EVIDENT

Personal data discovery and mapping

Know where the personal data is.
Before somebody asks you.

EVIDENT reads your databases, your code and the APIs you expose, and tells you where personal data actually lives — with the evidence behind every answer. An afternoon, not a quarter.

The schema, with what each column holds
Reads your systems without writing to them. Self-hosted, so your data need never leave.

The question nobody in the building can answer

Somebody asks where the customer telephone numbers are held. Not which application — which tables, in which databases, reached by which code, and who else it is sent to. The honest answer is usually a fortnight of interviews and a spreadsheet that is out of date the day it is finished.

It is not that nobody knows. It is that the knowledge is in eleven people, six repositories and a schema that has outlived three of the developers who wrote it.

Try it now, on a project made for this

EVIDENT Find out what EVIDENT is worth in under 20 minutes

Try it now, on a project made for this

A working EVIDENT on Nébula Shop, a fictional shop invented so this platform has something honest to read: a table whose name does not match its class, references the database does not enforce, a customer record handed whole to a logger. Every screen, every menu, the real engine.

  • No registration and no account.
  • No personal data, and nothing to fill in.
  • No cookies and no sign-in.
  • No sales call, no commitment, nothing to cancel.
  • A fresh copy of the project each time you open it. What you do there reaches nobody else, and nothing you do can spoil it for the next visitor.

Open the demonstration

The session lasts 20 minutes and then the copy is deleted, along with everything in it. Nothing you do in it is kept and nothing about you is recorded.

Three surfaces EVIDENT reads, and most inventories read one.

A database holds personal data, the code writes some of it to a log, and an API hands it to somebody else. Answering only the first is how an inventory ends up wrong. These are the three surfaces this platform correlates rather than the only places data can be — object stores, queues, data lakes and backups hold it too, and they are outside what this reads today rather than outside the problem.

What you store

Reads the catalogue of PostgreSQL, SQL Server, MySQL, MariaDB, Oracle and SQLite, then reads the code that maps onto it — Entity Framework, Prisma, TypeORM, Sequelize, SQLAlchemy, Django, JPA — and matches the two. You get a field, the column behind it, and the sentence explaining why they were matched.

What you write down

Finds the log calls that hand a whole customer to a logger. It is a common real leak, no schema can see it, and a field in a log is kept for as long as the log is — which is almost never the retention your record of processing declares.

What you hand over

Reviews your OpenAPI descriptions and GraphQL schemas for the questions a security reviewer will ask: which operations require a caller to prove who they are, which personal data leaves through them, and what a caller can reach that no operation returns directly.

Ask any finding why it says that

This is the part that decides whether a report survives being read by somebody whose job is to disbelieve it: everything the assessment holds about one field, in the order it was reached. Below is a real one, from the demonstration project. In the product it is what opens when you press WHY on a row.

customers.email holds personal data, and the whole customer record reaches the application log.

High risk · Confidence 0.94 · Confirmed by a reviewer

WHY?

  1. Observed · database

    Column email of customers is text and is never null.

    Read from the catalogue of orders-db on 4 March 2026. Structure only — not one row was read.

  2. Observed · repository

    Property Email of Customer is declared string.

    src/Customer.cs line 4, at commit 4f2a9c1.

  3. Inferred · correlation

    That property maps to that column. Confidence 0.95.

    Rule DECLARED_COLUMN, ruleset 1.1.0: the mapping decorator names the column, so this is a declaration rather than a guess about a name.

  4. Observed · code

    Logger.LogInformation("Checkout for {@Customer}", customer)

    src/Orders/CheckoutService.cs line 118. The whole entity is passed, so every field on it reaches the log — including this one.

  5. Decided · a person

    Confirmed on 12 March 2026.

    "The decorator names the column and the log call is real. Retention on this log is 400 days, which is not what our record of processing says."

Nothing on that path has been flattened into a generated summary. The observations come from the source, the inferences name the rule that reached them, and a human decision is shown as a human decision — which is why a reviewer can challenge a specific assumption instead of guessing what the tool never checked.

It tells you what it could not see

Every tool in this category produces findings. What many of them do not produce is the other half: the list of things they never checked. A report that does not say so is a report a reader assumes is complete.

EVIDENT states its limits in the document, at full size, under their own heading. Whether a token is really validated. Whether authorisation is enforced per record. Whether there is any rate limit at all. A reviewer can then challenge a specific assumption instead of guessing what the tool never checked.

Every finding carries the evidence behind it, in the words of the ecosystem it came from.
Every finding carries the evidence behind it, in the words of the ecosystem it came from.

What you actually get

Screens from a real analysis of the demonstration project that ships with it.

