Skyflow provides a data privacy vault platform for storing, managing, and analyzing sensitive data like PII in a secure, compliant way. It uses encryption and tokenization to isolate and protect personal information, and supports customizable vault schemas and flexible deployment. It differentiates itself by offering privacy-preserving data sharing, regional expansion, and AI-enabled tooling on top of its vault. Its goal is to simplify and speed up data privacy compliance, reducing the time to compliance and enabling safe data sharing at scale.
Company Size
51-200
Company Stage
Series B
Total Funding
$100.5M
Headquarters
Palo Alto, California
Founded
2019
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Vision Insurance
Dental Insurance
Unlimited Paid Time Off
Flexible Work Hours
Hybrid Work Options
Stock Options
Company Equity
Skyflow launches Skyflow for Glean, bringing runtime data control to Enterprise AI search. Skyflow's runtime AI data controls keep sensitive data governed and protected - so enterprises can search, summarize, and reason over it instead of blocking it. Enterprises shouldn't have to choose between searching their data and protecting it. Today, Skyflow, the runtime data control platform for agentic AI, announced Skyflow for Glean: a data security and governance layer for enterprise context. Enterprise context is the millions of documents and billions of records spread across systems that were never built to work together. Skyflow already protects billions of sensitive records for Fortune 500 companies. This launch extends that protection to the knowledge that powers enterprise AI search, starting with Glean deployments. Securing Enterprise Context in Production Kearney, a global management consulting firm, ran into this challenge directly. Rolling out Glean across thousands of consultants meant connecting terabytes of client work, all carrying strict confidentiality commitments to each client. Skyflow governs that context so consultants see only the engagements they're authorized for, with a full audit trail. "We don't want to be in the data sanitization business," said Mark Johnson, Partner and Chief Information and Digital Officer at Kearney. "Skyflow gave us per-field encryption, runtime policies, and customer-specific isolation as a platform - not a project." Extending Governance to the Context Layer AI agents don't work from one fixed dataset. They assemble context on demand from CRMs, SaaS apps, data lakes, and wikis - so the real question is no longer who can access a system, but what data an agent is allowed to see. The usual fix is to block the riskiest content, but blocking degrades search: identifiers stop matching across documents, and employees end up searching a fraction of what the company knows. Enterprise search platforms like Glean enforce permissions-aware access, ensuring employees and agents retrieve only the documents they're authorized to see. Skyflow adds a complementary layer of fine-grained control at the data field level - valuable because AI search turns raw documents into generated answers, summaries, and agent reasoning steps that can carry sensitive values. Skyflow for Glean works at two points: * Sanitize on ingest: Skyflow detects and tokenizes sensitive values before content enters the search index and embeddings, so raw values never reach the index or model memory. * Control the results: At retrieval and throughout agent execution, Skyflow enforces policy-based masking, rehydration, and context filtering, so users and agents see only what they're authorized to see. "Every search and every agent action touches your most sensitive records," said Anshu Sharma, co-founder and CEO of Skyflow. "Protecting that moment matters as much as protecting the storage behind it. Security and legal teams can move from blocking access to unblocking secure access - and that's what makes AI search safe to turn on." What This Means for Enterprise AI With governance satisfied at the data layer, pilots become firmwide deployments. Employees search the complete knowledge base, one client's information never surfaces in another's results, and sensitive data stays out of answers and summaries that shouldn't include it. Data stays in the region for GDPR, DPDP, and HIPAA, and every access is recorded.
Skyflow has launched Skyflow for Glean, a data security and governance layer for enterprise AI search. The platform adds field-level data control to Glean deployments, protecting sensitive information during search and retrieval. The solution works at two points: sanitising sensitive data before it enters search indexes, and enforcing policy-based access controls when results are retrieved. Kearney, a global management consulting firm, is using the platform to govern terabytes of confidential client work across thousands of consultants. Skyflow for Glean combines document-level permissions with fine-grained field controls, ensuring employees and AI agents only access authorised information. The platform maintains audit trails and supports regulatory requirements including GDPR and HIPAA. Skyflow already protects billions of sensitive records for Fortune 500 companies.
Coralogix and Skyflow have launched a partnership to help organisations protect sensitive customer data within logs without compromising observability. The collaboration addresses a key challenge: traditional redaction methods strip away context, making logs difficult to query and operationalise. Instead of removing sensitive data, Skyflow replaces it with privacy-preserving tokens, allowing logs to remain searchable whilst keeping underlying data centrally controlled and auditable. This approach maintains search functionality, event correlation and AI-driven operations whilst ensuring data protection. The solution enables policy-based data access, supports data residency requirements across regions, and allows AI agents to operate safely on telemetry without accessing raw sensitive data. Both companies serve enterprise clients across fintech, healthcare, retail and other regulated industries.
