Feature · TATER Security · Data Protection

Know what data you hold — and what protects it.

Inventory your sensitive data, put it on a consistent classification scheme with sensitivity labels, and map every asset to the controls and policies that are supposed to protect it. Data protection stops being a guess about where the crown jewels live.

See it in a walkthrough How it works
What it does

A single register of your sensitive data.

You can’t protect what you haven’t named. TATER holds one register of your data assets, each tagged with a classification tier and label, tied to the controls that guard it and the policy that governs it — so “how is our confidential data protected?” has an answer you can show.

Tiered classification scheme

Put every data asset on a consistent tier — Public, Internal, Confidential, Restricted, or your own scheme — so classification is a shared vocabulary instead of a judgment call that differs by team.

Sensitivity labeling

Attach a sensitivity label to each classified asset, capturing how it should be handled — the human-readable marker that tells anyone touching the data what care it demands.

Data inventory & asset mapping

Keep a living inventory of data assets — what it is, where it lives, who owns it, and which system holds it — so the sensitive-data map is a maintained record, not a workshop artifact from two years ago.

Control & policy mapping

Link each classification to the controls that protect it and the Data Classification policy that governs it, so a Restricted asset is visibly connected to the safeguards and the rules that apply — not just a label with nothing behind it.

Handling & retention rules

Record the handling and retention expectations that ride with each tier — how long it’s kept and how it’s treated — so retention is defined per classification instead of decided ad hoc when someone asks.

Audit-ready evidence

The classification register is the evidence an auditor asks for on data-protection controls — a maintained inventory with owners, tiers, and control mappings — ready to show instead of assembled the night before.

How it works

Inventory, classify, govern.

The module runs the classification lifecycle in one register, tied to the controls and policies TATER already holds.

Inventory

Record each data asset — what it is, where it lives, and who owns it — in one register.

Classify

Assign a tier and sensitivity label, and attach the handling and retention rules for that level.

Govern

Map each classification to its protecting controls and policy, and keep the register current as data changes.

In practice

Three questions this answers.

The data owner

“Where does our most sensitive data actually live, and who owns it?”

The inventory names each asset with its tier, location, and owner — so the sensitive-data map is a maintained record anyone can pull, not tribal knowledge.

The compliance manager

A framework asks you to prove how confidential data is classified and protected.

Each classification links to the controls that protect it and the policy that governs it, so the answer is a mapping you can show rather than an assertion.

The auditor, data-protection scope

“Show me your data classification scheme and evidence it’s applied.”

The register is the evidence — tiers, labels, owners, retention, and control mappings in one place — sampled directly instead of reconstructed for the review.

Ready to set it up?

The guide covers defining your classification scheme, building the data inventory, labeling assets, and mapping classifications to controls and policy.

Data classification guide  →

Put a name and a safeguard on every piece of sensitive data.

See the classification register, labeling, and control mapping on your own tenant in a live walkthrough.

Book a walkthrough All features