Skip to main content
Code auditCheck every pull request for privacy riskWebsite auditCatch scripts and vendors that appear in productionInth AgentAsk what changed and follow the answer to its sourceCookie consentFast consent that lives in your codebase
AboutHandbookBlogOSS
AI feature reviewsFundraising Due DiligencePrivacy impact reviewsEnterprise customer reviewsCookie and tracking audits
Pricing
Sign inRun a free scan
Run a free scan

Cite real privacy laws in agent

Make privacy decisions with cited evidence for product change

Inth's Agent combines product evidence with cited from real privacy laws. Legal, security and product teams can inspect the same answer without losing the human decision.

Run a free scanTalk to us
Inth Agent - Inth
Agent

What changed in checkout this week?

Research complete4 sources

Two privacy-impacting changes shipped since Monday.

  1. analytics-node@4 added to checkout-service Opens a new data flow to Segment. Flagged for review.

Sources2

PR #482

Product evidence

scan-1042

Product evidence

Ask about your product…

Legal information grounded in curated regulations and guidance, not legal advice. Always confirm with a qualified lawyer.

Inth Agent - Inth
InthPro
Search⌘ K
Inbox

Products

Agent
Checkout changesPolicy coverage
Audit
Consent

Organisation

Billing
Settings
Onboarding
Help
Alex Morgan
New chat

What changed in checkout this week?

Research complete4 sources

Two privacy-impacting changes shipped since Monday.

  1. analytics-node@4 added to checkout-service Opens a new data flow to Segment. Flagged for review.
  2. Marketing category added to the consent banner Approved by privacy on Tuesday. Policy still matches.

Sources4

PR #482

Product evidence

scan-1042

Product evidence

signal 88c1

Product evidence

policy v9

Product evidence

Does our privacy policy still cover the Segment flow?

Not yet. Policy v9 lists no analytics processor for checkout data. Legal review is queued, and the evidence pack is ready to attach.

Ask about your product…

Legal information grounded in curated regulations and guidance, not legal advice. Always confirm with a qualified lawyer.

01 / Workflow

Ask privacy questions and make informed moves with assurance

Inth answers from product records and shows the sources your teams need to review the answer.

  1. 01

    Ask in plain language

    Ask what changed, which vendor receives data, or what needs review.

  2. 02

    Ground every answer

    Connect the response to scans, signals, consent, policies, decisions, and cited law.

  3. 03

    Send the answer for review

    Send the answer to the person reviewing the change, fix or customer response.

02 / Capabilities

Align product context with privacy strategy

Answers stay tied to product evidence and show where human judgement is still required.

  • 01 / Capability

    Product-aware answers

    Answer from code, runtime, vendors, consent, and policy history.

  • 02 / Capability

    Evidence citations

    Link material claims to the record that supports them.

  • 03 / Capability

    Privacy law sources

    Bring cited legal sources into the answer while preserving legal judgment.

  • 04 / Capability

    Shared review context

    Give product, privacy, security, and legal the same evidence trail.

03 / Evidence

Answers that cite real privacy laws of every jurisdiction

The useful answer shows what changed, which evidence supports it, and where judgment is required.

Product
Scans, runtime signals, configuration, and review history
Sources
Policies, evidence records, and cited privacy law
Action
A review-ready answer another team can verify

Run a free scan and find your privacy gaps

Find the change, get it reviewed and keep the decision with the code of production event that caused it.

Run a free scanTalk to us
Inbox - Inth
Inbox

Open

9 items

Reviewing evidence
  • PII in request logs

    4m

    api-gateway forwards email addresses to the logging vendor.

    P0inth/api-gateway
  • Script calls new domain

    22m

    cdn.thirdparty.io detected in production before consent.

    P1Web audit
  • New tracker: pixel.js

    1h

    Marketing category script added without a vendor record.

    P1Web audit
Inbox - Inth
InthPro
Search⌘ K
Inbox
OpenResolvedDismissedAccepted risk

Products

Agent
Audit
Consent

Organisation

Billing
Settings
Onboarding
Help
Alex Morgan

Open

9 items

  • PII in request logs

    4m

    api-gateway forwards email addresses to the logging vendor.

    P0inth/api-gateway
  • Script calls new domain

    22m

    cdn.thirdparty.io detected in production before consent.

    P1Web audit
  • New tracker: pixel.js

    1h

    Marketing category script added without a vendor record.

    P1Web audit
  • New SDK: analytics-node@4

    5h

    Adds a data flow to Segment. Policy v9 has no match.

    P2inth/analytics
P0inth/api-gateway·Open·4m ago

PII in request logs

Recommended action

Remove the email field or replace it with a non-identifying internal user ID.

Evidence

Open scan report →
src/logging/request.ts:42-44
42
43
44
logger.info({
  email: request.user.email,
});

Technical summary

The API gateway forwards email addresses to a logging vendor without an approved data flow.

Inbox item resolved

New agent

Privacy agent

Research privacy requirements and turn guidance into practical next steps.

Ask anything about privacy…
Research

Legal information grounded in curated guidance, not legal advice.

Notes from building privacy into the product

Notes from building Inth. Sent occasionally.

Inth connects what your company promised to what engineers just shipped.

Platform

  • Code audit
  • Website audit
  • Inth Agent
  • Consent banner
  • Pricing

Use Cases

  • Privacy Impact Review
  • AI Feature Reviews

Company

  • About
  • Blog
  • Open source
  • Contact

Resources

  • Documentation
  • GitHub
  • Cookiebench
  • Status

© 2026 Inth. All rights reserved.

  • Contact us
  • Privacy
  • Cookies
  • Terms