All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Skyflow sells a data privacy vault that stores, tokenizes, and governs sensitive data through an API, and a line that keeps it out of large language models. The vault software is the copyable part. Harder to copy is that Skyflow holds the actual regulated data: it is PCI DSS Level 1 certified and a registered service provider with Mastercard and Visa, and its PCI pages present the vault as keeping a customer's front end out of PCI scope. Leaving would mean migrating vault-held data and reworking every integration and token mapping that references it, an exit path no public source documents. The tradeoff is reach: it protects only the data teams route into the vault. Its growth figures are self-reported, so the dependable proof is its named regulated customers and certifications.
| Description | Skyflow runs a data privacy vault that isolates, protects, and governs sensitive customer data across applications, data clouds, and AI systems through an API. | [f1] |
|---|---|---|
| Founded | 2019 | [f2] |
| HQ | Palo Alto, California, United States | [f3] |
| Funding | $100M total | [f2] |
| Latest funding | Series B extension, $30M, led by Khosla Ventures (2024) | [f2] |
| Product | What it does |
|---|---|
| Skyflow for PII | A data privacy vault that de-identifies and re-identifies PII using patented polymorphic encryption and tokenization, with access governance and secure data sharing. |
| Skyflow for GenAI | An LLM privacy vault that secures PII across the model lifecycle, de-identifying sensitive data before training, fine-tuning, RAG, and inference and re-identifying it on access. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Skyflow for PII isolates, governs access to, and protects sensitive data through tokenization and patented polymorphic encryption, and is mapped to the Cyber Defense Matrix. [f1]
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Skyflow for GenAI de-identifies PII before it reaches LLM training, fine-tuning, RAG, and inference, protecting the runtime and training data flowing through AI systems, and is mapped to the AI Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The buyer is well defined (engineering teams handling regulated PII), but the quantified pain (months of in-house build replaced by a vault deployed in weeks) comes from customer testimonials on vendor pages, and GDPR, PCI, and HIPAA ground the general need without independently quantifying the specific pain. [s2, s4, s7] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Product pages describe patented polymorphic encryption, tokenization, and an API-first design in concrete terms, and a public docs portal documents the Data API, governance, Connections, and client-side SDKs, but no demo, OSS footprint, third-party technical evaluation, or benchmark appears, and the customer testimonials are vendor-displayed quotes rather than external validation. [s2, s3, s7, s9] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The recent timing driver (keeping regulated data out of large language models) is argued through Skyflow's own GenAI line, and the 2024 Khosla extension is investor rather than buyer demand, while GDPR, PCI, and HIPAA are mature drivers rather than a recent inflection, leaving buyer-side demand indirect. [s3, s6] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Anshu Sharma's senior Salesforce role leading product, identity, and security is in-domain pedigree rather than a verifiable prior exit, and no named prior build or sustained publication record by the founders appears, so the team sits at elite pedigree without the exit a 4 needs. [s4, s7] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Multiple named reference customers across industries (GoodRx, ServiceNow, Nomi Health, Scalapay) appear with attributed quotes, and the company cites supporting nearly a billion records. These scale signals are vendor-published rather than independently reported. [s1, s2, s6] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Skyflow has raised about $100 million across rounds and grew from roughly 65 staff in 2021, and the latest round in the reviewed sources is the 2024 extension, so output per dollar reads as adequate without a visible recent scale signal. [s5, s6] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Skyflow is consistently described in its own material and in press as a data privacy vault, a recognizable slot that buyers and reporters place it in without explanation. It sits inside the broader data-security market alongside DSPM and tokenization vendors. [s6, s7] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The vault embeds into customer data pipelines through the API, which raises switching cost, but the core isolate-protect-govern capability is the kind of control a larger data-security suite or cloud provider could fold into a broader package. [s2, s7] |
Skyflow targets engineering and security teams at companies that handle regulated personal data and want to avoid building privacy infrastructure themselves. The company frames the problem as the recurring cost and breach risk of storing PII inside ordinary application databases, and it sells a separate vault as the alternative.
The pain is concrete for its buyers. Nomi Health and Scalapay describe the months of in-house engineering that a vault replaces, GoodRx reports a deployment in under three weeks, and Skyflow positions speed to compliance with GDPR, PCI, and HIPAA as the payoff. The 2024 extension round and the company's own messaging tie the same problem to a newer driver: enterprises adopting large language models need to keep sensitive data out of training, fine-tuning, and inference.
