← All posts

PII Scanning Tools: 15 Options Compared (2026)

August 4, 2026

"PII scanning tool" is a label stretched across at least four different products that solve four different problems. A tool that inventories personal data in a Snowflake warehouse has almost nothing in common with one that walks a 4TB file server looking for spreadsheets full of Social Security numbers, and neither one resembles a Python library you drop into a data pipeline to redact text before it reaches a model.

That mismatch is why comparisons are frustrating. Buyers land on a list, see fifteen logos, and can't tell which ones are even in the running. So before the list, here are the axes that actually decide it:

Quick comparison

Tool Deployment Primary scope Data leaves your network? Pricing model
BigID SaaS or self-hosted Cloud, on-prem, SaaS apps Yes (self-hosted option) Quote
Varonis SaaS or hybrid File shares, M365, cloud Yes Quote
Spirion On-prem or hybrid Endpoints, file shares, databases Optional Quote
Microsoft Purview SaaS (Microsoft 365) M365, Azure, some on-prem Yes Per-user / consumption
OneTrust SaaS Privacy programme plus discovery Yes Quote
Cyera SaaS (agentless) Cloud data stores, SaaS Metadata and samples Quote
Securiti SaaS Multicloud, governance, AI Yes Quote
Amazon Macie AWS service Amazon S3 Stays in your AWS account Per GB scanned
Nightfall AI SaaS API SaaS apps, endpoints, pipelines Yes Quote / usage
PII Crawler Local desktop and CLI Files, email, archives, endpoints No, fully local $497 one-time
ManageEngine DataSecurity Plus On-prem (Windows) Windows file servers No Per-server licence
PII Tools On-prem or private cloud Files, mail, databases Optional Quote
Microsoft Presidio Library / container Text and images in pipelines No Free (MIT)
SENF Local utility Files on a host No Free
CUSpider Local utility (Windows) Files on a host No Free

Enterprise data security platforms

These are broad platforms. They discover personal data as one capability inside access governance, DLP, and compliance reporting. Expect a sales cycle, professional services, and annual renewals.

BigID

BigID builds an inventory of personal data across cloud stores, on-premises systems, and SaaS applications, using ML classifiers alongside pattern matching. Its differentiator is correlation: linking scattered records back to a single identity, which is what makes automated DSAR fulfilment and data-subject mapping possible.

It is a genuine enterprise platform, priced and scoped accordingly. Deployment is a project, not an afternoon. If your problem is "we have a hundred data sources across three clouds and no idea what's in them," this is the category BigID was built for. If your problem is one file server, it is heavy. See our BigID comparison for detail.

Varonis

Varonis started in file-system permissions analytics and grew into a broader data security platform. Its strength remains the combination most tools lack: it tells you both what sensitive data exists and who can currently reach it, then flags over-permissioned shares and unusual access. For a Windows and Active Directory estate with sprawling shared drives, that permissions lens is often more actionable than the classification itself.

Varonis is agent-based and enterprise-priced. Compare Varonis and PII Crawler.

Spirion

Spirion, formerly Identity Finder and now part of archTIS, is one of the longest-running names in the category, with deep roots in higher education and healthcare. It emphasises classification accuracy and persistent labelling, and it will scan endpoints, file shares, and databases.

If you have seen "Identity Finder" recommended on a university IT page, that is this product under its old name. Compare Spirion and PII Crawler.

Microsoft Purview

If your data already lives in Microsoft 365, Purview is the path of least resistance. Sensitivity labels, DLP policies, and classification are wired into Exchange, SharePoint, OneDrive, and Teams, and licensing is often bundled into agreements you already hold.

The trade-off is gravity. Purview is excellent inside the Microsoft estate and progressively weaker outside it. Coverage of arbitrary on-premises file servers, Linux hosts, and third-party SaaS is thinner than the marketing implies, and the licensing tiers that unlock the good parts are not the ones most organisations start on. Compare Purview and PII Crawler.

