# Cyber Company Profiles: Skyflow

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-07-08
Canonical: https://cybercompanyprofiles.com/companies/skyflow
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Skyflow, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [skyflow.com](https://www.skyflow.com/)
- Profile: https://cybercompanyprofiles.com/companies/skyflow
- Type: Security for AI, Data Security, Privacy
- Also known as: Skyflow, Inc.
- Market readiness: Established (26/40)
- Defensibility: Contested (14/21)
- Founded: 2019
- Funding: $100M total
- Last updated: 2026-07-08

## Executive Summary

Skyflow sells a data privacy vault that stores, tokenizes, and governs sensitive data through an API, and a line that keeps it out of large language models. The vault software is the copyable part. Harder to copy is that Skyflow holds the actual regulated data: it is PCI DSS Level 1 certified and a registered service provider with Mastercard and Visa, and its PCI pages present the vault as keeping a customer's front end out of PCI scope. Leaving would mean migrating vault-held data and reworking every integration and token mapping that references it, an exit path no public source documents. The tradeoff is reach: it protects only the data teams route into the vault. Its growth figures are self-reported, so the dependable proof is its named regulated customers and certifications.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Skyflow runs a data privacy vault that isolates, protects, and governs sensitive customer data across applications, data clouds, and AI systems through an API. | [\[f1\]](#company-detail-sources) |
| Founded | 2019 | [\[f2\]](#company-detail-sources) |
| HQ | Palo Alto, California, United States | [\[f3\]](#company-detail-sources) |
| Funding | $100M total | [\[f2\]](#company-detail-sources) |
| Latest funding | Series B extension, $30M, led by Khosla Ventures (2024) | [\[f2\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Skyflow for PII | A data privacy vault that de-identifies and re-identifies PII using patented polymorphic encryption and tokenization, with access governance and secure data sharing. |
| Skyflow for GenAI | An LLM privacy vault that secures PII across the model lifecycle, de-identifying sensitive data before training, fine-tuning, RAG, and inference and re-identifying it on access. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f1\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Data |  | ✓ |  |  |  |

Skyflow for PII isolates, governs access to, and protects sensitive data through tokenization and patented polymorphic encryption, and is mapped to the Cyber Defense Matrix.

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f4\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| Runtime AI Data |  |  | ✓ |  |  |  |
| Training Data |  |  | ✓ |  |  |  |

Skyflow for GenAI de-identifies PII before it reaches LLM training, fine-tuning, RAG, and inference, protecting the runtime and training data flowing through AI systems, and is mapped to the AI Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (26/40)**

Analyzed 2026-07-05. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | The buyer is well defined (engineering teams handling regulated PII), but the quantified pain (months of in-house build replaced by a vault deployed in weeks) comes from customer testimonials on vendor pages, and GDPR, PCI, and HIPAA ground the general need without independently quantifying the specific pain. \[[s2](#profile-analysis-sources), [s4](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | Product pages describe patented polymorphic encryption, tokenization, and an API-first design in concrete terms, and a public docs portal documents the Data API, governance, Connections, and client-side SDKs, but no demo, OSS footprint, third-party technical evaluation, or benchmark appears, and the customer testimonials are vendor-displayed quotes rather than external validation. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s7](#profile-analysis-sources), [s9](#profile-analysis-sources)\] |
| Market Timing | 3/5 | The recent timing driver (keeping regulated data out of large language models) is argued through Skyflow's own GenAI line, and the 2024 Khosla extension is investor rather than buyer demand, while GDPR, PCI, and HIPAA are mature drivers rather than a recent inflection, leaving buyer-side demand indirect. \[[s3](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | Anshu Sharma's senior Salesforce role leading product, identity, and security is in-domain pedigree rather than a verifiable prior exit, and no named prior build or sustained publication record by the founders appears, so the team sits at elite pedigree without the exit a 4 needs. \[[s4](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | Multiple named reference customers across industries (GoodRx, ServiceNow, Nomi Health, Scalapay) appear with attributed quotes, and the company cites supporting nearly a billion records. These scale signals are vendor-published rather than independently reported. \[[s1](#profile-analysis-sources), [s2](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | Skyflow has raised about $100 million across rounds and grew from roughly 65 staff in 2021, and the latest round in the reviewed sources is the 2024 extension, so output per dollar reads as adequate without a visible recent scale signal. \[[s5](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Skyflow is consistently described in its own material and in press as a data privacy vault, a recognizable slot that buyers and reporters place it in without explanation. It sits inside the broader data-security market alongside DSPM and tokenization vendors. \[[s6](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | The vault embeds into customer data pipelines through the API, which raises switching cost, but the core isolate-protect-govern capability is the kind of control a larger data-security suite or cloud provider could fold into a broader package. \[[s2](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |

