Data Classification Tools and Data Classification Software: Sensitive Data Discovery Compared on Verified Pricing
Twelve platforms checked against vendor documentation, with real US list prices read from live AWS Marketplace rate cards and Microsoft's public price API. Seven vendors that are widely reported not to publish pricing do publish it, the range runs from $310 to $500,000 a year, and only one vendor in the whole category tells you how much data your money actually covers.
Read-only connection. Datatrail never moves or mutates your data.
Data classification tools scan your data stores, detect sensitive content such as PII, PHI and payment data, and apply labels that the rest of your security stack acts on. The best choice depends on where your sensitive data lives: BigID and Varonis for broad estates with files and SaaS, Cyera and Sentra for cloud data security posture, Immuta when the point of classifying is to enforce a masking policy, and the classification already built into Snowflake Horizon or Databricks Unity Catalog if you run one platform. Real US list prices span from $310 for a single Varonis SaaS connector to $500,000 a year for Sentra Enterprise. Classification tells you what a column is. It does not tell you where copies of it went, which is a lineage problem.
What data classification software actually costs
Nearly every article in this category says these vendors do not publish pricing. That is true of their own websites and false of their AWS Marketplace listings, because a transactable offer has to carry a real dollar amount. We read the live rate cards. Here is what they said, with the date each was read.
| Vendor and tier | What the listing sells | 12-month US list | Entitlement stated? | Read on |
|---|---|---|---|---|
| Sentra, Enterprise | Sentra Enterprise Plan | $500,000 | GB, quantity not stated | 2 Sep 2026 |
| Cyera, Enterprise | Cloud Data Security Platform, up to 250TB | $250,000 | Up to 250TB | 2 Sep 2026 |
| Sentra, Advanced | Sentra Advanced Plan | $250,000 | GB, quantity not stated | 2 Sep 2026 |
| BigID | BigID Next, Discovery Foundation, 1 Unit | $175,000 | Unit not defined | 31 Aug 2026 |
| Collibra | Collibra Cloud Platform, 1 Unit | $170,000 | Unit not defined | 1 Sep 2026 |
| Cyera, Business | Cloud Data Security Platform, up to 100TB | $100,000 | Up to 100TB | 2 Sep 2026 |
| Securiti | Securiti Platform Fee, 1 Unit | $100,000 | Unit not defined | 2 Sep 2026 |
| Sentra, Essential | Sentra Essential Plan | $100,000 | GB, quantity not stated | 2 Sep 2026 |
| Immuta | 960 Immuta Units | $96,000 | Unit not defined | 26 Aug 2026 |
| Cyera, Standard | Cloud Data Security Platform, up to 25TB | $50,000 | Up to 25TB | 2 Sep 2026 |
| Sentra, Standard | Sentra Standard Plan | $50,000 | GB, quantity not stated | 2 Sep 2026 |
| Varonis, Snowflake | Per-connector unit | $30,000 | One connector | 1 Sep 2026 |
| Varonis, any database | Universal Database Connector unit | $15,000 | One connector | 1 Sep 2026 |
| Varonis, one SaaS app | Per-connector unit, Box or Slack or Okta | $310 | One connector | 1 Sep 2026 |
US list prices read from the public AWS Marketplace product pages on the dates shown, excluding private offers, reseller margin and negotiated discounts. Cyera, Sentra and Securiti figures are published here for the first time as far as we can establish.
Only one vendor tells you what you are buying
The most useful thing in that table is not a price, it is the fourth column. Cyera names a data volume ceiling on every tier: up to 25TB, up to 100TB, up to 250TB. Sentra prices in gigabytes and never states how many. Securiti, Collibra, BigID and Immuta all sell a "Unit" that no listing defines. So for most of this category, the published price buys an undefined quantity of an undefined thing, and you cannot check it against your own estate before a demo.
That makes Cyera the only platform here you can sanity-check with arithmetic, so it is worth doing:
| Cyera package | Ceiling | 12-month list | Effective rate |
|---|---|---|---|
| Standard | Up to 25TB | $50,000 | $2,000 per TB per year |
| Business | Up to 100TB | $100,000 | $1,000 per TB per year |
| Enterprise | Up to 250TB | $250,000 | $1,000 per TB per year |
The volume discount stops at 100TB. Going from 25TB to 100TB halves your effective rate, from $2,000 to $1,000 per terabyte. Going from 100TB to 250TB buys no further break at all, because the rate stays flat at $1,000. Quadrupling the estate in the first step costs you double; growing it two and a half times in the second step costs you two and a half times. If your estate is heading past 100TB, the list price gives you no volume argument, which is precisely the point at which you should be asking for one.
