customer count. No word on whether data was stolen. Alation makes data cataloging software that enterprise customers use to search through massive amounts of internal files and data using natural language queries. In recent years, it has pushed further into AI, helping companies turn messy, scattered data into something usable. It claims to work with more than 500 global companies, including roughly half of the Fortune 1000. That's a significant concentration of sensitive corporate information sitting in or connected to its systems. The company's official statement, delivered through an external PR representative, read: "Alation recently identified an isolated incident involving unauthorized activity in one of its systems. We are conducting a thorough investigation of what occurred and we will provide additional information as appropriate." The phrase "as appropriate" is doing a lot of heavy lifting there. Appropriate for whom, exactly? For privacy-conscious observers, the gaps in this disclosure are the story. Alation has not confirmed whether it notified affected customers directly. It has not said whether any data was exfiltrated. Much of its infrastructure runs on Amazon Web Services, which raises questions about the scope of the intrusion and what cloud-stored data may have been exposed. This attack doesn't happen in isolation. It fits into a clear pattern of hackers going after companies that aggregate valuable corporate data on behalf of their clients. Earlier this month, multiple companies reported data thefts following a breach at European shipping giant Ceva Logistics. Financial firms and private equity companies have also reportedly been targeted in recent weeks. Attackers have figured out that hitting one data-rich intermediary can expose dozens of downstream victims. That's what makes Alation's tight-lipped response so frustrating. Its customers can't make informed decisions about their own risk if the company won't tell them what was accessed, when, and how. Saying the investigation is "thorough" costs nothing. Actual disclosure costs something. So far, Alation is choosing the cheaper option.
AI data giant Alation confirms cyberattack. Last updated: August 20, 2026 6:13 pm . The data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.
Suralink expands Agent Library, includes client document pre-screener. , an accounting-centered client collaboration platform, announced an expansion of its Agent Library. This includes what Suralink says is the very first Client Document Prescreen Agent that proactively notifies clients when they have incorrect or missing documents and works with them in real-time to resolve these issues. Suralink has also released a Multi-Level Vouching Agent that is made to handle highly complex vouching procedures, as well as a Version Compare Agent, which speeds up document review by identifying each change between drafts. Suralink also announced enhancements to its Client Data Vault platform. Launched earlier this year, the client-facing platform allows clients to independently control and utilize their prior-period engagement data. In addition to archived engagements, it now also captures inactivated or deleted engagements, so the Client Data Vault reflects a client's full engagement history rather than just a portion of it. TransFi launches Jarvis for cross-border payment compliance. Stablecoin-based cross-border infrastructure provider has introduced Jarvis, a proprietary AI-powered compliance intelligence platform that consolidates customer and transaction data from across its internal systems and third-party providers into a single, risk-based view. It combines Know Your Customer and sanctions screening, internet profiling, risk labelling, behavioral and biometric signals, and fiat and blockchain transaction monitoring into a single dashboard, giving compliance teams one view of every customer across a multi-entity, multi-regulator business. From that unified view, Jarvis creates a risk profile against each customer, merchant, sender and recipient in the system. It takes into account the result of all the internal controls at TransFi. Jarvis runs the analysis based on heuristics and AI-powered research, recommending actions on high-confidence matches and escalating complex or ambiguous cases for human review. For the cases that reach analysts, Jarvis prepares investigation summaries with key observations, supporting evidence, and recommended next steps, helping teams work faster with full context. Final decisions on KYC, Know Your Business, transaction monitoring and screening are always with the compliance team with the oversight of the money laundering reporting officer. The platform sharpens over time as it learns from historical decisions, fraud patterns, regulatory updates and analyst feedback. TransFi has positioned Jarvis as the central intelligence layer of its compliance function. As the platform develops, it is expected to extend into real-time behavior monitoring, predictive fraud detection and explainable, AI-driven recommendations, supporting the company's growth across regulated markets. PwC Canada joins with Alation to develop AI solutions. Big Four firm 's Canadian unit has partnered with AI solutions provider to combine PwC Canada's regulatory and implementation expertise with to deliver AI-powered, pre-built solutions for highly regulated industries. Together, Alation and PwC Canada will develop and deliver joint accelerators, including pre-built, self-improving, industry-specific solutions that compress the path from regulatory requirements to audit-ready evidence. The first solution under the partnership is the E-21 Compliance Accelerator, built for Canadian chartered banks facing OSFI Guideline E-21 data risk management requirements. AI agents running the accelerator automate Critical Data Element classification, data lineage tracing and audit evidence generation. Fieldguide rebrands to emphasize agentic collaboration. Audit and risk advisory solutions provider announced a refreshed brand identity anchored by a new logo and visual language. The changes reflect Fieldguide's evolution into an agentic AI platform used throughout the industry. This refresh is presented as more than a visual update, Fieldguide said it underscores the company's role in building a future where practitioners and AI agents work side by side across the full arc of an engagement, not just a single task. With this refresh, Fieldguide is also introducing a new brand expression, "Expertise, amplified," which conveys how Fieldguide's agentic platform augments practitioners' deep expertise. To this end, Fieldguide's two latest launches ( ) center on shifting manual tasks to Fieldguide's agents, so practitioners can stay focused on where they provide the most value. Crunchafi and Thomson Reuters host webinar on automating lease procedures in audit workflows. andia-faith/andiafaith - stock.adobe.com Lease accounting solutions provider announced a joint webinar on how CPA firms can use automation to simplify complex lease procedures and reduce manual work during the audit. The live session, "Automate Lease Procedures Inside Thomson Reuters Guided Assurance," will take place on August 18, 2026, at 1 p.m. CDT. Jess Vento, senior director of solutions engineering, education and support at Crunchafi, and Stuart Cobbe, head of product for audit at Thomson Reuters, will explore how automation can reduce that manual work and create a more efficient, connected audit process. Using Crunchafi and Thomson Reuters Guided Assurance as a practical example, they'll show how lease procedures can be automated from source contract to audit-ready workpaper, with a short technical segment demonstrating how outputs return to the engagement manager for review and sign-off. Attendees can continue the conversation with Crunchafi at , Thomson Reuters' annual user conference this November, where the team will demonstrate the lease automation workflow and discuss firm-specific use cases. TaxPlanIQ ranks 644 in Inc. 5000 list. larioslake - Fotolia Tax planning solutions provider has been ranked No. 644 on the 2026 Inc. 5000 list, the annual list of the fastest-growing private companies in America. TaxPlanIQ also ranked No. 50 in the Financial Services category. The list recognizes successful independent and entrepreneurial businesses hat have achieved remarkable growth while driving innovation, creating jobs and shaping the future of the economy. TaxPlanIQ posted 562% three-year revenue growth to earn its place among this year's honorees, joining an alumni network of past honorees that includes Microsoft, Meta, Chobani, Oracle, and Patagonia. Inc. will celebrate the honorees at the 2026 Inc. 5000 Conference & Gala, taking place Oct. 14-16 in Dallas, and the top 500 will be listed in the fall issue of Inc. Magazine.