Skip to main content
Code auditCheck every pull request for privacy riskWebsite auditCatch scripts and vendors that appear in productionInth AgentAsk what changed and follow the answer to its sourceCookie consentFast consent that lives in your codebase
AboutHandbookBlogOSS
AI feature reviewsFundraising Due DiligencePrivacy impact reviewsEnterprise customer reviewsCookie and tracking audits
Pricing
Sign inRun a free scan
Run a free scan

Cite real privacy laws in agent

Make privacy decisions with cited evidence for product change

Inth's Agent combines product evidence with cited from real privacy laws. Legal, security and product teams can inspect the same answer without losing the human decision.

Run a free scanTalk to us
Inth Agent - Inth
Agent

Inth Agent

What changed in checkout this week?

Two privacy-impacting changes shipped since Monday.

  • analytics-node@4 added to checkout-service

    Opens a new data flow to Segment. Flagged for review.

EvidencePR #482scan-1042
Ask about your product…
Research

Legal information grounded in curated regulations and guidance, not legal advice. Always confirm with a qualified lawyer.

Inth Agent - Inth
INInthPro
Search⌘ K

Products

Inbox
Agent
Checkout changesPolicy coverage
Audit
Consent
Billing
Settings
Getting started
Help
AMAlex Morgan

Inth Agent

What changed in checkout this week?

Two privacy-impacting changes shipped since Monday.

  • analytics-node@4 added to checkout-service

    Opens a new data flow to Segment. Flagged for review.

  • Marketing category added to the consent banner

    Approved by privacy on Tuesday. Policy still matches.

EvidencePR #482scan-1042signal 88c1policy v9

Does our privacy policy still cover the Segment flow?

Not yet. Policy v9 lists no analytics processor for checkout data. Legal review is queued, and the evidence pack is ready to attach.

Ask about your product…
Research

Legal information grounded in curated regulations and guidance, not legal advice. Always confirm with a qualified lawyer.

01 / Workflow

Ask privacy questions and make informed moves with assurance

Inth answers from product records and shows the sources your teams need to review the answer.

  1. 01

    Ask in plain language

    Ask what changed, which vendor receives data, or what needs review.

  2. 02

    Ground every answer

    Connect the response to scans, signals, consent, policies, decisions, and cited law.

  3. 03

    Send the answer for review

    Send the answer to the person reviewing the change, fix or customer response.

02 / Capabilities

Align product context with privacy strategy

Answers stay tied to product evidence and show where human judgement is still required.

  • 01 / Capability

    Product-aware answers

    Answer from code, runtime, vendors, consent, and policy history.

  • 02 / Capability

    Evidence citations

    Link material claims to the record that supports them.

  • 03 / Capability

    Privacy law sources

    Bring cited legal sources into the answer while preserving legal judgment.

  • 04 / Capability

    Shared review context

    Give product, privacy, security, and legal the same evidence trail.

03 / Evidence

Answers that cite real privacy laws of every jurisdiction

The useful answer shows what changed, which evidence supports it, and where judgment is required.

Product
Scans, runtime signals, configuration, and review history
Sources
Policies, evidence records, and cited privacy law
Action
A review-ready answer another team can verify

Run a free scan and find your privacy gaps

Find the change, get it reviewed and keep the decision with the code of production event that caused it.

Run a free scanTalk to us
Inbox - Inth
Inbox

Open

9 items

Reviewing evidence
  • PII in request logs

    4m

    api-gateway forwards email addresses to the logging vendor.

    P0Code scan·Project finding
  • Script calls new domain

    22m

    cdn.thirdparty.io detected in production before consent.

    P1Website activity·Project finding
  • New tracker: pixel.js

    1h

    Marketing category script added without a vendor record.

    P1Website activity·Project finding
Inbox - Inth
INInthPro
Search⌘ K

Products

Inbox
OpenResolvedDismissedAccepted risk
Agent
Audit
Consent
Billing
Settings
Getting started
Help
AMAlex Morgan

Open

9 items

  • PII in request logs

    4m

    api-gateway forwards email addresses to the logging vendor.

    P0Code scan·Project finding
  • Script calls new domain

    22m

    cdn.thirdparty.io detected in production before consent.

    P1Website activity·Project finding
  • New tracker: pixel.js

    1h

    Marketing category script added without a vendor record.

    P1Website activity·Project finding
  • New SDK: analytics-node@4

    5h

    Adds a data flow to Segment. Policy v9 has no match.

    P2Code scan·Project finding
P0Code scan·Open

PII in request logs

Summary

The API gateway forwards email addresses to a logging vendor without an approved data flow.

Evidence

Open scan report →
src/logging/request.ts:42-44
42
43
44
logger.info({
  email: request.user.email,
});

Recommended action

Remove the email field or replace it with a non-identifying internal user ID.
Inbox item resolved

New agent

Privacy agent

Research privacy requirements and turn guidance into practical next steps.

Ask anything about privacy…
Research

Legal information grounded in curated guidance, not legal advice.

Notes from building privacy into the product

Notes from building Inth. Sent occasionally.

Inth connects what your company promised to what engineers just shipped.

Platform

  • Code audit
  • Website audit
  • Inth Agent
  • Consent banner
  • Pricing

Use Cases

  • Privacy Impact Review
  • AI Feature Reviews

Company

  • About
  • Blog
  • Open source
  • Contact

Resources

  • Documentation
  • GitHub
  • Cookiebench
  • Status

© 2026 Inth. All rights reserved.

  • Contact us
  • Privacy
  • Cookies
  • Terms