### Business Risks

- A larger data-security platform or cloud provider could bundle vault-style tokenization and de-identification into a broader suite and undercut Skyflow's standalone pitch.
- The latest Skyflow round in the reviewed sources is the 2024 Khosla Ventures extension, and a longer gap before the next raise could constrain its ability to match larger data-security competitors on sales and engineering.
- Most public scale metrics (nearly a billion records of user data) are vendor-published, so traction could prove thinner than the figures imply if independent reporting does not corroborate them.
- The LLM privacy line depends on enterprises routing sensitive data through a third-party vault before AI use, a pattern cloud providers could absorb with native data-protection features.

### Problem & Market

Skyflow targets engineering and security teams at companies that handle regulated personal data and want to avoid building privacy infrastructure themselves. The company frames the problem as the recurring cost and breach risk of storing PII inside ordinary application databases, and it sells a separate vault as the alternative.

The pain is concrete for its buyers. Nomi Health and Scalapay describe the months of in-house engineering that a vault replaces, GoodRx reports a deployment in under three weeks, and Skyflow positions speed to compliance with GDPR, PCI, and HIPAA as the payoff. The 2024 extension round and the company's own messaging tie the same problem to a newer driver: enterprises adopting large language models need to keep sensitive data out of training, fine-tuning, and inference.

The buyer is well defined and the pain is corroborated by named customers, which supports a strong problem-clarity read. What keeps it from the top of the scale is that the underlying need, protecting regulated data, is one many data-security vendors now claim to solve. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s6](#profile-analysis-sources)\]

### Product Capabilities

Skyflow ships two product lines around one architecture. Skyflow for PII is a data privacy vault that de-identifies and re-identifies sensitive data using patented polymorphic encryption and tokenization, with access governance, data residency controls, and secure data sharing delivered through an API.

Skyflow for GenAI extends the same vault to AI workflows. It de-identifies PII before data reaches large language models and re-identifies it on access, covering training, fine-tuning, RAG, and inference, and supports sharing data with third parties and outside models, so customers can adopt generative AI without exposing regulated records.

The public material describes the mechanisms in specific terms rather than marketing generalities, and a public docs portal at docs.skyflow.com covers the Data API, data governance, Connections, and client-side SDKs with guides and samples. Named customers give attributed testimonials about the vault, but independent technical validation is lighter than the broader data-security platforms in the category show, which holds capability depth at a strong rather than exceptional level. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s9](#profile-analysis-sources)\]

### Competitive Positioning

Skyflow competes in the data-security and data-privacy market, where the vault sits alongside data security posture management, tokenization, and broader governance platforms. It is consistently described as a data privacy vault, and buyers place it in that recognizable slot.

Read against the data-security market, Skyflow occupies a narrower position than the broad data-security and data-privacy platforms that lead with enterprise-wide discovery and posture. Skyflow leads instead with a turnkey vault that engineering teams embed through an API, a more opinionated offering. Finovate reports roughly $100 million in total equity for Skyflow, citing Crunchbase.

