🚀 DataTamed now supports SQL Server on Linux — Get early access →
DataTamed for Compliance & GDPR

Prove your test environments
are clean. In one click.

Manual PII scrubbing scripts are inconsistent, hard to audit, and impossible to prove. DataTamed masks personal data automatically at import — and generates the evidence your auditors actually need.

6 PII
Categories auto-detected
3 strategies
Partial, Redact, Nullify
4 formats
CSV, Excel, Word, PDF export
Self-hosted
Data never leaves your network
GDPR & UK GDPR ready
CCPA compliant
Exportable masking audit log
Entirely self-hosted
PII masked before any clone is created

Three ways production PII ends up
where it shouldn't.

Non-production environments are the most common source of personal data exposure — and the hardest to audit after the fact.

⚠️

The Scrubbing Script Problem

Someone wrote a data scrubbing script in 2019. It covers the columns that existed then. Since then, twelve new tables have been added — nobody updated the script. Your test environment has customer phone numbers and addresses sitting in plain text.

DataTamed detects PII automatically from schema and data — no manual script maintenance
📋

Nothing to Show Auditors

Your ICO audit letter arrives. The auditor wants evidence that personal data hasn't reached your development and test environments. You know it's been masked — but you can't prove it. Institutional knowledge is not evidence.

Every detection and masking event is logged and exportable in four formats
🔓

Developer Access to Real Customer Data

GDPR Article 25 requires data protection by design and by default. Copying production data to a dev environment without masking isn't just a process failure — it's a potential Article 32 violation. "We trusted the developers" won't satisfy a regulator.

PII is masked before the image is stored — before developers ever see it

Detected. Masked. Logged.
Before any clone exists.

During every database import, DataTamed inspects the schema and data to identify personal information. It applies your configured masking strategy and records every action — before the database image is saved.

Names Email Phone Address IP Address Date of Birth
🔤

Partial Masking

Preserve the format while obscuring the value — e.g. J*** S*** for names. Data remains structurally valid for testing.

🚫

Redact

Replace the value entirely with a [REDACTED] placeholder. Applied to IP addresses and physical addresses.

Nullify

Set the column to NULL — the most conservative option for optional fields like date of birth, where even a redacted placeholder carries risk.

Data Masking Report — Audit Export

Schema.Table Column PII Type Strategy Rows
dbo.CustomersLastNameNamePartial12,841
dbo.CustomersFirstNameNamePartial12,841
dbo.CustomersEmailEmailPartial12,841
dbo.CustomersPhoneNumberPhonePartial12,841
dbo.CustomersAddressAddressRedact12,841
dbo.CustomersDateOfBirthDate of BirthNullify12,841
dbo.AuditLogIpAddressIP AddressRedact284,320

Not compliance as an afterthought.
Compliance as the default.

GDPR Article 25 requires data protection by design and by default. DataTamed makes that a product feature, not a policy aspiration.

Zero-Configuration PII Detection

DataTamed inspects schema metadata and data samples during every import. It identifies personal data without requiring a DBA to pre-configure which columns to mask. New columns added to production are detected on the next import automatically.

Evidence in Four Formats

The Data Masking Report is your audit artefact. Every PII detection, column, masking strategy, and row count is logged. Filter by database, PII type, or date — then export to CSV, Excel, Word, or PDF for direct handover to your auditor or DPA.

Entirely Self-Hosted

DataTamed runs on your own infrastructure. No database files, backup files, schema metadata, or report data are ever transmitted to DataTamed or any third party. You maintain complete control — a requirement under GDPR Article 28 (data processors).

Masking Before Storage

Personal data is detected and masked during the import process — before the database image is stored. This means no window exists where a developer could access an unmasked clone. The masked image is the only version that ever exists.

Backup History for Data Lineage

The Backup History Report records every backup job with agent, server, database, timestamp, and status. Combined with the Data Masking Report, you have complete data lineage from production backup to non-production environment — documented and exportable.

Consistent Masking, Every Clone

Masking happens at the image level, not the clone level. Every clone created from that image inherits the same masking — no risk of one team getting a masked clone and another getting an unmasked one. The image is the source of truth.

Built for the regulations your
organisation must meet.

DataTamed is designed around the data protection requirements that apply to organisations processing personal data in the UK, EU, and beyond.

UK GDPR

Automatic PII masking satisfies data minimisation and storage limitation principles. The masking audit log provides the documented evidence Article 5(2) accountability requires.

EU GDPR

Article 25 (data protection by design) and Article 32 (appropriate technical measures) are addressed directly. Pseudonymisation is an automatic product feature, not a manual process.

CCPA

Six PII categories are detected and masked. The exportable masking log provides the paper trail for demonstrating that personal information belonging to California residents was not exposed in non-production systems.

ISO 27001

DataTamed supports data protection controls relevant to ISO 27001 Annex A.8. Self-hosting means no third-party data processor relationship to manage or document.

How DataTamed maps to
specific GDPR obligations.

GDPR Articles DataTamed Addresses

Article 5(1)(c) — Data minimisation: Only the data necessary for testing reaches non-production environments. PII is removed at source, not filtered downstream.
Article 5(2) — Accountability: The Data Masking Report is a logged, timestamped, exportable record that personal data was handled in accordance with your masking policy.
Article 25 — Data protection by design: Masking is built into the import pipeline, not bolted on. The default state of every database image is masked.
Article 32 — Security of processing: Pseudonymisation of personal data in test environments is explicitly listed as an appropriate technical measure under Article 32(1)(a).

What You Can Give an Auditor

A timestamped Data Masking Report showing every PII column detected, the masking strategy applied, and rows affected — per database, per import.
A Backup History Report showing the full chain of custody from production backup to database image — which agent, which server, which backup type, and when.
Documented proof that personal data is masked before storage — not after — meaning no unmasked snapshot ever existed in the non-production environment.
Confirmation that DataTamed is entirely self-hosted: no personal data was transmitted to any third-party service during the cloning or masking process.

More DataTamed use cases

🔥

DBA Teams

Remove the provisioning bottleneck from your DBAs' workload.

⚙️

DevOps & CI/CD

Database provisioning that keeps up with your pipeline.

🖥️

Non-Prod Environments

Dev, QA, UAT, and staging — all fresh, all safe.

Compliance that's built in,
not bolted on.

Start a 14-day free trial and generate your first Data Masking Report within the hour. No credit card required. A member of our team will be in touch within one business day.

  • 14-day free trial, all features included
  • Data Masking Report generated at first import
  • Export to CSV, Excel, Word, or PDF
  • Self-hosted — data never leaves your network

Start your 14-day free trial

We'll be in touch within one business day.

By submitting you agree to our Privacy Policy. We'll never share your details.

Thanks! We'll be in touch within one business day.
Something went wrong — please email sales@datatamed.com directly.