Fifteen data loss prevention vendors, three published prices. That's what we found checking every vendor's own pricing page on 14 September 2026, and it's why budgeting for DLP feels like guesswork. Here's what the category costs, what leaks in 2026, and how to cut fifteen options down to two.
TL;DR
- What it is. Data loss prevention software classifies sensitive data, watches the exits (email, USB, browser uploads, cloud sync, AI prompts) and blocks or logs what shouldn't leave.
- What it costs. Three of fifteen vendors publish a price. The rest quote privately.
- What leaks. Accidental loss outnumbers deliberate theft by roughly two to one.
- Where it leaks now. Generative AI tools, and source code is the favourite cargo.
- What sets the bill. Tuning labour, not licences.
Fifteen Vendors, Side By Side
Every row below was checked against the vendor's own site on 14 September 2026. Where a price isn't published, the cell says so rather than guessing.
| Vendor | What it covers | Deployment | Published price | MSP / multi-tenant |
|---|---|---|---|---|
| Microsoft Purview DLP | Email, cloud, endpoint, browser, network, Copilot | SaaS, endpoint agent via Defender | Yes. Purview Suite add-on $12.00 per user/month billed yearly. M365 E3 $39.00, E5 $60.00 | CSP yes. Lighthouse doesn't list Purview policy management |
| Teramind DLP | Endpoint DLP plus user activity monitoring | Agent, cloud or on-prem | Yes. DLP tier EUR 30.00 per seat/month, EUR 28.00 yearly, 5-seat minimum. Page is geolocated, EUR is what we could verify | Yes. Multi-tenant, floating licences, white-label |
| Safetica | Endpoint DLP plus insider risk | SaaS console and agent, on-prem SKU | Yes. "Starts at" $72 / $96 / $144 per user/year across three tiers | Partner program includes MSPs. 2026 console unconfirmed |
| Forcepoint Data Security Cloud | Endpoint, network, email, web, CASB, DSPM | On-prem servers and agents, separate SaaS SKU | Not published | MSSP announcement dates to 2023 and covers SSE, not DLP |
| Symantec DLP (Broadcom) | Endpoint, network, cloud, discovery | On-prem Enforce server, agents | Not published. Licensing metric is published: per user, per device or per appliance | Partner programs exist. Broadcom's own MSP product list omits DLP |
| Fortra DLP (was Digital Guardian) | Endpoint, network, discovery | SaaS, on-prem, or fully managed | Not published | Fortra Protect program. Multi-tenant console unverified |
| Trellix DLP | Endpoint, network, discovery, gateway | Agent, ePO on-prem or SaaS | Not published | Xtend program relaunched January 2025 |
| Netwrix Endpoint Protector | Endpoint DLP and device control | Agent for Windows, macOS, Linux | Not published | Netwrix's MSP program is built on a different product. This one isn't in it |
| Proofpoint Enterprise DLP | Email, cloud, endpoint | SaaS with a light agent | Not published | MSP business unit launched 13 May 2026. Its seven named functions don't include DLP |
| Mimecast Incydr (was Code42) | Endpoint DLP and insider risk | SaaS, agent, browser extension | Not published | Mimecast has an MSP track. Incydr's availability in it is unconfirmed |
| Netskope One DLP | Cloud, web, email, endpoint, private apps | Cloud service plus endpoint client | Not published. There is no pricing page | Yes. Catalyst MSP program and a multi-tenant orchestrator, launched 17 June 2026 |
| Cyberhaven | Endpoint, browser, cloud | SaaS, agent, browser extension | Not published. There is no pricing page at all | Partner program has no MSP track |
| Nightfall AI | SaaS APIs, email, browser | SaaS with light agents | Not published. The page prints the unit, "$ per user/year", and leaves the number blank | Partner program, no multi-tenant console |
| Harmonic Security | AI channel governance | Browser extension, desktop, MCP gateway | Not published. Tiers are named, figures aren't | Program accepts MSSPs. No multi-tenant console |
| Akamai Workforce Protector (was LayerX) | Browser DLP and AI usage control | Browser extension, agentless | Not published | Not verified |
Two names in that table moved recently, which matters if you're reading older comparisons. Code42 was acquired by Mimecast in July 2024 and sells as Mimecast Incydr. LayerX was acquired by Akamai on 2 July 2026 and renamed Akamai Workforce Protector on 5 August 2026. If a roundup still lists either under the old name, check its date before trusting the rest of it.
