Pre-Sales Engineering, Datastore Sizing & Objection Handling Guide
A complete technical reference for channel pre-sales engineers, solutions architects, and cybersecurity consultants. Sizing enterprise environments, handling capacity objections, and proving turnkey Proof of Value (POV) ROI.
📏 Section 1: Enterprise Capacity Scoping & The "Will 25 TB Last for a Year?" Sizing Model
The most common question from enterprise CISOs and IT Directors during commercial qualification is: "Our data center has 500 servers and over 250 TB of raw storage. How can a 25 TB license cover us, and will 25 TB last for a full 1-year contract?"
In Custos DSPM, 25 TB is NOT a consumable download limit or metered scan quota. It is a High-Water Mark of Monitored Storage Capacity. The enterprise is licensed to continuously monitor up to 25 TB of active database tables and file shares concurrently. They can run scans daily, weekly, or continuously via Change Data Capture (CDC) for all 365 days of the year without paying a single cent more or "running out" of scans.
What Counts vs. What Does NOT Count Toward Capacity
Custos DSPM inspects and secures business data holding sensitive citizen and customer records. It does not count stateless compute, operating systems, or ephemeral infrastructure:
✓ What Counts Toward Licensed TB
- Core Relational Databases: MySQL, MariaDB, Oracle RAC, MSSQL, PostgreSQL production schemas containing customer/financial records.
- NoSQL Document Stores: MongoDB collections containing PII, customer profiles, or transaction records.
- Monitored Object Buckets: Designated enterprise S3 / MinIO buckets holding documents, invoices, or customer uploads.
- Target Network File Shares: Enterprise SMB/CIFS or NFS shares housing HR, legal, payroll, or executive records.
✕ What Does NOT Count (Exempted)
- OS Drives & Hypervisor LUNs: C: drives, `/dev/sda`, VM boot disks, hypervisor scratch space.
- Stateless Compute & Containers: Web frontends, microservice application nodes, Docker layers, Kubernetes ephemeral pods.
- Cold Infrastructure Logs: Syslog, firewall dumps, NetFlow records, raw ELK/Splunk indexes.
- Raw Backups & Snapshots: Commvault / Veeam cold tape dumps, VM snapshots, database WAL logs.
The 500-Server Sizing Reality Check (Case Study)
When an enterprise reports a fleet of 500 servers, pre-sales architects should break down the storage distribution using this proven sizing table:
| Server Tier / Role | Server Count | Raw Storage | Custos Monitored Scope | Sizing Rationale |
|---|---|---|---|---|
| Stateless App & Web Nodes | 350 servers | 140 TB | 0 TB | Run stateless business logic, NGINX, microservices. Zero sensitive datastores reside on disk. |
| Dev / QA / Staging Nodes | 50 servers | 25 TB | 0 TB | Exempted or populated with synthetic/masked data during staging. |
| Core Production Databases (MySQL, Oracle RAC, MSSQL, PG) |
60 servers | 50 TB | 12 to 18 TB | Core customer databases, billing records, CRM, ERP, core banking tables. (Primary data footprint). |
| Active Object & File Shares (S3/MinIO, SMB/NFS Shares) |
40 servers | 35 TB | 4 to 6 TB | Target folders housing sensitive documents (HR, financial statements, contracts, customer KYC). |
| Total Enterprise Estate | 250 TB Raw | 16 TB to 24 TB Monitored | Fits cleanly inside the 25 TB Baseline Tier! | |
The 1-Year Organic Data Growth Formula
Relational enterprise databases (MySQL, Oracle, MSSQL) experience an average annual growth rate of 15% to 20%. Use this formula during customer scoping:
• If Day 1 audit indicates ≤ 20 TB of sensitive datastores: Close on 25 TB Baseline (R 950,000 / yr).
• If Day 1 audit indicates > 20 TB of sensitive datastores: Recommend the 50 TB Tier (R 1,650,000 / yr) to guarantee 24 months of unconstrained expansion runway.
Mid-Year Capacity Expansion Playbook (Zero Service Disruption)
If a customer acquires a subsidiary or expands their database scope beyond 25 TB during Month 8:
- Zero Production Interruption: Custos DSPM never halts or hard-bricks active security monitoring.
- Soft Watermark Notice: An automated advisory is logged in the Partner and Admin dashboards.
- Prorated Expansion Billing: The partner invoices the customer for a co-termed capacity add-on (e.g. +25 TB or +50 TB upgrade) for the remaining months.
- Partner Commission: The partner collects their 32% gross margin on the expansion invoice immediately.
