---
title: "Priivacy — Data Discovery &amp; Remediation Software | USC Data"
description: "Priivacy is USC Data's proprietary platform for discovering, classifying, and remediating sensitive data across Microsoft 365, file shares, and SQL databases. $12,000 for a 60-day license. Air-gap capable. Your data never leaves your environment."
lang: en-US
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "How long does a typical scan take?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A small Microsoft 365 tenant (under 500 users) typically scans in 24-48 hours. Larger environments scale via auto-scaling workers and run continuously. Most scans run overnight against throttled connectors so daytime performance is unaffected."
          }
        },
        {
          "@type": "Question",
          "name": "Does scanning impact system performance?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No measurable impact on the source systems. The scanner throttles itself based on queue depth and system load. Scans can be scheduled for overnight or weekend windows. SQL scans run with read-only credentials and small batch sizes by default."
          }
        },
        {
          "@type": "Question",
          "name": "Does our data leave our network?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Priivacy installs inside your network or your cloud tenant. Scanning, classification, AI triage, and reporting all happen locally. The only thing that leaves is the report file you choose to export. Fully air-gap capable."
          }
        },
        {
          "@type": "Question",
          "name": "Can we customise detection patterns?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. The Detector Builder synthesises new regex detectors from example values. Document Type classification recognises industry-specific documents. Custom Header Mappings extend the tabular classifier with org-specific column names. All configurable in the admin UI."
          }
        },
        {
          "@type": "Question",
          "name": "How does Priivacy protect Microsoft Copilot and AI tools?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "By making sure the data they read is clean. Priivacy classifies, tags, and remediates sensitive data before it reaches Copilot, RAG systems, or AI training pipelines. Findings can drive permission changes that exclude sensitive content from AI exposure entirely."
          }
        },
        {
          "@type": "Question",
          "name": "Is this suitable for SMBs?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. The $12,000 60-day Starter Kit is designed for organisations with up to 1,000 active users. The professional services range starts at $5,000 — sized to the job, not the calendar quarter. We work with businesses from 50 to 10,000 employees as our primary band."
          }
        },
        {
          "@type": "Question",
          "name": "What if our environment is larger than 1,000 users?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "We'll scope it honestly on the first call. The 60-day Starter is designed for a single organisation; large multi-entity groups or enterprises are quoted separately with no surprise change orders."
          }
        },
        {
          "@type": "Question",
          "name": "What happens after the 60 days?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "You decide. Extend month-to-month at $5,000. Upgrade to the annual license for the $18,000 delta ($30,000 total, with your starter rolled in if within 90 days). Or walk away — keep the reports, keep the action list, keep the cleanup work already underway. No retention clause."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://uscdata.com/#organization",
      "name": "USC Data",
      "url": "https://uscdata.com/",
      "logo": "https://uscdata.com/usc-data-logo.png",
      "description": "USC Data cleans, governs, and restructures business data so AI, Copilot, audits, automation, and growth are safe — not risky.",
      "founder": {
        "@type": "Person",
        "name": "Shane Reid"
      },
      "email": "connect@uscdata.com",
      "telephone": "+1-844-988-1444",
      "sameAs": [
        "https://www.linkedin.com/company/usc-data"
      ],
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "7700 Windrose",
        "addressLocality": "Plano",
        "addressRegion": "TX",
        "postalCode": "75024",
        "addressCountry": "US"
      },
      "areaServed": [
        {
          "@type": "Country",
          "name": "United States"
        },
        {
          "@type": "Country",
          "name": "Australia"
        },
        {
          "@type": "Country",
          "name": "United Kingdom"
        },
        {
          "@type": "Country",
          "name": "New Zealand"
        }
      ],
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "sales",
          "telephone": "+1-844-988-1444",
          "email": "connect@uscdata.com",
          "areaServed": [
            "US",
            "CA"
          ],
          "availableLanguage": [
            "en"
          ]
        },
        {
          "@type": "ContactPoint",
          "contactType": "sales",
          "telephone": "+61-1300-80-95-80",
          "email": "connect@uscdata.com",
          "areaServed": [
            "AU",
            "NZ"
          ],
          "availableLanguage": [
            "en"
          ]
        },
        {
          "@type": "ContactPoint",
          "contactType": "customer support",
          "email": "connect@uscdata.com",
          "availableLanguage": [
            "en"
          ]
        }
      ],
      "knowsAbout": [
        "Data Governance",
        "PII Discovery",
        "Data Quality",
        "Metadata Management",
        "Data Integration",
        "Data Migration",
        "Compliance",
        "AI Readiness"
      ]
    }
  ]
---

