How it works

Five steps from read-only credential to audit-ready evidence.

The workflow is deliberately boring: connect a source, review what's found, apply a control, keep the proof. No agents on endpoints, no data leaving your boundary.

01 Connect Add a source. Credentials are encrypted per-tenant. Scope is defined before any scan runs.
02 Discover Lightweight schema pass. Maps tables, estimates volume, and surfaces likely-sensitive fields.
03 Scan Deep field-level scan with confidence scores, row counts, and context evidence for review.
04 Act Apply the right control: mask, anonymize, generate a synthetic export, or prepare a governed copy.
05 Prove The decision trail is complete. Show regulators what was found, what changed, and who approved it.
What makes it workable

Designed for the people who have to run it.

Scope is agreed before anything runs

Credentials are read-only and encrypted per tenant. You decide which schemas, buckets, or repositories are in scope. Nothing is scanned by default.

Findings come with evidence, not just labels

Each finding carries the detected entity type, row count, confidence score, and the context that produced the classification.

Controls are applied where the data lives

Masking, in-place anonymisation, or a synthetic export — the control runs inside your environment, and the output lands directly in staging or object storage.

The audit trail writes itself

What was found, what was changed, who approved it, and when — recorded in a hash-chained log as the work happens.

Watch the whole workflow run against your data.