Skyflow delivers Runtime AI Data Security for protecting sensitive data in agentic workflows. Skyflow announced the launch of its Runtime AI Data Security platform for AWS AgentCore. While AI models are improving every few months and the industry is investing hundreds of billions of dollars on AI infrastructure, most organizations still struggle to move from demos and prototypes to production-grade agentic applications. As enterprises and the startups and ISVs that serve them begin deploying agentic applications in production, they need a reliable way to protect sensitive customer data. Preventing data leakage, meeting global compliance requirements, and enforcing which data an agent can use in which context are now foundational requirements for any real-world agentic workflow. Traditional data security and newer AI security posture management tools can only block or redact sensitive data, stopping agents from completing the very workflows they're meant to automate. Skyflow removes these roadblocks by protecting data in use with fine-grained controls that go far beyond simple redaction and blocking. Sensitive customer data remains protected, governed, and auditable even when actively processed by agents and models. AWS recently released new offerings for agentic AI, Amazon Quick Suite and Amazon Bedrock AgentCore. Amazon Quick Suite is AWS's agentic AI application that helps employees transform how they find insights, conduct deep research, automate tasks, visualize data, and take action across applications. Amazon Bedrock AgentCore is an agentic platform to build, deploy, and operate highly capable agents securely at scale. Skyflow is launching its Runtime AI Data Security solution integrated with these AWS offerings to provide a secure-by-design foundation for agentic AI. This integration delivers runtime, field-level, contextual and identity-aware protections for sensitive data (PII, PHI, PCI). For example: * With Amazon Quick Suite, Skyflow enforces runtime sensitive data protection, inspecting and de-identifying PII/PHI before it reaches any agent or model, while ensuring compliance with regulations like GDPR and HIPAA as data flows across systems. * With Amazon AgentCore, Skyflow integrates with agent identity binding and enforces policy-based data access at runtime. This ensures agents only access the "minimum necessary" data and provides field-level logging for complete auditability. "Agentic AI is rewriting how enterprises use data, but it demands a new level of protection when autonomous agents interact with sensitive information. At AWS, security has always been our top priority - it's the foundation of everything we build. AWS Quick Suite and AgentCore enable organizations to operationalize AI at scale, and integrating Skyflow adds the fine-grained data protections and agent-level governance required in regulated industries. This combination helps customers move from pilots to production with confidence, knowing their most sensitive data remains protected at every step," said Andy Perkins, General Manager, US ISV sales - Data, Analytics, GenAI. Unblocking agentic workflows with Skyflow's Runtime AI Data Security. As AI shifts from simple LLM calls to fully autonomous, multi-step agents, enterprises face a core challenge: agents need access to sensitive data to complete workflows, but traditional tools that only block, redact, or monitor prevent the agent from doing its job. The result is stalled pilots and brittle demos that can't make it to production. Skyflow's Runtime AI Data Security provides a data-first, privacy-trust layer inside the AI data flow path. Powered by Skyflow's patented polymorphic engine, it keeps sensitive data protected while still allowing AI systems to use it productively and compliantly. * Real-time discovery, classification, and de-identification of sensitive data (PII, PHI, PCI) with entity preservation so models and agents can still reason, match, and take meaningful action. * Rehydration: Fine-grained, governed restoration of original values only at the exact point for a specific task in a workflow where it is permitted and required, allowing agents to finish end-to-end tasks without overexposing sensitive data. * Global Data Residency and Sovereignty Controls, ensuring sensitive data never leaves its jurisdiction. Even when agents, MCP servers, or models run globally, Skyflow enforces in-region processing and cross-border restrictions automatically. * Context-aware governance and policy enforcement, binding identity to each agent and enforcing "minimum necessary" access based on user, agent, purpose, data type, and regulatory rules. * Entity-preserving transformations, including secure embeddings and governed vectorization, enabling safe retrieval, RAG, orchestration, and agentic workflows without exposing raw data. * Comprehensive, field-level auditability, recording every access, transformation, residency decision, and rehydration event for internal governance, verifiability and regulatory compliance. With Skyflow, agentic AI workflows can move from prototypes to production, delivering automation without compromising security, privacy, or global regulatory requirements. "The success of agentic AI depends on absolute trust and data security when agents handle sensitive enterprise data. Skyflow's Runtime AI Data Security provides the essential guardrails - protecting data exactly at the moment of use. This enables enterprises to safely scale from cautious AI pilots to full production, supporting the AWS agentic AI mission," said Anshu Sharma, CEO, Skyflow. Skyflow's Runtime AI Data Security solution ensures sensitive data moves safely at the speed of AI. By combining Quick Suite and AgentCore with Skyflow for fundamental data security and governance, enterprises unlock responsible innovation.
