Personal data discovery

Find where personal data lives, without keeping a copy of it.

Sonar walks your Microsoft 365 and Google Workspace tenant, reads what it finds in memory, and records where personal data sits, how much of it there is, and how it is shared. It keeps the finding, never the file.

A finding, in full

National IDBank accountUnclassified, for review

Sheet 2, cell D14

The position, the category and the count. The value at that position is not stored and cannot be shown.

It scans what you point it at

Sites, drives, mailboxes, shared drives. You choose the scope, and the first sweep is bounded so you see something useful before you have committed to anything.

It builds an inventory first

Where personal data lives, grouped into the assets your register already thinks in, before it starts telling you what is wrong.

It keeps the finding, never the file

Content is read in memory and discarded. What persists is a location, a category, a count, a confidence and a position.

Limits

What this does not do yet, in the same place as what it does.

Microsoft 365 and Google Workspace
Microsoft 365 connects today. The Google Workspace connector is built and tested and cannot be used yet: its scopes are restricted, so Google verifies them first, and the Gmail scope additionally needs an independent security assessment. We have not put a date on it here because we do not have one worth holding you to.
How Google Workspace will connect
Through a service account your super administrator authorises once, acting as each person it reads for. An administrator sign-in on its own reaches shared drives and that administrator's own data, which would under-report the rest of your domain without saying so, and we would rather ask for more than report less.
Cloud only
Sonar reads what lives in Microsoft 365 and Google Workspace. It does not reach file shares, laptops, databases or anything on your own network.
Teams
Teams is covered as the files behind it, in SharePoint and OneDrive. Chat and channel messages are not read.
Mailboxes
Mailboxes are in scope only if you put them there, and Microsoft grants mail access tenant-wide. We give your Exchange administrator the script that narrows it to the mailboxes you chose, and we check whether it is in place.
What a finding shows you
Where a value is, not what it says. A finding gives you the page, the sheet or the cell and never the value at it.
Finding one person's data
Sonar maps where categories of personal data live. It does not yet answer 'where is this individual', and that feature is not in this release.
File types
Text-bearing documents, spreadsheets, presentations, PDFs, mail and their attachments. An image with no text layer is recorded as not read rather than counted as clean.
Size
An item above 50 MB is recorded as not read, with the reason, rather than skipped in silence.
How age is measured
By the date an item was last modified, not the date it was last opened. Microsoft's current interface does not report a last accessed date, so a rule about data nobody has touched in years reads the modified date instead, and an item that is read often but never edited looks old.
How fresh a finding is
As fresh as the last scan. Sonar does not subscribe to change notifications in this release, so a file shared this morning appears as shared after the next scan rather than within minutes.
Accuracy
We publish no accuracy figure yet. The measurement harness and its gates are part of the build, and every number we do publish will carry the cases it was measured on.
Region
A workspace is pinned to one region when it is created and cannot be moved afterwards. Frankfurt today, Stockholm by arrangement.

Where your data sits

One region, chosen once.

EU Frankfurt

Available

Your workspace, its database and the scanning worker all run here.

EU Stockholm

By arrangement

Available by arrangement. Talk to us before you create the workspace: the region is fixed at creation and cannot be changed afterwards.