Microsoft is the exception: published meters, no sales call
Purview is metered rather than packaged, and Microsoft publishes the rates through a public retail price API that needs no key or account. We re-read it on 2 September 2026. These are the East US consumption rates.
| Purview meter | Rate | Unit |
|---|---|---|
| Data Management Advanced Data Governance Processing Unit | $240.00 | per unit |
| Data Management Standard Data Governance Processing Unit | $60.00 | per unit |
| Data Management Basic Data Governance Processing Unit | $15.00 | per unit |
| Standard Data Security Processing Unit | $25.00 | per unit |
| Standard Assets | $20.00 | per 10,000 |
| Standard Asset (catalog and classification) | $0.0165 | per asset per day |
| Optical Character Recognition Transaction | $0.00 | per transaction |
Read from the Azure retail price API, East US, consumption price type, on 2 September 2026.
Two details worth pulling out. The governance processing units step by exactly four times at each tier, $15.00 to $60.00 to $240.00, which is an unusually steep ladder and means the Advanced tier costs sixteen times Basic rather than the two or three times most people assume when they budget. And the catalog and classification meter is $0.0165 per asset per day, which works out to about $6.02 per asset per year. That is the number to model with, because it scales with how much of your estate you point Purview at rather than with how many people log in. Ten thousand assets is roughly $60,000 a year before any other meter. The full breakdown is in our guide to Microsoft Purview pricing.
A longer contract buys you nothing at list
Buyers routinely open a negotiation assuming a three-year commitment carries a standard discount. On the published rate cards it does not. Every multi-year term we have read across this category and the neighboring data access governance tools is exactly two or three times the annual figure, with no reduction whatsoever. Collibra is $170,000, $340,000 and $510,000. All seventeen Varonis connector dimensions scale linearly. Cyera, Sentra, Securiti and Immuta offer a 12-month term only. Any multi-year discount you get is a concession you asked for, not a rate you qualified for.
Five kinds of tool all call themselves data classification
Most bad purchases in this category come from comparing tools that were never competing for the same job. Every vendor here describes itself as data classification software and they mean five different things by it. Work out which question you are answering before you take a demo.
These lead with finding and labeling data across everything you own, structured and unstructured, then attach permissions, workflow and privacy machinery to what they find. Buy one when the inventory itself is the problem and the estate is broad, especially when file shares, mailboxes and SaaS are in scope rather than only a warehouse.
Agentless, cloud-native, and built to scan very large object stores fast. They classify and then score identity-to-data combinations so you get a ranked risk list rather than a flat inventory. They generally will not enforce a rule at query time on a specific column for a specific analyst, which is the single most common mismatch between what teams buy and what they wrote in their requirements.
Classification exists here to feed policy. The tool tags warehouse columns and immediately uses the tags to drive masking and row filters. If the outcome you want is enforcement rather than an inventory, this is usually cheaper than buying a discovery platform and a policy engine separately.
Labels applied by a human or a trained classifier at creation time, then enforced downstream by DLP and rights management. Still the right model in defense, government and regulated manufacturing, where classification depends on context no scanner can see. Wrong model for an automated warehouse inventory.
Both warehouses ship classification and tagging at no extra license cost. For a single-platform estate this is often enough, and layering a third-party classifier on top is a frequent and expensive mistake. The case for a vendor starts when classification must stay consistent across two platforms, or across the warehouse and the file estate.
