Personal data discovery and mapping
Know where the personal data is.
Before somebody asks you.
EVIDENT reads your databases, your code and the APIs you expose, and tells you where personal data actually lives — with the evidence behind every answer. An afternoon, not a quarter.
The question nobody in the building can answer
Somebody asks where the customer telephone numbers are held. Not which application — which tables, in which databases, reached by which code, and who else it is sent to. The honest answer is usually a fortnight of interviews and a spreadsheet that is out of date the day it is finished.
It is not that nobody knows. It is that the knowledge is in eleven people, six repositories and a schema that has outlived three of the developers who wrote it.
Try it now, on a project made for this
Find out what EVIDENT is worth in under 20 minutes
Try it now, on a project made for this
A working EVIDENT on Nébula Shop, a fictional shop invented so this platform has something honest to read: a table whose name does not match its class, references the database does not enforce, a customer record handed whole to a logger. Every screen, every menu, the real engine.
- No registration and no account.
- No personal data, and nothing to fill in.
- No cookies and no sign-in.
- No sales call, no commitment, nothing to cancel.
- A fresh copy of the project each time you open it. What you do there reaches nobody else, and nothing you do can spoil it for the next visitor.
The session lasts 20 minutes and then the copy is deleted, along with everything in it. Nothing you do in it is kept and nothing about you is recorded.
Three surfaces EVIDENT reads, and most inventories read one.
A database holds personal data, the code writes some of it to a log, and an API hands it to somebody else. Answering only the first is how an inventory ends up wrong. These are the three surfaces this platform correlates rather than the only places data can be — object stores, queues, data lakes and backups hold it too, and they are outside what this reads today rather than outside the problem.
What you store
Reads the catalogue of PostgreSQL, SQL Server, MySQL, MariaDB, Oracle and SQLite, then reads the code that maps onto it — Entity Framework, Prisma, TypeORM, Sequelize, SQLAlchemy, Django, JPA — and matches the two. You get a field, the column behind it, and the sentence explaining why they were matched.
What you write down
Finds the log calls that hand a whole customer to a logger. It is a common real leak, no schema can see it, and a field in a log is kept for as long as the log is — which is almost never the retention your record of processing declares.
What you hand over
Reviews your OpenAPI descriptions and GraphQL schemas for the questions a security reviewer will ask: which operations require a caller to prove who they are, which personal data leaves through them, and what a caller can reach that no operation returns directly.
Ask any finding why it says that
This is the part that decides whether a report survives being read by somebody whose job is to disbelieve it: everything the assessment holds about one field, in the order it was reached. Below is a real one, from the demonstration project. In the product it is what opens when you press WHY on a row.
customers.email holds personal data, and the whole customer record reaches the application log.
WHY?
Observed · database
Column email of customers is text and is never null.
Read from the catalogue of orders-db on 4 March 2026. Structure only — not one row was read.
Observed · repository
Property Email of Customer is declared string.
src/Customer.cs line 4, at commit 4f2a9c1.
Inferred · correlation
That property maps to that column. Confidence 0.95.
Rule DECLARED_COLUMN, ruleset 1.1.0: the mapping decorator names the column, so this is a declaration rather than a guess about a name.
Observed · code
Logger.LogInformation("Checkout for {@Customer}", customer)
src/Orders/CheckoutService.cs line 118. The whole entity is passed, so every field on it reaches the log — including this one.
Decided · a person
Confirmed on 12 March 2026.
"The decorator names the column and the log call is real. Retention on this log is 400 days, which is not what our record of processing says."
Nothing on that path has been flattened into a generated summary. The observations come from the source, the inferences name the rule that reached them, and a human decision is shown as a human decision — which is why a reviewer can challenge a specific assumption instead of guessing what the tool never checked.
It tells you what it could not see
Every tool in this category produces findings. What many of them do not produce is the other half: the list of things they never checked. A report that does not say so is a report a reader assumes is complete.
EVIDENT states its limits in the document, at full size, under their own heading. Whether a token is really validated. Whether authorisation is enforced per record. Whether there is any rate limit at all. A reviewer can then challenge a specific assumption instead of guessing what the tool never checked.
What you actually get
Screens from a real analysis of the demonstration project that ships with it.
Personal-data discovery is the first job. Continuous evidence is the system behind it.
