Sidekick Lab – AI-Powered Data Discovery Platform
Sidekick Lab · Intelligence & Research
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 9 captures on record
What the publisher says
As described on Microsoft Marketplace.
Sidekick is an on-premises, inside-tenant AI
platform that gives enterprises a living, governed understanding of their
Show the rest of the publisher’s description (50 more lines)
entire data estate, automatically. It connects to data source systems including
Snowflake, Databricks, SAP, PostgreSQL, MySQL, Oracle, MongoDB and SQL Server,
discovers every data source, field and table, builds a plain-English data
dictionary and ontology, classifies sensitive data, and makes it queryable in
natural language.
The core problem Sidekick solves: 73% of
enterprise AI projects fail, most often because of poor data quality, unknown
assets and a data estate that nobody fully understands before the project
begins. Most organizations believe 80% of their data estate is documented, when
the reality is closer to 30%. Sidekick closes that gap before any AI initiative
begins.
- Sidekick is not a chatbot or a copilot that
only answers the questions it is asked. It is an autonomous agent that
discovers, audits, analyzes, maps and reasons over data without waiting for a
user query, and improves its understanding of the estate continuously over
time.
- Sidekick runs on fully supported Microsoft reference stack.
- Deploys in your tenant, burns your Azure commit/credits, solves your data-discovery and ontology problem.
What Sidekick delivers per source system: a
data dictionary, sensitivity and PII classification, a cleanliness assessment,
use case identification and ontology mapping. Across the organization it
delivers an enterprise data catalogue, a cross-source interoperability map, an
AI-readiness report, data monetisation opportunities and a proposed data
strategy and roadmap.
Deployment and security:
Sidekick deploys
fully inside the customer's own environment (Azure, on-premises, or other
approved region), with no data leaving the customer's perimeter. Access to
source systems is read-only with zero write access. The platform uses data
minimisation, accessing only schemas and configurable sampled records rather
than full extractions, and customers control scope using allow-lists,
deny-lists or schema/table restrictions. Access control is managed through
Microsoft Entra ID with role-based and field-level security. Full audit trails
are available for SIEM integration, and the architecture is POPIA and GDPR
aligned, HIPAA-suitable and built to ISO 27001 and SOC2 practices. Encryption
is AES-256 at rest and TLS 1.3 in transit. No customer data is used for model
training and no cross-tenant data sharing is possible.
Infrastructure:
Sidekick runs on a Windows
VM (SQL Server 2022, minimum 4 vCPU / 16GB RAM) and a Linux VM (Docker
containers via Docker Compose, minimum 2 vCPU / 8GB RAM). It is strategically
aligned with Microsoft, running on Microsoft AI Foundry and Azure, and
extending into Microsoft Fabric and Copilot. The platform is cloud-agnostic and
can also run on AWS or GCP, and a partner-hosted LLM option is available for
fully air-gapped environments.
Current agents include Discovery and
Cataloguing (scans the full environment, builds and maintains the catalogue,
identifies cross-source use cases) and Reporting and Insights (natural language
questions with real-time answers, shareable dashboards, improves with feedback
over time).
Preview
5 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Plans and pricing as listed
3 listed- Data Source Type: $6,000.00 per data source
- Data Source Type: $5,000.00 per data source
Sources
Publisher resources
4 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






