Full-Time
Posted on 9/11/2025
Data privacy mapping and compliance SaaS
$190k/yr
Remote in USA
Remote
DataGrail provides an integrated data privacy management platform that helps organizations identify, map, and protect personal data across the entire tech stack. It connects with third‑party SaaS apps, internal systems, and APIs to create a live data map, track data flows, and inventory personal data. The platform also supports privacy operations such as responding to data subject requests, cookie consent management, and privacy risk assessments, all through a subscription-based SaaS model. Unlike some competitors, DataGrail emphasizes ease of use and scalability, aiming to reduce time and resources spent on privacy compliance while improving trust with customers. Its goal is to help businesses comply with data privacy regulations, manage data risk, and demonstrate responsible data handling to stakeholders.
Company Size
51-200
Company Stage
Series C
Total Funding
$124.2M
Headquarters
San Francisco, California
Founded
2018
Help us improve and share your feedback! Did you find this helpful?
Competitive compensation package + equity
Work from anywhere
Unlimited paid-time-off (+2 weeks mandatory!)
Treat yourself with 8 scheduled “DataGrail Days” a year for personal wellness
Annual career development stipend
Health, dental, & vision
401(k) plan
Monthly hardware & remote office stipends
UberEats meal program
MLS teams up with DataGrail for AI-driven data governance. As part of the agreement, MLS and 23 clubs will onboard the DataGrail platform. North America's Major League Soccer (MLS) has brought in data software company DataGrail to manage fan data as part of its wider governance and digital transformation plans. The partnership comes as part of a broader league-wide initiative, which requires all clubs to implement a formal privacy management platform, with 23 MLS clubs set to onboard the DataGrail platform throughout the year, with the remaining seven clubs to use approved third-party solutions. As part of the agreement, MLS and DataGrail will implement a centralized solution to automate privacy workflows, manage personal data across its Fan Genome 360 intelligence platform, stream compliance processes, and deliver a personalized consent experience for fans. The initiative comes as MLS experiences major growth both on and off the pitch, with the league projecting further growth on the back of the US hosting the flagship FIFA 2026 World Cup later this year. John Sullivan, MLS chief information officer, said: "Sportcal is in one of the most important moments in the evolution of global soccer, where data, AI, and fan engagement are becoming deeply interconnected. "Our collaboration with DataGrail allows us to modernize how we manage and protect fan data by leveraging AI-driven automation and continuous data intelligence. Just as importantly, it establishes a scalable governance model - empowering clubs to operate independently while giving the league centralized visibility and control across a rapidly expanding digital ecosystem." The league said the partnership will further its digital transformation objectives by using DataGrail's data privacy platform to "enable automated data mapping and discovery across 2,500 systems, centralized data subject request fulfilment, and verifiable consent management." Daniel Barber, chief executive of DataGrail, said: "MLS needed a platform built for the complexity of modern multi-entity organizations. Only DataGrail provides continuous data mapping, complete multi-brand governance, and the scalability to support a world-class privacy program. "Combined with best-in-class implementation support, we're not just deploying technology - we're helping MLS build a program that strengthens their brand and minimizes risk as their digital footprint grows." The partnership comes after MLS brought in US financial technology heavyweight Chime as a new commercial partner to join Audi, Walmart, Polymarket, Continental Tres, Corpay, and Adidas. Give your business an edge with its leading industry insights.
