- 60% of Glean's document repositories were blocked due to unsanitized client data, according to a Fortune 500 CIO.
- Skyflow's solution tokenizes sensitive data, allowing AI to identify patterns without exposing raw values.
- Kearney, a global consulting firm, adopted Skyflow to ensure client data isolation across terabytes of confidential projects.
Experts would likely conclude that Skyflow's approach represents a significant advancement in balancing AI-driven efficiency with stringent data governance, potentially setting a new standard for secure enterprise search.
Unlocking the AI Vault: A New Bid to Secure Enterprise Search
PALO ALTO, CA – August 25, 2026 – The promise of enterprise AI is a tantalizing one: to instantly summon the collective knowledge of an entire organization. Platforms like Glean have emerged as powerful tools to realize this vision, indexing millions of documents across disparate systems to provide employees with a single, intelligent search bar for everything the company knows. But this promise has a perilous catch.
Lurking within those terabytes of documents—in contracts, client files, CRM entries, and HR records—is a minefield of sensitive data. Personally identifiable information (PII), protected health information (PHI), and confidential client data create a massive liability. The fear of an AI model inadvertently surfacing a client’s secrets in another client’s search results, or exposing employee salary data in a generated summary, is enough to halt ambitious AI projects in their tracks. The default solution has been blunt and costly: block entire repositories of sensitive content from the AI’s view. As one CIO at a Fortune 500 firm noted, “Without a solution, we would have had to kill 60% of Glean's doc repos after legal found unsanitized client data.”
This is the structural dilemma facing the modern enterprise: a choice between knowledge and security, between AI-driven efficiency and regulatory compliance. Today, data security firm Skyflow launched a new platform, Skyflow for Glean, that wades directly into this conflict, arguing that companies shouldn't have to choose. It represents a fundamental shift from blocking access to enabling secure, controlled access, potentially redefining the relationship between data governance and artificial intelligence.
The Governance Gap in the Age of Agentic AI
Enterprise data has never been neat. It is a sprawling, chaotic ecosystem of CRMs, SaaS applications, data lakes, and wikis—what Skyflow calls “enterprise context.” AI search platforms do an admirable job of respecting the permissions that govern these source systems, ensuring an employee can only retrieve documents they are already authorized to see.
However, the advent of generative AI and agentic systems introduces a new layer of complexity. The real question is no longer just who can access a document, but what data an AI agent is allowed to see and use from within it. When an AI generates an answer, a summary, or a list of key points, it synthesizes information from multiple sources. A single generated sentence could inadvertently combine and expose sensitive values from documents that, while technically accessible, were never meant to be aggregated in such a way. This is the governance gap where traditional, document-level security begins to fray.
This challenge is magnified for organizations that handle highly sensitive third-party data, such as consulting firms, financial institutions, and healthcare providers. For them, the risk of data cross-contamination isn't just a compliance headache; it's an existential threat to their business model, which is built on a foundation of trust and confidentiality.
A Look Under the Hood: Runtime Control vs. Static Security
Skyflow’s approach is not to replace the permissions-aware security inherent in platforms like Glean, but to add a complementary, more granular layer of control. The solution operates at two critical junctures: data ingestion and data retrieval.
First, as data is ingested into the search index, the platform acts as a sanitization engine. Using a “Data Privacy Vault” architecture, it automatically detects and tokenizes sensitive data fields. Instead of storing a client's name or a social security number in the search index, it stores a non-sensitive, format-preserving token. Crucially, this tokenization is deterministic; the same piece of sensitive data will always generate the same token, allowing the AI to still identify patterns and connections across documents without ever touching the raw, sensitive values. The original data is isolated in a secure vault, which can be hosted in specific geographic regions to meet data residency requirements.
Second, and perhaps more innovatively, is the enforcement of policy at runtime. When a user or an AI agent performs a search, the system retrieves the tokenized results. Skyflow’s policy engine then intervenes in real time. Based on the user’s role, their permissions, and the context of the query, the engine decides what to display. An authorized user might see the sensitive data fully “rehydrated” from the vault. A different user might see the same field with data masked (e.g., XXX-XX-1234). A third user might not see the field at all. This dynamic, policy-based control extends from simple retrieval to the complex steps of an AI agent's reasoning process, ensuring governance is maintained throughout.
From Theory to Practice: The Kearney Case
The abstract nature of data governance becomes concrete when examining the case of Kearney, a global management consulting firm and an early adopter of the technology. Rolling out an enterprise search tool across thousands of consultants meant connecting terabytes of client work, each project bound by strict confidentiality agreements.
The challenge was clear: how to give consultants a powerful tool to find internal expertise and past project data without ever risking the exposure of one client’s sensitive information in the search results for another. The firm needed bulletproof data isolation at a granular level.
Mark Johnson, Partner and Chief Information and Digital Officer at Kearney, articulated the firm’s need succinctly: “We don't want to be in the data sanitization business.” The statement underscores a critical insight for many large organizations—data governance cannot be a perpetual, manual cleanup project. Kearney adopted Skyflow to provide per-field encryption, runtime policies, and customer-specific data isolation as an integrated platform. This allowed them to move forward with their firmwide Glean deployment, confident that a full audit trail was being recorded and that the informational walls between client engagements would remain intact.
The Broader Implications for a Regulated World
The launch of Skyflow for Glean is more than a product release; it’s a bellwether for the maturation of the enterprise AI market. As regulators worldwide grapple with the implications of AI, solutions that embed privacy and governance directly into the data layer will become foundational. The ability to guarantee data stays within a specific region to comply with GDPR, India's DPDP, or HIPAA is no longer a feature but a prerequisite for doing business.
By transforming sensitive data into a usable but protected asset, this approach reframes the role of security and legal teams. “Security and legal teams can move from blocking access to unblocking secure access—and that's what makes AI search safe to turn on,” said Anshu Sharma, co-founder and CEO of Skyflow. This shift from a posture of prevention to one of managed enablement is critical for fostering innovation without inviting unacceptable risk.
As organizations continue their rapid adoption of AI, the systems that hold our digital world together are being tested. The integrity of our public and private institutions depends on our ability to manage the flow of information with precision and accountability. The development of fine-grained, runtime data controls represents a significant step in reinforcing those systems, ensuring the immense power of artificial intelligence can be harnessed safely and responsibly.
Topics & Related
Generative AI
Cybersecurity
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →