You Cannot Protect Data You Cannot Find
Ask most security teams where every copy of customer PII lives across their environment and you will get a confident-sounding answer that is almost certainly incomplete. Data has a way of spreading: a support engineer exports a customer table for debugging, a data scientist copies a production snapshot into a notebook, a backup lands in a bucket nobody remembers creating. None of this happens out of malice. It happens because modern engineering organizations move fast, and data follows the path of least resistance. The result is that sensitive information, personally identifiable data, health records, payment card data, and secrets, ends up scattered across systems that were never scoped for it, and nobody finds out until an auditor or an incident forces the question.
Data security posture management exists to answer that question before someone else has to ask it under pressure. Safeguard's DSPM capability appears in the scanner catalog today, per internal confirmation, as part of the platform's broader engine set. As with the other newer first-party engines, depth varies and this is best understood as available and expanding rather than a finished, fully mature product, so a scoped demo against your own data estate is the right next step rather than assuming a complete feature list up front.
Classification that goes beyond a keyword search
The core job of DSPM is discovery and classification: finding where PII, PHI, PCI data, and secrets actually live, then labeling what was found so the rest of the organization can act on it. This is a harder problem than it sounds. A field labeled "notes" can contain a social security number just as easily as a field labeled "ssn" can contain nothing sensitive at all. Real classification has to look at the actual content and context, not just the schema, to be trustworthy enough for a compliance team to rely on.
Grounding this inside the same platform that already inventories your dependencies, your SBOMs, and your assets means the sensitive data map does not live in a separate silo. When a new data store shows up in the environment, it becomes visible the same way a new dependency or a new container image would.
Mapping data risk to the frameworks that matter
Discovery on its own is only half the story. The other half is connecting what was found to the regulatory obligations that apply to it. Data classified as PHI carries different handling requirements than data classified as PCI, and a posture tool that cannot make that distinction is not much more useful than a keyword grep. Framing findings against the relevant regimes, whether that is healthcare, payment, or general privacy obligations, is what turns a data inventory into something a compliance team can build evidence around rather than a spreadsheet that ages badly.
Why this matters for a supply-chain security platform
It is worth being direct about why a data security capability sits inside a platform built around software supply-chain risk. The two problems are more connected than they look. A vulnerable dependency or an over-permissioned pipeline is often the mechanism by which sensitive data gets exposed in the first place. Knowing what is running in your environment without knowing what data that code touches leaves half the risk picture missing. Bringing data discovery into the same findings model as vulnerabilities, secrets, and misconfigurations means a security team can reason about exposure end to end, from the code that processes the data to the data itself.
Because this is one of the newer engines in the catalog, we would rather be precise than impressive: treat it as a capability worth testing against your own environment, not a certainty to write into a contract without confirming scope first. That precision is exactly what should make it easier to trust the parts of the answer that are solid.
Start with visibility
The uncomfortable truth about most data security programs is that they are built on assumptions about where sensitive data lives rather than verified facts. Closing that gap, discovering what is actually there, classifying it honestly, and mapping it to the obligations that apply, is the groundwork every other data protection control depends on.
If your organization is trying to answer, with confidence, where your PII, PHI, PCI data, and secrets actually sit today, reach out through safeguard.sh to scope a demo of the DSPM engine against your own environment.