Not three tools. One graph, asked three ways.

Code, cloud and consent share a single model of your personal data. That is why the answers agree with each other, and why questions exist here that no single-purpose tool can ask.

CODE
Read the source

Values followed across functions and files, plus infrastructure definitions, dependencies and committed secrets.

See it →
CLOUD
Grade what you run

The account the data actually rests in, graded against the same clauses, with drift between snapshots.

See it →
CONSENT
Prove what was agreed

A banner, a hash-chained record, and the runtime check that tags did not fire before anyone agreed.

See it →
01 · The joinsTHE REASON FOR ONE GRAPH

Questions that need more than one module.

Consent coverage
The purposes you declared, checked against the personal data your code actually collects. Needs both halves; neither module could ask it alone.
Blast radius
The dependency graph crossed with the data graph, so a CVE is ranked by whether it can reach a person.
The evidence pack
One asset as of one date, joining the Record of Processing to the cloud position and the consent state.
02 · One decision, everywhere

Classify a field once.

Deciding whether a field counts as personal data is the input every other view depends on. Make that call once in the data dictionary and it updates the flow map, the RoPA, the blast radius and the findings at the same moment, with no re-scan. In separate tools it is a decision you make repeatedly and inconsistently.

03 · The shape of it

What the engine covers.

310+Rules
26Frameworks
12Languages
11IaC formats
3Cloud providers

The full coverage detail, including what we do not assess →