Data Privacy AI Adoption is lagging behind. DataGrail launches Vera AI agent to close the Gap. New secure, human-governed AI agent helps privacy teams scale operations and mitigate growing risks. March 18, 2026 09:00 ET | Source: DataGrail SAN FRANCISCO, March 18, 2026 (GLOBE NEWSWIRE) - DataGrail today announced the launch of Vera, the first complete AI agent purpose-built for privacy operations. Integrated natively with the DataGrail platform, Vera allows privacy teams to safely automate work across complex environments and maintain ongoing regulatory readiness. Privacy demands have outpaced human capacity and the business impact is material. Organizations large and small face rising enforcement actions, increased litigation exposure, and heightened scrutiny from boards and customers. "Privacy teams are being asked to manage explosive AI growth and global regulatory complexity with static workflows and limited staff," said Daniel Barber, CEO of DataGrail. "The question is no longer whether privacy will use AI, it's how they can use it securely and responsibly. We've built Vera so that, for the first time, resource-strapped teams can adopt secure, scalable privacy AI with confidence." The Privacy AI Adoption Gap While AI is rapidly transforming enterprise functions, privacy teams face unique barriers to adoption: * General-purpose AI tools have no clear operational starting point. * Homegrown agents can introduce risks related to black-box models and sensitive data exposure. * AI-powered systems lack contextual awareness of systems, processing activities, and regulatory requirements. * Limited connectivity impacts agent execution options across the business. Privacy teams know AI tools can generate answers, but they lack the context and security required to operate responsibly in a live privacy environment. Vera Brings Privacy Into the Agentic Era Vera is a complete AI agent intentionally integrated into the DataGrail platform, allowing Vera to take advantage of DataGrail's unmatched contextual awareness, deep connectivity, and no-compromise security architecture. Unlike homegrown agents or bolted-on chatbots, Vera is: * Fully integrated across DataGrail workstreams * Context-aware, with a full library of regulations, risks, and privacy program metadata * Human-governed, adopting user permissions and acting only with approval * Secure by design, operating within a single-tenant architecture with six-stage prompt protection and zero external data training This combination of context, connectivity, and control enables true agentic task automation for privacy teams in a way other platforms cannot. What Privacy Teams Can Do with Vera Vera introduces new levels of scale and automation for privacy teams. Here are a few of the use cases Vera supports at launch. Complete accurate assessments in minutes by drafting PIAs, DPIAs, AI risk assessments, and TIAs using live system metadata and documentation. Continuously detect and prioritize risk, including AI usage and sensitive data exposure across 22,000+ applications. Automate consent governance by detecting, categorizing, and updating rules for new cookies with human approval. Generate executive-ready insights on regulatory readiness and operational risk. Orchestrate tasks across external AI tools with the first production-ready privacy MCP server. Customer impact "Vera's AI rule suggestions significantly accelerated our rule creation process," said Michele Sheets, Senior Manager, Digital Experience at NETGEAR. "What previously required manual iteration and refinement became faster and more intuitive, helping us move forward with greater confidence and efficiency." "Unlike a static data mapping exercise, which is likely out of date and inaccurate the moment it's complete, DataGrail can proactively notify you of changes and guide your next steps," said Adrienne Komogorov, Vice President, Legal at Poppulo The Future of AI-Powered Privacy DataGrail defines the Agentic Data Privacy Platform as the next evolution of privacy technology, replacing reactive compliance models with secure, human-led AI automation. "Privacy work has fundamentally changed," added Barber. "Vera is not a chatbot. It's a governed AI agent embedded into daily privacy operations. This unlocks new levels of scale for privacy teams without added risk." Vera is available to all DataGrail customers now. ABOUT DATAGRAIL DataGrail is the Agentic Data Privacy Platform. We help the world's leading brands such as NETGEAR, FanDuel, Dexcom, GoFundMe, and Commvault automate privacy and control risk with secure, human-governed AI that scales. Powered by Vera, the complete privacy AI agent, and underpinned by an unrivaled 2,500+ integrations and no-compromise security architecture, DataGrail is built to solve complex privacy challenges that others can't. DataGrail is rated 4.8/5 stars on G2 and is a two-time recognized privacy leader by IDC.
This AI startup advised congress on the security risks of TikTok and DeepSeek. Read the pitch deck it used to raise $14M. * Feroot, a cybersecurity startup, helps companies comply with privacy regulations using AI. * The Canadian company's research played a part in US legislation about TikTok and DeepSeek. * Read the pitch deck Feroot used to raise its recent $14 million Series A investment. In the age of vibe coding, almost anyone can quickly spin up a basic app or website. But that doesn't mean your app is secure. Working with AI as your code assistant can lead to a product that's pretty on the outside and riddled with risk on the backend. If your code fails to comply with modern privacy laws and other regulations, such as the European Union's GDPR rules, for example, it could lead to a lawsuit or a fine. Enter Feroot, an AI startup that scans websites and apps to make sure their code is up to snuff with all the latest legal requirements. The Canada-based company just raised $14 million in a Series A round led by True Ventures, with participation from Y Combinator, Preface Ventures, and Industry Ventures. "Having a noncompliant website is really expensive because of litigations, penalties, and enforcements," Feroot's CEO Ivan Tsarynny said. While large companies hire teams to audit every inch of their digital