What DLP Does
Three steps, and the jargon maps onto them cleanly.
First it classifies: it works out which files and which strings are sensitive. That's card numbers, patient records, source code, a contract. Some tools match patterns, some read content, some track where a file came from.
Then it watches the exits. Email, USB sticks, web uploads, cloud sync folders, print, screenshots, and now the prompt box in a chat tool. Each of those is a channel, and no single product covers all of them equally well.
Then it acts. Block the action, warn the user, or log it quietly for review. Running in log-only mode first is standard practice, and skipping that step is how teams end up with an angry sales floor on day two.
If you want the mechanics rather than the theory, this walkthrough builds one policy end to end in Purview: picking sensitive information types, scoping it, setting the action, running it in simulation mode, and what the user sees when it fires.
Who Loses The Data, And How
The picture the category is sold on is a disgruntled employee walking out with a database. The measured one is different.
Verizon's 2026 Data Breach Investigations Report splits insider incidents into two patterns. Plain mistakes (sending to the wrong recipient, misconfiguring a share, losing a device) account for nearly 9% of all breaches, and every one of them involves personal data in 98% of cases. Deliberate misuse of access accounts for just under 4%. Accidents outnumber theft about two to one.
The motive data is the part worth sitting with. Among deliberate insider breaches, Verizon puts convenience at 60%, ahead of financial gain at 33%. Their own example of convenience is an employee emailing company data to a personal account so they can work from home. That isn't an attacker. That's someone trying to finish a task.
Which reframes what you're buying. DLP earns its keep on the accidental and the convenient, not on the spy. Proofpoint's 2025 survey of 1,000 security professionals lands in the same place: 58% attribute their most significant data loss to careless employees or contractors, against 32% to malicious insiders. The same research found 1% of users generate 76% of all data loss events, which is a strong argument for finding those users before buying anything.
The Leak Moved To The AI Box
Here's where the category changed in the last two years.
Verizon's DLP telemetry recorded 858,440 policy events in 2025 where the destination was a generative AI tool. Shadow AI is now the third most common non-malicious insider action in that dataset, up fourfold in share year on year. The most common cargo, by a wide margin, is source code.
The account is the problem more than the tool. Verizon found 67% of AI users on corporate devices are logged into non-corporate accounts, which puts the session outside every tenant control you own. Netskope's 2026 report counts 223 genAI policy violations per month at the average organisation and 2,100 in the top quartile, more than double the previous year. Browser telemetry from LayerX in 2025 put generative AI at 32% of all corporate-to-personal data movement, making it the single largest exfiltration channel they measured.
MSPs hit this in the field before the reports landed.
The layered answer in that thread holds up: policy at the org level, tenant DLP with labelling, block app consent, block non-corporate AI at the device, force corporate login where you can, and train for the rest. One reply names the limit plainly, and every vendor demo skips it. You can block downloads, printing, screenshots and copy-paste. You can't block someone photographing the screen and running OCR on their phone.
Worth knowing which half of the problem you have. Harmonic Security's Q2 2025 study of a million prompts found 4.37% of typed prompts carried sensitive content, against 21.86% of uploaded files. People are more careless with attachments than with typing.
What It Costs, And Why You Can't Find Out
Three vendors out of fifteen publish a number. That's the state of the category, and it's worth saying out loud because nothing else on the first page of Google for this search will tell you.