[connect@uscdata.com](mailto:connect@uscdata.com)

[![USC Data logo](/assets/header-logo-JqaV6ADN.png)](/)

Priivacy Services [BDOS](/bdos)[Discovery](/services/discovery)Resources Company

[Request a Risk Assessment](/contact)

Fast response. No obligation.

-   [Overview](/services/priivacy)
-   [How It Works](/priivacy/how-it-works)
-   [Security](/priivacy/security)
-   [Reports](/priivacy/reports)
-   [Pricing](/priivacy/pricing)
-   Industries
-   [Partners](/priivacy/partners)

Priivacy — Data Discovery & Remediation Software

# Find sensitive data. Remediate it. Defend it.

Priivacy is the software platform USC Data uses to locate, classify, and remediate sensitive personal data across Microsoft 365, SharePoint, OneDrive, Exchange, file shares, and SQL databases — before it becomes a breach, a DSAR scramble, an AI exposure, or a regulator visit.

$12,000 for a 60-day license. Full platform. Done on your infrastructure.

[Request a Demo](/contact) [See Sample Reports](#reports)

ISO 27001 certified | Read-only by default | No external transmission | Air-gap capable | Single-tenant deployment

10+ years

Built by the Umlaut Solutions team. Operating since 2016. Our core team has worked together longer than that.

Royal Commission veterans

Major engagements during Australia's Hayne Royal Commission 2017–2019. For US readers: think of it as a full Senate inquiry into the entire financial services industry, with every advisor required to retrospectively prove best-interest duty across ten years of advice.

AU. US. UK. NZ.

Cross-jurisdictional delivery from day one. ISO 27001 certified data governance and privacy program.

## No snakes and ladders. Here's the whole offer on one page.

One fixed price. Sixty days. Every tool in the platform — switched on. Works for any business with up to 1,000 active users. Industry-specific versions available if you want pre-built configuration for your sector.

Start

60-day license

$12,000

Full platform. Unlimited scanning. Every report. Every remediation tool.

Extend

Month-to-month

$5,000 / month

Keep the platform running while you work through remediation at your own pace.

Upgrade

Annual license

$18,000 upgrade

Roll your $12,000 starter into an annual license. Total annual: $30,000 if upgraded within 90 days.

Optional help

Professional services

$5,000 – $20,000

Sized to the job, not to our quarter. If a half-day session fixes the problem, we charge for half a day.

Pricing applies to organisations with up to 1,000 active users. Larger institutions and group structures scoped on the first call.

Looking for an industry-specific version? [Schools & Colleges](/priivacy/for/schools) | [Financial Services](/priivacy/for/financial-services) | [Wealth Management](/priivacy/for/wealth-management) | [Healthcare](/priivacy/for/healthcare) | [Legal & Professional](/priivacy/for/legal)

## Three pressures converging in 2026.

If you're a CIO, CISO, CFO, or business owner, you're being asked harder questions about data than at any time in the last decade. Privacy regulators, cyber-insurance underwriters, audit committees, and AI safety reviews are all converging on the same root question: where is your sensitive data and who can access it?

### Privacy regulation has caught up

The 2023–2026 wave of state privacy laws in the US (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA) joined GDPR, UK GDPR, the Australian Privacy Act, and the EU AI Act. DSAR clocks tick in 30 days. Notifiable Data Breach windows are measured in hours. Most organisations couldn't answer "where is this person's data" inside a week.

### AI made the data problem urgent

Microsoft Copilot, RAG systems, and AI assistants are only as safe as the data they can read. If a Copilot license can see a folder with thirty unsecured KYC packs or a SharePoint site holding student records, you've expanded your exposure surface in ways the regulator won't excuse.