The positioning advantage is the recognizable vault category and the API embedding that makes the offering hard to rip out. The exposure is that the isolate-protect-govern capability is no longer unique, so larger data-security suites and cloud providers can fold vault-style controls into a broader package. \[[s2](#profile-analysis-sources), [s6](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Go-to-Market & Traction

Skyflow shows named reference customers across several industries, which is the strongest part of its public traction. GoodRx, ServiceNow, Nomi Health, and Scalapay appear with attributed quotes describing deployments, and the company reports supporting close to a billion records of user data.

The go-to-market reaches into AI data ecosystems through the LLM privacy line, which extends the vault into the generative-AI use case that the company now emphasizes.

The named logos support a strong traction read, but the scale metrics are vendor-published rather than confirmed by independent reporting or analyst placement. Without that third-party corroboration, the evidence supports a strong rather than category-leading position. \[[s1](#profile-analysis-sources), [s2](#profile-analysis-sources), [s6](#profile-analysis-sources)\]

### Team & Credibility

Skyflow was founded in 2019, and its co-founders include chief executive Anshu Sharma and engineering co-founder Roshmik Saha. Anshu Sharma was vice president of product and strategy at Salesforce, where he led identity, security, and user data management, a background directly relevant to the company's domain.

Sharma is also a serial entrepreneur and active angel investor who has backed many startups, and Saha previously built platform and high-performance computing systems at Microsoft and Lyft. That track record gives the founding story verifiable depth beyond job titles, which supports a strong team-credibility read.

The public record is clearest on the founding leadership. Broader bench signals, such as widely recognized research output or prior exits in the same category, are less prominent in the material, which keeps the score strong rather than exceptional. \[[s4](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Trust Readiness

Skyflow's product is itself a compliance and data-protection control, and its customers adopt it specifically to meet regimes such as GDPR, PCI, and HIPAA. The company markets data residency, governed access, and the vault architecture as the means to that compliance.

The customer base skews toward regulated industries, including healthcare and financial services, where buyers expect strong security and privacy posture before deployment. Named customers in those sectors signal that Skyflow clears enterprise procurement in practice.

Skyflow's security page lists ISO 27001:2022, SOC 2 Type II, and PCI DSS Level 1 certifications, GDPR and HIPAA assessments, and registered-service-provider listings with Mastercard and Visa. Those published attestations back the compliance-enabling positioning, and buyers who adopt the vault to meet those regimes can verify Skyflow's own certifications on its site. \[[s2](#profile-analysis-sources), [s7](#profile-analysis-sources), [s8](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| BigID | competes with |  |
| Securiti | competes with |  |
| Cyera | competes with |  |
| Varonis | competes with |  |
| Sentra | adjacent |  |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (14/21)**

Band guidance: reinforce or reposition. Analyzed 2026-07-08. Scope: whole company.

