Customer account records
- Customers
payments-api · customers.ts:48
SourcesORM entity with an email column.
Processing activities
Ethira reads your systems and your vendors’ contracts and DPAs, and proposes each processing activity with the file, line, or passage it came from. You decide what the register keeps.
No manifests to write. No pipeline changes.
Trusted by
The register
The processing activities report is the register. Each activity carries its controllers, processors, data subjects, personal data, purposes, legal basis, retention, and security measures. Filter by third party, data subject, or personal data category.
A codebase scan files what it finds as Discovered. Vendor onboarding fills processing from the contract and the DPA. You move a row to Active when the evidence holds.
Reports · Processing activities
Discovered
3Customer account records
payments-api · customers.ts:48
SourcesORM entity with an email column.
Product analytics
web · track.ts:12
SourcesThird-party analytics SDK on the page.
Support drafts
support-bot · reply.ts:86
SourcesLLM call that includes the ticket body.
Active
2Support ticket handling
Master DPA · clause 4.2
SourcesProcessor may engage the listed sub-processors.
Payroll administration
Employment DPA · section 3
Retired
1Legacy newsletter export
Inside and out
From the code you ship and the contracts you sign. The same record, filled from your systems and your vendors.
01
Ethira reads the code, finding processing in databases, trackers, third-party SDKs, and LLM calls.
02
When you onboard a vendor, Ethira reads their contracts and DPA and fills in the processing.
03
Every value cites the file and line in the code, or the contract passage it came from.
04
Nothing is maintained in the register without you. Ethira proposes the activity and attaches the evidence. You accept it, edit it, or leave it out.
A quick self-check
Take your most recently onboarded vendors and product releases. Are all of them in the register, with up-to-date processing activities?
A new tool appears, and you hear about it later.
Product ships a feature and forgets to tell you.
An existing vendor adds a sub-processor, or starts processing new data.
FAQ
Ethira checks the repository out in a locked sandbox and reads it there. The register receives a proposed activity and the file and line behind it, not a standing copy of the repository. You decide what stays. Suggestions on a vendor record only fill fields that are still empty.
The scan reads the repository as it is checked out. It is not tied to one language or framework. It looks for processing in schemas, endpoints, jobs, trackers, third-party SDKs, and model calls.
GitHub and GitLab, including a GitLab instance you run. Connect the organization, and Ethira scans the repositories you have already connected.
Yes. Load the register you already keep through the API, the Agent, or MCP. A later scan matches what it finds to those rows instead of filing a second copy. You still accept what stays.
International transfers sit on the activity. When processing is high risk, Ethira drafts a DPIA or a transfer impact assessment from your templates, using the controllers, processors, and processing already on the register.
Get started
Get a demo. Ethira reads the code and the contracts, cites every value, and leaves the decision with you.