🔒 Confidential // Accredited Systems Integrators & Resellers Only

Pre-Sales Engineering, Datastore Sizing & Objection Handling Guide

A complete technical reference for channel pre-sales engineers, solutions architects, and cybersecurity consultants. Sizing enterprise environments, handling capacity objections, and proving turnkey Proof of Value (POV) ROI.

DOC REF: GX-ENG-PRESALES-2026.1
PLATFORM: Custos DSPM v2026.1
PUBLISHER: GovernX Pre-Sales Group

📏 Section 1: Enterprise Capacity Scoping & The "Will 25 TB Last for a Year?" Sizing Model

The most common question from enterprise CISOs and IT Directors during commercial qualification is: "Our data center has 500 servers and over 250 TB of raw storage. How can a 25 TB license cover us, and will 25 TB last for a full 1-year contract?"

The Pre-Sales Golden Rule: Capacity Under Management vs. Consumable Quota

In Custos DSPM, 25 TB is NOT a consumable download limit or metered scan quota. It is a High-Water Mark of Monitored Storage Capacity. The enterprise is licensed to continuously monitor up to 25 TB of active database tables and file shares concurrently. They can run scans daily, weekly, or continuously via Change Data Capture (CDC) for all 365 days of the year without paying a single cent more or "running out" of scans.

What Counts vs. What Does NOT Count Toward Capacity

Custos DSPM inspects and secures business data holding sensitive citizen and customer records. It does not count stateless compute, operating systems, or ephemeral infrastructure:

✓ What Counts Toward Licensed TB

  • Core Relational Databases: MySQL, MariaDB, Oracle RAC, MSSQL, PostgreSQL production schemas containing customer/financial records.
  • NoSQL Document Stores: MongoDB collections containing PII, customer profiles, or transaction records.
  • Monitored Object Buckets: Designated enterprise S3 / MinIO buckets holding documents, invoices, or customer uploads.
  • Target Network File Shares: Enterprise SMB/CIFS or NFS shares housing HR, legal, payroll, or executive records.

✕ What Does NOT Count (Exempted)

  • OS Drives & Hypervisor LUNs: C: drives, `/dev/sda`, VM boot disks, hypervisor scratch space.
  • Stateless Compute & Containers: Web frontends, microservice application nodes, Docker layers, Kubernetes ephemeral pods.
  • Cold Infrastructure Logs: Syslog, firewall dumps, NetFlow records, raw ELK/Splunk indexes.
  • Raw Backups & Snapshots: Commvault / Veeam cold tape dumps, VM snapshots, database WAL logs.

The 500-Server Sizing Reality Check (Case Study)

When an enterprise reports a fleet of 500 servers, pre-sales architects should break down the storage distribution using this proven sizing table:

Server Tier / Role Server Count Raw Storage Custos Monitored Scope Sizing Rationale
Stateless App & Web Nodes 350 servers 140 TB 0 TB Run stateless business logic, NGINX, microservices. Zero sensitive datastores reside on disk.
Dev / QA / Staging Nodes 50 servers 25 TB 0 TB Exempted or populated with synthetic/masked data during staging.
Core Production Databases
(MySQL, Oracle RAC, MSSQL, PG)
60 servers 50 TB 12 to 18 TB Core customer databases, billing records, CRM, ERP, core banking tables. (Primary data footprint).
Active Object & File Shares
(S3/MinIO, SMB/NFS Shares)
40 servers 35 TB 4 to 6 TB Target folders housing sensitive documents (HR, financial statements, contracts, customer KYC).
Total Enterprise Estate 250 TB Raw 16 TB to 24 TB Monitored Fits cleanly inside the 25 TB Baseline Tier!

The 1-Year Organic Data Growth Formula

Relational enterprise databases (MySQL, Oracle, MSSQL) experience an average annual growth rate of 15% to 20%. Use this formula during customer scoping:

Projected Year-End Volume = Active_Starting_TB × (1 + Annual_Growth_Rate)
Starting at 15 TB on Day 1:
15 TB × 1.20 = 18.0 TB at Month 12
✓ 7.0 TB (28%) headroom remaining. 25 TB tier easily lasts the full year.
Starting at 18 TB on Day 1:
18 TB × 1.20 = 21.6 TB at Month 12
✓ 3.4 TB (14%) headroom remaining. 25 TB tier comfortably covers year 1.
Pre-Sales Qualification Rule of Thumb:

• If Day 1 audit indicates ≤ 20 TB of sensitive datastores: Close on 25 TB Baseline (R 950,000 / yr).
• If Day 1 audit indicates > 20 TB of sensitive datastores: Recommend the 50 TB Tier (R 1,650,000 / yr) to guarantee 24 months of unconstrained expansion runway.

Mid-Year Capacity Expansion Playbook (Zero Service Disruption)

If a customer acquires a subsidiary or expands their database scope beyond 25 TB during Month 8:

  1. Zero Production Interruption: Custos DSPM never halts or hard-bricks active security monitoring.
  2. Soft Watermark Notice: An automated advisory is logged in the Partner and Admin dashboards.
  3. Prorated Expansion Billing: The partner invoices the customer for a co-termed capacity add-on (e.g. +25 TB or +50 TB upgrade) for the remaining months.
  4. Partner Commission: The partner collects their 32% gross margin on the expansion invoice immediately.

🔌 Section 2: Technical Datastore Support & Agentless Architecture

Custos DSPM connects natively to on-premises and sovereign cloud datastores via read-only cursor protocols. No intrusive agents are installed on production database hosts.

Engine / Storage System Supported Versions Streaming Driver / Protocol Database CPU Impact
MySQL & MariaDB MySQL 5.7, 8.0+
MariaDB 10.3–11.x, Percona
Streaming cursor over TCP (`go-sql-driver/mysql`) with windowed fetch limits. < 1.8% CPU
Oracle RAC / Enterprise 11g, 12c, 19c, 21c (Single & RAC) Native Oracle TNS cursor protocol (`sijms/go-ora`), multi-node RAC failover. < 1.9% CPU
Microsoft SQL Server 2014, 2016, 2017, 2019, 2022 TDS protocol with `WITH (NOLOCK)` adaptive reads; secondary replica routing. < 1.5% CPU
PostgreSQL & TimescaleDB PostgreSQL 11–16+, TimescaleDB Server-side declared cursors (`DECLARE NO SCROLL CURSOR`), zero client RAM buffering. < 1.4% CPU
MongoDB & Redis Mongo 4.x–7.x, Redis 6.x–7.x BSON document cursor iteration; Redis scanning for cached auth tokens & session PII. < 1.2% CPU
Object Storage (S3 Lakes) MinIO, Ceph RGW, AWS S3, Azure Blob Direct S3 API streaming; chunks CSV, Parquet, JSON, and DB dumps in memory. < 1.0% CPU
Network Shares (Unstructured) SMB / CIFS, NFS (v3/v4), POSIX Kernel-level asynchronous POSIX read streams with configurable bandwidth throttling. < 1.5% CPU

Zero Production Overhead Engineering Guarantees

💼 Section 3: Commercial Deal Structuring & Modular Capability Packs

GovernX protects partner margins across all deal sizes with a guaranteed 32% software margin.

Mandatory Foundation Architecture:

Custos™ DSPM Core is the mandatory platform engine. Modules 01 through 04 cannot be purchased standalone; they attach to an active Core capacity baseline.