Data classification tools compared
| Platform | Lane | How it classifies | Estate it covers | List price |
|---|---|---|---|---|
| BigID | Discovery-led | ML, correlation and identity linking | Everything, structured and unstructured | $175,000 / yr list |
| Varonis | Discovery-led | Pattern matching plus permissions analysis | Files, M365, SaaS, some databases | $310 to $30,000 per connector |
| Microsoft Purview | Platform-native | Sensitivity labels, trainable classifiers, DLP | Microsoft 365, Azure, some third party | Published metered rates |
| Cyera | DSPM | Agentless cloud scanning and AI classification | Cloud stores, SaaS, some on-premises | $50,000 to $250,000 / yr |
| Sentra | DSPM | Agentless scanning, OCR and clustering | Multicloud, SaaS, on-premises | $50,000 to $500,000 / yr |
| Securiti | Discovery-led | Data command center, mapping and classification | Multicloud and SaaS | $100,000 / yr list |
| Immuta | Enforcement-led | Sensitive data discovery, then policy pushdown | Warehouses and lakehouses | $96,000 / yr list |
| Collibra | Governance program | Automated classification inside a governance suite | Enterprise-wide | $170,000 / yr list |
| Netwrix | Discovery-led | Content scanning and permission analysis | File servers, AD, M365 | No published rate card |
| Fortra Data Classification Suite | Labeling-led | User-applied and automated labels, DLP integration | Endpoints, email, on-premises and cloud files | No published rate card |
| Snowflake Horizon and Databricks Unity Catalog | Platform-native | Built-in classification and tagging | One warehouse or lakehouse only | Included in the platform |
| Datatrail | Lineage and impact | Does not classify data | Snowflake, BigQuery, Redshift, Databricks, Postgres | Planned, self-serve |
Every platform, and who each one is actually for
BigID
$175,000 / yr listBigID is the strongest option on this page when the honest answer to "where is our regulated data" is that nobody knows. Its differentiator is correlation: rather than only matching a column against a pattern, it links records back to a specific identity across systems, which is what subject-access requests and privacy work actually require. Classification covers structured databases, warehouses, file shares, SaaS and unstructured stores. The trade is weight, because it is a program purchase with a rollout, not something a data team switches on in an afternoon. Its BigID Next listing carries the highest 12-month list price we have found in this category, $175,000.00, and the vendor description attached to that same price reads "Please contact BigID for custom pricing." Both things are true at once. Full table on our BigID comparison.
Varonis
$310 to $30,000 per connectorVaronis answers a question most warehouse-native tools cannot: of the twelve million files, mailboxes and SharePoint sites nobody has audited since 2019, which contain regulated data and who can currently open them. Classification and effective-permissions mapping are welded together, which is the right design for unstructured data, because knowing a file holds Social Security numbers is useless until you know that 4,000 people can read it. It is also the only vendor in this category you can estimate from the bottom up, because its Marketplace listing publishes seventeen separate per-connector unit prices rather than one platform fee. Those prices span a factor of about 97, from $310 to cover a SaaS application to $30,000 to cover Snowflake, which tells you plainly where the vendor thinks the risk sits. Connector by connector in our guide to Varonis pricing.
Microsoft Purview
Published metered ratesPurview is the only platform here that publishes exact metered rates you can query from a public API before you ever speak to a salesperson, which matters a lot when you have to build a business case. Sensitivity labels, trainable classifiers and DLP are genuinely strong inside Microsoft 365 and Azure, and they get weaker the further you travel from Redmond. Two traps. The naming is a mess, because three different products have carried the Purview label and the classic Data Catalog is in customer support mode. And the meters are per asset per day, so cost scales with how much you point it at rather than with how many people use it. We break the meters down in our guide to Microsoft Purview pricing.
Cyera
$50,000 to $250,000 / yrCyera is agentless cloud data security posture management: it connects to your cloud accounts, discovers and classifies data at scale, and scores which identity-to-data combinations are dangerous. What makes it unusual on this page has nothing to do with the technology. Cyera is the only vendor in this comparison whose published price states what you get for the money. Its three Marketplace packages name a data volume ceiling, up to 25TB, up to 100TB and up to 250TB, where almost every rival sells an undefined "unit". That single fact makes it the easiest platform here to sanity-check against your own estate before a demo. The limitation is scope: like every DSPM tool it will tell you where the exposure is and will not stop a named analyst from reading a specific column at query time.
Sentra
$50,000 to $500,000 / yrSentra competes directly with Cyera and reaches higher. Its Marketplace listing runs four tiers to $500,000.00 a year, the largest single published figure anywhere in this comparison, which is consistent with a product aimed at estates where the unstructured problem is measured in petabytes. It classifies across cloud object storage, databases, SaaS and on-premises, and its own material emphasizes OCR and clustering for content that regex-era tools simply miss. The caveat is the one Cyera does not have: Sentra prices in gigabytes but its listing never says how many gigabytes any tier includes. The meter is published and the entitlement is not, so the four prices are starting coordinates rather than quotes.
Securiti
$100,000 / yr listSecuriti sells a broad data command center covering discovery, classification, DSPM, privacy operations, consent and, since 2025, AI governance. It is a credible single-vendor answer when your buying committee is led by a privacy office or general counsel rather than a data platform team, because the subject-rights and consent machinery is built in rather than bolted on. It overlaps heavily with BigID and you should expect to see both on the same shortlist. Its AWS Marketplace listing sells a single dimension named Platform Fee at $100,000.00 for 12 months. Note that the dimension is one Unit and the listing does not define what a Unit entitles you to, so the figure is a floor rather than a quote.
