Integrations
Enterprise data estates are rarely tidy. A decades-old Oracle instance sits beside a warehouse that went live last quarter, file shares nobody owns, an ERP older than the cloud. Mage Data connects to all of it — on a connector framework built to add whatever comes next — so one set of protection policies covers the whole estate, not just the handful of platforms a point tool happens to support.
Every capability on the platform runs against your existing estate — on-premises, cloud-hosted and managed services alike.
Where Mage Data sits in your stack
Identity directories
+ plugins for new directories
users, groups and attributes drive access decisions
applied everywhere data lives
Data sources
any of them
Databases · Warehouses · Lakes · Files · SaaS · ERP · Streams · Endpoints — and whatever comes next
Your data stays in your environment
Masking, virtualization and monitoring run inside your infrastructure. Virtual copies live on your servers; the Mage Data repository holds metadata and policies, not a copy of your production data.
Installed in your environment — not SaaS
On-premises, in your cloud account, or hybrid across both. The platform runs on infrastructure you control, and the same policies apply wherever it and the data sit.
Agentless by default
Databases and warehouses connect over native drivers with nothing installed on the host. Agents are used only where the platform requires one.
Part one · Your data
Where your data lives
Databases, warehouses, lakes, file storage, SaaS and packaged applications, streams and endpoints — discovered, classified and protected wherever it sits.
A few of the platforms in each category — not the full list. Coverage extends on the same connector framework.
Databases
-
-
-
-
-
- + more
Data Lakes
-
-
-
-
-
- + more
SaaS & Web Apps
-
-
-
-
-
- + more
File Storage
-
-
-
-
-
- + more
Warehouses
-
-
-
-
-
- + more
Streams & Logs
-
-
-
as a log source
- + more
Packaged Apps
-
-
-
-
-
- + more
Endpoints
-
-
-
- + more
Formats we read inside those stores
-
-
-
-
-
- + more
Examples, not an exhaustive list. The connector architecture is extensible, and new connectors are added based on customer requirements — if yours is not shown, ask.
Data platforms Mage Data supports (representative list)
This is a representative list, not an exhaustive one. Mage Data is built on an extensible connector architecture, and new connectors are added based on customer requirements. If a platform is not listed here, it may already be supported or can be added — contact Mage Data to confirm. Mage Data is installed in the customer's own environment — on-premises, in their cloud account, or hybrid — and is not a SaaS service.
- Databases
- Oracle Database, Microsoft SQL Server, IBM Db2, MongoDB, Amazon RDS, PostgreSQL, MySQL, MariaDB, Sybase, IBM Informix, Azure Cosmos DB, Amazon Aurora, Azure SQL Database, Google Cloud SQL, IBM Db2 for z/OS, IBM Db2 for i (AS/400), VSAM and mainframe fixed-width extracts, and others.
- Data Lakes
- Databricks, Cloudera / Hadoop ecosystem, Apache Spark, Apache Hive, Apache HBase, Apache Hadoop and HDFS, Azure Data Lake Storage, and others.
- SaaS & Web Apps
- Salesforce, Workday, ServiceNow, Microsoft Dynamics 365, Bullhorn, Zoho, Coupa, Infor, Sage, Magento, and others.
- File Storage
- Amazon S3, Azure Blob / Data Lake Storage, Google Cloud Storage, Microsoft SharePoint, NAS, file shares and local files, Microsoft OneDrive, Google Drive, Network file shares, Local and server filesystems, and others.
- Warehouses
- Snowflake, Google BigQuery, SAP HANA, Amazon Redshift, Teradata, Azure Synapse Analytics, Vertica, Starburst, Greenplum, and others.
- Streams & Logs
- Apache Kafka, Elasticsearch, Splunk (as a log source), Kafka Streams, Application and database logs, and others.
- Packaged Apps
- Oracle PeopleSoft, Oracle E-Business Suite, Oracle JD Edwards, SAP ECC, SAP S/4HANA, SAP SuccessFactors, and others.
- Endpoints
- Windows, macOS, Linux, and others.