Skyflow unveils DPDP Data Privacy Vault for India. Bengaluru, Dec 01st: Skyflow, the global leader in AI data security and privacy, today announced the launch of a purpose-built solution to meet Digital Personal Data Protection (DPDP) Act's toughest technical requirements. Skyflow's DPDP Data Privacy Vault Platform helps enterprises exclusively protect personal data, govern its use, and accelerate safe AI innovation, while staying compliant with the rules. The DPDP Rules, notified on November 13, 2025, officially mark India's shift towards a privacy-first digital economy. With only 18 months to comply and penalties reaching up to ₹250 crore (~$30 million) per violation, enterprises must modernize their personal data protection architecture now. The Personal Data Sprawl Problem India's rapid digital growth has powered major advances across sectors, but it has also created massive exposure. Personal data now flows through every product, decision, and AI workflow, and in the process gets copied into countless systems. This "Personal data sprawl" shows up in app databases, logs, analytics warehouses, SaaS tools, reports, data lakes, and AI training pipelines. It's a growing risk: a 2024 Protiviti - CII survey found that only 24% of Indian organizations feel prepared for the privacy challenges posed by emerging technologies. The result is fragmented data that's nearly impossible to govern, protect, or use safely for AI with traditional security models. Data Protection Built for DPDP and AI Skyflow Data Privacy Vault Platform tackles this challenge by isolating and protecting sensitive customer data in a centralized data privacy vault while securing the flow of data across datastores, agents and models.Skyflow's platform provides an architectural foundation to meet the technical requirements of DPDP rules which require system-level actions and safeguard personal data throughout its lifecycle. * Personal Data Security Safeguards: Ensures personal data stays protected across every system where it is processed. Skyflow applies advanced privacy controls including polymorphic encryption, format-preserving tokenization, masking, and obfuscation, so data remains secure throughout its lifecycle and yet usable, even when implemented in analytics or AI workflows. (Adheres to rule 6 (a, d)) * Personal Data Governance: Provides engineering teams with visibility and access to fine-grained, purpose-aware controls, and reliable retention rules, with internal and external data processors. (Adheres to rule 6 (b, c, e, f, g)) * Audit-Ready Compliance Reporting: Supplies immutable logs, observability and consolidated audit reports on personal data, simplifying compliance and security teams' efforts on audit & regulatory reviews. (Adheres to rule 6 (c, e)) * Consent & Data Principal Rights Enforcement: Once consent is collected, ensures accurate enforcement of itemized consent updates and data principal requests consistently. (Adheres to rules 3, 14) * Privacy-First AI Enablement: Uses entity-preserving tokens to support analytics, model training, inference pipelines, and agentic AI systems without exposing underlying personal data. (Adheres to rule 6 (a)) Commenting on the announcement, Anshu Sharma, CEO and Co-founder of Skyflow said, "India has 1.4 billion people and will soon have 1.4 trillion agents with AI. Protecting the personal data of 1.4 billion people requires purpose-built infrastructure and architecture, not incremental fixes. The DPDP Act raises the bar for trust and accountability, and Skyflow helps enterprises meet it while safely adopting AI." "The notification of the DPDP Rules marks a pivotal moment in India's data privacy and governance landscape, catalysing a shift towards privacy-centric architectures and cryptographically resilient ecosystems. Organizations must now operationalize privacy vaults and dynamic access controls ensuring that personal data is not just protected but strategically leveraged with accountability and transparency. Privacy by design and robust privacy practices become a cornerstone of organizational excellence and a differentiator in building stakeholder trust." - Murali Rao, Senior Partner and Leader, Cybersecurity Consulting, EY India "Customer privacy and data security is one of our core values at Urbanic. Skyflow enables us to meet compliance requirements while ensuring our customers' personal data is handled with the highest standards of security." - Ashutosh Sharma, GM Strategy and Product Ops, Urbanic "At Dezerv, data privacy has never been a mere compliance tick-box. We took a proactive approach by integrating with Skyflow to tokenize client PII and strengthen investor trust." - Rishikesh Bhise, Head of Policy and Governance, Dezerv As the 18-month compliance window begins, organizations that embrace data privacy vault platform today will emerge tomorrow as leaders in India's AI-driven economy and protect as well as improve their own customer lifetime value.