DataMasque for Guidewire Cloud enables insurers to de-identify sensitive Guidewire policyholder and claims data. DataMasque generates synthetically identical data that can be safely used across testing, analytics and AI use cases. Fully functional, realistic and privacy compliant.
Insurers need realistic policyholder and claims data to develop new capabilities, improve digital experiences, run analytics and power AI transformation. Using real production data outside of secure environments introduces significant privacy and compliance risk.
DataMasque for Guidewire Cloud enables insurers using the Guidewire Snapshot export service with DataMasque to irreversibly de-identify sensitive Guidewire data, producing synthetically identical data that can then be returned securely to sandbox environments. The result is high-fidelity data that supports development, AI experimentation and transformation without any of the privacy risks.
DataMasque automatically preserves referential integrity across policies, claims and related records, ensuring critical data relationships are maintained for end-to-end insurance workflow testing.
Highlights
Guidewire Cloud customers deploy DataMasque within their secure AWS environment. A pre-configured automation takes a secure snapshot of the Guidewire instance and, using a pre-defined Guidewire Cloud ruleset, DataMasque replaces sensitive information with synthetically identical customer data.
DataMasque can preserve referential integrity across Guidewire and other core systems. Policies, claims and related records remain connected and consistent, ensuring full utility and fidelity for end-to-end insurance workflow testing.
DataMasque's synthetically identical customer data looks and behaves the same way as your real data, maintaining patterns, statistical accuracy and edge cases, without any sensitive information. Irreversible de-identification removes compliance friction from AI development, migrations, software development and third-party data sharing.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing uses a single pricing dimension based on Guidewire TB, so you pay according to the volume of Guidewire Cloud data you mask, measured in terabytes. Pricing scales with the amount of data you process rather than by user count or number of masking runs. As your masked data volume grows, your cost adjusts to match. This is a contract-based purchase, so you commit to a term and settle billing through your AWS account for consolidated invoicing.
Top-of-mind questions for buyers
What does one Guidewire TB unit measure for billing?
One unit equals one terabyte of Guidewire Cloud data that the software masks. Billing counts the volume of data processed, not the number of users, databases, or masking runs. As the volume of masked data grows, the number of terabyte units you consume increases accordingly.
Are there limits on how many masking runs or data sizes I can process?
You can perform masking runs on data of any size. Your cost tracks the terabytes of Guidewire Cloud data you mask, so running more or larger jobs raises the volume billed. There is no separate charge tied to the count of runs.
What masking capabilities are included when I process Guidewire Cloud data?
The software discovers and masks sensitive data using keyword and pattern searches. It applies irreversible masking through a salted cryptographic hash, keeps masked values consistent across sources, and maintains referential integrity for primary, unique, and foreign keys. It integrates with existing CI/CD tools through an API-first design.
datamasque.com+3
Helpful?
Vendor refund policy
Refunds and cancellations are not available.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Table References
A table reference points at an existing table or a file of key-to-value rows, and a ruleset can read it as a lookup while masking. Used as a masking seed, it keeps masked values consistent across separate systems.
Condition Values from a Table Reference
The in and not_in conditions can now read their values from a table reference column, so the list of permitted values lives outside the ruleset instead of being repeated inside it.
Shared Hash Columns Across Foreign Keys
A new ruleset generator option, on by default, applies your Table Hash Column selection to the matching column in every table it joins to, letting related tables share a single hash column.
Cross-Account Resource Tagging
PostgreSQL, MySQL, MariaDB, Oracle, SQL Server, IBM Db2 LUW and Amazon Redshift connections can now hold an IAM role ARN, which DataMasque assumes to tag an RDS, Aurora or Redshift resource in another AWS account. Tagging now also works in the China and ISO partitions.
File Discovery Summary in the Run Log
Discovery runs now report how many files were scanned and how many were skipped, with a per-extension count for each reason a file was passed over.
Filter Run Logs by Multiple Statuses
The run logs can now be filtered by more than one Run Status at a time.
Shared In-Data Discovery Settings
A discovery configuration library can hold an idd_settings block, letting discovery configurations import their In-Data Discovery settings instead of repeating them.
In-Data Discovery On by Default
In-Data Discovery is now enabled by default for discovery runs and in new discovery configurations. Safe Data Preview remains opt-in, and saved discovery configurations keep whatever setting they already have.