- Formats we read inside those stores
- Microsoft Office formats (Word, Excel, PowerPoint), Apache Avro, Apache Parquet, PDF, HL7, Microsoft Word, Microsoft Excel, Microsoft PowerPoint, ORC, CSV, Fixed-width and binary fixed-width files, JSON, XML, SWIFT, X12 EDI, and others.
Part two · Your tooling
The rest of the stack we plug into
Beyond the data itself: the directory that decides who sees what, the catalog that records it, the SIEM your security operations team already watches, the vaults that hold your keys, and the pipeline that provisions environments.
Identity directories
-
-
-
-
- + more
SIEM and security operations
Any SIEM that ingests syslog or CEF — these are examples.
-
-
-
-
- + more
Data catalogs and governance
Metadata and classifications exchanged both ways by API — ingested from and published to your catalog.
-
-
-
-
-
-
- + more
DLP and information protection
Enforcement tools act on Mage Data classification tags.
-
-
-
- + more
Key management
Keys for encryption and tokenization stay under your control.
-
KMS
-
-
-
KMS
-
-
CipherTrust - + more
Secrets and privileged access
-
-
secrets
-
-
secrets
- + more
CI/CD and orchestration
Any orchestrator that can call a REST endpoint.
-
-
-
-
- + more
Examples, not an exhaustive list. The connector architecture is extensible, and new connectors are added based on customer requirements — if yours is not shown, ask.
Security, identity and DevOps tools Mage Data integrates with (representative list)
This is a representative list, not an exhaustive one. Mage Data is built on an extensible connector architecture, and new connectors are added based on customer requirements. If a platform is not listed here, it may already be supported or can be added — contact Mage Data to confirm. Mage Data is installed in the customer's own environment — on-premises, in their cloud account, or hybrid — and is not a SaaS service.
- Identity directories
- Microsoft Entra ID, Okta, Ping Identity, Active Directory / LDAP, Additional identity directories through the plugin architecture, and others.
- SIEM and security operations
- IBM QRadar, Splunk, Microsoft Sentinel, Syslog / CEF, Any SIEM that ingests syslog or CEF, Email alerts, and others.
- Data catalogs and governance
- Collibra, Alation, Microsoft Purview, Google Dataplex, AWS Glue Data Catalog, Databricks Unity Catalog, Any catalog with an API, Ingest of existing metadata and classification results from enterprise catalogs, Publishing of classification results and sensitivity metadata to enterprise catalogs, and others.
- DLP and information protection
- Microsoft Purview Information Protection, Exchange Online, Your existing DLP tooling, and others.
- Key management
- HashiCorp Vault, Oracle Key Vault, AWS KMS, Azure Key Vault, Google Cloud KMS, Thales CipherTrust, and others.
- Secrets and privileged access
- CyberArk, HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, and others.
- CI/CD and orchestration
- Jenkins, GitLab CI, GitHub Actions, Azure DevOps Pipelines, Any orchestrator that can call a REST API, and others.
How each integration works
Identity, catalogs, security operations, logs and pipelines — pick a layer.
Identity directories
Access decisions are only as good as the identity data behind them.
Two integration points, one directory.
-
Microsoft Entra ID
-
-
-
Active Directory / LDAP
- + new directories via plugin architecture
Platform access
Sign-in to Mage Data federates to your identity provider (Microsoft Entra ID, Okta, Ping, Active Directory/LDAP), so Mage Data administrators and users are managed where every other user is managed — no separate account store.
Policy definition
Directory users, groups and attributes are read into Mage Data, and Dynamic Data Masking and Database Firewall rules are written against those groups. A rule scoped to "Finance-Analysts" resolves against the membership your IAM team maintains, not a list someone re-keys into Mage Data.
Role-based access
Directory groups and roles map to masking policies, so an analyst, a developer and a DBA can query the same table and each see what their role permits.
Attribute-based access
Policies read directory attributes alongside session context — source IP, client tool and time of day — for rules like restricting access to card data outside business hours.
Enforced at query time
Dynamic Data Masking masks results as they are returned; Database Firewall blocks the connection outright.