The buyer is well defined and the pain is corroborated by named customers, which supports a strong problem-clarity read. What keeps it from the top of the scale is that the underlying need, protecting regulated data, is one many data-security vendors now claim to solve. [s2, s3, s4, s6]
Skyflow ships two product lines around one architecture. Skyflow for PII is a data privacy vault that de-identifies and re-identifies sensitive data using patented polymorphic encryption and tokenization, with access governance, data residency controls, and secure data sharing delivered through an API.
Skyflow for GenAI extends the same vault to AI workflows. It de-identifies PII before data reaches large language models and re-identifies it on access, covering training, fine-tuning, RAG, and inference, and supports sharing data with third parties and outside models, so customers can adopt generative AI without exposing regulated records.
The public material describes the mechanisms in specific terms rather than marketing generalities, and a public docs portal at docs.skyflow.com covers the Data API, data governance, Connections, and client-side SDKs with guides and samples. Named customers give attributed testimonials about the vault, but independent technical validation is lighter than the broader data-security platforms in the category show, which holds capability depth at a strong rather than exceptional level. [s2, s3, s9]
Skyflow competes in the data-security and data-privacy market, where the vault sits alongside data security posture management, tokenization, and broader governance platforms. It is consistently described as a data privacy vault, and buyers place it in that recognizable slot.
Read against the data-security market, Skyflow occupies a narrower position than the broad data-security and data-privacy platforms that lead with enterprise-wide discovery and posture. Skyflow leads instead with a turnkey vault that engineering teams embed through an API, a more opinionated offering. Finovate reports roughly $100 million in total equity for Skyflow, citing Crunchbase.
The positioning advantage is the recognizable vault category and the API embedding that makes the offering hard to rip out. The exposure is that the isolate-protect-govern capability is no longer unique, so larger data-security suites and cloud providers can fold vault-style controls into a broader package. [s2, s6, s7]
Skyflow shows named reference customers across several industries, which is the strongest part of its public traction. GoodRx, ServiceNow, Nomi Health, and Scalapay appear with attributed quotes describing deployments, and the company reports supporting close to a billion records of user data.
The go-to-market reaches into AI data ecosystems through the LLM privacy line, which extends the vault into the generative-AI use case that the company now emphasizes.
The named logos support a strong traction read, but the scale metrics are vendor-published rather than confirmed by independent reporting or analyst placement. Without that third-party corroboration, the evidence supports a strong rather than category-leading position. [s1, s2, s6]
Skyflow was founded in 2019, and its co-founders include chief executive Anshu Sharma and engineering co-founder Roshmik Saha. Anshu Sharma was vice president of product and strategy at Salesforce, where he led identity, security, and user data management, a background directly relevant to the company's domain.
Sharma is also a serial entrepreneur and active angel investor who has backed many startups, and Saha previously built platform and high-performance computing systems at Microsoft and Lyft. That track record gives the founding story verifiable depth beyond job titles, which supports a strong team-credibility read.
The public record is clearest on the founding leadership. Broader bench signals, such as widely recognized research output or prior exits in the same category, are less prominent in the material, which keeps the score strong rather than exceptional. [s4, s7]
Skyflow's product is itself a compliance and data-protection control, and its customers adopt it specifically to meet regimes such as GDPR, PCI, and HIPAA. The company markets data residency, governed access, and the vault architecture as the means to that compliance.
The customer base skews toward regulated industries, including healthcare and financial services, where buyers expect strong security and privacy posture before deployment. Named customers in those sectors signal that Skyflow clears enterprise procurement in practice.
