---
title: "Priivacy — Data Discovery &amp; Remediation Software | USC Data"
description: "Transform data chaos into data clarity. USC Data provides enterprise data management, PII protection, M-Files integration, and AI readiness solutions to help organizations unlock the full potential of their data."
lang: en-US
json-ld: |
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://uscdata.com/#organization",
    "name": "USC Data",
    "url": "https://uscdata.com/",
    "logo": "https://uscdata.com/usc-data-logo.png",
    "description": "USC Data helps organizations clean, govern, and restructure business data so AI, audits, automation, and compliance are safe — not risky.",
    "founder": {
      "@type": "Person",
      "name": "Shane Reid"
    },
    "sameAs": [
      "https://www.linkedin.com/company/usc-data"
    ],
    "areaServed": [
      {
        "@type": "Country",
        "name": "United States"
      },
      {
        "@type": "Country",
        "name": "Australia"
      },
      {
        "@type": "Country",
        "name": "United Kingdom"
      },
      {
        "@type": "Country",
        "name": "New Zealand"
      }
    ],
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "Sales",
        "email": "connect@uscdata.com",
        "availableLanguage": [
          "en"
        ]
      }
    ],
    "knowsAbout": [
      "Data Governance",
      "PII Discovery",
      "Data Quality",
      "Metadata Management",
      "Data Integration",
      "Data Migration",
      "Compliance",
      "AI Readiness"
    ],
    "parentOrganization": {
      "@type": "Organization",
      "name": "USC Data",
      "url": "https://uscdata.com/"
    }
  }
---

[connect@uscdata.com](mailto:connect@uscdata.com)

[![USC Data logo](/assets/header-logo-JqaV6ADN.png)](/)

Priivacy Services [BDOS](/bdos)[Discovery](/services/discovery)Resources Company

[Request a Risk Assessment](/contact)

Fast response. No obligation.

Priivacy — Data Discovery & Remediation Software

# Find sensitive data. Remediate it. Defend it.

Priivacy is the software platform USC Data uses to locate, classify, and remediate sensitive personal data across Microsoft 365, SharePoint, OneDrive, Exchange, file shares, and SQL databases — before it becomes a breach, a DSAR scramble, an AI exposure, or a regulator visit.

$12,000 for a 60-day license. Full platform. Done on your infrastructure.

[Request a Demo](/contact) [See Sample Reports](#reports)

ISO 27001 certified | Read-only by default | No external transmission | Air-gap capable | Single-tenant deployment

10+ years

Built by the Umlaut Solutions team. Operating since 2016. Our core team has worked together longer than that.

Royal Commission veterans

Major engagements during Australia's Hayne Royal Commission 2017–2019. For US readers: think of it as a full Senate inquiry into the entire financial services industry, with every advisor required to retrospectively prove best-interest duty across ten years of advice.

AU. US. UK. NZ.

Cross-jurisdictional delivery from day one. ISO 27001 certified data governance and privacy program.

## No snakes and ladders. Here's the whole offer on one page.

One fixed price. Sixty days. Every tool in the platform — switched on. Works for any business with up to 1,000 active users. Industry-specific versions available if you want pre-built configuration for your sector.

Start

60-day license

$12,000

Full platform. Unlimited scanning. Every report. Every remediation tool.

Extend

Month-to-month

$5,000 / month

Keep the platform running while you work through remediation at your own pace.

Upgrade

Annual license

$18,000 upgrade

Roll your $12,000 starter into an annual license. Total annual: $30,000 if upgraded within 90 days.

Optional help

Professional services

$5,000 – $20,000

Sized to the job, not to our quarter. If a half-day session fixes the problem, we charge for half a day.

Pricing applies to organisations with up to 1,000 active users. Larger institutions and group structures scoped on the first call.

Looking for an industry-specific version? [Schools & Colleges](/priivacy/for/schools) | [Financial Services](/priivacy/for/financial-services) | [Wealth Management](/priivacy/for/wealth-management) | [Healthcare](/priivacy/for/healthcare) | [Legal & Professional](/priivacy/for/legal)

## Three pressures converging in 2026.

If you're a CIO, CISO, CFO, or business owner, you're being asked harder questions about data than at any time in the last decade. Privacy regulators, cyber-insurance underwriters, audit committees, and AI safety reviews are all converging on the same root question: where is your sensitive data and who can access it?