OneTrust

OneTrust is a privacy programme platform first, covering consent, assessments, vendor risk, and DSAR workflow, with data discovery as a supporting module. Buy it when the organising problem is running a privacy function and proving compliance to regulators, not when the problem is finding SSNs in a folder. Compare OneTrust and PII Crawler.

Cloud-native and DSPM tools

Data Security Posture Management tools assume your data is in cloud infrastructure. They connect via API, often agentlessly, and continuously assess where sensitive data sits and how exposed it is. They are generally poor at on-premises file shares and endpoints, which is not the problem they were built for.

Cyera

Cyera is an agentless DSPM platform that connects to cloud accounts and data stores and classifies what it finds, emphasising fast time-to-value: connect the account, get an inventory without deploying agents. Strong for multicloud estates and increasingly positioned around AI data security. Not a fit for a NAS in a branch office.

Securiti

Securiti positions itself as a "Data Command Center," combining discovery and classification with privacy operations, governance, and controls for AI pipelines. Broad scope, cloud-centric, enterprise sales motion. Useful if you want discovery and privacy operations from one vendor.

Amazon Macie

Macie uses managed ML and pattern matching to discover sensitive data in Amazon S3. Within its lane it is excellent, and a real advantage is that scanning happens inside your own AWS account, so your objects are not shipped to a third-party SaaS.

The lane is narrow. Macie is S3-focused and is not a general-purpose scanner for file servers, laptops, or non-AWS storage. Pricing is consumption-based per GB, which is cheap for a small bucket and surprising for a large lake.

Nightfall AI

Nightfall is an AI-native DLP product that detects sensitive data in SaaS applications, endpoints, and, via API, your own applications and data pipelines. The developer-facing detection API is genuinely good if you want to classify text inside software you are building.

By design it is a cloud service: content is sent to Nightfall for analysis. That is the correct trade for a Slack or Jira integration and the wrong one for classified data. Compare Nightfall and PII Crawler.

File- and endpoint-focused scanners

This is the older, narrower category. Point a tool at storage, get a report of what personal data is in it. Less governance ceremony, faster to a first answer.

PII Crawler

Full disclosure: this is our tool, so weigh the following accordingly.

PII Crawler is a desktop and command-line scanner that runs entirely on your own hardware. Nothing is uploaded, there is no API key, and it works on a machine with the network cable pulled out. It reads Office documents, PDFs, email (EML, MSG, MBOX, PST), archives, SQLite and Access databases, and images. Scanned PDFs and pictures go through a local OCR engine so text inside images is still detected. Findings go to a local SQLite database, with DSAR lookups across every prior scan and a watch mode for continuous monitoring of a directory. It costs $497 once, for unlimited users, machines, and scans.

Where it fits: file shares, NAS devices, laptops, mail archives, and anywhere the data genuinely cannot leave the building. See the full list of detected data types and supported file formats.

Where it does not fit: it is not a DSPM platform. It does not connect to Snowflake, crawl your SaaS tenants, manage consent records, or govern access permissions. If your personal data lives mostly in cloud warehouses and SaaS applications, a tool from the section above is the better answer.

ManageEngine DataSecurity Plus

DataSecurity Plus is an on-premises Windows product combining file server auditing, DLP, and data discovery. It reports on file activity and permissions alongside sensitive-data classification, licensed per server. A reasonable middle option for Windows-centric IT teams who want auditing and discovery together without an enterprise platform commitment. Windows-only in practice.

PII Tools

PII Tools is a commercial scanner aimed squarely at discovery and DSAR work across files, mail archives, and databases, with OCR for scanned documents. Notably, it can be deployed on-premises or in your own private cloud, which keeps it viable for organisations that rule out SaaS. Pricing is quote-based.

Free and open-source options

Microsoft Presidio

Presidio is an open-source (MIT) Python framework for detecting and anonymising personal data in text and images. It pairs spaCy or Hugging Face NER models with regex and context rules, and splits cleanly into an Analyzer and an Anonymizer so you can detect, redact, mask, or replace. It runs locally, in Docker, or on Kubernetes.

