Skip to content

Omit Redact vs cloud DLP

Google Cloud DLP recognises 213 kinds of sensitive text. Omit recognises 191 of them, on your own machine, with nothing uploaded. The difference that decides this is not the size of the list: it is that a cloud scanner has to receive your document before it can tell you the document was sensitive.

Does the document leave your machine

Omit
No. Detection runs on the computer the file is already on
cloud DLP
Yes. It is uploaded to the vendor cloud to be classified

Kinds of sensitive text recognised

Omit
191 of Google's 213 text types, on a default install
cloud DLP
213, the published Google Cloud DLP catalogue

Accuracy where both tools compete

Omit
Matched or beat Google on all 21 of the types both attempt
cloud DLP
Beat Omit on none of the 21, in either configuration

PII actually redacted, across all 34 types tested

Omit
Caught 30 of 34, on the tier bundled with every install
cloud DLP
Caught 16 of 34 at best, though 13 misses ship no detector

Watching a whole organisation at once

Omit
Nothing. It protects the one desktop it runs on
cloud DLP
Monitors many cloud apps and data stores from one console

Dashboards, case management, data lineage

Omit
One local report per run, and no central console at all
cloud DLP
Central dashboards, incident workflows, and lineage

What it costs

Omit
One-time licence, with nothing metered
cloud DLP
Typically per seat or per volume, billed on data processed

Works with the network unplugged

Omit
Yes, and you can prove it on an isolated machine in two minutes
cloud DLP
No. Classification needs the DLP cloud

When cloud DLP is the better choice

These two sound like competitors and mostly are not. Cloud DLP answers the question 'what sensitive data does my organisation already hold, and where'. Omit answers 'do not let this document leave my desk with names still in it'. If you need the first question answered across dozens of SaaS apps from one console, buy a cloud DLP platform, because Omit does none of that and is not trying to. Where the two really do compete is the desktop, and specifically the case where sending a file away to be inspected is itself the disclosure you were trying to prevent.

What we checked, and where it came from

Two different claims, measured two different ways. Coverage is counted from a mapping file inside our own engine against a committed snapshot of Google's published catalogue. Accuracy is a benchmark we built and ran against the live Google Cloud DLP v2 API on 22 July 2026, giving Google two runs: once on its default infoTypes, and once told exactly which infoTypes to look for.

Verified 13 August 2026.

Coverage: 191 of Google's 213 text infoTypes on a default install

All 213 map to an Omit detector in a data file inside the engine, and a test fails the build if one is left unmapped. But the mapping is not uniform: 171 are one to one, 34 are caught at a coarser label, and 8 only through an open-ended catch-all. 22 of the 213 need the opt-in coverage mode switched on, which is why the honest default-install figure is 191 and not 213.

The full coverage breakdown

Detector quality: matched or beat Google on all 21 types both tools attempt

Of 34 entity types benchmarked, Google offers no text detector for 13, so 21 are genuinely comparable and no other exclusion is needed. On those, Omit matched or beat Google's defaults on 21 of 21 and its best configuration on 21 of 21. Three exclusions we argued for when this was first published have since stopped being true: the Fast tier now carries passport and driving licence detectors, and the harness bug that pinned our region config to Europe plus India is fixed.

Results, method, and where we are still weak

Product outcome: 30 of 34 caught, against 16 for Google at its best

The question a buyer actually asks is whether the PII comes out redacted, and for that, a vendor shipping no detector is not an excuse: the passport number is still in the document. Counting every one of the 34 types, Omit caught 30 and Google caught 16 configured at its best, 4 on its defaults. In fairness to Google, 13 of its misses are types it does not offer, not detectors that failed. In fairness to you, all 4 of our misses are ours: two are open-ended catch-all types the Accuracy tier carries and the Fast tier does not, and two are ties at zero where no engine scored.

Both ways of counting, in full

We published these numbers wrong once and corrected them in public

An earlier version of this claim said 30 of 34 against Google's best configuration. A scoring bug had counted the 13 types Google does not offer as Google failures instead of excluding them, turning races Google was never entered in into wins for us. Re-scoring the identical predictions moved our aggregate down and Google's up, roughly halving the measured lead. We would rather you heard that from us than found it yourself.

The correction in full

Cloud scanning makes the inspection itself a disclosure

That is inherent to the model and not a flaw in any particular product. The content has to arrive before it can be classified. For material that must not leave a device or a jurisdiction, being scanned and being shared are the same event, and the assessment you have to write says so.

Where our detection runs

Central visibility is a real capability we simply do not have

Cloud DLP watches data across many SaaS applications and stores from one console, with dashboards, workflows and lineage. Omit protects the desktop it runs on and writes a local report. If your requirement is org-wide monitoring, we are not a substitute and we will not pretend to be.

How the pieces fit

Choose Omit when

Choose Omit when the exposure is at the desktop, when the file must not be uploaded even to be inspected, or when you want a control people apply to their own documents before sending them rather than a report on what already went out.

Choose the alternative when

Choose a cloud DLP platform when you need to find sensitive data across many cloud services centrally, with dashboards, case management and lineage. That is what those products are built for and an endpoint tool cannot replace it. And if passports or US bank routing numbers are the core of your use case, test both before you decide, because those are types we measurably lose.

Questions people ask

What is an infoType, and why does 213 keep coming up?

An infoType is Google's word for one item on its list of things it knows how to find. EMAIL_ADDRESS is one, IBAN_CODE is another. Google publishes the whole list, which is rare and useful, so the industry uses it as the yardstick for coverage. It has 261 entries, of which 213 describe text, not document or image types.

So does Omit detect all 213?

No, and we will not round it up. A default install detects 191. The other 22 need the broader coverage mode switched on: 8 are open-ended catch-alls such as GENERIC_ID, and 14 are demographic types backed by wordlists. Of the 191, some are found at a coarser label than Google uses. Google separates FIRST_NAME and LAST_NAME where we detect one PERSON type, which redacts identically but reads differently in an audit report.

Is Omit more accurate than Google?

There are two fair ways to count and we publish both. On the 21 types both tools attempt, Omit matched or beat Google's default configuration on all 21 and its best possible configuration on all 21. Counting instead whether the PII came out redacted at all, across all 34 types tested, Omit caught 30 and Google caught 16 at best. The benchmark is synthetic, it is ours, nobody independent has audited it, every type in it is a structured identifier, and it measures our Fast tier.

Which tier posted those numbers?

The Fast tier, which is the lighter of the two and the one bundled with every install, including the small one. It is also the tier running inside Protect, the clipboard guard that is free for everyone. The Accuracy tier is measured in part two of the comparison, on the same corpus and on a second corpus of ordinary prose, which is the material the two tiers actually differ on.

Can Omit replace an enterprise cloud DLP programme?

No. Cloud DLP monitors data flowing through cloud services centrally and Omit has no equivalent to that. Many teams run both, using cloud DLP for discovery and Omit to stop sensitive data being put into an outbound copy in the first place.

Is there any central management?

Only a ceiling policy that fleet admins push to restrict which operators and entity types are available, plus a local HTML audit report per run. There is no cloud incident console of the kind cloud DLP suites offer.

Keep the data on your device

Omit runs fully offline, and the Omit Redact beta is a free download. Read the Trust Center and verify the offline promise yourself.