🔌 Section 2: Technical Datastore Support & Agentless Architecture
Custos DSPM connects natively to on-premises and sovereign cloud datastores via read-only cursor protocols. No intrusive agents are installed on production database hosts.
| Engine / Storage System | Supported Versions | Streaming Driver / Protocol | Database CPU Impact |
|---|---|---|---|
| MySQL & MariaDB | MySQL 5.7, 8.0+ MariaDB 10.3–11.x, Percona |
Streaming cursor over TCP (`go-sql-driver/mysql`) with windowed fetch limits. | < 1.8% CPU |
| Oracle RAC / Enterprise | 11g, 12c, 19c, 21c (Single & RAC) | Native Oracle TNS cursor protocol (`sijms/go-ora`), multi-node RAC failover. | < 1.9% CPU |
| Microsoft SQL Server | 2014, 2016, 2017, 2019, 2022 | TDS protocol with `WITH (NOLOCK)` adaptive reads; secondary replica routing. | < 1.5% CPU |
| PostgreSQL & TimescaleDB | PostgreSQL 11–16+, TimescaleDB | Server-side declared cursors (`DECLARE NO SCROLL CURSOR`), zero client RAM buffering. | < 1.4% CPU |
| MongoDB & Redis | Mongo 4.x–7.x, Redis 6.x–7.x | BSON document cursor iteration; Redis scanning for cached auth tokens & session PII. | < 1.2% CPU |
| Object Storage (S3 Lakes) | MinIO, Ceph RGW, AWS S3, Azure Blob | Direct S3 API streaming; chunks CSV, Parquet, JSON, and DB dumps in memory. | < 1.0% CPU |
| Network Shares (Unstructured) | SMB / CIFS, NFS (v3/v4), POSIX | Kernel-level asynchronous POSIX read streams with configurable bandwidth throttling. | < 1.5% CPU |
Zero Production Overhead Engineering Guarantees
- Zero Data Replication: Raw rows are streamed into volatile memory, analyzed against African PII regex filters (Luhn-checked SA IDs, SARS tax numbers, Nigerian NIN/BVN, Kenya KRA PINs), and immediately zeroed out.
- Lightweight Catalog Footprint: Only cryptographic metadata, risk scores, and column-level classifications are stored in the local encrypted SQLite catalog (<25 GB per 50 TB scanned).
- Read-Only Least Privilege: Only requires `SELECT` permissions on designated schemas. Custos never requests `INSERT`, `UPDATE`, `ALTER`, or `DROP` privileges.
💼 Section 3: Commercial Deal Structuring & Modular Capability Packs
GovernX protects partner margins across all deal sizes with a guaranteed 32% software margin.
Custos™ DSPM Core is the mandatory platform engine. Modules 01 through 04 cannot be purchased standalone; they attach to an active Core capacity baseline.
A. Mandatory Baseline Platform: Custos™ DSPM Core
| Core Capacity Scope | 1-Year Annual MSRP | Partner 32% Margin (1-Yr) | 3-Year Upfront Price (Customer 15% OFF) | Partner 3-Year Upfront Profit (32%) |
|---|---|---|---|---|
| Core 25 TB Baseline | R 950,000 / yr | R 304,000 / yr | R 2,422,500 | R 775,200 |
| Core 50 TB Enterprise | R 1,650,000 / yr | R 528,000 / yr | R 4,207,500 | R 1,346,400 |
| Core 100 TB Hyperscale | R 2,850,000 / yr | R 912,000 / yr | R 7,267,500 | R 2,325,600 |
B. Numbered Modular Add-On Packs (Attach to Active Core)
| # | Modular Capability Pack | Annual Add-On MSRP | Partner 32% Margin | 3-Yr Upfront Partner Profit |
|---|---|---|---|---|
| 01 | Custos™ Guard & Cryptographic Provenance Universal AI LLM Proxy & SHA-256 Ledger |
+ R 280,000 / yr | + R 89,600 / yr | R 228,480 |
| 02 | Governance & Privacy Automation Pack DSAR, Section 24 Erasure & ROT Reclaim |
+ R 260,000 / yr | + R 83,200 / yr | R 212,160 |
| 03 | Active Defense & SecOps Pack Quarantine Vault & HoneyData Canaries |
+ R 220,000 / yr | + R 70,400 / yr | R 179,520 |
| 04 | Enterprise AI Governance Pack Vector RAG ACL, Prompt Shield & Shadow AI |
+ R 280,000 / yr | + R 89,600 / yr | R 228,480 |
| ★ All 4 Modular Add-Ons Pack (Save 25%) | + R 780,000 / yr | + R 249,600 / yr | R 636,480 | |
|
★ The Complete Sovereign Suite (Core 25 TB + All 4 Modules) Flagship Turnkey Deployment (Save R 400k/yr) |
R 1,590,000 / yr | R 508,800 / yr | R 1,297,440 | |
C. Competitor Pricing Benchmark (Why Custos Wins)
| Vendor | Typical Annual Cost | Architecture Weakness | Winning Custos Advantage |
|---|---|---|---|
| BigID | $120k – $250k+ / yr (R 2.2M – R 4.6M ZAR) |