footprints, startups typically lack the same resources. Feroot's AI agents can complete compliance reviews in seconds, Tsarynny said, which eliminates a key growing pain for young companies. Feroot's AI agents scan code to check for violations of over 50 different privacy laws and regulations related to consumer information, health data, and other personally identifying details. Ultimately, the humans at a company are responsible for signing off on compliance, but Feroot's tools can help them spot issues more quickly. Feroot's work has grabbed the attention of legislators in Washington, DC, who cited the company's research in their national security reviews of apps like TikTok and DeepSeek. In February 2024, Tsarynny testified on privacy risks before the US-China Economic and Security Review Commission. Feroot, which has raised $25 million to date, went to investors for its Series A with a simple pitch: AI can save security chiefs and their teams "tens of thousands of hours of work," Tsarynny said. It's not the only cybersecurity company utilizing AI to meet its clients' demands. Other security startups include DataGrail and Reflectiz, another website security startup, which recently announced a $22 million Series B funding round. Feroot has racked up a client list of media and tech companies, including Reddit, Forbes, and Xerox. With its fresh funding, Feroot is focused on hiring more engineering talent, opening additional offices, and expanding into markets such as the Middle East and Southeast Asia, Tsarynny said. Read the pitch deck Feroot used to raise its $14 million Series A: Note: Feroot redacted several slides from the pitch deck, as well as some details, so that the document could be shared publicly. Feroot's deck starts by introducing what it does. Always-on AI Agent platform that keeps websites, web and mobile applications secure and compliant with 50+ regulations, standards and laws. It lists out several regulations websites need to consider. Non-compliant websites cost 10's to 100's of millions of dollars. Litigators and regulators hold companies liable for websites violating data privacy laws. Insurers deny coverage for non-compliance, citing negligence clauses. The slide lists several regulations, such as HIPAA, which protects the privacy of medical records. It emphasizes how compliance is taxing on 'human employees' Making and keeping websites compliant with 50+ regulations is expensive, nearly impossible, and a huge pain for Human Employees: * Discovery takes forever, and it's super tough and riddled with errors. * Data is scattered across many silos, not centralized, and always outdated. * It takes months of FTE team's time to manually assess compliance with 50+ laws and standards. * Results are full of errors. Ongoing manual fixes, redos, and support of many systems are expensive. Feroot brings AI to compliance and security processes of all Payment Pages, Healthcare Pages, iFrames, Websites, and Web Applications - replaces manual work, errors and overhead costs with continuous automation. The slide also includes news clips from Feroot's report on DeepSeek. Feroot explains how its AI agents work. Feroot AI security and compliance agents work 24/7. 1. Deep Discovery: Feroot AI Agents continuously scan and provide up to date, context-rich factual insights. 2. Single Source of Truth: They maintain one database with all real-time insights of all digital assets and across time. 3. Reasoning and GenAI: Provides hyper-precise compliance verification and security analysis beyond human capability. 4. Proactive and Always-On 24/7/365 Protection: AI Agents don't take time off, no sick days, and no vacations. The deck includes product imagery to explain how it works. "Security teams love Feroot's 1-click protection," the slide says. It includes several charts and product images. The deck concludes by introducing Feroot's team. The slide introduces Ivan Tsarynny, Feroot's CEO and cofounder, and Vitalily Lim, CTO and cofounder. It also lists investors like True Ventures, Y Combinator, Preface Ventures, Haystack, and Stonemill Ventures. The slide lists several individual angel investors, too. The last side summarizes what Feroot does one last time. Read next. Business insider tells the innovative stories you want to know.
Ahead of the RSA conference, DataGrail (Booth #243), a leader in data privacy, released its 2024 Data Privacy Trends Report, which illustrates consumers' growing desire to take control over their data and helps businesses understand what to expect amid the rising demands.
DataGrail's 2024 Privacy Trends Report shows 246% boost in privacy requests since 2021 as consumers seek to clear personal data onlineData Privacy request cost to businesses increases 36%, estimated to reach $881,000 per year, per one million identitiesSAN FRANCISCO, May 1, 2024 /PRNewswire/ -- Ahead of the RSA conference, DataGrail (Booth #243), a leader in data privacy, released its 2024 Data Privacy Trends Report , which illustrates consumers' growing desire to take control over their data and helps businesses understand what to expect amid the rising demands. The findings reveal that Data Subject Requests (DSRs) — formal requests made to a company by a person to access, delete or request not to sell/share the personal data that the company holds on them — increased by 32% from 2022 to 2023. Data deletion requests were the most common type of DSR, on average accounting for more than 40% of requests across businesses.As data privacy requests increase, findings show increased financial pressures on the brands processing them. According to Gartner , a single access or deletion request costs around $1,524 to complete. DataGrail's data suggests that a company handling one million identities receives 578 access and data deletion requests in an average year, meaning these DSRs could cost businesses nearly $1 million per year.Privacy Trends 2024 Report Key Findings2023 saw a 246% increase in the total volume of data privacy requests compared to 2021. In 2021, there was an average of 248 DSRs per million identities, and 2023 reached 859 DSRs per million identities.In 2021, there was an average of 248 DSRs per million identities, and 2023 reached 859 DSRs per million identities