A. Mandatory Baseline Platform: Custos™ DSPM Core

Core Capacity Scope 1-Year Annual MSRP Partner 32% Margin (1-Yr) 3-Year Upfront Price (Customer 15% OFF) Partner 3-Year Upfront Profit (32%)
Core 25 TB Baseline R 950,000 / yr R 304,000 / yr R 2,422,500 R 775,200
Core 50 TB Enterprise R 1,650,000 / yr R 528,000 / yr R 4,207,500 R 1,346,400
Core 100 TB Hyperscale R 2,850,000 / yr R 912,000 / yr R 7,267,500 R 2,325,600

B. Numbered Modular Add-On Packs (Attach to Active Core)

# Modular Capability Pack Annual Add-On MSRP Partner 32% Margin 3-Yr Upfront Partner Profit
01 Custos™ Guard & Cryptographic Provenance
Universal AI LLM Proxy & SHA-256 Ledger
+ R 280,000 / yr + R 89,600 / yr R 228,480
02 Governance & Privacy Automation Pack
DSAR, Section 24 Erasure & ROT Reclaim
+ R 260,000 / yr + R 83,200 / yr R 212,160
03 Active Defense & SecOps Pack
Quarantine Vault & HoneyData Canaries
+ R 220,000 / yr + R 70,400 / yr R 179,520
04 Enterprise AI Governance Pack
Vector RAG ACL, Prompt Shield & Shadow AI
+ R 280,000 / yr + R 89,600 / yr R 228,480
★ All 4 Modular Add-Ons Pack (Save 25%) + R 780,000 / yr + R 249,600 / yr R 636,480
★ The Complete Sovereign Suite (Core 25 TB + All 4 Modules)
Flagship Turnkey Deployment (Save R 400k/yr)
R 1,590,000 / yr R 508,800 / yr R 1,297,440

C. Competitor Pricing Benchmark (Why Custos Wins)

Vendor Typical Annual Cost Architecture Weakness Winning Custos Advantage
BigID $120k – $250k+ / yr
(R 2.2M – R 4.6M ZAR)
Heavy multi-node K8s sprawl; $50k+ mandatory services Custos is ~50% lower cost, lightweight single binary, zero professional services lock-in.
Cyera $80k – $150k+ / yr
(R 1.5M – R 2.8M ZAR)
US Cloud SaaS only; zero on-prem or air-gap capability Custos is 100% sovereign; zero telemetry leaves South African / client perimeter.
Varonis $100k – $220k+ / yr
(R 1.8M – R 4.0M ZAR)
Opaque user/volume tiering; severe renewal bill shocks Custos licenses clean monitored storage high-water mark; zero per-scan or per-user penalties.
Securiti.ai $75k – $180k+ / yr
(R 1.4M – R 3.3M ZAR)
Foreign currency billing exposed to exchange rate volatility Fixed Rand (ZAR) invoicing protects corporate budgets from currency depreciation.
Why Pitch the 3-Year Upfront Deal?
  • For the Customer: They save 15% upfront, lock in fixed currency pricing against ZAR volatility, and guarantee regulatory compliance continuity.
  • For the Partner: You collect 3 full years of 32% margin on Day 1 (e.g. R 775,200 on a 25 TB deal; R 1,297,440 on a Suite deal).

Turnkey Proof of Value (POV) Economics & Workflow

🛡️ Section 4: Enterprise CISO Objection Handling Playbook

Objection 1: "We already have Microsoft Purview / Defender. Why do we need Custos?"

Pre-Sales Response: "Microsoft Purview operates natively inside Azure and Microsoft 365, but enterprise banks and government departments cannot stream on-premises Oracle RAC, MySQL, and core banking databases to US cloud SaaS platforms without violating South Africa POPIA Section 72 and NDPA Section 41. Custos is 100% on-premises and air-gapped—zero bytes of database telemetry or data leave your perimeter. Furthermore, Custos features specialized African regulatory classifiers (Luhn-checked SA IDs, SARS tax refs, Nigerian NIN) and in-flight LLM guardrails that Purview does not provide for on-prem models."

Objection 2: "Will Custos scanning bring down or slow down our core production databases?"

Pre-Sales Response: "No. Custos utilizes non-blocking, read-only streaming cursors configured with query rate-limiting and off-peak execution windows. CPU impact on Oracle, MySQL, and MSSQL nodes is verified at under 2%. For clustered environments like MSSQL AlwaysOn or Oracle RAC, Custos routes scan traffic to read-only secondary replicas, completely eliminating contention on the primary write node."