Immuta
$96,000 / yr listImmuta classifies for a specific reason: it wants to enforce a rule on what it finds. Its sensitive data discovery tags warehouse columns, and those tags then drive attribute-based access policy compiled down into the native controls of Snowflake, Databricks, BigQuery and Starburst. If your goal is to mask a column rather than to inventory a file estate, buying a discovery platform and an enforcement platform separately is often the more expensive path. It is a poor fit for unstructured data, where Varonis and BigID are far stronger. Its listing sells 960 Immuta Units for $96,000.00, exactly $100.00 per Unit, and never defines a Unit. See our Immuta comparison.
Collibra
$170,000 / yr listCollibra approaches classification as one input to a governance program rather than as the product. It will classify, but what you are really buying is the record around it: who approved this classification, against which written policy, reviewed on what date, and the evidence pack an auditor will accept without arguing. That is worth a great deal when a regulator holds a named person in your organization accountable, and close to nothing when a platform engineer just needs to find the PII in a Snowflake schema this week. Its Marketplace listing is $170,000.00 for 12 months, re-verified 1 September 2026 and unchanged. Details on our Collibra comparison.
Netwrix
No published rate cardNetwrix is the pragmatic mid-market answer to the problem Varonis solves at the top of the market. If your sensitive data genuinely lives on Windows file shares and in Microsoft 365 rather than in a warehouse, and your access reviews currently happen in a spreadsheet once a year, it is frequently the correct purchase and materially cheaper than the enterprise DSPM platforms. It is not a warehouse classification engine and does not claim to be. Worth noting for context: Netwrix publishes widely read roundups of data classification tools, and unlike Cyera, Sentra, Securiti, BigID and Varonis it has no transactable AWS Marketplace listing we could find, so we have no verified price to quote for it.
Fortra Data Classification Suite
No published rate cardFortra sits in a different tradition from the cloud scanners. Its Data Classification Suite is built around labels applied at the point of creation, often by the person writing the document, and then enforced downstream by DLP and rights management. That model is still the right answer in defense, government and regulated manufacturing, where the classification of a document depends on context a scanner cannot see and where an auditor expects a human decision on the record. It is the wrong answer if you want an automated inventory of a cloud warehouse with no user involvement. Fortra does not publish a rate card we could verify.
Snowflake Horizon and Databricks Unity Catalog
Included in the platformBefore you buy anything on this page, check what your warehouse already ships. Snowflake Horizon includes sensitive data classification, tagging, row access policies, dynamic masking and column-level lineage, with lineage requiring Enterprise Edition or higher. Unity Catalog covers tagging, grants, column masks and lineage across workspaces. For a single-platform estate with a manageable number of classifications, that is genuinely sufficient, and buying a third-party classifier to sit on top of native controls is a common and expensive mistake. The cost nuance people repeat wrongly is that Unity Catalog is not free, because the governance tier is Premium and Premium Jobs Compute runs at exactly double the Standard rate per DBU-hour. Meter detail in our Unity Catalog lineage guide.
Datatrail
Planned, self-serveWe should say this plainly rather than waste your time: Datatrail is not a data classification tool. We do not scan content, we do not detect PII, and we apply no labels. What we do is the job that starts the moment classification finishes. You connect a read-only role, we parse query history alongside your dbt manifest into a column-level lineage graph, and that graph answers the question every classification program eventually runs into: this column is tagged sensitive, so which other tables, models, exposures and dashboards now hold values derived from it? Classification tools label the columns they scanned. They do not follow a value into a derived mart six hops later, which is exactly where an unlabeled copy of regulated data tends to be sitting when an auditor finds it. Buy a classifier to find and label the data. Use lineage to find out where the labeled data already spread.
The copy your classifier never scanned
Here is the failure mode that shows up in audits rather than in rollouts, and no tool on this page catches it.
A classifier scans your warehouse and correctly tags a column of Social Security numbers in the source table. Someone selects that column into a staging table. An analyst aggregates staging into a mart. A dbt model joins the mart into a wider table that feeds a dashboard shared with a partner. Six hops later, a field derived from regulated data is sitting somewhere no label was ever applied, and every scan still reports clean, because classification labels the objects it scanned and does not follow values as they propagate.
That is a lineage question, not a classification question. Answering it means being able to say, for a given source column, every downstream table, model, exposure and dashboard that derives from it. Datatrail builds that from query history and dbt artifacts as column-level lineage, then turns it into impact analysis, so you see the blast radius of a classification or a schema change before it ships rather than after. Our data governance use case covers how teams pair the two, and data lineage vs data catalog unpacks why the categories keep getting confused.