Skyflow's security page lists ISO 27001:2022, SOC 2 Type II, and PCI DSS Level 1 certifications, GDPR and HIPAA assessments, and registered-service-provider listings with Mastercard and Visa. Those published attestations back the compliance-enabling positioning, and buyers who adopt the vault to meet those regimes can verify Skyflow's own certifications on its site. [s2, s7, s8]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| BigID | competes with | ||
| Securiti | competes with | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. | |
| Cyera | competes with | ||
| Varonis | competes with | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. | |
| Sentra | adjacent |
Add analyzed competitors to compare them side by side with Skyflow.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Skyflow's switching cost comes from custody, not installation: because it stores and tokenizes the data itself, once card or health records live in the vault and its protection reaches into warehouses like Databricks and BigQuery, replacing it would mean migrating vault-held data and reworking every integration and token mapping that references it. No public source documents that exit path or quantifies its cost. Its PCI DSS Level 1 certification and Mastercard and Visa registered-service-provider listings are a real barrier for the payment-data case, since a rival must earn them independently to serve it. Less durable is the isolate-protect-govern capability itself, which a larger suite or cloud provider could rebuild, and no proprietary cross-customer dataset appears in the record.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Skyflow delivers software the customer integrates through an API and Skyflow operates, sold as a product rather than a service that accepts accountability for outcomes. Automated de-identification and governance are software output, which places it at the software-product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Because the vault stores and tokenizes the data itself, its protection reaches into downstream systems like Databricks and BigQuery, so replacing it would require migrating vault-held data and reworking every integration and token mapping that references it, a meaningful integration cost. No public source documents Skyflow's exit process or quantifies that effort, and no multi-year contractual lock appears in the record, so this is judged a moderate barrier rather than a high one. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | Skyflow's PCI DSS Level 1 certification and Mastercard and Visa registered-service-provider listings are a use-case-specific barrier: a rival must earn them independently to serve as a card-data vault, and Skyflow's own PCI material presents the certified vault as keeping a customer's front end out of PCI compliance scope. Its ISO and SOC 2 marks alone would be procurement table stakes, but the payment-network attestations create a genuine switching barrier for that case. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Building a vault that tokenizes and de-identifies sensitive data with patented polymorphic encryption while providing governed access and data residency across structured and unstructured data is a hard engineering problem. The same difficulty that lets Skyflow charge for it also makes the capability non-trivial to replicate cheaply. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Skyflow's buyers are regulated enterprises in fintech, healthcare, retail, and travel, including named customers like GoodRx, Nomi Health, and Scalapay, whose security and compliance teams put any data-handling vendor through review. That is the demanding, high-switching-cost buyer profile. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The vault sits in the runtime data path, storing and tokenizing records that applications and downstream services reference, so removing it disrupts live data flows rather than a passive monitor. It sits in the live data path and is consequential to remove, but a point control for sensitive data rather than a foundational platform others build on. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Skyflow holds patented polymorphic encryption, but a funded rival could build competing tokenization, and no proprietary cross-customer dataset appears in the record. The vault protects data teams route in rather than accumulating a cross-customer asset, keeping this at the no-data-moat level. |
Skyflow targets engineering and security teams at companies that handle regulated personal data and would otherwise build privacy infrastructure themselves. Skyflow's own material says its customers span fintech, retail, travel, and healthcare, and it frames the buying trigger as compliance, naming each product line for the obligation it answers: satisfying HIPAA, streamlining PCI compliance, and complying with global data-residency laws.
The segmentation narrows further through the GenAI line, which addresses the same regulated buyers as they adopt large language models and need to keep personal data out of training, fine-tuning, and inference. That positions Skyflow where two mandates overlap: standing privacy regulation and new AI adoption.
The segment is real but narrow in a specific way. Skyflow's model asks the buyer to route regulated data into a vault, so the reachable population is teams willing to make that architectural change rather than teams looking to cover data where it already sits. The sources cited here are Skyflow's own material and press coverage of it, and they carry no independent competitive-landscape analysis, so how contested that population is cannot be established from them.
Skyflow for PII de-identifies and re-identifies sensitive data using patented polymorphic encryption and tokenization, with governed access, data-residency controls, and secure sharing delivered through an API. A public docs portal documents a Data API, tokenization, governance, Connections, and client-side SDKs, so the capability claims rest on developer-facing material rather than marketing alone.
Skyflow for GenAI extends the same vault to AI workflows, detecting and redacting personal data across collection, training, fine-tuning, RAG, and inference, and re-identifying it on access. The AI line repackages the core de-identification engine for a new consumer rather than adding a separate technology.
The differentiator is architectural: Skyflow takes custody of the data and tokenizes it rather than leaving it where it was, so the protection travels with the record instead of describing it. That is a real capability, but the isolate-protect-govern function it performs is one a funded rival could rebuild, and no third-party technical evaluation or benchmark appears in the public record.