### Breach economics shifted

The average cost of a data breach reached new highs in 2025, and cyber insurers are denying coverage or hiking premiums for organisations that can't demonstrate basic data hygiene. Defensible data discovery is no longer a "nice to have" for renewal conversations.

## Built for the data problems regulators, AI, and breaches now create.

Eight capabilities. Every one designed to convert a vague risk into a specific action.

### AI & Copilot Safety

Detects and remediates sensitive data in content that feeds Copilot, RAG systems, and AI training — preventing privacy leaks before they reach the model.

### Intelligent Document Classification

Classifies documents by type — contracts, medical records, HR files, financial statements, KYC packs, trust deeds — so findings have context, not just content. Configurable to your industry's document landscape.

### Affected Person Tracking

Identity resolution across files. See which individuals appear where, what PII types are associated with them, and the sensitivity of their exposure. Essential for breach response — know exactly who is affected.

### Permission Auditing (SharePoint & OneDrive)

Discover who has access to files containing PII. Identify files with unique (non-inherited) sharing, flag stale links older than 12 months, see the intersection of sensitive data and excessive access.

### DSAR & Privacy Response Automation

10-stage workflow for statutory data subject access requests. Identity verification, jurisdiction-locked responses (GDPR Article 15, UK GDPR, Australian APP 12), AI-assisted triage via a local LLM that never leaves your environment, and a sealed disclosure PDF.

### Breach Investigation & Impact Reporting

When incidents occur, identify whose data was affected and what was exposed in hours, not months. Per-person exposure reports ready for notification.

### Pre-Migration & Cloud Readiness

Clean and classify data before cloud migrations. Stop toxic data moving forward into modern platforms where it becomes a Copilot risk on day one.

### Multi-Framework Compliance Reporting

Built-in mapping to Australian Privacy Act (APP 11), GDPR, UK GDPR, CCPA/CPRA + state privacy laws, HIPAA, PCI DSS 4.0, EU AI Act, FERPA, GLBA. Article-level reporting with evidence and recommended actions.

## See the actual reports before you buy.

Priivacy ships four built-in HTML reports plus a Privacy Posture assessment and a per-owner exposure breakdown. Each one is designed for the audience that actually reads it. Click any sample to open the full report in a new tab — these are real outputs from anonymised customer scans.

Heads of business, CFOs, CISOs, executive committee 

### PII Security Assessment

The primary client deliverable. Jurisdiction-aware narrative, risk score, framework overlay, prioritised actions.

[View sample report](/sample-reports/pii-security-assessment.html)

GRC team, compliance officers, auditors 

### Compliance Deep-Dive (CCPA / CPRA shown)

Maps every finding to every article of a chosen framework — CCPA/CPRA sample here, with APP, GDPR, and HIPAA also supported. Article-level evidence and recommended actions.

[View sample report](/sample-reports/compliance-deep-dive-cpra.html)

Boards, trustees, ELT briefings 

### Executive One-Pager

A single page. Risk headline, KPIs, top PII types, top three actions. Designed to fit a board pack.

[View sample report](/sample-reports/executive-one-pager.html)

IT teams, data stewards, department heads 

### Owner Exposure

Ranks data custodians by PII volume. Per-owner severity, PII type chips, top files. Answers "who do I need to talk to?"

[View sample report](/sample-reports/owner-exposure.html)

CISO, privacy office 

### Cross-Owner Awareness

All-owners view across an estate. Sees the data-custodian footprint of your organisation in one place.

[View sample report](/sample-reports/owner-awareness-all-owners.html)

CISO, IT director, MSP 

### Privacy Posture (M365 tenant assessment)

35 read-only tests across the Microsoft 365 tenant — SharePoint (13), OneDrive (3), Exchange (7), Entra ID / Identity (5), and PII-aware compliance (7). Seven of the 35 tests cross-reference tenant exposure against the sensitive data actually found in your environment, so an anonymous sharing link only fires as a real finding when it's actually sitting on a file containing PII, not just a theoretical risk. Posture grade and remediation guidance per finding. Sample shown for "Vantage" — a fictitious tenant.

