The Industry's First Discriminative Pre-Trained Transformer (DPT)
A breakthrough in sensitive data protection technology, introducing the revolutionary DPT architecture - a new class of AI model specifically engineered to make allow, warn, and block enforcement decisions in real time.
DataFence Onyx delivers enterprise-grade performance that redefines what's possible in data protection
Coverage across PII, PHI, PCI, API keys, contact identifiers, and document classification
Real-time data protection at enterprise scale
Optimized for real-time processing
Minimal memory footprint for maximum efficiency
Seamless integration across platforms
Unlike generative models that create content, DataFence Onyx's DPT architecture is purpose-built for discriminative tasks - making real-time allow, warn, and block decisions on sensitive data.
Specialized design optimized specifically for entity recognition and classification tasks
Uses the surrounding context of a document — not pattern matching alone — to recognize sensitive entities
Detects sensitive data across formatting and obfuscation variations that defeat rule-based tools
Classifies documents by sensitivity type — routing enforcement by how sensitive a document is, not just what data it contains
Binary classification decisions vs content generation
Lightning-fast processing with minimal resources
Built for high-performance enterprise environments
Dedicated secure API infrastructure for org policy enforcement
No generative AI used in analysis
Trained on our exclusive dataset comprising over 10 million labeled examples across diverse industries
Comprehensive dataset covering real-world scenarios across a wide range of business documents and data types
Understands nuanced differences that escape rule-based systems, reducing false positives dramatically
Specialized in document and entity recognition across financial services, healthcare, and contact and identity information
That's not our claim about the competition. It's what the DLP vendors publish about themselves.
of DLP alerts are false positives — 65% of leaders say benign alerts overwhelm them.
Cyberhaven
false positives — with more than a third of teams fielding up to 10,000 alerts every month.
IDC, cited by Zscaler
false positives across legacy DLP — averaging 35%, and reaching 90% in some deployments.
Spin.AI
Every one of those figures is vendor-published — so we hold our own to the same skepticism. Cyberhaven, who put the 51% on the record, also states plainly that there is no universal standard for an acceptable false-positive rate, and that any vendor quoting you a precise benchmark without knowing your environment is guessing. That applies to them. It applies to us. So we won't hand you a single magic number — we'll tell you exactly how we measure and let you pressure-test it.
Here's the part most vendors gloss over: nearly all "DLP false positives" aren't the engine missing. The engine matched the policy exactly — the flagged content simply didn't pose any risk in that context. The tool did precisely what it was told, and alerted you anyway.
As Zscaler describes it, the engine correctly matched the policy — the content just didn't pose any risk in that context.
That's what the industry tells you is normal — because they can't fix their own product. A better rule won't help; the rule was right. The only thing that cuts this noise is understanding context: whether the data that matched is actually sensitive — here, in this document, for this purpose.
Onyx doesn't just match patterns — it judges whether flagged content is genuinely sensitive in context, so benign matches don't become alerts. And we measure it the honest way: precision and recall, scored per category, on an independent third-party benchmark the model was never trained on. Fewer false positives isn't a slogan here — it's the axis we optimize, and the number we let you check.
Most DLP tools round their accuracy up. We built our validation to be hostile to our own marketing — so the claims that survive are ones a security team can rely on.
Measured exclusively on public benchmark data the engine was never trained or tuned on — so the numbers reflect real generalization, not memorization.
Every category scored on its own, at the character level — never blended into a single flattering figure that could hide a weak spot.
Structured identifiers are validated against their real-world format before flagging — so a 12-digit invoice or order number is rejected, not mistaken for a payment card. Fewer false positives on routine documents.
An inflated result from an overlapping benchmark was deliberately excluded from every claim. We report the harder, honest number instead.
Measured against established, third-party public benchmark datasets we don't control, spanning multiple domains — so the numbers come from independent, real-world data rather than a test set of our own choosing.
Catches a wide spectrum of sensitive data — national IDs, payment and financial data, credentials, medical and biometric identifiers, contact details, and personal names — plus bulk collections like customer lists and prospect rosters.
We validate recall (of the sensitive data present, how much we catch) and precision (of what we flag, how much is truly sensitive) — scored per category on an independent, third-party benchmark the model was never trained on. We report the harder, honest number, never a blended score that hides a weak category.
