Privado scans code repositories of your products, applications, and backend services to surface privacy information. Like SAST tools, Privado connects with source code management (SCM) tools like GitHub, GitLab, Bitbucket.
What is Privacy Code Scanning?
Privacy code scanning provides real-time visibility and governance for how personal data is collected, used, shared, and stored by continuously scanning the code that runs your websites, user-facing applications, and backend systems. The scanning approach is similar to SAST tools in that they both connect SCM and CI/CD tools to scan code repositories, but they scan code for different purposes. SAST tools look for security vulnerabilities, and privacy code scanning identifies personal data usage and privacy risks.
Per laws like GDPR and CPRA, personal data is defined as any data linked directly or indirectly to a user. This includes identifiers like PII (email, SSN, ad IDs), sensitive data (health data, biometric data, PCI data), and a broader set of personal data. Privado currently supports and identifies over 200 personal data elements.
The privacy code scanning platform has the following components:
Personal Data Identification: Identify and classify personal data processed by each application. Map each data element to all collection points including forms, API rest end points, and app permissions
Data Destination Discovery: Discover destinations or sinks of personal data including third parties (sharing), databases (storage), leakages (logs, SIEM), and internal APIs(services)
Data Flow Discovery: Discover flows of personal data across infrastructure, third parties, and microservices
Use Cases
For applications built by your company's developers, Privado automates privacy compliance reporting and discover risks such as excessive data sharing or leaks to logs. See the following key use cases of Privado:
Auto-Risk Discovery: Find and fix privacy risks identified in the code
Risk Prevention via CI/CD Integration: Integrate privacy code scanning into CI/CD (continuous integration / continuous deployment) dev tools