Skyflow's switching cost comes from custody, not installation: because it stores and tokenizes the data itself, once card or health records live in the vault and its protection reaches into warehouses like Databricks and BigQuery, replacing it would mean migrating vault-held data and reworking every integration and token mapping that references it. No public source documents that exit path or quantifies its cost. Its PCI DSS Level 1 certification and Mastercard and Visa registered-service-provider listings are a real barrier for the payment-data case, since a rival must earn them independently to serve it. Less durable is the isolate-protect-govern capability itself, which a larger suite or cloud provider could rebuild, and no proprietary cross-customer dataset appears in the record.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Skyflow delivers software the customer integrates through an API and Skyflow operates, sold as a product rather than a service that accepts accountability for outcomes. Automated de-identification and governance are software output, which places it at the software-product level. \[[s2](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Because the vault stores and tokenizes the data itself, its protection reaches into downstream systems like Databricks and BigQuery, so replacing it would require migrating vault-held data and reworking every integration and token mapping that references it, a meaningful integration cost. No public source documents Skyflow's exit process or quantifies that effort, and no multi-year contractual lock appears in the record, so this is judged a moderate barrier rather than a high one. \[[s1](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Compliance Moat | 2/3 | Skyflow's PCI DSS Level 1 certification and Mastercard and Visa registered-service-provider listings are a use-case-specific barrier: a rival must earn them independently to serve as a card-data vault, and Skyflow's own PCI material presents the certified vault as keeping a customer's front end out of PCI compliance scope. Its ISO and SOC 2 marks alone would be procurement table stakes, but the payment-network attestations create a genuine switching barrier for that case. \[[s8](#deep-dive-sources), [s12](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Building a vault that tokenizes and de-identifies sensitive data with patented polymorphic encryption while providing governed access and data residency across structured and unstructured data is a hard engineering problem. The same difficulty that lets Skyflow charge for it also makes the capability non-trivial to replicate cheaply. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | Skyflow's buyers are regulated enterprises in fintech, healthcare, retail, and travel, including named customers like GoodRx, Nomi Health, and Scalapay, whose security and compliance teams put any data-handling vendor through review. That is the demanding, high-switching-cost buyer profile. \[[s1](#deep-dive-sources), [s2](#deep-dive-sources), [s10](#deep-dive-sources), [s12](#deep-dive-sources)\] |
| Layer | 2/3 | The vault sits in the runtime data path, storing and tokenizing records that applications and downstream services reference, so removing it disrupts live data flows rather than a passive monitor. It sits in the live data path and is consequential to remove, but a point control for sensitive data rather than a foundational platform others build on. \[[s1](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | Skyflow holds patented polymorphic encryption, but a funded rival could build competing tokenization, and no proprietary cross-customer dataset appears in the record. The vault protects data teams route in rather than accumulating a cross-customer asset, keeping this at the no-data-moat level. \[[s2](#deep-dive-sources), [s6](#deep-dive-sources)\] |

### Strategic Market Segmentation

Skyflow targets engineering and security teams at companies that handle regulated personal data and would otherwise build privacy infrastructure themselves. Skyflow's own material says its customers span fintech, retail, travel, and healthcare, and it frames the buying trigger as compliance, naming each product line for the obligation it answers: satisfying HIPAA, streamlining PCI compliance, and complying with global data-residency laws.

The segmentation narrows further through the GenAI line, which addresses the same regulated buyers as they adopt large language models and need to keep personal data out of training, fine-tuning, and inference. That positions Skyflow where two mandates overlap: standing privacy regulation and new AI adoption.

The segment is real but narrow in a specific way. Skyflow's model asks the buyer to route regulated data into a vault, so the reachable population is teams willing to make that architectural change rather than teams looking to cover data where it already sits. The sources cited here are Skyflow's own material and press coverage of it, and they carry no independent competitive-landscape analysis, so how contested that population is cannot be established from them. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s7](#deep-dive-sources), [s11](#deep-dive-sources), [s12](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

Skyflow for PII de-identifies and re-identifies sensitive data using patented polymorphic encryption and tokenization, with governed access, data-residency controls, and secure sharing delivered through an API. A public docs portal documents a Data API, tokenization, governance, Connections, and client-side SDKs, so the capability claims rest on developer-facing material rather than marketing alone.

Skyflow for GenAI extends the same vault to AI workflows, detecting and redacting personal data across collection, training, fine-tuning, RAG, and inference, and re-identifying it on access. The AI line repackages the core de-identification engine for a new consumer rather than adding a separate technology.

The differentiator is architectural: Skyflow takes custody of the data and tokenizes it rather than leaving it where it was, so the protection travels with the record instead of describing it. That is a real capability, but the isolate-protect-govern function it performs is one a funded rival could rebuild, and no third-party technical evaluation or benchmark appears in the public record. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Skyflow sells through a direct enterprise motion anchored by named reference customers. GoodRx, Nomi Health, and Scalapay appear on Skyflow's pages with attributed quotes from their chief technology officers, GoodRx reporting a deployment in under three weeks and Nomi Health in hours against the months an in-house build would take. ServiceNow's chief information security officer appears in the same strip, but his quote describes Skyflow supporting ServiceNow's own customers, a partnership rather than a deployment of his own.