EVIDENT keeps the evidence, the rule versions and the human decisions across runs, so what changed comes back for review instead of disappearing into a new spreadsheet. That is what a continuous evidence platform for data governance is, and finding the personal data is where it starts rather than where it ends.
Not another inventory you rebuild next year
The first assessment is the one everybody plans for. The second one decides whether the first was worth doing — because by then the schema has moved, four of the fields you settled are gone, and somebody has to say which of your decisions still hold.
- AvailableRe-run it, and your decisions survive. A fortnight of review is not repeated because a migration ran. What a person confirmed stays confirmed, on the next run and the one after it.
- AvailableWhat moved comes back, rather than being quietly kept. A decision whose mapping changed returns to the queue marked stale. Agreeing with yourself about a column that no longer exists is not agreement.
- AvailableLast year’s report still resolves. Evidence is kept per run and nothing is overwritten, so a document exported in March still points at what it pointed at in March.
- AvailableSee exactly what changed between two assessments. A summary sits under a report’s date — a table more, four fields, two findings raised, one resolved. Under the documents, the walk takes that summary apart: every subject that moved, what it no longer concludes, what it concludes now, and the rule that reached it. What did not move is counted rather than listed.
- PreviewVerify that a remediation actually landed. A corrective action is recorded against a finding and nobody may declare it verified — only the next analysis can, and only where it looked. Available over the API and watched end to end on a running platform; the screen for it is not built.
- AvailableRe-assess on a schedule, with nobody starting it. Continuous rather than annual. A project says when it expects to be assessed — weekly on a named day, every few days, or monthly on a day of the month — in its own timezone, and the scheduler claims the occurrence and runs it. Nobody presses anything.
Available is in the product today. Preview is built and reachable, and still changing shape. Planned is specified and not built — published in advance so it can be judged before it exists.
Priced on what it is measuring
A seat is the right meter for a team assessing their own systems, and the wrong one for an estate. Start on the trial; nothing is held back in it.
Free trial
Free
Every capability available today, one person, thirty days. It ends by itself and nothing is charged.
- Every extension
- 2 projects
- 20 reports
- Ends by itself
Team
€19per person / month
Billed annually
One team assessing systems they own. Priced per person, because that is what grows.
- Relational engines
- Application framework & ORM readers
- Logging analysis
- 10 projects · 10 people
Professional
€790per workspace / month
Billed annually
A consultancy running assessments for several clients, or an organisation with an estate rather than a system. Everyone in the workspace, and the meter is the estate.
- Everything in Team
- OpenAPI & GraphQL analysis
- Unlimited reports and people
- Up to 50 systems / data sources
Enterprise
Annual contractpriced on the estate, not on seats
Where the deployment is the requirement. None of this becomes more valuable because a fourth person signs in, so none of it is sold that way.
- Self-hosted or air-gapped
- SSO, roles and an audit trail
- Offline licence, no egress needed
- Report exports and the HTTP API
The questions everybody asks
Does it write to my databases?
No, and not as a policy — as a design. It connects read-only, and every engine states what its read-only promise rests on. The SQLite engine opens the file read-only in the driver, so the promise is enforced rather than trusted.
Does my source code have to leave my network?
No. Run EVIDENT self-hosted and nothing leaves at all: it reads where you put it. On the hosted service a repository is read and analysed, and what is kept afterwards is the derived model rather than your source. Nothing is sent to an AI model in either case unless you switch that on and say what it may send.
What if my schema is a mess?
Then it is a normal schema. It handles a table whose name does not match its class, relationships the database never enforced, and rows pointing at records that were deleted. Broken references are reported as evidence and never repaired: this platform reads your database and does not write to it.
How long until the first result?
Minutes. Point it at a connection and a repository and it produces a correlation report on the first run. The demonstration project is already there if you would rather look before configuring anything.
What happens when the trial ends?
Everything you produced stays readable and exportable, for ever. You cannot start a new analysis or issue a new report until you have a licence. A governance platform that hid your evidence over an invoice would not deserve to hold it.
Can we run it on our own infrastructure?
Yes. Self-hosting is a first-class deployment mode: containers, a volume, and a licence that is a signed code you paste in and that is checked offline against a public key — so it works on a network with no route to the internet, which is where the systems worth assessing usually live.