Skyflow sells through a direct enterprise motion anchored by named reference customers. GoodRx, Nomi Health, and Scalapay appear on Skyflow's pages with attributed quotes from their chief technology officers, GoodRx reporting a deployment in under three weeks and Nomi Health in hours against the months an in-house build would take. ServiceNow's chief information security officer appears in the same strip, but his quote describes Skyflow supporting ServiceNow's own customers, a partnership rather than a deployment of his own.
The company pairs that with an experienced enterprise revenue leader and reaches AI buyers through the GenAI line, extending the same sales motion into the generative-AI use case it now emphasizes.
The gap is independent confirmation. The testimonials and scale figures are vendor-displayed, and independent confirmation remains limited: press coverage includes a product profile that names customers, but the testimonials and scale claims still largely come from vendor-displayed or vendor-supplied material, and no analyst placement appears in the record.
Skyflow does not publish pricing. Its pages carry a get-a-demo call to action and a contact-sales link with no price list, the pattern of a vendor selling negotiated enterprise deals rather than self-serve subscriptions. That reading is an inference from the routing, not something Skyflow states.
The absence fits the buyer and the product: regulated enterprises routing sensitive data through a vault expect scoped, contract-led purchasing. The unit Skyflow charges on is not disclosed, so whether its price metric tracks the value a buyer measures cannot be verified from the public record.
Skyflow delivers as a managed cloud service consumed through an API, with client-side SDKs and three documented deployment models for customers with residency or isolation requirements: multi-tenant SaaS, a dedicated managed private cloud, and bring-your-own-cloud. Two of the three run on Skyflow-operated infrastructure, so those customers offload the operational burden of storing and protecting sensitive data, while the third places the vault in the customer's own cloud account under its own infrastructure control.
Operational maturity shows in the security program: Skyflow's security page describes application, infrastructure, and operational controls, and the docs cover deployment models, authentication, and security best practices. That backs the claim that Skyflow runs production-grade infrastructure for regulated data.
The public record does carry scale and resilience material, though all of it traces to Skyflow. Press coverage repeats vendor-supplied volume figures for records held and quarterly API calls, and Skyflow's security page describes continuous backup, cross-region backup for regional recovery, multi-availability-zone deployment, and stated recovery-point and recovery-time objectives. What it does not carry is any independently verified scale metric, any published uptime or availability commitment, or any numeric target attached to those recovery objectives, so delivery maturity still rests on the attestations and the named production customers.
Trust sits at the center of Skyflow's proposition because the product is itself a compliance control. Skyflow's security page lists ISO 27001:2022, SOC 2 Type II, and PCI DSS Level 1 certifications, GDPR and HIPAA assessments, and registered-service-provider status with Mastercard and Visa, with links to the underlying certificates and registry listings.
These attestations do more than clear procurement. PCI DSS Level 1 and the card-network registered-service-provider listings let Skyflow hold cardholder data as a certified service provider. Skyflow presents the payoff as scope reduction: its PCI page says capturing card data in the vault keeps a customer's front end out of PCI compliance scope, and its Scalapay case study says the arrangement decreases that customer's compliance scope. Both statements are Skyflow's own, so how much scope any particular buyer sheds is not independently established. That makes the certifications part of the value delivered, not just a trust signal.
The customer base reinforces the posture: named customers in healthcare and financial services signal that Skyflow clears enterprise security review in practice. The one caveat is that the strongest efficacy claims remain vendor-stated.
Skyflow positions the vault as an integration point in the data stack rather than a standalone silo. Skyflow Connections sends protected data to downstream APIs such as Stripe and Adyen, and client-side SDKs collect sensitive data before it touches customer systems, so the vault sits in the flow between applications and the services that consume the data.
The GenAI line extends the ecosystem into AI infrastructure, covering data shared with third parties and outside models across the LLM lifecycle. The GoodRx deployment shows Skyflow's protection reaching into data warehouses like Databricks and BigQuery, which is where the platform embedding creates switching cost.
The ecosystem is integration-deep rather than partner-broad: the public record shows developer integrations and a systems-integrator reference, but no marketplace listings or reseller network that would give Skyflow a distribution reach an incumbent could not match.
Skyflow was founded in 2019 by Anshu Sharma and Prakash Khot. Chief executive Anshu Sharma was vice president of product and strategy at Salesforce, where he led identity, security, and user-data management, a background directly on point for a data-privacy vault, and he is an active angel investor across dozens of startups.