Sensitive Classification Takes Precedence
When a column or file field matches both a sensitive and a non-sensitive rule, discovery now reports the sensitive classification. Existing discovery results may show a different classification after upgrading.
New Default Matcher Priority
The default matcher priority for unstructured masking is now context_sources, regex, checksum, seed_files, ai_detect. Masked output can change for an existing ruleset where two matchers find the same text.
Smaller PDFs and Lower Memory Use
PDF masking now embeds one copy of each substitute font per document rather than one per page, producing smaller masked PDFs and using considerably less memory on long documents.
Multi-Table and Parallel DynamoDB Masking
An Amazon DynamoDB ruleset can now mask more than one table, run its task blocks in parallel, and split the masking of a single table across several workers.
Explicit Label Masking in Ruleset Generation
Each label in a ruleset generation configuration must now set exactly one of preset_mask, mask, skip_generation or the new use_data_type_default. A label setting none of them stops the configuration from generating a ruleset; add use_data_type_default: true to preserve its previous behaviour.
Direct Navigation to a Run
Opening a run from a link now loads its page in the run logs immediately, instead of stepping through each page to find it.
API Keys Survive Password Changes
A user's API key is now replaced rather than removed when their password changes, so View run command always has a token available. New accounts receive their first key when the temporary password is replaced.
XML CDATA Masking Fix
Fixed XML masking leaving an element's text unmasked when wrapped in CDATA, and masking only part of the text when a child element or comment split it. A text transform now masks an element's whole text as a single value and writes CDATA sections back as plain text.
File Discovery Sensitive Results Fix
Fixed file discovery hiding a result from the sensitive-only view unless the displayed match was itself sensitive. A result now counts as sensitive unless every one of its matches is non-sensitive, so its data no longer drops out of the review or the generated ruleset.
IBM Db2 LUW Foreign Key Discovery Fix
Fixed foreign key discovery on IBM Db2 LUW reporting a table's own primary key as a foreign key when another table held a constraint of the same name.
PDF Image Placement Fix
Fixed PDF masking discarding the flip and rotation carried by an image's placement. Open vector paths are also no longer closed when the document is rebuilt.
Unstructured Preview Non-ASCII Fix
Fixed the Unstructured Ruleset Builder preview masking the wrong part of text containing non-ASCII characters, which could leave some of the original text visible. Masking runs were not affected.
Additional details
Usage instructions
Please follow the steps below to complete setting up your DataMasque instance:
Access the application via a web browser at https://<instance-ip-or-hostname>. The application may take a few minutes to start. Please refresh the page if you encounter the "Unexpected Error" message.
Complete the first-time installation page by providing the following information:
Email address of the DataMasque admin user. This email address is stored on the DataMasque EC2 instance and is used for the purposes of providing 'Forgotten Password' account recovery and critical system notifications. DataMasque will not have access to this information.
Password for the admin user.
Hostnames or IP addresses to access the DataMasque instance.
The SMTP settings specific to your organisation.
The instance ID of your EC2 instance.
You will be re-directed to the DataMasque login screen. Please proceed to login with the admin password you have just configured.
Note:
When you use our software we may receive and store usage data and information relating to the performance and use of the Software. We will not disclose any system information which identifies the user or the user environment to third parties.
DataMasque provides full product and installation support within 72 hours of making an enquiry. Contact the support team at support@datamasque.com for any enquiries you may have.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
DataMasque helps enterprises accelerate development, testing, analytics and AI with synthetically identical customer data. Fully functional, realistic and privacy compliant.
A self-contained DataMasque Ready-to-Run Sample Set. Launches with a bundled PostgreSQL database and PGAdmin so you can mask realistic sample data and inspect before/after results in minutes - no setup, no data of your own required.
DataMasque is a data masking platform that transforms sensitive production data into realistic, fully functional and privacy-compliant datasets.
Its synthetically identical data preserves the statistical characteristics, complexity and edge cases of your original data while maintaining referential integrity and data consistency - without sensitive information ever leaving your secure environment.
Deploy DataMasque on AWS for a production-ready, limited-scope implementation that delivers real data masking using your own environment. This reduces compliance risk and builds a foundation for expansion.
This Quick Start engagement covers discovery, configuration, and execution of DataMasque masking jobs across supported AWS databases and file formats. It produces masked, audit-ready datasets and transfers knowledge so internal teams can extend usage independently.