### Privacy regulation has caught up

The 2023–2026 wave of state privacy laws in the US (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA) joined GDPR, UK GDPR, the Australian Privacy Act, and the EU AI Act. DSAR clocks tick in 30 days. Notifiable Data Breach windows are measured in hours. Most organisations couldn't answer "where is this person's data" inside a week.

### AI made the data problem urgent

Microsoft Copilot, RAG systems, and AI assistants are only as safe as the data they can read. If a Copilot license can see a folder with thirty unsecured KYC packs or a SharePoint site holding student records, you've expanded your exposure surface in ways the regulator won't excuse.

### Breach economics shifted

The average cost of a data breach reached new highs in 2025, and cyber insurers are denying coverage or hiking premiums for organisations that can't demonstrate basic data hygiene. Defensible data discovery is no longer a "nice to have" for renewal conversations.

## Built for the data problems regulators, AI, and breaches now create.

Eight capabilities. Every one designed to convert a vague risk into a specific action.

### AI & Copilot Safety

Detects and remediates sensitive data in content that feeds Copilot, RAG systems, and AI training — preventing privacy leaks before they reach the model.

### Intelligent Document Classification

Classifies documents by type — contracts, medical records, HR files, financial statements, KYC packs, trust deeds — so findings have context, not just content. Configurable to your industry's document landscape.

### Affected Person Tracking

Identity resolution across files. See which individuals appear where, what PII types are associated with them, and the sensitivity of their exposure. Essential for breach response — know exactly who is affected.

### Permission Auditing (SharePoint & OneDrive)

Discover who has access to files containing PII. Identify files with unique (non-inherited) sharing, flag stale links older than 12 months, see the intersection of sensitive data and excessive access.

### DSAR & Privacy Response Automation

10-stage workflow for statutory data subject access requests. Identity verification, jurisdiction-locked responses (GDPR Article 15, UK GDPR, Australian APP 12), AI-assisted triage via a local LLM that never leaves your environment, and a sealed disclosure PDF.

### Breach Investigation & Impact Reporting

When incidents occur, identify whose data was affected and what was exposed in hours, not months. Per-person exposure reports ready for notification.

### Pre-Migration & Cloud Readiness

Clean and classify data before cloud migrations. Stop toxic data moving forward into modern platforms where it becomes a Copilot risk on day one.

### Multi-Framework Compliance Reporting

Built-in mapping to Australian Privacy Act (APP 11), GDPR, UK GDPR, CCPA/CPRA + state privacy laws, HIPAA, PCI DSS 4.0, EU AI Act, FERPA, GLBA. Article-level reporting with evidence and recommended actions.

## See the actual reports before you buy.

Priivacy ships four built-in HTML reports plus a Privacy Posture assessment and a per-owner exposure breakdown. Each one is designed for the audience that actually reads it. Click any sample to open the full report in a new tab — these are real outputs from anonymised customer scans.

Heads of business, CFOs, CISOs, executive committee 

### PII Security Assessment

The primary client deliverable. Jurisdiction-aware narrative, risk score, framework overlay, prioritised actions.

[View sample report](/sample-reports/pii-security-assessment.html)

GRC team, compliance officers, auditors 

### Compliance Deep-Dive (CCPA / CPRA shown)

Maps every finding to every article of a chosen framework — CCPA/CPRA sample here, with APP, GDPR, and HIPAA also supported. Article-level evidence and recommended actions.

[View sample report](/sample-reports/compliance-deep-dive-cpra.html)

Boards, trustees, ELT briefings 

### Executive One-Pager

A single page. Risk headline, KPIs, top PII types, top three actions. Designed to fit a board pack.

[View sample report](/sample-reports/executive-one-pager.html)

IT teams, data stewards, department heads 

### Owner Exposure

Ranks data custodians by PII volume. Per-owner severity, PII type chips, top files. Answers "who do I need to talk to?"

