DataHub & SecuPi Partner to Provide Data Governance to Runtime Control: Governing What AI Agents Can Access, See and Do
Integration combines DataHub’s trusted data and agent context with SecuPi’s AI Enterprise Data Access Fabric to accelerate secure, governed AI adoption.
NEW YORK, NY, UNITED STATES, September 8, 2026 /EINPresswire.com/ -- DataHub and SecuPi today announced a partnership designed to accelerate enterprise AI agent adoption by addressing critical challenges around agentic access to trusted data. The joint solution allows customers to expand AI agent adoption across employees, business units, and use cases without requiring every end user to be individually provisioned into Snowflake, Databricks, or every underlying enterprise data platform.AI agents frequently access Snowflake, Databricks, data lakes, operational databases, and enterprise applications through shared service accounts and non-human identities (NHIs). SecuPi preserves the identity and authorization context of the requesting end user and dynamically limits each agent’s effective privileges based on DataHub data context, user identity and attributes, agent purpose, data sensitivity, and regulatory requirements.
To maintain consistent AI governance and security, agent activity operating outside approved DataHub-governed workflows can be detected and monitored. SecuPi runtime policies can alert, restrict, quarantine, or block unauthorized agent access and actions, providing continuous control over what AI agents can access, what sensitive data they can see, and what they are permitted to do. SecuPi further extends DataHub’s trusted enterprise data context by discovering and classifying sensitive information and applying dynamic masking, tokenization, FPE encryption, or de-identification when required.
Identity-Aware Control: From Human to Agent to Data
SecuPi can associate:
End User → AI Agent → NHI/Service Account → Purpose → Data → Action
and evaluate access dynamically using attributes such as user identity, role, agent identity, business purpose, data classification, location, and risk.
Fine-Grained Enforcement Down to the Sensitive Data
The integration allows DataHub metadata, classifications, ownership, and business context to inform SecuPi runtime policies. Depending on the user, agent, purpose, and sensitivity of the requested information, SecuPi can dynamically:
* Allow access
* Block access
* Restrict actions
* Filter rows, fields or objects
* Mask sensitive fields
* Tokenize or encrypt sensitive information
* De-identify personal or regulated data
* Alert or quarantine risky activity
Controls can be enforced at the object, file, table, column, row, field, or cell level, allowing AI agents to receive the information required for an approved task without unnecessarily exposing the complete underlying dataset.
Complete Human-to-Agent-to-Data Auditability
The combined approach also gives security, data governance, and compliance teams greater visibility into AI activity. Organizations can understand:
Who initiated an AI request?
Which agent acted on the request?
Which identity or account was used?
What sensitive data did the agent access?
What actions did it perform?
What security policy was applied?
This creates an end-to-end audit trail connecting human intent with AI-agent activity and actual enterprise data access.
Key Benefits:
Trusted context for every agent: Give agents continuously maintained enterprise metadata, lineage, ownership, classifications, definitions, and data quality context.
Deterministic runtime enforcement: Translate governance and data context into real-time authorization decisions rather than relying solely on instructions provided to an LLM.
Agent controls everywhere: Apply consistent controls across cloud and legacy data platforms, enterprise applications, APIs, files, data lakes, and AI environments.
Identity-aware agent access: Connect AI activity to the end user, agent, service account, business purpose, sensitive data, and actions performed.
Dynamic data minimization: Mask, filter, tokenize, encrypt, or de-identify sensitive information so an agent receives only the data required for its task.
Continuous auditability: Create a unified record of human, agent, data, and action activity for security operations, compliance, and investigations.
Swaroop Jagadish, Co-founder and CEO, DataHub:
“Enterprise AI agents need more than access to data - they need trusted context that tells them what the data means, where it came from, and how it should be used. By combining DataHub's enterprise context with SecuPi's runtime enforcement, organizations can extend governance from understanding data to controlling what agents see and do with it.”
Alon Rosenthal, CEO and Co-Founder, SecuPi:
“AI agents are creating an entirely new data-access path across the enterprise. Identity alone is not enough - the fundamental question is what every agent is allowed to see and do once it reaches enterprise data. Together, DataHub and SecuPi can connect trusted enterprise context with deterministic enforcement across data platforms, systems, and files, allowing organizations to deploy AI agents without surrendering control of their sensitive data.”
About DataHub
DataHub transforms enterprise data into trusted context, enabling intelligent decision-making by humans and AI agents. The company was founded by the creators of the popular DataHub open source product that has more than 16,000 contributors and is used by thousands of organizations. The company’s flagship product, DataHub Cloud, is the leading context management platform trusted by the Global 2000 to ensure that context is always relevant, reliable, and continuously refreshed across the entire data estate. DataHub is backed by Bessemer Venture Partners, LinkedIn, and 8VC. For more information, go to: datahub.com.
About SecuPi
SecuPi enables organizations to expand the trusted use of enterprise data by AI agents and humans while maintaining security, privacy, and compliance. Its flagship product, the SecuPi Runtime Data Access Control Platform, applies governance, identity, purpose, and data sensitivity context to enforce runtime controls over what every agent and human can access, what sensitive data they can see, and what actions they can perform across Snowflake, Databricks, data lakes, applications, databases, and files in cloud and on-premises environments. SecuPi is trusted by Fortune 500 organizations, including major Swiss banks, five of the world’s largest financial services organizations, and four of the world’s largest telecommunications companies. For more information, visit secupi.com.
Deena Moskovitz
SecuPi
email us here
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.