ingrid.fyi India's software hiring trends, explained.
Sign in to ingrid.fyi with Google
Your Google account
name@gmail.com
Continue with Google
Home / Product companies / I · Networking, infrastructure and security / Cybersecurity / Data security and privacy
On this page
Data security and privacy Guarding the data itself, wherever it is kept Every Market Segment so far in Industry Vertical 4 guards a place: an inbox, a login, a device, a network, a cloud, a codebase. This one guards the thing all those places exist to hold: the data. It starts from an uncomfortable fact. Most companies do not know where their sensitive data is.

Picture a 2,000-person insurance company in Mumbai. Ask it where its customers' personal data is, and it probably cannot give a full answer:

  • Customer records sit in a spreadsheet on an employee's laptop.
  • A copy of the customer database sits in a test environment, where developers try out new code.
  • Salary data was pasted into a chat tool last year.

The companies in this Market Segment find that data and label what it is. They stop it from leaving. And where it cannot be locked away, they make it useless to whoever takes it. Their buyers are the security, data and legal teams of companies like the insurer. Privacy law turned this from a security preference into a legal duty. Examples are Europe's General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act of 2023.

Most companies in this Market Segment are small. A few large companies covered mainly in other Market Segments also appear here, and two of them have the most job postings here.

Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.

This Market Segment has four sub-segments:

Stopping the data from leaving: watching every exit, and blocking what must not leave. Finding out where it is: searching every system for sensitive data in the first place. Making it safe to use: encryption, tokens and masking, for data the business must keep using. The privacy programme: consent, requests from customers, and now AI, as the law demands. Four jobs for the insurer's data: stop it from leaving (Forcepoint, Cyberhaven), find where it is (BigID, Varonis), make it safe to use (Fortanix, Protegrity), and run the privacy programme of consent and customer requests (Privacy Pillar, PrivaSapien). Privacy law turned this from a security preference into a legal duty.Four jobs for the insurer's data: stop it from leaving (Forcepoint, Cyberhaven), find where it is (BigID, Varonis), make it safe to use (Fortanix, Protegrity), and run the privacy programme of consent and customer requests (Privacy Pillar, PrivaSapien). Privacy law turned this from a security preference into a legal duty.

Keep reading, free

Four more sections are on this page: Stopping the data from leaving, Finding out where it is, Making it safe to use, and The privacy programme. Sign in to read them here, in full.

Continue with Google
  • Stopping the data from leaving
  • Finding out where it is
  • Making it safe to use
  • The privacy programme
Stopping the data from leaving Data loss prevention, insider risk, digital rights management, data detection and response

Back to the insurer from the start of this Market Segment. An employee is about to leave for a rival, and tries to take the customer list along. The oldest product in this Market Segment watches the exits:

  • the email attachment
  • the USB stick
  • the upload to a personal drive
  • the paste into a chat

It blocks the ones carrying what the company's rules say must not leave. This product is called data loss prevention, or DLP. The risk it guards against, staff leaking data on purpose or by mistake, is called insider risk.

Watching the exits. An employee leaving for a rival tries to take the customer list by email attachment, USB stick, upload to a personal drive or paste into a chat. Data loss prevention checks each exit against the company's rules and blocks what must not leave. Newer tools recognise a customer list by where it came from, not by what it looks like.Watching the exits. An employee leaving for a rival tries to take the customer list by email attachment, USB stick, upload to a personal drive or paste into a chat. Data loss prevention checks each exit against the company's rules and blocks what must not leave. Newer tools recognise a customer list by where it came from, not by what it looks like.

Older DLP products work by pattern matching: they look for things that look sensitive, like a 16-digit card number. The newer companies follow the data's history instead, which the industry calls lineage. A file is recognised as a customer list because of where it came from, not because of what it looks like. This newer approach is called data detection and response.

Forcepointis the long-established DLP company, with engineers in Mumbai. It also sells a gateway, which is one of the ways the rules are enforced. Cyberhavenwith engineers in Bengaluru, follows every piece of data from where it was created to where it is going. Nightfall AIalso in Bengaluru, built the same detection for SaaS applications and, lately, for the AI tools where data now leaks. Straca young company from Bellevue with engineers in Bengaluru, works in the same space. Seclorefrom Mumbai, is the Indian company with the oldest idea in this Market Segment: rights management, also called digital rights management. It wraps the file itself in permissions, so the file stays protected even after it has left the company.

Three companies covered mainly in other Market Segments enforce the same rules through their own products:

Skyhigh Securitywatches data moving into cloud applications through its cloud access security broker. (More on it, and on Forcepoint's gateway, in Market Segment 4.5, Network security, firewalls and SASE.) Proofpointapplies the rules to email. (More on it in Market Segment 4.1, Email security and anti-phishing.) NetDocumentsbuilds loss prevention into the document system that law firms keep their files in. (More on it in Market Segment 43.3, Legal practice and matter management software, in Industry Vertical 43, Legaltech.)
Finding out where it is Data discovery and classification, data security posture management, data access governance

Back to the insurer from the start of this Market Segment, and the forgotten copy of its customer database. A company cannot protect what it cannot find. The companies in this sub-segment go looking:

  • They scan every database, file share, storage bucket and SaaS application.
  • They decide what each record is, which is called classification.
  • They map who can reach it, which is called data access governance.

