PII in request logs
Summary
The API gateway forwards email addresses to a logging vendor without an approved data flow.
Evidence
Open scan report →43
44
logger.info({
email: request.user.email,
});Inth reviews your website for what users receive and compares behavior with your consent, policy and vendor records.
Capture scripts, requests, vendors, domains, storage, and consent signals.
Check what loaded against region, consent state, vendor record, and policy.
Create a reviewable signal with the page, request, timing, and mismatch attached.
Runtime monitoring catches changes that are not visible in a pull request or vendor dashboard.
See third-party scripts and destinations as soon as they appear.
Connect observed domains to vendor records and ownership.
Verify categories and vendors stay blocked until allowed.
Surface when production stops matching controls and disclosures.
Each signal preserves enough runtime context to reproduce the issue and verify the fix.