Read the source. Follow the data.
Every path a value takes, from the line that touches it to the store, log or sub-processor it reaches. Not a grep for field names.
One field, three destinations. The leak sits two lines after the lookup nobody would question. Clone the repo and read it.
Ordinary code from a well-run open-source project. That is the point: this is not a bad codebase, it is a normal one.
Everything you ship, not just the application code.
12 languages, parsed to a syntax tree. Values are followed across functions and files. The analysis knows a variable, not a word.
11 IaC formats (Terraform, Kubernetes, Dockerfiles, pipelines), read as configuration rather than as text.
The full tree, with advisories resolved against the packages that actually sit on a regulated-data path.
Credentials, keys and tokens committed to the repository, including the ones inside build files and CI config.
270+ rules, one pass, one graph.
Every finding explains itself.
Why it matters, the exact path the data took, and the change to make, all on one screen, so nobody has to go and interpret a rule id.
Grouped by what they break, not by file.
A list of 69 findings is a backlog. The same 69 grouped by the obligation they touch is a plan, and the severity mix tells you whether to start today or this quarter.
You decide once what counts as personal data.
Every scanner guesses at what is personal data, and every scanner gets some of it wrong. The difference is what happens next: one decision here updates the data flow, the RoPA, the blast radius and the findings at once, rather than being re-litigated on every screen, every scan.
Confirmed or rejected, the decision is yours and it sticks. The scanner proposes; it does not overrule you.
Point it at a repository.
A public repository, read once and not kept. You get the data map: every personal-data field, where it lands, and who receives it. Or run the container on your own runner, and the source never reaches us.