The bench adds relevant depth: engineering co-founder Roshmik Saha previously built platform and high-performance-computing systems at Microsoft and Lyft, and the executive team adds product and enterprise-sales leaders drawn from large software companies. The founding story carries verifiable domain pedigree beyond job titles.
What the record does not show is a prior exit in the category or a widely recognized research output, so the team reads as strong in-domain operators rather than proven category-definers. That is the ceiling on the team's signal, not a weakness in it.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Skyflow: Secure PII and Sensitive Data | official | 2026-06-24 |
| f2 | Finovate: Data Privacy Vault Skyflow Secures $30 Million in New Funding | press | 2026-06-24 |
| f3 | YourStory: Skyflow tackles data privacy and security for enterprises who use LLMs | press | 2026-06-24 |
| f4 | AI Defense Matrix Catalog mapping | other | 2026-06-24 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Skyflow: GoodRx, Nomi Health, Scalapay, and ServiceNow secure data at runtime “Securing the flow of data across datastores, models, and agents. With Skyflow's zero-trust vault architecture, we can isolate, protect and govern PII (Nitin Shingate, CTO at GoodRx).” | official | 2026-06-24 |
| s2 | Skyflow for PII: Secure PII and Sensitive Data “Protect and de-identify sensitive data using patented polymorphic encryption and tokenization.” | official | 2026-06-24 |
| s3 | Skyflow for GenAI: GenAI Data Privacy and LLM Data Security “Skyflow helps you secure during the end-to-end LLM lifecycle, including training, fine tuning, RAG, data re-identification, and sharing data with third parties and outside models.” | official | 2026-06-24 |
| s4 | Skyflow: Company “Anshu Sharma is the co-founder and CEO of Skyflow. ... Roshmik Saha has over 15 years of experience building platforms and high performance computing systems, ranging from software engineering at Microsoft to founding the Lyft Autonomous Vehicle Platform Team” | official | 2026-07-02 |
| s5 | TechCrunch: Skyflow's data privacy API business raises $45M Series B “The startup has around 65 staff today and is looking to roughly double that by the end of 2022.” | press | 2026-06-24 |
| s6 | Finovate: Data Privacy Vault Skyflow Secures $30 Million in New Funding “Data privacy vault Skyflow has raised $30 million in an extension Series B round led by Khosla Ventures. The investment takes the company's total equity capital to $100 million, according to Crunchbase.” | press | 2026-06-24 |
| s7 | YourStory: Skyflow tackles data privacy and security for enterprises who use LLMs “Founded in 2019 by Anshu Sharma and Prakash Khot, Skyflow is a data privacy vault built to simplify how companies isolate, protect, and govern their customers' most sensitive data.” | press | 2026-06-24 |
| s8 | Skyflow: Security “Our platform environment and team adhere to the following standards: ISO 27001:2022 Certified. SOC 2 Type II Certified. PCI DSS Level 1 Certified. GDPR Assessed and Compliant. HIPAA Assessed and Eligible.” | official | 2026-07-02 |
| s9 | Skyflow Docs: Welcome to Skyflow “Here you’ll find guides, demos, and samples to help you build with Skyflow.” | official | 2026-07-02 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Skyflow: Runtime AI Data Control “With Skyflow's zero-trust vault architecture, we can isolate, protect and govern PII in Databricks & BigQuery (Nitin Shingate, CTO at GoodRx).” | official | 2026-07-08 |
| s2 | Skyflow for PII: Secure PII and Sensitive Data “Protect and de-identify sensitive data using patented polymorphic encryption and tokenization.” | official | 2026-07-08 |
| s3 | Skyflow for GenAI: GenAI Data Privacy and LLM Data Security “Skyflow helps you secure during the end-to-end LLM lifecycle, including training, fine tuning, RAG, data re-identification, and sharing data with third parties and outside models.” | official | 2026-07-08 |
| s4 | Skyflow: Company “Anshu Sharma is the co-founder and CEO of Skyflow... Previously, Anshu served as vice president of product and strategy at Salesforce leading identity, security and user data management. ... Roshmik Saha ... software engineering at Microsoft to founding the Lyft Autonomous Vehicle Platform Team” | official | 2026-07-08 |