The industry calls the whole job data security posture management, or DSPM. It has become the fastest-growing part of this Market Segment, because data in the cloud multiplies faster than anyone can list it.

BigIDsells discovery and classification across structured data, in database tables, and unstructured data, like documents and emails. Privacy workflows sit on top. It has a team in Chennai. Varonisis by far the largest and the oldest of the three. It started from the file server, mapping which employees can open which folders, and how far a stolen account could reach. It has since extended that to the cloud. It has engineers in Kolkata. Concentric AIwith engineers in Pune, does the classification with language models instead of rules. So a contract is recognised as a contract without anyone writing a pattern for it.
You're reading as a guest. Sign in free to follow links for five minutes, once an hour. Making it safe to use Encryption and key management, tokenisation and masking, confidential computing

Back to the insurer from the start of this Market Segment. Some of its data cannot be locked away, because the business runs on it:

  • the card number the payment system needs
  • the patient records an analyst is studying to price health cover
  • the customer table that the test environment copies

This sub-segment makes such data safe while it is in use. There are three ways to do it:

Encryption and key managementscramble the data, and control who holds the keys that unscramble it. Tokenisationreplace the real value with a token, a stand-in value that can be used in its place. The real value stays locked in one safe place. Maskinghide part of the value, the way a card number shows only its last four digits. Three ways to make data safe to use. Encryption scrambles the data so only the key holder can unscramble it, as Fortanix sells. Tokenisation puts a stand-in token in place of the real value, which stays in one safe place, as Protegrity sells. Masking hides part of the value, like a card number showing only its last four digits, as Protecto does before data reaches an AI model.Three ways to make data safe to use. Encryption scrambles the data so only the key holder can unscramble it, as Fortanix sells. Tokenisation puts a stand-in token in place of the real value, which stays in one safe place, as Protegrity sells. Masking hides part of the value, like a card number showing only its last four digits, as Protecto does before data reaches an AI model. Fortanixwhose engineering is in Bengaluru, sells a platform for key management and encryption. It also sells the newer idea it was founded on, confidential computing. This runs code inside a hardware enclave, a locked-off area of the processor, so even the cloud provider cannot see the data while it is being processed. Protegritywith a team in Mumbai, is the tokenisation specialist. It replaces the sensitive fields in a database with tokens, so the data can be used across a company without the real values ever moving. Protectofrom San Jose with engineers in Bengaluru, is the newer version, built for the AI era. It finds sensitive data and masks it before the data reaches an AI model. (More on it in Market Segment 4.13, AI security.) The data the model must not see.

Every company in this sub-segment now makes the same new promise. Sensitive data is found, masked or tokenised before it is used to train an AI model or is typed into one. The model's answers are checked on the way back. Protecto and Nightfall built their recent products around this promise. Fortanix's enclaves are the hardware version of it.

The privacy programme Consent, data subject requests, privacy risk, AI governance

Back to the insurer from the start of this Market Segment. A customer writes in, asks what data the company holds about them, and asks it to delete that data. The law adds this fourth job:

  • A person can ask what a company holds about them, and demand that it be deleted. This is called a data subject request.
  • A website must record a person's consent before it tracks them.
  • A regulator can ask the company for its map of where personal data is.

Two small companies with engineering in Bengaluru serve this market here:

Privacy Pillarsells consent management, and the workflow for handling data subject requests. PrivaSapiensells tools that show a company its privacy risks. It now also tests and governs AI systems against privacy rules.

OneTrust, the best-known company in this market, is covered mainly in Market Segment 4.14, Governance, risk and compliance (GRC), where the privacy programme meets the rest of compliance.

One company here sits on the other side of the same coin:

LexisNexis Risk Solutionssells data about people: identity resolution, which matches records that belong to the same person, and sanctions screening. That is exactly the kind of data processing the privacy programme exists to govern. (More on it in Market Segment 18.3, Credit bureaus, scoring and underwriting, in Industry Vertical 18, Lending and credit.) So the insurer from the start of this Market Segment has four jobs to do with its data. It must stop the data from leaving, and find out where it is. It must make the data safe to use. And it must answer to its customers and the law about all of it.
Who they hire

Who these companies hire, and for what, is on What cybersecurity hires for.

Privacy Terms Refunds and cancellation Shipping and delivery © 2026 ingrid.fyi · Payments by Razorpay
You're browsing as a guest. Sign in free to follow links for five minutes, once an hour.