Built for small & medium enterprises, worldwide

Know what data you hold.
Protect what matters.

ClassifyHub automatically finds and labels your sensitive business information — customer records, financials, credentials, personal data — so you can secure it, prove compliance, and sleep at night. No consultants required.

Free plan forever · Set up in 15 minutes · Works on macOS & Windows
4
Sensitivity levels out of the box
14+
Built-in detection rules
15 min
From signup to first scan
2
Endpoint agents: macOS & Windows

You can't protect what you can't see

Every SME has the same story. Here's how it usually goes — and where it ends.

1

Your data quietly sprawls

Customer lists in spreadsheets. Payroll on a laptop. Contracts in Downloads folders. API keys pasted into notes. After a few years of growth, nobody knows where the sensitive data actually lives — and that's normal, not negligent.

2

Then someone asks the question

A big customer sends a security questionnaire. An auditor asks for your data inventory. A regulator investigates a breach. The first question is always the same: "What data do you hold, and how is it classified?" Most SMEs can't answer.

3

Classification is the answer

Labeling data as Public, Internal, Confidential or Restricted is the foundation of every security program: it tells you what to encrypt, who gets access, what to back up, and what a breach actually exposed. Do it once, automatically, and keep it current.

$4.9M
average cost of a single data breach IBM Cost of a Data Breach Report, 2024
43%
of cyberattacks target small & medium businesses Verizon DBIR / Accenture industry research
277 days
average time to identify and contain a breach IBM Security industry benchmark
15 min
to your first classified inventory with ClassifyHub No consultants. No projects.

One pyramid your whole company understands

Four levels, color-coded everywhere — in dashboards, exports and agent reports. Everyone from intern to auditor instantly knows what they're looking at.

RESTRICTEDregulated · secret · breach = crisis
CONFIDENTIALsensitive business & personal data
INTERNALday-to-day business information
PUBLICapproved for public release
  • Restricted — SSNs, card numbers, credentials, health records. Encrypt, restrict access, never email. The smallest slice of your data — and the one that ends companies.
  • Confidential — customer PII, payroll, contracts, financials. Share on a need-to-know basis; track where it lives.
  • Internal — plans, notes, source code, policies. Fine inside the company, not for the public internet.
  • Public — marketing, press releases, published docs. Knowing what's truly public is half the battle.

Not optional anymore — it's in the standards

Data classification is an explicit requirement or baseline expectation in every major cybersecurity and privacy framework. Wherever your customers are, one of these applies to you.

Global

ISO/IEC 27001

Control 5.12 requires information to be classified by sensitivity, and 5.13 requires it to be labeled. You cannot certify without a working classification scheme.

Europe · Global reach

GDPR

Articles 30 & 32 require a record of processing and "appropriate" protection — which supervisory authorities interpret as knowing which data is personal and treating it accordingly.

USA · SaaS buyers

SOC 2

The Confidentiality criteria expect you to identify and designate confidential information. Enterprise customers increasingly demand SOC 2 from their SME vendors.

Europe

NIS2

The EU's expanded directive pushes risk-management duties — built on knowing your information assets — down to thousands of mid-size companies and their suppliers.

India

DPDP Act 2023

India's data protection law requires reasonable safeguards for digital personal data — you must first know where personal data resides to safeguard it.

Payments & health

PCI DSS · HIPAA

Card data and health information must be located, inventoried and isolated. Classification is step zero of scoping both frameworks.

How ClassifyHub works

A complete classification program in four steps — most teams finish the first three before lunch.

📥

Collect

Paste text, upload CSV inventories, or let macOS & Windows agents scan automatically

🧠

Detect

14+ rules match PII, credentials, financial & health data — plus any rules you add

🏷️

Label

Highest-sensitivity match wins: Public, Internal, Confidential or Restricted

📊

Prove & act

Live dashboard, CSV evidence exports and a full audit trail for assessors

🏷️

1 · Sign up, get a ready-made scheme

Creating your workspace instantly sets up the four standard levels — Public Internal Confidential Restricted — plus 14 detection rules for PII, credentials, financial and health data. Rename, recolor or extend them to match your policy.

⚙️

2 · Tune the rules (or don't)

Rules are simple keywords or regex patterns mapped to a label — no query language to learn. Add "project-phoenix → Restricted" in ten seconds from the admin console. The defaults already catch SSNs, card numbers, API keys, passwords and more.

📥

3 · Classify everything, three ways

Paste a document for an instant verdict. Upload a CSV of your asset inventory for bulk classification. Or download the lightweight macOS / Windows agent — it scans Documents, Desktop and Downloads on every machine and reports back automatically.

📊

4 · See it, prove it, act on it

A live dashboard shows your data estate by sensitivity. Export the inventory as CSV for auditors and customer questionnaires. The audit log records every change — exactly what ISO and SOC 2 assessors ask to see.

Try it right now — no signup

Paste any text below (or use a sample) and watch the default rule engine classify it instantly. This demo runs entirely in your browser; nothing is sent anywhere.

Want the full app — dashboards, CSV bulk upload, endpoint agents, your own rules? Open the live demo workspace (one click, pre-loaded with sample data — credentials demo@classifyhub.app / demo1234) or create a free account.

8% is Restricted
  • Public 34%
  • Internal 41%
  • Confidential 17%
  • Restricted 8%

Your entire data estate, one glance

A typical SME discovers that less than a tenth of its data is truly sensitive — but before classification, nobody knows which tenth, so everything is either over-protected (expensive) or under-protected (dangerous).

ClassifyHub's live dashboard shows exactly this chart for your data, updated with every scan. Focus your security budget, your access reviews and your encryption where they actually matter.

See your own chart — free

Enterprise-grade, SME-simple

Classification tools were built for banks, priced for banks, and deployed by consultants. ClassifyHub was built for the rest of us.

🚀

Live in 15 minutes

Sign up, download the agent, done. No servers to run, no schema workshops, no six-month "data governance initiative".

🧠

No training needed

If your team can use a spreadsheet, they can use ClassifyHub. Rules are plain keywords; results are color-coded labels anyone understands.

🌍

Works anywhere

Cloud-hosted, browser-based, with agents for macOS and Windows. Whether your team is in Mumbai, Munich or Minneapolis, everyone sees the same picture.

Start free. Upgrade when you grow.

Every plan includes the full rule engine, dashboards, CSV import/export, endpoint agents and audit logs.

Free

$0
forever
  • 3 team members
  • 2 endpoint agents
  • 500 classified assets
  • All detection rules
Start free

Enterprise

$199
per month
  • 1,000 team members
  • 1,000 endpoint agents
  • 1,000,000 classified assets
  • Dedicated support
Talk to us

The next security questionnaire is already on its way

Be the SME that answers "what data do you hold?" with a dashboard, not a shrug.

Create your free workspace