The company pairs that with an experienced enterprise revenue leader and reaches AI buyers through the GenAI line, extending the same sales motion into the generative-AI use case it now emphasizes.

The gap is independent confirmation. The testimonials and scale figures are vendor-displayed, and independent confirmation remains limited: press coverage includes a product profile that names customers, but the testimonials and scale claims still largely come from vendor-displayed or vendor-supplied material, and no analyst placement appears in the record. \[[s1](#deep-dive-sources), [s2](#deep-dive-sources), [s4](#deep-dive-sources), [s5](#deep-dive-sources), [s6](#deep-dive-sources), [s7](#deep-dive-sources), [s10](#deep-dive-sources), [s11](#deep-dive-sources)\]

### Pricing Model

Skyflow does not publish pricing. Its pages carry a get-a-demo call to action and a contact-sales link with no price list, the pattern of a vendor selling negotiated enterprise deals rather than self-serve subscriptions. That reading is an inference from the routing, not something Skyflow states.

The absence fits the buyer and the product: regulated enterprises routing sensitive data through a vault expect scoped, contract-led purchasing. The unit Skyflow charges on is not disclosed, so whether its price metric tracks the value a buyer measures cannot be verified from the public record. \[[s10](#deep-dive-sources), [s11](#deep-dive-sources)\]

### Product Delivery & Operations

Skyflow delivers as a managed cloud service consumed through an API, with client-side SDKs and three documented deployment models for customers with residency or isolation requirements: multi-tenant SaaS, a dedicated managed private cloud, and bring-your-own-cloud. Two of the three run on Skyflow-operated infrastructure, so those customers offload the operational burden of storing and protecting sensitive data, while the third places the vault in the customer's own cloud account under its own infrastructure control.

Operational maturity shows in the security program: Skyflow's security page describes application, infrastructure, and operational controls, and the docs cover deployment models, authentication, and security best practices. That backs the claim that Skyflow runs production-grade infrastructure for regulated data.

The public record does carry scale and resilience material, though all of it traces to Skyflow. Press coverage repeats vendor-supplied volume figures for records held and quarterly API calls, and Skyflow's security page describes continuous backup, cross-region backup for regional recovery, multi-availability-zone deployment, and stated recovery-point and recovery-time objectives. What it does not carry is any independently verified scale metric, any published uptime or availability commitment, or any numeric target attached to those recovery objectives, so delivery maturity still rests on the attestations and the named production customers. \[[s2](#deep-dive-sources), [s6](#deep-dive-sources), [s8](#deep-dive-sources), [s9](#deep-dive-sources), [s14](#deep-dive-sources), [s15](#deep-dive-sources), [s17](#deep-dive-sources)\]

### Earning Customers' Trust

Trust sits at the center of Skyflow's proposition because the product is itself a compliance control. Skyflow's security page lists ISO 27001:2022, SOC 2 Type II, and PCI DSS Level 1 certifications, GDPR and HIPAA assessments, and registered-service-provider status with Mastercard and Visa, with links to the underlying certificates and registry listings.

These attestations do more than clear procurement. PCI DSS Level 1 and the card-network registered-service-provider listings let Skyflow hold cardholder data as a certified service provider. Skyflow presents the payoff as scope reduction: its PCI page says capturing card data in the vault keeps a customer's front end out of PCI compliance scope, and its Scalapay case study says the arrangement decreases that customer's compliance scope. Both statements are Skyflow's own, so how much scope any particular buyer sheds is not independently established. That makes the certifications part of the value delivered, not just a trust signal.

The customer base reinforces the posture: named customers in healthcare and financial services signal that Skyflow clears enterprise security review in practice. The one caveat is that the strongest efficacy claims remain vendor-stated. \[[s8](#deep-dive-sources), [s2](#deep-dive-sources), [s12](#deep-dive-sources), [s13](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Skyflow positions the vault as an integration point in the data stack rather than a standalone silo. Skyflow Connections sends protected data to downstream APIs such as Stripe and Adyen, and client-side SDKs collect sensitive data before it touches customer systems, so the vault sits in the flow between applications and the services that consume the data.