Presidio is a library, not a product. There is no file crawler, no scheduling, no report, and no UI. You write the code that feeds it documents and does something with the results. For redacting text inside an application or pipeline, especially before it reaches a model, it is the obvious starting point. For "scan this file server by Friday," it is a project.

SENF and CUSpider

Two free utilities from university security teams, both still available and both showing their age.

SENF (Sensitive Number Finder), from the University of Texas at Austin, hunts for structured numeric identifiers such as SSNs, credit card numbers, and medical record numbers across a host's files. CUSpider, from Columbia University, is an open-source Windows scanner built for the same job on desktops and laptops.

Both are number-pattern matchers, so expect false positives and no coverage of names, addresses, or context. Neither has meaningful support. They remain genuinely useful for a one-off look at a single machine at zero cost, and they are honest about what they are, which is more than can be said for some commercial tools. Just do not build a compliance programme on them.

How to choose

Work through these in order. The first one usually eliminates most of the list.

1. Can your data leave your network? If the answer is no, covering defence, healthcare, legal, financial, and anything classified or air-gapped, you have immediately excluded most SaaS platforms. What remains: PII Crawler, on-premises Spirion or PII Tools, ManageEngine, Presidio, or the free utilities. We wrote about why this constraint matters more than it seems.

2. Where does the data actually live? Be honest rather than aspirational. Cloud warehouses and SaaS point to DSPM (Cyera, Securiti, BigID). Amazon S3 specifically points to Macie. Microsoft 365 points to Purview. Windows file shares and NAS point to Varonis, ManageEngine, Spirion, or PII Crawler. Laptops point to Spirion or PII Crawler. Inside your own application, use Presidio or Nightfall's API.

3. Do you need an audit or a programme? A one-time inventory before an audit is a very different purchase from continuous monitoring with workflow and reporting. Do not buy a platform to answer a question.

4. What do you do with a finding? If nobody has the authority or time to act on results, the most accurate scanner in the world changes nothing. Tools that only report are fine when a human is ready to act. If you need automatic quarantine or permission changes, that narrows things sharply.

5. Model the three-year cost. Per-user and per-GB pricing scales with your organisation, not with the value delivered. Run the numbers on your actual headcount and data volume, including renewal increases, before comparing against a one-time or per-server licence.

Frequently asked questions

What is a PII scanning tool? Software that searches data, including files, databases, email, and cloud storage, for personally identifiable information such as names, Social Security numbers, credit card numbers, and dates of birth, then reports where it found them. Some also classify, label, redact, or restrict access to what they find.

What is the difference between PII scanning and data discovery? Largely marketing. "Data discovery" usually implies a broader inventory across many systems with ongoing governance, while "PII scanning" implies pointing a tool at storage and getting a report. The same products are sold under both labels.

Are there free PII scanning tools? Yes. Microsoft Presidio (MIT-licensed) is the strongest if you can write code around it. SENF and CUSpider are free host-level utilities. Most commercial tools offer trials, and several open-source regex rule sets exist. See our PII regex patterns reference.

Can PII scanning work without sending data to the cloud? Yes. PII Crawler, on-premises deployments of Spirion and PII Tools, ManageEngine, Presidio, SENF, and CUSpider all run locally. Amazon Macie is a middle case: it is a cloud service, but scanning happens within your own AWS account.

How accurate are these tools? Accuracy varies most on unstructured, context-dependent data. Checksum-validated identifiers like credit card numbers and SSNs are matched reliably by nearly everything. Names, addresses, and free-text personal data are much harder, and this is where ML-based classification separates from pure regex, and where false-positive rates diverge sharply between products. Always evaluate against a sample of your own data rather than a vendor's demo set.

Which tool is best for scanning file shares for PII? For Windows estates where permissions matter as much as content, Varonis. For a fast, local, low-cost inventory of shares and NAS, PII Crawler. For Windows-centric teams wanting auditing and discovery bundled, ManageEngine DataSecurity Plus.

Vendor capabilities and pricing models change. This comparison was last reviewed in August 2026. Verify current details with each vendor before purchasing. Corrections are welcome at [email protected].