[View sample report](/sample-reports/owner-exposure.html)

CISO, privacy office 

### Cross-Owner Awareness

All-owners view across an estate. Sees the data-custodian footprint of your organisation in one place.

[View sample report](/sample-reports/owner-awareness-all-owners.html)

CISO, IT director, MSP 

### Privacy Posture (M365 tenant assessment)

24 read-only tests across the Microsoft 365 tenant — anonymous shares, mailbox forwarding, dormant guests, public sites, oversharing patterns. Posture grade and remediation guidance per finding. Sample shown for "Vantage" — a fictitious tenant.

[View sample report](/sample-reports/privacy-posture-report.html)

Sample reports are anonymised outputs from real scans. The reports in your engagement are generated from your actual data and never leave your environment unless you choose to export them.

## Your data stays in your environment. Period.

Priivacy is not a SaaS data lake. We don't ingest, copy, or replicate your files, mailboxes, or database content to a USC Data cloud. The platform installs inside your network or your cloud tenant. Scanning, classification, indexing, AI triage, and reporting all happen locally.

### On-premises

Priivacy runs as a set of Docker containers on a Linux host inside your network. Fully air-gap capable. Nothing leaves unless you export it.

### Your cloud tenant

Install Priivacy in your existing Azure, AWS, or Google Cloud environment. Same isolation as on-prem. No third-party cloud touches your data.

### USC Data dedicated cloud

Single-tenant cloud server we provision and manage. You retain administrative control, authentication, and encryption keys. We don't see your data.

Local AI triage uses an on-prem language model — your DSAR review data never leaves the appliance. Original file content is never persisted. Only metadata and findings are stored, with HTTPS for all transit, OAuth 2.0 tokens encrypted at rest, and audit-grade logging of every action.

[Read the full architecture](/priivacy/how-it-works) [Read the full security overview](/priivacy/security)

## Three ways to buy. One platform underneath.

### Buy Priivacy direct

Sign up, install, run. We'll help you stand it up and walk you through the first scan, but the platform is yours to operate. Best for in-house IT and security teams who want a tool they control.

### Buy Priivacy with USC Data services

Our consultants configure the platform, tune detection for your environment, interpret the findings, and guide remediation. Best for organisations that want expert delivery without building in-house capability first.

### Buy Priivacy through a partner

Many of our customers come to Priivacy through MSPs, GRC consultants, fractional CISOs, or industry advisors who know our platform and bundle it into their own engagements. Same platform, your existing trusted relationship.

Want to become a Priivacy partner? [See the partner program](/priivacy/partners)

## 51 PII types across 7 categories.

Built-in detectors with mathematical checksum validation. Multi-jurisdiction by design: Australia, New Zealand, United Kingdom, European Union, United States, Singapore, France, Germany, Netherlands, Ireland.

### National identifiers

TFN, Medicare, Passport, SSN, NHS, NINO, IRD, NHI, NRIC/FIN, INSEE, Personalausweis, BSN, PPS, driver's licences (AU, NZ, UK, US, EU)

### Financial

Credit card, IBAN, SWIFT/BIC, AU/NZ bank accounts, ABN, ACN

### Contact

Email, phone (AU, NZ, international), Person name, Address, Location, Organisation

### Personal

Date of birth, Date of expiry, Gender, Nationality, Country of issue, Face image, Personal number (MRZ)

### Sensitive (GDPR Article 9)

Racial/ethnic origin, Political opinions, Religious beliefs, Trade union membership, Health data, Sexual orientation, Biometric data

### Health & medical

Medical record numbers, healthcare member IDs

### Technical

IP address, MAC address

Don't see a pattern you need? Our Detector Builder synthesises a regex from a handful of example values you provide — "port the pattern from another system" takes minutes, not weeks.

