Map, track, and report your file risk
The Compass module turns what DataXray has read into clear views of where sensitive files sit, how that changes over time, and which issues need work. Compliance, IT, and leadership work from the same numbers, and reports are ready for auditors.
Decisions backed by evidence
DataXray finds and classifies every file. The Compass module turns that into something a compliance team, an auditor, or a board can act on, and gives compliance and IT one set of numbers to work from.
Posture, issues, and history come from the DataXray index, dated and ready for an auditor, an assessor, or leadership, including CMMC and ITAR assessments.
See what's new since the last capture, what was resolved, and which data sources are getting worse.
The Compass module shows where owner, age, location, and content meet, such as old files owned by leavers, card numbers in a finance share, or personal data open to everyone.
One place for compliance and IT
Compliance and risk teams read the posture dashboard, the issues, and the report. IT and data teams use scan operations and the Cube, Compass's free-form explorer, to decide where to act. Both work from the same captures, so they argue about what to do, not about whose number is right.
Views and reports over the same index
Configured to how you work. Your policies, frameworks, severities, and saved views are set up around your teams. If you need a view or report Compass doesn't have yet, we can build it with you.
- Explore by dimensionPick 2 or 3 dimensions, such as owner, age, label, or sharing, and see the estate as a table, heatmap, or folder tree. Click any cell to list its files, export them, or turn them into a DataXray smart label.
- Data posture at a glanceSee how many files hold sensitive data and which categories they contain. See how that share has moved since the last capture, per datasource and across the estate.
- Change over timeThe Compass module keeps a dated history of captures, so you can see what's new, what was resolved, and what's trending the wrong way. No file is read again to show it.
- Issues to workPolicies open an issue when a datasource holds data it shouldn't, such as card numbers or credentials in plain text. Each issue has a severity, an owner, and a status.
- Framework scorecards and reportsGroup policies by framework (PCI DSS, GDPR, CPRA, GLBA, FTC Safeguards Rule, CMMC, and ITAR) and print a dated compliance report. Framework tags group your policies. They aren't a certification.
- Ask the Compass module agentAsk in plain language which datasources hold the most card data, or what changed since last month. Answers come back as tables and charts, limited to the datasources you can access.
Compass never shows anyone more than DataXray does
Compass installs as a sidecar inside your DataXray environment, one install per DataXray, and no data leaves that environment.
People sign in with their own DataXray account, and Compass never shows anyone data they could not already see in DataXray. The agent is held to the same limit.
Scheduled captures run under a read-only service identity, and analysis flows one way, from DataXray to Compass. The only write-back is a smart label you choose to create.
Frequently asked questions
What is DataXray Compass?
Compass is the DataXray module for visualizing and reporting on your data. It gives you interactive views of the index, a data posture dashboard, tracked issues, framework scorecards, printable compliance reports, and an agent that answers in tables and charts.
Do I need DataXray to use Compass?
Yes. Compass is a DataXray module and works from the files DataXray has already read and classified.
What is the difference between Compass and Cube?
Compass is the module. Cube is its free-form explorer, one view alongside Posture, Issues, Operations, the compliance report, and the agent.
Does Compass rescan my data to show trends?
No. It keeps a dated history of captures from the DataXray index and compares them, so trends come from that history rather than from new scans.
Which compliance frameworks does it cover?
Suggested policies are tagged for PCI DSS, GDPR, CPRA, GLBA, FTC Safeguards, CMMC, and ITAR, and you can tag your own. Scorecards show how your policies stand, grouped by framework. They are not a certification of control coverage.
Where does Compass run, and can it see data I cannot?
It runs as a sidecar inside your DataXray environment, and data never leaves. It works with the signed-in user's own DataXray access, so it can never show anyone something they could not already see in DataXray.
Can it be configured to our needs?
Yes. Your policies, frameworks, severities, and views are set up around your teams, and we can build new views or reports with you.
Does it run in air-gapped or classified environments?
It runs wherever DataXray runs, including air-gapped networks.
Built on every file DataXray has already read
Modules extend the DataXray platform into the workflows customers ask for most. Each one runs on files DataXray has already read and classified, so no file is read twice. Every module is configured to fit how your team works.
- AI PlatformLet AI assistants use your files safely, within each user's permissions.
- CompassExplore what is in your data and build the taxonomy to govern it.
- CuratorManage retention, disposition, and records capture, with every decision logged in a tamper-evident audit trail.
- AutoFOIATake FOIA and Privacy Act requests from intake to a redacted, Bates-numbered release.
- eDiscoveryReview, redact, and produce documents for litigation, regulatory, and privacy requests without exporting them.