Discover dataflow mapping from your codebase.

Every personal-data field, followed from the line that touches it to the log, store or third party it reaches. Read out of the repository, not out of a workshop.

01 · Every field, one view

Every field your code touches, mapped to where it lands.

TRACKED DATAWHERE IT GOESaccountNumberpasswordemail_addressdate_of_birthip_addressaccessTokennational_idpostal_codeApplication logplaintext · 2 fieldsDatabase storeno encryption asserted · 3 fieldsEncrypted storesealed · 1 fieldAt restdeclared · 2 fields

Inside the product the same view is live: hover a node to trace its flows, click a sink to land on the file and line.

02 · Why the spreadsheet fails

A map drawn by hand is out of date the day it is signed.

IT IS AN INTERVIEW, NOT A MEASUREMENT

Someone asks the team where the data goes. The team answers from memory, about the parts they wrote, as of the last time they looked.

IT AGES ON EVERY MERGE

The map is a document. The system is not. Every release moves them further apart and nothing tells you by how much.

IT CANNOT SEE THE ACCIDENTS

The paths that matter are the ones nobody would think to mention: a debug log, a retry payload, a vendor SDK doing its own collection.

03 · The shape of it109 TOUCHPOINTS TO 20 NODES

Who enters data, what processes it, where it lands.

Code-level touchpoints are collapsed into the architecture they describe, so the map is small enough to reason about and every box still drills back to the line it came from.

scrutora · architecture view
Dataflow architecture view: who, enters at, processed by, lands in, across 15 subsystems.
Four columns, read left to right: who the data is about, where it enters, what touches it, and where it comes to rest.
04 · One field, drilled inACCOUNT_IDENTIFIER

Every location, every hop, every recipient.

Go granular: see the details of a dataflow at the field level.

scrutora · account_identifier
ONLINE_IDENTIFIERaccount_identifierSensitivity: medium · 10 locations
GDPRDPDPACCPALGPDPIPEDA
Collection
Logging
Sharing
Application
10 locations
Application log
…/businessstep/…:63
Application log
…/businessstep/…:57
Application log
…/loan/…:98
Application log
+3 more call sites
Vector store
embeddings
Personal data in a vector database is hard to erase

Data flows to different stores. Can you fulfil a deletion request if you did not know the data was flowing to an embedding store?

05 · Where you correct itADD CUSTOM COMPONENTS

Dataflow Designer

Start from what the scan found. Add the systems it could not see: vendors, internal services, anything outside the repository, directly on the canvas.

Anything you add by hand, including the vendors and COTS systems that were never in the repository, flows into the Record of Processing with everything the scan found.

scrutora · dataflow designer
The dataflow designer canvas: data elements traced to processing, storage and external recipients such as Segment, Sentry and a vector database.
06 · Try itPUBLIC REPOSITORIES

Discover your dataflow.

Scan a public repository. We do not store your code: we process it to generate the findings, then discard it. We will give you this in writing.

Want to run it locally in your IDE? Check out our integrations.