| s5 | TechCrunch: Skyflow's data privacy API business raises $45M Series B “The market for corporate data privacy products is heating up, with Skyflow announcing a $45 million Series B this morning, just a day after TripleBlind announced a $24 million round.” | press | 2026-07-08 |
| s6 | Finovate: Data Privacy Vault Skyflow Secures $30 Million in New Funding “Data privacy vault Skyflow has raised $30 million in an extension Series B round led by Khosla Ventures. The investment takes the company's total equity capital to $100 million, according to Crunchbase.” | press | 2026-07-08 |
| s7 | YourStory: Skyflow tackles data privacy and security for enterprises who use LLMs “Founded in 2019 by Anshu Sharma and Prakash Khot, Skyflow is a data privacy vault built to simplify how companies isolate, protect, and govern their customers' most sensitive data.” | press | 2026-07-08 |
| s8 | Skyflow: Security “ISO 27001:2022 Certified. SOC 2 Type II Certified. PCI DSS Level 1 Certified. GDPR Assessed and Compliant. HIPAA Assessed and Eligible. Mastercard Site Data Protection (SDP) Compliant Registered Service Provider. Visa Global Registry Registered Service Provider.” | official | 2026-07-08 |
| s9 | Skyflow Docs: Welcome to Skyflow “Use Skyflow Connections to securely send sensitive data to downstream APIs like Stripe, Adyen, etc.” | official | 2026-07-08 |
| s10 | Skyflow Customers: attributed deployment quotes from GoodRx, Nomi Health, and Scalapay (targeted recapture 2026-08-01) “We were able to successfully deploy Skyflow in less than three weeks ... Nitin Shingate CTO, GoodRx ... We were up and running on Skyflow in just hours, rather than the months it would take to build ... Boe Hartman CTO, Nomi Health ... Johnny Mitrevski CTO, Scalapay ... sign up for a demo today” | official | 2026-08-01 |
| s11 | Skyflow homepage recapture: customer quote strip including ServiceNow's CISO, product lines named for their compliance driver, and the demo path (2026-08-01) “TRUSTED BY Skyflow customers secure sensitive data at runtime ... Skyflow's solutions support our customers as they grow into new markets. ... Jeffrey DiMuro ... CISO at ServiceNow ... Get a Demo ... Protect PHI and satisfy HIPAA ... Streamline PCI compliance ... Contact Sales” | official | 2026-08-01 |
| s12 | Skyflow for PCI: stated PCI scope reduction and the named customer verticals (targeted recapture 2026-08-01) “keeping your front end out of PCI compliance scope ... Skyflow customers span verticals like fintech, retail, travel, and healthcare and use the data privacy vault architecture to comply with data residency laws, keep sensitive data out of LLMs, govern access to PII, and more.” | official | 2026-08-01 |
| s13 | Skyflow and Scalapay case study: stated compliance-scope reduction (targeted recapture 2026-08-01) “This keeps Scalapay's backend infrastructure and database free of sensitive data and decreases their compliance scope.” | official | 2026-08-01 |
| s14 | Skyflow Docs: three deployment models, one of them in the customer's own cloud account (targeted recapture 2026-08-01) “Skyflow supports three deployment models to meet different security, compliance, and infrastructure requirements. ... Multi-tenant SaaS is the default Skyflow deployment model: fully managed on shared infrastructure. ... Bring Your Own Cloud (BYOC) ... Customer cloud account” | official | 2026-08-01 |
| s15 | Skyflow Docs: security best practices checklist, alongside the authentication and deployment-model pages (targeted recapture 2026-08-01) “Here is a checklist of our security best practices that you can use for your implementation. ... Authenticate ... Deployment models ... Security best practices ... Compliance and certifications” | official | 2026-08-01 |
| s16 | Skyflow Company page: Roshmik Saha's stated title (targeted recapture 2026-08-01) “Roshmik Saha ... Co-founder (Engineering) ... has over 15 years of experience building platforms and high performance computing systems, ranging from software engineering at Microsoft to founding the Lyft Autonomous Vehicle Platform Team.” | official | 2026-08-01 |
| s17 | Skyflow Security page: the three-pronged control program (targeted recapture 2026-08-01) “Skyflow's team, processes and technologies use a three-pronged approach to protect customer data ... 1. Application-Level Security Control ... 2. Infrastructure-Level Security Control ... 3. Operation-Level Security Control” | official | 2026-08-01 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.