So buy a classifier to find and label the data. It is the right tool for that job and we do not compete with it. Then use lineage to find out where the labeled data already went, because that is the copy that leaks.
Data classification questions buyers actually ask
What are data classification tools?
Data classification tools are software that scans your data, identifies what is sensitive or regulated, and applies consistent labels so the rest of your security and governance stack can act on them. A complete tool does four things: connects to your data stores, detects sensitive content such as PII, PHI or payment data, assigns a category or sensitivity label, and keeps that label current as data changes. The category splits into discovery-led platforms like BigID and Varonis, cloud DSPM like Cyera and Sentra, enforcement-led tools like Immuta, and the classification already built into Snowflake and Databricks.
How much does data classification software cost?
Far more than most published guidance suggests, and the real figures are verifiable. Read from live AWS Marketplace rate cards, Sentra runs four tiers from $50,000 to $500,000 a year, Cyera runs $50,000 to $250,000, Securiti lists a $100,000 platform fee, BigID lists $175,000 and Immuta $96,000. Varonis is the exception that lets you build a bottom-up estimate, publishing seventeen per-connector unit prices from $310 for a SaaS application to $30,000 for Snowflake. Microsoft Purview is metered instead, at $0.0165 per asset per day for catalog and classification.
Which data classification tools publish their pricing?
Almost none publish on their own website, but a transactable AWS Marketplace listing must carry a real dollar figure, and that is where the prices are. Cyera, Sentra, Securiti, BigID, Immuta, Collibra and Varonis all have live rate cards with real US list prices. Microsoft publishes Purview meters through a public retail price API that needs no key. Netwrix, Fortra and Concentric AI have no transactable rate card we could verify. Treat any figure on a review site with suspicion, because those numbers contradict each other badly and almost none of them cite a source.
What is the difference between data discovery and data classification?
Discovery finds the data and classification decides what it is. Discovery answers "there is a column here containing nine-digit numbers in 47 tables across three accounts." Classification answers "those are Social Security numbers, so this is regulated PII under CCPA." Every serious tool does both in one pass, which is why the market sells them together as data discovery and classification tools. The practical reason to keep them separate in your requirements is that discovery quality is about coverage and connectors, while classification quality is about accuracy and false positives, and vendors are rarely equally good at both.
What is the difference between data classification and DSPM?
Classification is a capability and DSPM is a product category built on top of it. Every data security posture management tool classifies, because it cannot score risk without knowing what the data is, but it then adds the part classification alone does not give you: a map of which identities can reach that data and a ranking of which combinations are actually dangerous. If you only need an inventory and labels, a classification tool is enough. If the question your security team is asking is which exposures to fix first, you want DSPM.
Do you get a discount for a multi-year data classification contract?
Not at list price. Across every vendor in this category whose rate card offers multi-year terms, the 24 and 36 month prices are exactly two times and three times the annual figure, with no reduction at all. Collibra runs $170,000, $340,000 and $510,000. All seventeen Varonis connector dimensions scale linearly. Several vendors, including Cyera, Sentra, Securiti and Immuta, offer only a 12-month term. So a longer commitment buys nothing on the published rate card, and any multi-year discount you receive is a concession you negotiated rather than a standard rate.
Can data classification tools classify data in Snowflake and Databricks?
Yes, and both platforms also classify natively at no extra license cost. Snowflake Horizon provides sensitive data classification and tagging, and Databricks Unity Catalog provides tagging and governance across workspaces. Third-party tools add value when classification must stay consistent across more than one platform, when unstructured file and SaaS data is in scope, or when you need the privacy and subject-rights workflow that neither warehouse provides. For a single-warehouse estate, start with what you already own before you buy a vendor.
Do data classification tools show where sensitive data went downstream?
Generally no, and this is the gap that surfaces during an audit rather than during a rollout. Classification tools label the objects they scanned. They do not trace a value as it is selected into a derived table, aggregated into a mart, joined by a dbt model and landed in a dashboard, so an unlabeled copy of regulated data can sit six hops downstream while every scan reports clean. Answering that requires column-level lineage across the warehouse, which is a different tool. Datatrail connects read-only and parses query history to produce exactly that graph.
Related comparisons
The enforcement layer that acts on the labels a classifier applies, with verified prices for Privacera, Satori and Immuta.
The wider program around classification: ownership, stewardship, policy and the audit evidence pack.
Where classification labels usually get stored, searched and surfaced to analysts.
All seventeen published per-connector unit prices, from $310 to $30,000.
See where your classified columns actually went
Connect a read-only role and get a column-level map of your warehouse in an afternoon. No agent, no proxy in the query path, and nothing to install.