Heavy multi-node K8s sprawl; $50k+ mandatory services | Custos is ~50% lower cost, lightweight single binary, zero professional services lock-in. |
| Cyera | $80k – $150k+ / yr (R 1.5M – R 2.8M ZAR) |
US Cloud SaaS only; zero on-prem or air-gap capability | Custos is 100% sovereign; zero telemetry leaves South African / client perimeter. |
| Varonis | $100k – $220k+ / yr (R 1.8M – R 4.0M ZAR) |
Opaque user/volume tiering; severe renewal bill shocks | Custos licenses clean monitored storage high-water mark; zero per-scan or per-user penalties. |
| Securiti.ai | $75k – $180k+ / yr (R 1.4M – R 3.3M ZAR) |
Foreign currency billing exposed to exchange rate volatility | Fixed Rand (ZAR) invoicing protects corporate budgets from currency depreciation. |
- For the Customer: They save 15% upfront, lock in fixed currency pricing against ZAR volatility, and guarantee regulatory compliance continuity.
- For the Partner: You collect 3 full years of 32% margin on Day 1 (e.g. R 775,200 on a 25 TB deal; R 1,297,440 on a Suite deal).
Turnkey Proof of Value (POV) Economics & Workflow
- Prepayment to GovernX: The $15,000 USD (approx. R 280,000 ZAR) POV evaluation fee must be paid over to GovernX first prior to staging.
- Immediate Sovereign Key Provisioning: Upon payment receipt, the 30-day node-locked cryptographic evaluation key is generated and sent to the partner immediately.
- Final Conversion Settlement (100% Credit): When the enterprise client converts, GovernX bills for the software subscription MINUS the $15,000 POV prepayment, providing a 100% credit.
- Deliverable Guarantee: In all cases, the customer permanently retains their comprehensive sovereign audit report, cataloging data, and compliance gap analysis.
🛡️ Section 4: Enterprise CISO Objection Handling Playbook
Objection 1: "We already have Microsoft Purview / Defender. Why do we need Custos?"
Pre-Sales Response: "Microsoft Purview operates natively inside Azure and Microsoft 365, but enterprise banks and government departments cannot stream on-premises Oracle RAC, MySQL, and core banking databases to US cloud SaaS platforms without violating South Africa POPIA Section 72 and NDPA Section 41. Custos is 100% on-premises and air-gapped—zero bytes of database telemetry or data leave your perimeter. Furthermore, Custos features specialized African regulatory classifiers (Luhn-checked SA IDs, SARS tax refs, Nigerian NIN) and in-flight LLM guardrails that Purview does not provide for on-prem models."
Objection 2: "Will Custos scanning bring down or slow down our core production databases?"
Pre-Sales Response: "No. Custos utilizes non-blocking, read-only streaming cursors configured with query rate-limiting and off-peak execution windows. CPU impact on Oracle, MySQL, and MSSQL nodes is verified at under 2%. For clustered environments like MSSQL AlwaysOn or Oracle RAC, Custos routes scan traffic to read-only secondary replicas, completely eliminating contention on the primary write node."
Objection 3: "Does Custos require an ongoing internet connection for licensing or signatures?"
Pre-Sales Response: "No. Custos is engineered for strict sovereign air-gap isolation. Licensing is cryptographic (Ed25519 digital signatures validated locally against hardcoded public keys). It requires zero outbound WAN connections, zero telemetry reporting, and zero cloud callbacks during installation, runtime, or license renewal."
Objection 4: "Why should we pay $15,000 USD for a 30-day Proof of Value (POV)?"
Pre-Sales Response: "Unlike superficial vendor slide demos, the Custos POV is a fully managed, turnkey sovereign assessment conducted inside your secure perimeter. Within 30 days, your executive team receives a board-ready Sovereign Risk & Statutory Compliance Audit Report (covering POPIA, Mauritius DPA 2017 / FSC / BoM, EU GDPR, and NDPA), identifying exact shadow datastores, unencrypted citizen PII, and AI pipeline vulnerabilities. Best of all, 100% of the $15,000 fee is credited toward your annual enterprise subscription upon conversion."