Objection 3: "Does Custos require an ongoing internet connection for licensing or signatures?"

Pre-Sales Response: "No. Custos is engineered for strict sovereign air-gap isolation. Licensing is cryptographic (Ed25519 digital signatures validated locally against hardcoded public keys). It requires zero outbound WAN connections, zero telemetry reporting, and zero cloud callbacks during installation, runtime, or license renewal."

Objection 4: "Why should we pay $15,000 USD for a 30-day Proof of Value (POV)?"

Pre-Sales Response: "Unlike superficial vendor slide demos, the Custos POV is a fully managed, turnkey sovereign assessment conducted inside your secure perimeter. Within 30 days, your executive team receives a board-ready Sovereign Risk & Statutory Compliance Audit Report (covering POPIA, Mauritius DPA 2017 / FSC / BoM, EU GDPR, and NDPA), identifying exact shadow datastores, unencrypted citizen PII, and AI pipeline vulnerabilities. Best of all, 100% of the $15,000 fee is credited toward your annual enterprise subscription upon conversion."

📋 Section 5: The 10-Minute Pre-Sales Discovery Checklist

Ask these 8 questions during the initial technical discovery call with the CISO and Head of Enterprise Architecture:

  1. Primary Datastore Engines: What are your core production database engines? (e.g. Oracle RAC, MSSQL AlwaysOn, MySQL/MariaDB, PostgreSQL, MongoDB, S3/MinIO?)
  2. Active Sensitive Volume: Excluding OS disks, backup tapes, and VM snapshots, what is the estimated active data footprint of tables containing citizen/customer PII? (Typically 10–25 TB).
  3. Sovereign Cloud / Perimeter Policy: Does your security policy or regulator (SARB / PA, Bank of Mauritius / FSC, CBN, ODPC, or EU GDPR) permit streaming database metadata or PII to US-hosted multi-tenant SaaS platforms?
  4. AI & LLM Adoption: Are development or business teams testing LLMs (e.g., Azure OpenAI, Gemini, Claude, or private on-prem Ollama/DeepSeek)? Do you have real-time guardrails intercepting citizen PII?
  5. Regulatory Deadlines: What upcoming internal audit, POPIA Prior Authorisation, Mauritius DPA 2017 / BoM cloud directives, or EU GDPR compliance deadlines are driving this initiative?
  6. Secondary Replicas: Do your database clusters maintain read-only standby replicas (e.g., AlwaysOn Secondary or Oracle Active Data Guard) for offloading scans?
  7. SIEM Integration: Where does your SOC centralize telemetry? (Microsoft Sentinel, Splunk, IBM QRadar, or local Syslog TLS?)
  8. Target Evaluation Window: Can your team approve a read-only service account for a 30-day turnkey Proof of Value (POV) beginning within the next 30 days?

⚔️ Section 6: Next-Gen Strategic Modules (Sizing & Competitor Knockdown Battlecards)

How to pitch and size the 5 strategic enterprise modules against US cloud DSPMs (Cyera, BigID, Varonis, Securiti.ai):

1. Custos SovereignFence™ (Active eBPF Egress Blocker)

Technical Sizing: Deployed as an in-kernel eBPF bytecode filter attached to egress network interfaces (tc egress or cgroup_skb). Requires Linux kernel >= 5.4. Adds <1 microsecond packet latency. CPU overhead < 1.5% at 10 Gbps line rate.

Competitor Knockdown (Cyera / BigID / Varonis): "Cloud DSPMs only send you a notification email after your data has crossed the border to an offshore cloud. SovereignFence drops the TCP connection inside the kernel in <1 microsecond, making POPIA Section 72 and Mauritius DPA 2017 Section 36 cross-border violations physically impossible."