Microsoft publishes the clearest ladder, and it is the one buyers get wrong most often. DLP for Exchange, SharePoint and OneDrive is included in Microsoft 365 E3 and in Business Premium, so you may already own part of it. Endpoint DLP and Teams DLP are not: those sit at E5 tier or come through the Purview Suite add-on at $12.00 per user per month on an annual commitment, on top of an E3 base. E3 is $39.00 and E5 is $60.00 per user per month billed yearly, as published on 14 September 2026. If someone tells you DLP comes free with Microsoft 365, ask which channels they mean.
Safetica publishes "starts at" figures of $72, $96 and $144 per user per year across three tiers. Teramind publishes a per-seat monthly price with a five-seat minimum, which makes it one of the few options a ten-person firm can price without a sales call. Their page geolocates, and EUR 30.00 per seat per month for the DLP tier is what we could verify from our location.
The other twelve quote privately. Some are quiet about it, some are loud: one has no pricing page at all, and another prints the unit, "$ per user/year", with the figure left blank.
Quote-only isn't automatically a red flag. Enterprise DLP genuinely varies with seat count, data volume and which channels you light up. But it does mean a shortlist costs you calendar time before you see a number, so build the shortlist on architecture first and let price break the tie.
The Suites, The Specialists, The AI-Native
Three groups, and they're bought for different reasons.
The suite modules are Microsoft Purview, Proofpoint, Trellix and Symantec. You buy these because you already own the platform and DLP is a line item inside it. The advantage is one console and no new vendor. The catch is coverage that stops at the suite's own edges, which is the recurring complaint about Microsoft DLP on structured data and PDF content.
The specialists are Forcepoint, Fortra, Netwrix Endpoint Protector, Safetica, Teramind and Mimecast Incydr. These are bought when the data problem is the main problem rather than a checkbox: intellectual property on endpoints, device control, insider investigations. Forcepoint and Symantec are the two with a real on-prem story if you can't put classification in someone else's cloud. Netwrix Endpoint Protector covers Windows, macOS and Linux with feature parity, which narrows the field fast if you run mixed endpoints.
The AI-native tier is Cyberhaven, Nightfall, Harmonic Security, Akamai Workforce Protector and Netskope. These start from the channel the older products were never built for: the browser, the prompt box, the OAuth grant to an AI agent. Several don't describe themselves as DLP at all. If the risk in front of you is staff pasting into chat tools, this group deserves a look before the incumbents, and Netskope is the one of them with a multi-tenant MSP path shipping today.
For email specifically, the control usually lives in your mail security layer rather than a separate DLP purchase. We've covered what to look for in email security separately.
The Bill Nobody Quotes Is Labour
Licences are the visible cost. They're rarely the largest one.
Ponemon's 2026 insider risk study, across 354 organisations that had a material insider event, puts the total average annual cost of insider incidents at $19.5 million, up from $17.4 million. The negligent share alone is $10.3 million, up 17% year on year. Containment averages 67 days, and the speed matters enormously: incidents closed inside 30 days averaged $14.2 million against $21.9 million for those running past 90.
That's the enterprise end. At the small end, practitioners have been consistent about where the money goes for years.
Five separate people in that thread reach the same conclusion independently: the software is the cheap part, and making the policy engine fit the business is where the hours go. One puts it as a choice rather than a saving. You're either paying in labour or paying for software, and usually both.
So price the labour before the licence. Someone has to define what sensitive means in your business, write the rules, run them in log-only mode long enough to see the noise, tune the false alarms down, and answer the people whose work just got blocked. Netskope's 2026 data shows 63% of organisations now use DLP to watch movement into personal apps, which is a far broader policy surface than the card-number matching the category started with. A rollout that skips the monitoring phase produces alert fatigue in week one, and an ignored console is worse than no console because it looks like coverage.
Open Source Has No Entry Here
Search for open-source DLP and you'll find lists. Check the repositories and the lists fall apart.
OpenDLP's last release was version 0.5.1 in August 2012. Its GitHub mirror hasn't been pushed to since May 2014, and opendlp.org is now a parked domain listed for sale. MyDLP's repository last saw a commit in February 2014; the project was acquired that year and the free version was withdrawn. Its site is still up, with a blog frozen in 2010 and spam injected into the post bodies. Neither is a 2026 option, and a roundup recommending either hasn't checked.
