Enterprises are attempting to bridge the gap between deploying generative AI search and maintaining strict data privacy mandates. Skyflow, a runtime data control platform, has launched Skyflow for Glean to provide a governance layer for enterprise context. This integration aims to allow organizations to search, summarize, and reason over massive datasets without exposing sensitive information. By targeting the "context layer"—the documents and records spread across disparate systems—Skyflow seeks to prevent the common practice of blocking risky content, which often degrades the effectiveness of enterprise AI tools.
Securing the Enterprise Context Layer
The launch addresses a specific friction point in AI adoption: the tension between data utility and data security. As AI agents assemble context from CRMs, SaaS applications, and data lakes, the security challenge shifts from system access to granular data visibility. Skyflow for Glean operates through two primary mechanisms to manage this risk. First, it sanitizes data during ingestion by detecting and tokenizing sensitive values before they reach search indexes or model memory. Second, it controls results during retrieval by enforcing policy-based masking, rehydration, and context filtering. This ensures that both human users and AI agents only interact with authorized data fields during execution.
Implementation via Kearney Deployment
The strategic value of this integration is illustrated by the deployment at Kearney, a global management consulting firm. Kearney faced the challenge of connecting terabytes of client work across thousands of consultants while adhering to strict confidentiality commitments. Rather than engaging in manual data sanitization, the firm utilized Skyflow to implement per-field encryption, runtime policies, and customer-specific isolation. This approach allows consultants to access only the engagements they are authorized for, supported by a full audit trail. For enterprises, this suggests a path toward moving from pilot programs to firmwide deployments by satisfying security and legal requirements at the data layer.
Key Takeaways
- Skyflow for Glean provides runtime data controls, including per-field encryption and policy-based masking, to secure enterprise AI search.
- The platform sanitizes data at ingestion to ensure raw sensitive values do not reach search indexes or model memory.
- Global consulting firm Kearney uses the platform to manage client confidentiality across terabytes of data through customer-specific isolation.
TechInsyte's Take
In our view, Skyflow is positioning itself to solve the "all-or-nothing" dilemma that currently plagues enterprise AI rollouts. Most organizations currently manage AI risk by sanitizing datasets or blocking access to sensitive silos, both of which cripple the intelligence of the AI. By moving security to the runtime layer, Skyflow is betting that enterprises will prioritize "unblocking" data over "blocking" access. This shift from static storage security to dynamic, field-level control is critical as agentic AI begins to move from simple retrieval to active reasoning. If successful, this becomes a foundational requirement for any firm deploying AI across highly regulated sectors.
Questions & Answers
How does Skyflow prevent sensitive data from entering AI model memory?
Skyflow detects and tokenizes sensitive values during the ingestion phase. This ensures that raw, sensitive information is replaced before the content enters the search index or the embeddings used by the AI.
What is the difference between traditional access control and Skyflow's approach?
While traditional access control focuses on who can access a specific system, Skyflow provides fine-grained control at the data field level. This allows for policy-based masking and rehydration during the actual retrieval and execution of AI agent tasks.
Can this integration help with regional data residency requirements?
Yes. The company states that the solution allows data to stay in specific regions to support compliance with regulations such as GDPR, DPDP, and HIPAA, while maintaining a full audit trail of all access.
How does this technology impact the quality of AI search results?
By using runtime controls instead of simply blocking risky content, the technology aims to prevent the degradation of search results. This allows identifiers to match across documents, ensuring employees search a more complete knowledge base.
Source: Businesswire