Data catalogs and metadata
Mage Data keeps a built-in catalog of your data estate — tables, columns, types, ownership and classifications, as the metadata foundation for discovery and protection. It is infrastructure for the platform, not a replacement for your enterprise catalog — and it works both ways with the catalog you already run.
Your enterprise catalog
or any catalog with an API
Ingest
Existing metadata and classification results are read in, so discovery builds on the work your data governance team has already done.
Publish
Mage Data classification results and sensitivity metadata are pushed back by API, so privacy context travels with the asset.
Native catalog and lineage
Every discovered structure and applied classification, recorded centrally and available through the interface and the API.
File and endpoint tagging
Classification results are written into file metadata as Microsoft Purview Information Protection sensitivity labels, or as filename and inline markers for formats that carry none, so Purview, Exchange Online mail-flow rules and your existing DLP tooling enforce on Mage Data tags.
-
Purview Information Protection
-
Exchange Online
Keys and credentials stay yours
Encryption and tokenization keys live in your KMS — HashiCorp Vault, Oracle Key Vault, AWS KMS, Azure Key Vault, Google Cloud KMS or Thales CipherTrust. Database credentials are retrieved from your secrets vault at connection time.
-
HashiCorp Vault
-
Oracle Key Vault
-
AWS KMS
-
Azure Key Vault
-
Google Cloud KMS
-
Thales CipherTrust -
SIEM and security operations
Activity events and rule-based alerts are forwarded to the tooling your security operations team already watches — any SIEM that ingests syslog or CEF. That covers database activity events and, from Activity Monitoring for AI, prompt, upload and unsanctioned-tool events.
Events
- Database activity events
- Rule-based alerts
- AI prompt and upload events
- Unsanctioned AI tool use
forwards over
Syslog / CEF
+ email alerts
Your SIEM
-
-
-
- any syslog / CEF SIEM
Logs and data streams
Sensitive values leak into places nobody thinks to protect. Application and database logs are one of the most common.
Before
INFO payment user=[email protected] card=4111 1111 1111 1111 status=ok
After
INFO payment user=j*******@example.com card=**** **** **** 1111 status=ok
Log Masking Plugin
Redact, mask, encrypt or tokenize sensitive data in application and database logs at the point it is written.
Stream masking
Masking plugins for message streams, including Kafka Streams.
DevOps, CI/CD and APIs
Test data provisioning belongs in the pipeline, not in a ticket queue. Trigger it from whatever already runs your builds.
-
Step 1
Commit
Code lands in the repo
-
Step 2
Build
Your CI server runs the job
-
Step 3
Provision data
Mage Data REST call: masked, subset or virtual copy
-
Step 4
Test
Suites run on safe, realistic data
-
Step 5
Expire
The environment is removed on schedule
REST APIs across the platform
Trigger discovery, masking, subsetting and virtual copy creation from any orchestrator.
-
Jenkins
-
GitLab CI
-
GitHub Actions
-
Azure DevOps
Pipeline-native provisioning
Request a masked, subset or virtual environment as a build step, with automated expiry.
Secure File Gateway
Watch an S3, Blob, Cloud Storage or filesystem location and mask files automatically as they land.
-
Amazon S3
-
Azure Blob
-
Google Cloud Storage
-
NAS & file shares
Self-service portal and file upload
Role-based access for developers and testers, without DBA mediation.
Part three · Your AI
AI tools and agents
The Data Security and Privacy for AI line is a set of integration points — into the data your models are trained on, the GenAI tools your employees use, the LLMs your agents call, and the code your teams write.
Training and fine-tuning data
Training Data Guardrails
Every model is a function of its training data, and the copies teams make to build, fine-tune and evaluate it — extracts, notebooks, feature stores, experiment runs — are rarely governed. Training Data Guardrails discovers sensitive data across structured, semi-structured and unstructured content, and protects it by policy before it fans out: masking, encryption, tokenization, anonymization or synthetic data, so the dataset stays fit to train on.
It runs on every data source on this page — the connectors are shared — inside your environment.
