Skip to main content
Code auditCheck every pull request for privacy riskWebsite auditCatch scripts and vendors that appear in productionInth AgentAsk what changed and follow the answer to its sourceCookie consentFast consent that lives in your codebase
AboutHandbookBlogOSS
AI feature reviewsFundraising Due DiligencePrivacy impact reviewsEnterprise customer reviewsCookie and tracking audits
Pricing
Sign inRun a free scan
Run a free scan

Pull request & codebase audits

Find privacy risks before they reach production

Privacy risks can live in every pull request and codebase change. Inth helps you catch them before they reach production, without leaving your existing review workflow.

Run a free scanTalk to us
All audits - Inth
Audit

All audits

inth/dashboardCompleted
Full audit·Entire repository · mainToday, 14:08

6 findings

inth.comCompleted
Web audit·marketing-siteToday, 12:42

3 vendors

inth/checkoutFailed
PR audit·Pull request · feature/checkoutToday, 10:17

Scan failed

All audits - Inth
INInthPro
Search⌘ K

Products

Inbox
Agent
Audit
OverviewAll auditsCode auditsWebsitesVendorsCookies
Consent
Billing
Settings
Getting started
Help
AMAlex Morgan

Audit

All audits

Search auditsAll statuses
AuditTypeStatusOutcomeStarted
inth/dashboardEntire repository · mainFull auditCompleted6 findingsToday, 14:08View audit
inth.commarketing-siteWeb auditCompleted3 vendorsToday, 12:42View audit
inth/checkoutPull request · feature/checkoutPR auditFailedScan failedToday, 10:17View audit
app.inth.comdashboardWeb auditCompletedNo changesYesterday, 18:31View audit
inth/apiBranch · mainFull auditCompleted2 findingsYesterday, 16:04View audit

5 audits

01 / Workflow

The pull request still has the context

The author, reason and technical detail are still present. Inth uses that context to explain what changed and which company promise it may affect.

  1. 01

    Observe the change

    Read additions and upgrades that create new collection, storage, sharing, tracking, or vendor behavior.

  2. 02

    Explain the impact

    Show the data involved, where it moves, which vendor receives it, and why the change needs review.

  3. 03

    Resolve in context

    Route the finding, propose a code fix when possible, and preserve the decision beside the change.

02 / Capabilities

Give engineering and compliance the same change

Developers see the finding with the code. Privacy, legal and compliance get the context they need in Inth.

  • 01 / Capability

    Data flow mapping

    Trace personal data from collection through processing, storage, and external destinations.

  • 02 / Capability

    Tracker and SDK detection

    Spot new analytics, advertising, identity, and vendor dependencies as they enter the product.

  • 03 / Capability

    Vendor call graph

    Connect outbound requests to the service, data category, consent state, and policy record they affect.

  • 04 / Capability

    Checks in CI

    Run privacy review in the delivery workflow before the change loses its technical context.

03 / Evidence

Every finding stays attached to the code that caused it

Each finding becomes a durable record of the source, review, fix and final decision.

Source
Commit, pull request, file, and data flow
Decision
Owner, status, rationale, and approval
Evidence
Fix history and the record that closed the finding

Run a free scan and find your privacy gaps

Find the change, get it reviewed and keep the decision with the code of production event that caused it.

Run a free scanTalk to us
Inbox - Inth
Inbox

Open

9 items

Reviewing evidence
  • PII in request logs

    4m

    api-gateway forwards email addresses to the logging vendor.

    P0Code scan·Project finding
  • Script calls new domain

    22m

    cdn.thirdparty.io detected in production before consent.

    P1Website activity·Project finding
  • New tracker: pixel.js

    1h

    Marketing category script added without a vendor record.

    P1Website activity·Project finding
Inbox - Inth
INInthPro
Search⌘ K

Products

Inbox
OpenResolvedDismissedAccepted risk
Agent
Audit
Consent
Billing
Settings
Getting started
Help
AMAlex Morgan

Open

9 items

  • PII in request logs

    4m

    api-gateway forwards email addresses to the logging vendor.

    P0Code scan·Project finding
  • Script calls new domain

    22m

    cdn.thirdparty.io detected in production before consent.

    P1Website activity·Project finding
  • New tracker: pixel.js

    1h

    Marketing category script added without a vendor record.

    P1Website activity·Project finding
  • New SDK: analytics-node@4

    5h

    Adds a data flow to Segment. Policy v9 has no match.

    P2Code scan·Project finding
P0Code scan·Open

PII in request logs

Summary

The API gateway forwards email addresses to a logging vendor without an approved data flow.

Evidence

Open scan report →
src/logging/request.ts:42-44
42
43
44
logger.info({
  email: request.user.email,
});

Recommended action

Remove the email field or replace it with a non-identifying internal user ID.
Inbox item resolved

New agent

Privacy agent

Research privacy requirements and turn guidance into practical next steps.

Ask anything about privacy…
Research

Legal information grounded in curated guidance, not legal advice.

Notes from building privacy into the product

Notes from building Inth. Sent occasionally.

Inth connects what your company promised to what engineers just shipped.

Platform

  • Code audit
  • Website audit
  • Inth Agent
  • Consent banner
  • Pricing

Use Cases

  • Privacy Impact Review
  • AI Feature Reviews

Company

  • About
  • Blog
  • Open source
  • Contact

Resources

  • Documentation
  • GitHub
  • Cookiebench
  • Status

© 2026 Inth. All rights reserved.

  • Contact us
  • Privacy
  • Cookies
  • Terms