What does exist is adjacent and partial, which is worth knowing before you budget for a commercial tool you may not need in full.
| Project | What it covers | Licence | Latest release |
|---|---|---|---|
| Presidio | PII detection, redaction and anonymisation in text, images and structured data | MIT | 2.2.364, July 2026 |
| USBGuard | USB device authorisation policy, Linux only | GPL-2.0 | 1.1.4, July 2025 |
| Gitleaks | Secrets and credentials in code and repositories | MIT | Active, 29.3k stars |
| TruffleHog | Leaked credential discovery and verification | AGPL-3.0 | Active, 27.9k stars |
None of these is a DLP platform. There's no policy engine, no console, no endpoint enforcement. What they do is cover specific slices well: if your actual risk is API keys reaching a public repository, a secrets scanner solves more of it than an enterprise DLP suite would, at no licence cost. Presidio is also worth watching for a governance reason. It moved out of Microsoft's GitHub organisation in 2026 to a community-governed home, with the project stating it won't be owned or operated by a commercial entity.
Compliance That Has A Date
Compliance is what put DLP on the shortlist in both threads above, and the dates get misreported often enough to be worth stating precisely.
PCI DSS is live and past its deadline. Version 4.0.1 is the only active version, and the 51 future-dated requirements stopped being best practice and became mandatory on 31 March 2025. Requirement 3.4.2 is the one that reads like a DLP control: technical measures preventing copy or relocation of card data during remote access.
The HIPAA Security Rule update is not law. The proposed rule published in January 2025 would make encryption of patient data mandatory rather than addressable, add multi-factor authentication and require 72-hour incident reporting. It has been moved to long-term actions with an anticipated final action date of July 2027. Treat it as a planning input, and be sceptical of anything claiming HIPAA already requires encryption today.
GDPR hasn't changed, but enforcement has scaled. Articles 32 and 33 still require appropriate technical measures and notification within 72 hours. DLA Piper's January 2026 survey counts EUR 7.1 billion in cumulative fines since 2018 and 443 breach notifications per day across Europe, a 22% annual rise. Three more US state privacy laws took effect on 1 January 2026, in Indiana, Kentucky and Rhode Island, bringing the total to twenty. Rhode Island's has no cure period. If you're mapping controls to frameworks, our cybersecurity frameworks list covers how these map together.
Which One Fits You
There's no single answer to which DLP tool is best, and any page that gives you one is answering a different question than yours. Start with where your data leaves, not with a feature grid.
| If this is your situation | Look at |
|---|---|
| Everything lives in Microsoft 365 and you're on E3 | Purview first. Check whether you need endpoint or Teams coverage before paying to move up |
| Intellectual property on endpoints, mixed Windows/macOS/Linux | The endpoint specialists. Device control and OS parity matter more than channel breadth |
| Data can't leave your own infrastructure | Forcepoint or Symantec. They're the two with a genuine on-prem deployment |
| The risk is staff pasting into AI tools | The AI-native tier. Traditional endpoint DLP wasn't built for the prompt box |
| You manage many clients and need one console | Netskope or Teramind. Both ship multi-tenant today. Verify DLP is in the MSP catalogue, not just the platform |
| Under 25 seats and a contract clause to satisfy | Whatever your existing platform already includes, plus a secrets scanner if code is the exposure |
Then run it before you sign. Two weeks in log-only mode against real traffic tells you more than any demo: how many alerts per day, how many are wrong, and how long a policy change takes. If a vendor won't let you test that, you've learned something useful anyway.
Fifteen vendors, three prices, and one category that has quietly moved its centre of gravity from the USB port to the prompt box. If you take one thing into a vendor call, make it the log-only trial: it prices the labour that the quote won't. Next, read our MSP security stack guide for where DLP sits against the rest of the controls.
Content Marketing Lead
Ohayo! I'm Kristina, and I'm doing good things with content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