Unlike legacy DLP solutions like Microsoft Purview, DataFence Onyx's DPT architecture delivers real-time protection with automated allow, warn, and block enforcement
See how Onyx DPT compares to enterprise alternatives
Unlike Microsoft Purview (which requires you to build and train your own models) or Symantec DLP (which is rules-based only), DataFence includes Onyx DPT AI out-of-the-box on all plans
| Feature | DataFence Onyx DPT | Microsoft Purview | Symantec DLP (Broadcom) |
|---|---|---|---|
| Real-Time GenAI / AI-Chat Protection | ✓ Browser-native (blocks at paste/upload into ChatGPT, Claude, Gemini) |
Endpoint/network-based (not inline in the browser) |
Requires CASB/proxy |
| Model Availability | ✓ Out-of-the-box AI (Onyx DPT included) |
✗ Must build/train your own AI models | ✗ Rule-based (not AI-native) |
| Real-Time Enforcement | ✓ Inline in the browser (blocks before data leaves; no model to build) |
Runtime evaluation (requires manual model build + rule refinement first) |
Runtime match (requires rule tuning; enforced via endpoint/proxy) |
| PHI Detection | ✓ Detects healthcare identifiers (SSNs, record & contact identifiers) |
✓ Built-in healthcare SITs (requires policy configuration & tuning) |
✓ Template-based (requires SOC engineer tuning) |
| Spreadsheet Support | ✓ Supported | ✓ Supported | ✓ Supported |
| Security Team to Operate | Not required (run by existing staff or MSP) |
Required (security/compliance staff to configure) |
Required (dedicated security staff) |
| Deployment Speed | Minutes (comes fully configured) |
3-12 months (requires configuration) |
3-12 months (requires configuration) |
| Insurance Readiness | Automated controls & reporting | Requires manual evidence | Requires manual evidence |
| User Experience / UI | Modern, lightweight dashboards | Legacy, complex interfaces | Legacy, complex interfaces |
| Compliance Support | Control mapping & evidence export (SOC 2, ISO 27001, HIPAA, GDPR) |
Templates, but resource-heavy | Templates, but resource-heavy |
| Image & Scanned-Document Detection (OCR) | ✓ Included (screenshots, photos, image-only PDFs) |
✓ Premium tier (configured & capacity-metered) |
✓ Separate add-on (licensed OCR module) |
| Bulk / Roster Detection | ✓ Included (flags customer lists & rosters as bulk exposure) |
Individual matches only | Individual matches only |
| Document Classification | ✓ Included (auto-classifies by document type & sensitivity) |
✗ Not included | ✗ Not included |
Cost to deploy and what it takes to run — including whether you need a security team at all. Legacy DLP assumes one; DataFence doesn't. Modeled for a 10,000-user deployment.
Example: 10,000 users
| Platform License | $100,000/yr |
| AI DLP | ✓ Included |
| Setup Fee (one-time) |
MSP or MDM Deployed |
Set-and-forget — no security team to hire. Your existing engineers or compliance owner export and review flagged events as needed, or hand it to your MSP.
Example: 10,000 users
| License Cost | ~$500,000/yr |
| AI DLP | ✗ Not included |
| Setup Fee (one-time) |
$175,000+ |
Self-managed on-prem stack (servers to patch) needs dedicated security staff to deploy, tune, and triage. Modular licensing priced separately; figures are modeled estimates.
Example: 10,000 users
| License Cost | Depends (see below) |
| AI DLP | ✗ Not included |
| Setup Fee (one-time) |
$200,000+ |
SaaS (Microsoft runs the infrastructure), but configuring, tuning, and triaging Purview still requires security/compliance staff — license breakdown below.
Microsoft Purview DLP · 10,000 users
| Your starting point | Purview DLP license |
|---|---|
| Already on Microsoft 365 E5 | $0 incremental (Purview included) |
| On E3, scoped to regulated users | ~$120K–$300K/yr |
| On E3, Purview Suite estate-wide | ~$1.44M/yr |
| No Microsoft estate | Not a Purview evaluation |
DataFence protects browser uploads, pastes, and form submissions regardless of your Microsoft licensing — the implementation and staffing figures above apply in every scenario.
Reach compliance without a security team — something legacy DLP can't offer.
Symantec and Purview require dedicated security staff to deploy, tune, and triage — a hire that runs $150K–$200K+ fully loaded, or an MSP retainer. DataFence is set-and-forget: your existing engineers or compliance owner review flagged events as needed, or your MSP does.
Figures are modeled estimates for illustration; license and implementation costs vary by Microsoft licensing, contract, module selection, deployment scope, and negotiation, and competitor list pricing is not always published. "Security team to operate" reflects the specialized staff needed to deploy, tune, and triage each platform day-to-day; a dedicated security hire runs roughly $150K–$200K+ fully loaded.
Join leading enterprises already protecting their sensitive data with DataFence Onyx's revolutionary DPT technology