📋 Section 5: The 10-Minute Pre-Sales Discovery Checklist
Ask these 8 questions during the initial technical discovery call with the CISO and Head of Enterprise Architecture:
- Primary Datastore Engines: What are your core production database engines? (e.g. Oracle RAC, MSSQL AlwaysOn, MySQL/MariaDB, PostgreSQL, MongoDB, S3/MinIO?)
- Active Sensitive Volume: Excluding OS disks, backup tapes, and VM snapshots, what is the estimated active data footprint of tables containing citizen/customer PII? (Typically 10–25 TB).
- Sovereign Cloud / Perimeter Policy: Does your security policy or regulator (SARB / PA, Bank of Mauritius / FSC, CBN, ODPC, or EU GDPR) permit streaming database metadata or PII to US-hosted multi-tenant SaaS platforms?
- AI & LLM Adoption: Are development or business teams testing LLMs (e.g., Azure OpenAI, Gemini, Claude, or private on-prem Ollama/DeepSeek)? Do you have real-time guardrails intercepting citizen PII?
- Regulatory Deadlines: What upcoming internal audit, POPIA Prior Authorisation, Mauritius DPA 2017 / BoM cloud directives, or EU GDPR compliance deadlines are driving this initiative?
- Secondary Replicas: Do your database clusters maintain read-only standby replicas (e.g., AlwaysOn Secondary or Oracle Active Data Guard) for offloading scans?
- SIEM Integration: Where does your SOC centralize telemetry? (Microsoft Sentinel, Splunk, IBM QRadar, or local Syslog TLS?)
- Target Evaluation Window: Can your team approve a read-only service account for a 30-day turnkey Proof of Value (POV) beginning within the next 30 days?
⚔️ Section 6: Next-Gen Strategic Modules (Sizing & Competitor Knockdown Battlecards)
How to pitch and size the 5 strategic enterprise modules against US cloud DSPMs (Cyera, BigID, Varonis, Securiti.ai):
1. Custos SovereignFence™ (Active eBPF Egress Blocker)
Technical Sizing: Deployed as an in-kernel eBPF bytecode filter attached to egress network interfaces (tc egress or cgroup_skb). Requires Linux kernel >= 5.4. Adds <1 microsecond packet latency. CPU overhead < 1.5% at 10 Gbps line rate.
2. Custos Synth™ (Differential Privacy Test Cloner)
Technical Sizing: Operates directly on-premises using DAG schema dependency resolution. Clones 1,000,000 rows in < 45 seconds on 8 vCPUs. Preserves foreign key relationships across Oracle RAC, MSSQL, and PostgreSQL with zero real customer records.
3. Custos BlastRadius™ (Zero-Trust Identity Graph)
Technical Sizing: Traverses identity-to-datastore attack paths using high-performance in-memory graph simulation. Maps over 500,000 permissions in under 10 seconds.
4. Custos AgentShield™ (Autonomous AI & Tool Governor)
Technical Sizing: Reverse proxy for Model Context Protocol (MCP) servers and LLM tool-calling endpoints. Latency < 3.5ms. Analyzes function call arguments for prompt injection, SQLi, and path traversal vectors.
5. Custos CleanRoom™ (Ephemeral M&A Data Risk Auditor)
Technical Sizing: Single-binary zero-footprint ephemeral container deployed on candidate acquisition targets. Completes comprehensive PII and compliance audits within 24 to 48 hours.
6. Custos WireShield™ (Zero-Touch SQL Wire Virtual Masking)
Technical Sizing: In-stream network wire proxy for PostgreSQL, MSSQL TDS, and Oracle TNS protocols. Latency < 0.8ms. Inspects tabular result sets, applying dynamic regex/Luhn PII masking for unprivileged analysts and BI tools.
7. Custos VectorGuard™ (Neural DLP & Vector DB / RAG Firewall)
Technical Sizing: Pre-embedding ingestion gate and vector similarity retrieval proxy for Pinecone, Milvus, Qdrant, Chroma, and pgvector. Filters RAG context chunks against Active Directory/Entra ID ACLs.
8. Custos SafeHarbor™ (Cryptographic CISO Legal Defense Ledger)
Technical Sizing: Merkle Tree cryptographic engine aggregating all daily security events (scans, quarantines, proxy redactions) into an Ed25519-signed Statutory Safe Harbor Dossier.