The schema, with what each column holds
The schema, with what each column holds — The same model drawn as a diagram, every table open. The dot on a column says how sensitive it looks; press it and the panel gives the legal category, the rule that proposed it and the article it rests on.
The documents somebody is waiting for
The documents somebody is waiting for — The Article 30 record, the risk register, coverage and gaps, logging exposure, interface security, referential integrity. Built once, kept, rebuilt on demand, and exported in the format the reader expects.
The queue of what still needs a person
The queue of what still needs a person — What the analysis could not settle on its own, ordered by what it costs to be wrong about. Decisions survive re-analysis, so a fortnight of review is not repeated when the schema moves.

Personal-data discovery is the first job. Continuous evidence is the system behind it.

EVIDENT keeps the evidence, the rule versions and the human decisions across runs, so what changed comes back for review instead of disappearing into a new spreadsheet. That is what a continuous evidence platform for data governance is, and finding the personal data is where it starts rather than where it ends.

Not another inventory you rebuild next year

The first assessment is the one everybody plans for. The second one decides whether the first was worth doing — because by then the schema has moved, four of the fields you settled are gone, and somebody has to say which of your decisions still hold.

  • AvailableRe-run it, and your decisions survive. A fortnight of review is not repeated because a migration ran. What a person confirmed stays confirmed, on the next run and the one after it.
  • AvailableWhat moved comes back, rather than being quietly kept. A decision whose mapping changed returns to the queue marked stale. Agreeing with yourself about a column that no longer exists is not agreement.
  • AvailableLast year’s report still resolves. Evidence is kept per run and nothing is overwritten, so a document exported in March still points at what it pointed at in March.
  • AvailableSee exactly what changed between two assessments. A summary sits under a report’s date — a table more, four fields, two findings raised, one resolved. Under the documents, the walk takes that summary apart: every subject that moved, what it no longer concludes, what it concludes now, and the rule that reached it. What did not move is counted rather than listed.
  • PreviewVerify that a remediation actually landed. A corrective action is recorded against a finding and nobody may declare it verified — only the next analysis can, and only where it looked. Available over the API and watched end to end on a running platform; the screen for it is not built.
  • AvailableRe-assess on a schedule, with nobody starting it. Continuous rather than annual. A project says when it expects to be assessed — weekly on a named day, every few days, or monthly on a day of the month — in its own timezone, and the scheduler claims the occurrence and runs it. Nobody presses anything.

Available is in the product today. Preview is built and reachable, and still changing shape. Planned is specified and not built — published in advance so it can be judged before it exists.

Priced on what it is measuring

A seat is the right meter for a team assessing their own systems, and the wrong one for an estate. Start on the trial; nothing is held back in it.

Free trial

Free

Every capability available today, one person, thirty days. It ends by itself and nothing is charged.

  • Every extension
  • 2 projects
  • 20 reports
  • Ends by itself
Start the trial

Professional

€790per workspace / month

Billed annually

A consultancy running assessments for several clients, or an organisation with an estate rather than a system. Everyone in the workspace, and the meter is the estate.

  • Everything in Team
  • OpenAPI & GraphQL analysis
  • Unlimited reports and people
  • Up to 50 systems / data sources
Talk to us

Enterprise

Annual contractpriced on the estate, not on seats

Where the deployment is the requirement. None of this becomes more valuable because a fourth person signs in, so none of it is sold that way.

  • Self-hosted or air-gapped
  • SSO, roles and an audit trail
  • Offline licence, no egress needed
  • Report exports and the HTTP API
Talk to us

The questions everybody asks

Does it write to my databases?

No, and not as a policy — as a design. It connects read-only, and every engine states what its read-only promise rests on. The SQLite engine opens the file read-only in the driver, so the promise is enforced rather than trusted.

Does my source code have to leave my network?

No. Run EVIDENT self-hosted and nothing leaves at all: it reads where you put it. On the hosted service a repository is read and analysed, and what is kept afterwards is the derived model rather than your source. Nothing is sent to an AI model in either case unless you switch that on and say what it may send.

What if my schema is a mess?

Then it is a normal schema. It handles a table whose name does not match its class, relationships the database never enforced, and rows pointing at records that were deleted. Broken references are reported as evidence and never repaired: this platform reads your database and does not write to it.

How long until the first result?

Minutes. Point it at a connection and a repository and it produces a correlation report on the first run. The demonstration project is already there if you would rather look before configuring anything.

What happens when the trial ends?

Everything you produced stays readable and exportable, for ever. You cannot start a new analysis or issue a new report until you have a licence. A governance platform that hid your evidence over an invoice would not deserve to hold it.

Can we run it on our own infrastructure?

Yes. Self-hosting is a first-class deployment mode: containers, a volume, and a licence that is a signed code you paste in and that is checked offline against a public key — so it works on a network with no route to the internet, which is where the systems worth assessing usually live.