Training Data Guardrails- 1
Your data sources
Databases, lakes, files and apps on this page
- 2
Protect at collection
Secure pipelines apply policy as data is pulled
- 3
Protect at preprocessing
SDK / API inside notebooks and pipelines
- 4
Train, fine-tune, evaluate
Models built on protected, still-useful data
Employee GenAI tools
AI Usage Guardrails
Browser extension and endpoint agent for public GenAI tools: ChatGPT, Gemini, Claude, and more.
-
ChatGPT
-
Gemini
-
Claude
LLM providers
Dynamic Data Masking for AI
A proxy between your agents and the models they call, masking output for the human behind the agent.
-
Your LLM endpoints
Agent frameworks and SDKs
AI Development Guardrails
SDKs and MCP tools so agent builders embed authorization checks and masking in the agent's code path.
-
SDK
-
MCP
Security operations
Activity Monitoring for AI
AI usage events forward to your SIEM alongside database activity.
Most estates have one system nobody covers
Usually it's older than the team maintaining it, or it arrived with an acquisition. That's the platform worth talking about — what's in it, who can reach it, and whether it can come under the same policies as everything else.
Tell us what you run
We'll show you what's covered today, and what it would take for the rest.
Frequently Asked Questions
Which databases and data warehouses does Mage Data support?
Mage Data supports Oracle, Microsoft SQL Server, PostgreSQL, MySQL, MariaDB, SAP HANA, IBM Db2, Teradata, Sybase, Informix, Snowflake, Google BigQuery, Google Cloud SQL, Azure Synapse, Databricks, MongoDB and Azure Cosmos DB, along with mainframe sources including Db2 for z/OS, Db2 for i and VSAM. This is a representative list, not an exhaustive one. The connector architecture is extensible, and new connectors are added based on customer requirements — if a database or warehouse you run is not listed, ask.
Does Mage Data integrate with Microsoft Entra ID, Okta and Ping?
Yes. Mage Data integrates with Microsoft Entra ID, Okta, Ping and Active Directory/LDAP for single sign-on and platform authentication, and reads directory groups and attributes into Dynamic Data Masking and Database Firewall policy evaluation. Additional identity directories can be added through the platform's plugin architecture.
Does Mage Data support cloud data lakes?
Yes. Mage Data discovers, classifies and protects sensitive data in Amazon S3, Azure Data Lake Storage, Google Cloud Storage, Hadoop and HDFS, Apache Spark and Databricks, under the same policies applied to databases rather than a separate rule set.
Can Mage Data protect mainframe data?
Yes. Mage Data covers IBM Db2 for z/OS, Db2 for i (AS/400) and VSAM, including fixed-width and binary fixed-width mainframe extracts, under the same discovery and masking policies as the rest of the estate.
Can Mage Data use the classifications already in our data catalog?
Yes. Mage Data integrates both ways with enterprise data catalogs such as Collibra, Alation, Microsoft Purview, Google Dataplex, AWS Glue Data Catalog and Databricks Unity Catalog. It ingests existing metadata and classification results from the catalog, so discovery builds on work already done, and publishes its own classification results and sensitivity metadata back by API, so privacy context travels with the asset.
Does Mage Data copy or move our data?
No. The Mage Data repository holds metadata and policies only and stores no customer data. Dynamic Data Masking masks query results as they are returned, and Extract-Mask-Load applies masking in transit so sensitive values never land at the destination.
Can Mage Data be deployed on-premises?
Yes. Mage Data is installed in your own environment — on-premises, in your cloud account, or as a hybrid deployment across both. It is not a SaaS service: the platform runs on infrastructure you control, and your data never passes through a Mage Data cloud. The same policies and protection methods apply regardless of where the platform and the data sit.
Is the list of supported platforms on this page complete?
No. The platforms shown are representative examples, not an exhaustive list. Mage Data is built on an extensible connector architecture, and new connectors — databases, warehouses, file stores, applications, identity directories and security tools — are added based on customer requirements. If a platform you run is not listed, ask: it is often already supported, or can be added.