[View sample report](/sample-reports/privacy-posture-report.html)

Sample reports are anonymised outputs from real scans. The reports in your engagement are generated from your actual data and never leave your environment unless you choose to export them.

## Your data stays in your environment. Period.

Priivacy is not a SaaS data lake. We don't ingest, copy, or replicate your files, mailboxes, or database content to a USC Data cloud. The platform installs inside your network or your cloud tenant. Scanning, classification, indexing, AI triage, and reporting all happen locally.

### On-premises

Priivacy runs as a set of Docker containers on a Linux host inside your network. Fully air-gap capable. Nothing leaves unless you export it.

### Your cloud tenant

Install Priivacy in your existing Azure, AWS, or Google Cloud environment. Same isolation as on-prem. No third-party cloud touches your data.

### USC Data dedicated cloud

Single-tenant cloud server we provision and manage. You retain administrative control, authentication, and encryption keys. We don't see your data.

Local AI triage uses an on-prem language model — your DSAR review data never leaves the appliance. Original file content is never persisted. Only metadata and findings are stored, with HTTPS for all transit, OAuth 2.0 tokens encrypted at rest, and audit-grade logging of every action.

[Read the full architecture](/priivacy/how-it-works) [Read the full security overview](/priivacy/security)

## Three ways to buy. One platform underneath.

### Buy Priivacy direct

Sign up, install, run. We'll help you stand it up and walk you through the first scan, but the platform is yours to operate. Best for in-house IT and security teams who want a tool they control.

### Buy Priivacy with USC Data services

Our consultants configure the platform, tune detection for your environment, interpret the findings, and guide remediation. Best for organisations that want expert delivery without building in-house capability first.

### Buy Priivacy through a partner

Many of our customers come to Priivacy through MSPs, GRC consultants, fractional CISOs, or industry advisors who know our platform and bundle it into their own engagements. Same platform, your existing trusted relationship.

Want to become a Priivacy partner? [See the partner program](/priivacy/partners)

## 60 PII types across 6 categories.

Built-in detectors with mathematical checksum validation. Multi-jurisdiction by design: Australia, New Zealand, United Kingdom, European Union, United States, Singapore, France, Germany, Netherlands, Ireland.

### National — 22 types

TFN, Medicare, Passport, SSN, NHS, NINO, IRD, NHI, NRIC/FIN, INSEE, Personalausweis, BSN, PPS, driver's licences (AU, NZ, UK, US, EU)

### Financial — 9 types

Credit card, IBAN, SWIFT/BIC, AU/NZ bank accounts, ABN, ACN

### Contact — 8 types

Email, phone (AU, NZ, international), Person name, Address, Location, Organisation

### Personal — 4 types

Date of birth, Date of expiry, Gender, Nationality, Country of issue, Face image, Personal number (MRZ)

### Sensitive — 12 types

Racial/ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, biometric data, and health/medical identifiers such as Medical Record Number, Patient ID/MRN, Individual Healthcare Identifier, and National Health Index

### Technical — 5 types

IP address, MAC address

Don't see a pattern you need? Our Detector Builder synthesises a regex from a handful of example values you provide — "port the pattern from another system" takes minutes, not weeks.

## Every system where your sensitive data actually lives.

### Microsoft 365

SharePoint Online, OneDrive, Exchange Online (via Graph API)

### File systems

On-premises and cloud file servers, via lightweight remote agents (Windows, macOS, Linux)

### SQL databases

SQL Server, Azure SQL, PostgreSQL, MySQL, MariaDB (read-only)

### Mounted server folders

SFTP / FTP drop locations

### Salesforce

Files, Attachments, and Documents via the Salesforce REST API. Redact or secure-erase writes back to Salesforce directly.

### Xplan (Iress)

Client-note attachments via the Xplan API. Redact or secure-erase at source — no manual export.

### Amazon S3 & S3-compatible

AWS S3, MinIO, Wasabi, Cloudflare R2, Backblaze B2 via IAM keys. Versioned-bucket remediation purges every prior unredacted version.