2. Custos Synth™ (Differential Privacy Test Cloner)

Technical Sizing: Operates directly on-premises using DAG schema dependency resolution. Clones 1,000,000 rows in < 45 seconds on 8 vCPUs. Preserves foreign key relationships across Oracle RAC, MSSQL, and PostgreSQL with zero real customer records.

Competitor Knockdown: "Competitors require buying separate masking tools or cloud SaaS data generation platforms that expose your schemas. Custos Synth runs air-gapped on-prem with mathematical ε-differential privacy guarantees."

3. Custos BlastRadius™ (Zero-Trust Identity Graph)

Technical Sizing: Traverses identity-to-datastore attack paths using high-performance in-memory graph simulation. Maps over 500,000 permissions in under 10 seconds.

Competitor Knockdown: "Varonis inundates your SOC with millions of permission alerts. BlastRadius translates identity permissions into exact dollar/ZAR regulatory fine liability ($ / ZAR) linked to compromised DBA accounts."

4. Custos AgentShield™ (Autonomous AI & Tool Governor)

Technical Sizing: Reverse proxy for Model Context Protocol (MCP) servers and LLM tool-calling endpoints. Latency < 3.5ms. Analyzes function call arguments for prompt injection, SQLi, and path traversal vectors.

Competitor Knockdown: "Traditional DSPMs and Microsoft Purview only audit logs after the fact. When employees query Microsoft 365 Copilot or autonomous Copilot Studio bots, Purview cannot actively strip in-flight PII or block semantic grounding against over-permissioned SharePoint shares in real time. Custos Guard and AgentShield actively govern Microsoft Copilot & autonomous agent tools with sub-5ms latency."

5. Custos CleanRoom™ (Ephemeral M&A Data Risk Auditor)

Technical Sizing: Single-binary zero-footprint ephemeral container deployed on candidate acquisition targets. Completes comprehensive PII and compliance audits within 24 to 48 hours.

Competitor Knockdown: "Competitors require permanent agents or complex cloud onboarding that target companies refuse to permit. CleanRoom runs completely memory-resident, generating an encrypted M&A due diligence dossier with escrow holdback valuations without copying data."

6. Custos WireShield™ (Zero-Touch SQL Wire Virtual Masking)

Technical Sizing: In-stream network wire proxy for PostgreSQL, MSSQL TDS, and Oracle TNS protocols. Latency < 0.8ms. Inspects tabular result sets, applying dynamic regex/Luhn PII masking for unprivileged analysts and BI tools.

Competitor Knockdown: "Cyera and BigID are read-only reporting shelfware. When they discover PII, they force DBAs into high-risk schema migrations that break legacy core banking systems. WireShield delivers active zero-touch remediation at the network layer with zero database migrations."

7. Custos VectorGuard™ (Neural DLP & Vector DB / RAG Firewall)

Technical Sizing: Pre-embedding ingestion gate and vector similarity retrieval proxy for Pinecone, Milvus, Qdrant, Chroma, and pgvector. Filters RAG context chunks against Active Directory/Entra ID ACLs.

Competitor Knockdown: "All traditional DLP and DSPM tools are 100% blind to high-dimensional floating-point vectors. Once sensitive data is embedded, it cannot be regex-scanned. VectorGuard sanitizes before embedding and firewalls vector semantic retrieval in real time."

8. Custos SafeHarbor™ (Cryptographic CISO Legal Defense Ledger)

Technical Sizing: Merkle Tree cryptographic engine aggregating all daily security events (scans, quarantines, proxy redactions) into an Ed25519-signed Statutory Safe Harbor Dossier.

Competitor Knockdown: "Following the SEC SolarWinds case and POPIA Section 107 criminal penalties, CISOs face personal criminal liability. Competitors only provide mutable text logs. SafeHarbor generates court-admissible, mathematically verified proof of continuous due diligence."
© 2026 GovernX (Pty) Ltd. All Rights Reserved. • Cape Town, Western Cape, South Africa • Direct Desk: Enterprise Contact Form →