The GenAI line extends the ecosystem into AI infrastructure, covering data shared with third parties and outside models across the LLM lifecycle. The GoodRx deployment shows Skyflow's protection reaching into data warehouses like Databricks and BigQuery, which is where the platform embedding creates switching cost.

The ecosystem is integration-deep rather than partner-broad: the public record shows developer integrations and a systems-integrator reference, but no marketplace listings or reseller network that would give Skyflow a distribution reach an incumbent could not match. \[[s1](#deep-dive-sources), [s3](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Team & Execution Capability

Skyflow was founded in 2019 by Anshu Sharma and Prakash Khot. Chief executive Anshu Sharma was vice president of product and strategy at Salesforce, where he led identity, security, and user-data management, a background directly on point for a data-privacy vault, and he is an active angel investor across dozens of startups.

The bench adds relevant depth: engineering co-founder Roshmik Saha previously built platform and high-performance-computing systems at Microsoft and Lyft, and the executive team adds product and enterprise-sales leaders drawn from large software companies. The founding story carries verifiable domain pedigree beyond job titles.

What the record does not show is a prior exit in the category or a widely recognized research output, so the team reads as strong in-domain operators rather than proven category-definers. That is the ceiling on the team's signal, not a weakness in it. \[[s4](#deep-dive-sources), [s7](#deep-dive-sources), [s16](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Skyflow: Secure PII and Sensitive Data](https://www.skyflow.com/product/pii-data-privacy-vault) | official | 2026-06-24 |
| f2 | [Finovate: Data Privacy Vault Skyflow Secures $30 Million in New Funding](https://finovate.com/data-privacy-vault-skyflow-secures-30-million-in-new-funding/) | press | 2026-06-24 |
| f3 | [YourStory: Skyflow tackles data privacy and security for enterprises who use LLMs](https://yourstory.com/2024/07/skyflow-tackles-data-privacy-and-security-for-enterprises-who-use-llms) | press | 2026-06-24 |
| f4 | [AI Defense Matrix Catalog mapping](https://catalog.aidefensematrix.com/products/skyflow-for-genai/) | other | 2026-06-24 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Skyflow: GoodRx, Nomi Health, Scalapay, and ServiceNow secure data at runtime](https://www.skyflow.com/) “Securing the flow of data across datastores, models, and agents. With Skyflow's zero-trust vault architecture, we can isolate, protect and govern PII (Nitin Shingate, CTO at GoodRx).” | official | 2026-06-24 |
| s2 | [Skyflow for PII: Secure PII and Sensitive Data](https://www.skyflow.com/product/pii-data-privacy-vault) “Protect and de-identify sensitive data using patented polymorphic encryption and tokenization.” | official | 2026-06-24 |
| s3 | [Skyflow for GenAI: GenAI Data Privacy and LLM Data Security](https://www.skyflow.com/product/skyflow-for-genai) “Skyflow helps you secure during the end-to-end LLM lifecycle, including training, fine tuning, RAG, data re-identification, and sharing data with third parties and outside models.” | official | 2026-06-24 |
| s4 | [Skyflow: Company](https://www.skyflow.com/company) “Anshu Sharma is the co-founder and CEO of Skyflow. ... Roshmik Saha has over 15 years of experience building platforms and high performance computing systems, ranging from software engineering at Microsoft to founding the Lyft Autonomous Vehicle Platform Team” | official | 2026-07-02 |
| s5 | [TechCrunch: Skyflow's data privacy API business raises $45M Series B](https://techcrunch.com/2021/10/19/skyflows-data-privacy-api-business-raises-45m-series-b/) “The startup has around 65 staff today and is looking to roughly double that by the end of 2022.” | press | 2026-06-24 |