### Legacy archives

Apache Tika fallback for 1,000+ additional file formats

The remote agent is a single ~10 MB binary. No installer. WebSocket connection, one-time pairing code, runs as a background service.

## One platform. Every framework your team reports against.

Compliance Deep-Dive reports map findings to the framework that matters to you. Per-article risk, evidence, and recommended actions.

### United States

CCPA / CPRA + state privacy laws (VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA) | HIPAA / HITECH | GLBA | NYDFS 23 NYCRR 500 | SEC Reg S-P | FINRA recordkeeping | PCI DSS 4.0 | SOX 404 / ITGC | FERPA | EU AI Act (for US firms with EU customers)

### Australia & New Zealand

Australian Privacy Act (APP) | Notifiable Data Breaches Scheme | APRA CPS 234 | APRA CPS 230 | AUSTRAC AML/CTF | AFSL recordkeeping | Consumer Data Right (CDR) | NZ Privacy Act

### United Kingdom & EU

UK GDPR + Data Protection Act 2018 | EU GDPR | DORA | FCA SYSC 9 | MiFID II recordkeeping | EU AI Act

## Get clarity before a breach, an audit, or a Copilot deployment forces the issue.

A 45-minute demo against your real environment. We'll scope it, show you what we'd find, walk you through the four reports, and answer whatever's on your list. No slide deck. No sales pressure.

Bring a real document from your own environment and we'll run it through Priivacy's Detection Sandbox live on the call — you'll see exactly what gets flagged, why, and what wouldn't be caught, before you commit to anything.

[Request a Demo](/contact)

[Email connect@uscdata.com](mailto:connect@uscdata.com) | Call [+1 844 988 1444 (US)](tel:+18449881444) or [+61 1300 80 95 80 (AU)](tel:+611300809580)

## Common questions.

### How long does a typical scan take?

A small Microsoft 365 tenant (under 500 users) typically scans in 24-48 hours. Larger environments scale via auto-scaling workers and run continuously. Most scans run overnight against throttled connectors so daytime performance is unaffected.

### Does scanning impact system performance?

No measurable impact on the source systems. The scanner throttles itself based on queue depth and system load. Scans can be scheduled for overnight or weekend windows. SQL scans run with read-only credentials and small batch sizes by default.

### Does our data leave our network?

No. Priivacy installs inside your network or your cloud tenant. Scanning, classification, AI triage, and reporting all happen locally. The only thing that leaves is the report file you choose to export. Fully air-gap capable.

### Can we customise detection patterns?

### How does Priivacy protect Microsoft Copilot and AI tools?

### Is this suitable for SMBs?

### What if our environment is larger than 1,000 users?

### What happens after the 60 days?

![USC Data — Unified. Secured. Connected.](/assets/usc-data-logo-white-tagline-zlFrNz8X.png)

USC Data helps growing and regulated organizations clean, govern, and restructure business data so AI, analytics and automation finally work — while hidden compliance risk disappears.

We deliver right-sized, phase-based data governance, privacy remediation, and AI readiness programs across the U.S., Australia, and the U.K.

#### Quick Links

-   [Services](/services)
-   [Discovery](/services/discovery)
-   [AI Readiness](/services/metadata)
-   [Privacy & Compliance](/priivacy)
-   [SharePoint & File Chaos](/services/data-integration)
-   [Data Cleanup](/services/data-cleanup)
-   [Case Studies](/case-studies)
-   [Resources](/resources)
-   [Privacy Policy](/privacy)
-   [Terms of Use](/terms)

![ISO 27001 Certified](/lovable-uploads/a3a9df20-c3b3-4cc8-a059-2400491a0dbb.png)

ISO 27001 Certified Data Governance & Privacy Programs

#### Get in touch

Get fast, no-obligation clarity on your data risk, privacy exposure, and AI readiness.

North America:  [+1 844 988 1444](tel:+18449881444)

Australia:  [+61 1300 80 95 80](tel:+611300809580)

[Request a Risk Assessment](/contact)

© 2026 USC Data. All rights reserved. An affiliate of the Umlaut Solutions Group — delivering trusted data governance and compliance programs since 2016.