ethira

FAQ

Questions teams ask before a demo.

Practical answers for security, legal, and GRC evaluating Ethira as ICT governance. If something is not specific enough, get a demo on your estate.

Risk assessment and configuration

Can we run multiple parallel assessment tracks?

Yes. Security DDQ, DPIA, transfer impact, and AI impact can run as separate tracks on the same vendor or system, with different owners on each gate.

Can different people own different gates?

Yes. Ownership is a node on the graph. Legal, security, and GRC can own different steps without keeping parallel registers.

How configurable is the risk rubric?

Write what you care about in plain language as Custom Findings. Ethira evaluates those rules against the live graph so the rubric stays current as the estate changes.

If we update a playbook later, can we re-assess existing vendors?

Yes. Automations and evaluations re-run against current inventory. A playbook change becomes a new pass over the same graph, not a new spreadsheet project.

What does the agent fetch during onboarding?

Public and connected sources that fill corporate profile, certificates, subprocessors, and contract clues. A human still reviews. The agent does not replace your judgement.

Vendors, products, and subprocessors

How does Ethira handle vendors with multiple products?

A legal entity and the services it actually runs are separate nodes. Google with ten tools is not one row. Each service keeps its own reach, owners, and evidence.

Can we remove subprocessors we have contractually excluded?

Yes. You can mark exclusions. The graph still shows what discovery observes, so a contractual exclusion and live use cannot silently diverge.

What about open source and embedded components?

They sit on the graph as assets when discovery sees them in code, packages, or runtime, even when there is no classic vendor record.

AI, MCP, agents, and shadow IT

Do you cover AI tools, MCPs, and agents inside our environment?

Yes. Browser extension, workstation agent, OSINT, and GitHub feed the same ICT graph as vendors and systems. AI governance is ICT governance plus those assets.

How do you detect shadow IT and shadow AI?

From use, not from a register: browser activity, local runtimes, public footprint, and repositories, correlated continuously.

If a subprocessor reports an incident, can we find every system that uses them?

Impact analysis walks the graph from the third party through services and stores to the datasets and fields they can reach. Observation, not request-path blocking.

Operations

How does offboarding work?

Offboarding is a run on the graph: owners, access, evidence, and downstream systems that still depend on the vendor. The record stays as history, not a deleted row.

Can we maintain a do-not-reassess list?

Yes. You can mark vendors you have already declined so they do not re-enter the onboarding cadence unless discovery shows a material change.

Can Ethira flag redundant tools?

Overlap is visible when several services reach the same function or data class. That is a finding with owners, not an automatic block.

Integrations, data, and access

Do we have to use the Ethira UI?

No. Slack, APIs, and GRC tools (Vanta, Drata, OneTrust) can carry findings and evidence. The graph remains the system of record.

Where does our data live?

Platform processing is contracted for EU residency or appropriate safeguards. See the Privacy policy and, for the hosted product, the DPA.

Can we pull our data out via API or MCP?

Yes. Export and API access are part of the platform agreement. The marketing site does not host your workspace data.

Anything not covered here? We will walk through your environment, including a workspace pre-loaded with your playbooks.