| s6 | [Finovate: Data Privacy Vault Skyflow Secures $30 Million in New Funding](https://finovate.com/data-privacy-vault-skyflow-secures-30-million-in-new-funding/) “Data privacy vault Skyflow has raised $30 million in an extension Series B round led by Khosla Ventures. The investment takes the company's total equity capital to $100 million, according to Crunchbase.” | press | 2026-06-24 |
| s7 | [YourStory: Skyflow tackles data privacy and security for enterprises who use LLMs](https://yourstory.com/2024/07/skyflow-tackles-data-privacy-and-security-for-enterprises-who-use-llms) “Founded in 2019 by Anshu Sharma and Prakash Khot, Skyflow is a data privacy vault built to simplify how companies isolate, protect, and govern their customers' most sensitive data.” | press | 2026-06-24 |
| s8 | [Skyflow: Security](https://www.skyflow.com/security) “Our platform environment and team adhere to the following standards: ISO 27001:2022 Certified. SOC 2 Type II Certified. PCI DSS Level 1 Certified. GDPR Assessed and Compliant. HIPAA Assessed and Eligible.” | official | 2026-07-02 |
| s9 | [Skyflow Docs: Welcome to Skyflow](https://docs.skyflow.com/) “Here you’ll find guides, demos, and samples to help you build with Skyflow.” | official | 2026-07-02 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Skyflow: Runtime AI Data Control](https://www.skyflow.com/) “With Skyflow's zero-trust vault architecture, we can isolate, protect and govern PII in Databricks & BigQuery (Nitin Shingate, CTO at GoodRx).” | official | 2026-07-08 |
| s2 | [Skyflow for PII: Secure PII and Sensitive Data](https://www.skyflow.com/product/pii-data-privacy-vault) “Protect and de-identify sensitive data using patented polymorphic encryption and tokenization.” | official | 2026-07-08 |
| s3 | [Skyflow for GenAI: GenAI Data Privacy and LLM Data Security](https://www.skyflow.com/product/skyflow-for-genai) “Skyflow helps you secure during the end-to-end LLM lifecycle, including training, fine tuning, RAG, data re-identification, and sharing data with third parties and outside models.” | official | 2026-07-08 |
| s4 | [Skyflow: Company](https://www.skyflow.com/company) “Anshu Sharma is the co-founder and CEO of Skyflow... Previously, Anshu served as vice president of product and strategy at Salesforce leading identity, security and user data management. ... Roshmik Saha ... software engineering at Microsoft to founding the Lyft Autonomous Vehicle Platform Team” | official | 2026-07-08 |
| s5 | [TechCrunch: Skyflow's data privacy API business raises $45M Series B](https://techcrunch.com/2021/10/19/skyflows-data-privacy-api-business-raises-45m-series-b/) “The market for corporate data privacy products is heating up, with Skyflow announcing a $45 million Series B this morning, just a day after TripleBlind announced a $24 million round.” | press | 2026-07-08 |
| s6 | [Finovate: Data Privacy Vault Skyflow Secures $30 Million in New Funding](https://finovate.com/data-privacy-vault-skyflow-secures-30-million-in-new-funding/) “Data privacy vault Skyflow has raised $30 million in an extension Series B round led by Khosla Ventures. The investment takes the company's total equity capital to $100 million, according to Crunchbase.” | press | 2026-07-08 |
| s7 | [YourStory: Skyflow tackles data privacy and security for enterprises who use LLMs](https://yourstory.com/2024/07/skyflow-tackles-data-privacy-and-security-for-enterprises-who-use-llms) “Founded in 2019 by Anshu Sharma and Prakash Khot, Skyflow is a data privacy vault built to simplify how companies isolate, protect, and govern their customers' most sensitive data.” | press | 2026-07-08 |
| s8 | [Skyflow: Security](https://www.skyflow.com/security) “ISO 27001:2022 Certified. SOC 2 Type II Certified. PCI DSS Level 1 Certified. GDPR Assessed and Compliant. HIPAA Assessed and Eligible. Mastercard Site Data Protection (SDP) Compliant Registered Service Provider. Visa Global Registry Registered Service Provider.” | official | 2026-07-08 |