## Every system where your sensitive data actually lives.

### Microsoft 365

SharePoint Online, OneDrive, Exchange Online (via Graph API)

### File systems

On-premises and cloud file servers, via lightweight remote agents (Windows, macOS, Linux)

### SQL databases

SQL Server, Azure SQL, PostgreSQL, MySQL, MariaDB (read-only)

### Mounted server folders

SFTP / FTP drop locations

### Legacy archives

Apache Tika fallback for 1,000+ additional file formats

The remote agent is a single ~10 MB binary. No installer. WebSocket connection, one-time pairing code, runs as a background service.

## One platform. Every framework your team reports against.

Compliance Deep-Dive reports map findings to the framework that matters to you. Per-article risk, evidence, and recommended actions.

### United States

CCPA / CPRA + state privacy laws (VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA) | HIPAA / HITECH | GLBA | NYDFS 23 NYCRR 500 | SEC Reg S-P | FINRA recordkeeping | PCI DSS 4.0 | SOX 404 / ITGC | FERPA | EU AI Act (for US firms with EU customers)

### Australia & New Zealand

Australian Privacy Act (APP) | Notifiable Data Breaches Scheme | APRA CPS 234 | APRA CPS 230 | AUSTRAC AML/CTF | AFSL recordkeeping | Consumer Data Right (CDR) | NZ Privacy Act

### United Kingdom & EU

UK GDPR + Data Protection Act 2018 | EU GDPR | DORA | FCA SYSC 9 | MiFID II recordkeeping | EU AI Act

## Get clarity before a breach, an audit, or a Copilot deployment forces the issue.

A 45-minute demo against your real environment. We'll scope it, show you what we'd find, walk you through the four reports, and answer whatever's on your list. No slide deck. No sales pressure.

[Request a Demo](/contact)

[Email connect@uscdata.com](mailto:connect@uscdata.com) | Call [+1 844 988 1444 (US)](tel:+18449881444) or [+61 1300 80 95 80 (AU)](tel:+611300809580)

## Common questions.

### How long does a typical scan take?

A small Microsoft 365 tenant (under 500 users) typically scans in 24-48 hours. Larger environments scale via auto-scaling workers and run continuously. Most scans run overnight against throttled connectors so daytime performance is unaffected.

### Does scanning impact system performance?

No measurable impact on the source systems. The scanner throttles itself based on queue depth and system load. Scans can be scheduled for overnight or weekend windows. SQL scans run with read-only credentials and small batch sizes by default.

### Does our data leave our network?

No. Priivacy installs inside your network or your cloud tenant. Scanning, classification, AI triage, and reporting all happen locally. The only thing that leaves is the report file you choose to export. Fully air-gap capable.

### Can we customise detection patterns?

### How does Priivacy protect Microsoft Copilot and AI tools?

### Is this suitable for SMBs?

### What if our environment is larger than 1,000 users?

### What happens after the 60 days?

![USC Data — Unified. Secured. Connected.](/assets/usc-data-logo-white-tagline-zlFrNz8X.png)

USC Data helps growing and regulated organizations clean, govern, and restructure business data so AI, analytics and automation finally work — while hidden compliance risk disappears.

We deliver right-sized, phase-based data governance, privacy remediation, and AI readiness programs across the U.S., Australia, and the U.K.

#### Quick Links

-   [Services](/services)
-   [Discovery](/services/discovery)
-   [AI Readiness](/services/metadata)
-   [Privacy & Compliance](/services/priivacy)
-   [SharePoint & File Chaos](/services/data-integration)
-   [Data Cleanup](/services/data-cleanup)
-   [Case Studies](/case-studies)
-   [Resources](/resources)
-   [Privacy Policy](/privacy)
-   [Terms of Use](/terms)

![ISO 27001 Certified](/lovable-uploads/a3a9df20-c3b3-4cc8-a059-2400491a0dbb.png)

ISO 27001 Certified Data Governance & Privacy Programs

#### Get in touch

Get fast, no-obligation clarity on your data risk, privacy exposure, and AI readiness.

North America:  [+1 844 988 1444](tel:+18449881444)

Australia:  [+61 1300 80 95 80](tel:+611300809580)

[Request a Risk Assessment](/contact)

© 2026 USC Data. All rights reserved. An affiliate of the Umlaut Solutions Group — delivering trusted data governance and compliance programs since 2016.