Enterprise masking

When the data has to
come from production.

Synthetic data covers most testing. For the rest, GoMask masks and subsets live databases with referential integrity intact, from a UI or from YAML in your repo.

Runs in your VPC or on-prem · Audit log on every run
Two products, one decision

Generate it, or mask it?

Data FactorySynthetic, from a brief
New features, load tests, ML training, demos, teaching
No production access needed, nothing to leak
Self-serve, one credit per row
Cannot reproduce a specific production bug
Enterprise maskingReal shape, real edge cases, no PII
Reproducing production incidents, migrations, regression suites
Masked copies keep joins, distributions and history
Runs where the data lives; priced per engagement
Needs a production replica and a security review
Capabilities

Four things it does, each explained once.

Masking, discovery, subsetting and rules as code. Each one explained once.

Deterministic masking

Format-preserving encryption keeps joins, lengths and checksums intact. The same input masks to the same output across every table and run.

PII discovery

Scans schemas and samples to propose which columns carry personal data, then lets a human confirm before anything is masked.

Subsetting

Pull a coherent slice of production, with every foreign key satisfied, instead of a full copy.

GoMask as Code

Rules in YAML, versioned in Git, executed in your pipeline. Preview a run before it touches a target.

Connectors

What it connects to today.

Native connectors are listed; everything else is reached through drivers on request.

Native database connectors
PostgreSQLMySQLSQL ServerOracleMongoDBSnowflakeDatabricks
Other sources are reached through CData drivers, added per engagement.
Pipelines
GitHub ActionsGitLab CIJenkinsCLI
Any CI that can run a container can run GoMask as Code.
Assurance

What you can hold us to.

The commitments that matter when the source is production.

Security posture

Encryption in transit and at rest, role-based access control, and an audit log on every run. A data processing agreement is available on request.

Read the DPA
Deploy where the data lives

Managed cloud, your private VPC, or on-prem. Masking runs next to the source; nothing leaves the boundary you choose.

Book a demo
Regulated data first

Built for GDPR and HIPAA workloads: deterministic masking keeps referential integrity while personal data never reaches a test environment.

Privacy policy
CONNECTS TO
  • PostgreSQL
  • MySQL
  • Oracle
  • MongoDB
  • Snowflake
  • Databricks
  • BigQuery
  • GitHub Actions
  • Parquet
Book a demo

Thirty minutes with a solutions engineer.

Bring a schema. We will show masking rules drafted against it, a subset run, and the audit log it produces. No deck.

We reply within one business day. No mailing list.