| s9 | [Skyflow Docs: Welcome to Skyflow](https://docs.skyflow.com/) “Use Skyflow Connections to securely send sensitive data to downstream APIs like Stripe, Adyen, etc.” | official | 2026-07-08 |
| s10 | [Skyflow Customers: attributed deployment quotes from GoodRx, Nomi Health, and Scalapay (targeted recapture 2026-08-01)](https://www.skyflow.com/customers) “We were able to successfully deploy Skyflow in less than three weeks ... Nitin Shingate CTO, GoodRx ... We were up and running on Skyflow in just hours, rather than the months it would take to build ... Boe Hartman CTO, Nomi Health ... Johnny Mitrevski CTO, Scalapay ... sign up for a demo today” | official | 2026-08-01 |
| s11 | [Skyflow homepage recapture: customer quote strip including ServiceNow's CISO, product lines named for their compliance driver, and the demo path (2026-08-01)](https://www.skyflow.com/) “TRUSTED BY Skyflow customers secure sensitive data at runtime ... Skyflow's solutions support our customers as they grow into new markets. ... Jeffrey DiMuro ... CISO at ServiceNow ... Get a Demo ... Protect PHI and satisfy HIPAA ... Streamline PCI compliance ... Contact Sales” | official | 2026-08-01 |
| s12 | [Skyflow for PCI: stated PCI scope reduction and the named customer verticals (targeted recapture 2026-08-01)](https://www.skyflow.com/solutions/by-compliance/pci) “keeping your front end out of PCI compliance scope ... Skyflow customers span verticals like fintech, retail, travel, and healthcare and use the data privacy vault architecture to comply with data residency laws, keep sensitive data out of LLMs, govern access to PII, and more.” | official | 2026-08-01 |
| s13 | [Skyflow and Scalapay case study: stated compliance-scope reduction (targeted recapture 2026-08-01)](https://www.skyflow.com/customers/scalapay) “This keeps Scalapay's backend infrastructure and database free of sensitive data and decreases their compliance scope.” | official | 2026-08-01 |
| s14 | [Skyflow Docs: three deployment models, one of them in the customer's own cloud account (targeted recapture 2026-08-01)](https://docs.skyflow.com/docs/fundamentals/deployment-models) “Skyflow supports three deployment models to meet different security, compliance, and infrastructure requirements. ... Multi-tenant SaaS is the default Skyflow deployment model: fully managed on shared infrastructure. ... Bring Your Own Cloud (BYOC) ... Customer cloud account” | official | 2026-08-01 |
| s15 | [Skyflow Docs: security best practices checklist, alongside the authentication and deployment-model pages (targeted recapture 2026-08-01)](https://docs.skyflow.com/docs/fundamentals/security-best-practices) “Here is a checklist of our security best practices that you can use for your implementation. ... Authenticate ... Deployment models ... Security best practices ... Compliance and certifications” | official | 2026-08-01 |
| s16 | [Skyflow Company page: Roshmik Saha's stated title (targeted recapture 2026-08-01)](https://www.skyflow.com/company) “Roshmik Saha ... Co-founder (Engineering) ... has over 15 years of experience building platforms and high performance computing systems, ranging from software engineering at Microsoft to founding the Lyft Autonomous Vehicle Platform Team.” | official | 2026-08-01 |
| s17 | [Skyflow Security page: the three-pronged control program (targeted recapture 2026-08-01)](https://www.skyflow.com/security) “Skyflow's team, processes and technologies use a three-pronged approach to protect customer data ... 1. Application-Level Security Control ... 2. Infrastructure-Level Security Control ... 3. Operation-Level Security Control” | official | 2026-08-01 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
