> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses.md).

# Understand Cortex Data Security Licenses

Cortex Data Security is licensed on a workload basis rather than per endpoint or agent. A Cortex Data Security license entitles you to a pool of Data Security Workload units, which enable the full range of capabilities within Cortex Data Security and are consumed by the data assets you protect. For details on how assets consume workload units, see [License allocation](/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses/license-allocation.md).

To view the product license and add-ons associated with your tenant, go to **Settings** → **Cortex Data Security License**.

## Deployment and availability

Cortex Data Security can be deployed in the following ways:

* **Standalone:** A dedicated Cortex tenant focused exclusively on Cortex Data Security.
* **Add-on:** Integrated into an existing Cortex XDR or Cortex XSIAM tenant, providing a unified management experience for your security operations and data security posture.

{% hint style="info" %}
**Note:** Cortex Data Security capabilities may be included or available based on your existing license:

* **Cortex XSIAM Premium (X5):** Natively includes the full suite of Cortex Data Security capabilities (DSPM and DDR) across cloud, SaaS, and on-premises environments.
* **Cortex Cloud Runtime Security (C3):** Provides comprehensive protection, detection, and response across cloud workloads and SaaS applications (such as Microsoft 365 or Slack). It includes Data Security Posture Management (DSPM) and Cloud Data Detection and Response (DDR) as core capabilities.

  To extend these data-centric protections to on-premises data stores or to provide a dedicated workspace for data security teams, you can add the Cortex Data Security license to your tenant.
  {% endhint %}

## Capabilities

The Cortex Data Security license includes core data security functionality and can be extended with additional capabilities as your needs grow.

#### Key features

Key features of the Cortex Data Security License include:

| Feature                                          | Description                                                                                                                                                                                                                                                                                                                                                |
| ------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Data Security Posture Management (DSPM)          | Discover, classify, and assess the risk of your data assets at rest across cloud, SaaS, DBaaS, and on-premises environments.                                                                                                                                                                                                                               |
| AI Security Posture Management (AI-SPM)          | Map and monitor the data that powers your AI pipelines—models, agents, endpoints, and training data—and assess their associated risk.                                                                                                                                                                                                                      |
| Data Access Governance (DAG) / Identity Security | Analyze identities and entitlements, calculate effective permissions, and govern access to sensitive data to enforce least privilege.                                                                                                                                                                                                                      |
| Data Detection and Response (DDR)                | Real-time monitoring and automated response for data threats in cloud and SaaS environments. It uses machine learning and behavioral models to analyze cloud activity logs to detect and block anomalies like mass data exfiltration, unauthorized cross-region transfers, and suspicious identity behavior, while filtering out unrelated security noise. |
| Core Analytics                                   | Detects anomalies and threats using machine learning and behavioral models.                                                                                                                                                                                                                                                                                |
| Automation                                       | Orchestrates and automates security workflows with prebuilt and customizable playbooks.                                                                                                                                                                                                                                                                    |
| Data Ingestion                                   | Collects and normalizes data from supported cloud and SaaS sources to create a unified foundation for data-centric analytics, investigation, and risk detection, enabling behavioral models to identify data-specific risks and prioritize security issues across the data estate.                                                                         |

#### Capacity add-ons

Use the following add-ons to expand your capacity.

| Capacity add-on     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| GB ingestion        | Provides daily-ingested-GB (GB/day) capacity, which is not included in the base workload license (minimum 100 GB/day). Includes 30 days of ingested-data retention and 180 days of alerts and incidents retention.                                                                                                                                                                                                                                                      |
| Compute Units       | Additional compute resources beyond the included allocation, to support scaling during peak workloads and cold-storage queries.                                                                                                                                                                                                                                                                                                                                         |
| Data Retention      | Extends hot, cold, per-dataset, and Case and Issue retention beyond the defaults. For details, see [Data retention in Cortex Data Security](/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses/data-retention-in-cortex-data-security.md) and [Data storage lifecycle](/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses/data-storage-lifecycle.md). |
| GB Event Forwarding | Enables exporting parsed logs to an external SIEM for storage, so you can keep data in your own storage in addition to the Cortex Data Layer, for compliance requirements and machine learning purposes.                                                                                                                                                                                                                                                                |

#### XDR integration for DLP

To enforce DLP policies directly on user endpoints (such as blocking unauthorized data transfers or browser-based exfiltration), you need the Cortex agent, which requires a base product like Enterprise Runtime Security ([Cortex XDR](/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/readme-1.md)) to deploy.

You must also purchase the Endpoint DLP add-on license. Once this license is applied and policies are configured in your console, the Cortex agent automatically downloads and activates the [Cortex Data Loss Prevention (DLP) module](/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview.md) to enforce your data security rules directly on the device.

Any resulting endpoint DLP incidents or sensitive asset detections are seamlessly integrated and surfaced within the Data Security Command Center.&#x20;

## More information

For more information about licensing, see the following topics:

* [License allocation](/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses/license-allocation.md)
* [License expiration](/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses/license-expiration.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
