Skip to main content
Code auditCheck every pull request for privacy riskWebsite auditCatch scripts and vendors that appear in productionInth AgentAsk what changed and follow the answer to its sourceCookie consentFast consent that lives in your codebase
AboutHandbookBlogOSS
AI feature reviewsFundraising Due DiligencePrivacy impact reviewsEnterprise customer reviewsCookie and tracking audits
Pricing
Sign inRun a free scan
Run a free scan

Detect privacy risks on your site

Monitor your site for third-party scripts, cookies, and destinations. Find vendors introduced outside pull requests or dashboards, and catch mismatches between production behavior and your privacy controls.

Scan your siteTalk to us
All audits - Inth
Audit

All audits

inth/dashboardCompleted
Full audit·Entire repository · mainToday, 14:08

6 findings

inth.comCompleted
Web audit·marketing-siteToday, 12:42

3 vendors

inth/checkoutFailed
PR audit·Pull request · feature/checkoutToday, 10:17

Scan failed

All audits - Inth
INInthPro
Search⌘ K

Products

Inbox
Agent
Audit
OverviewAll auditsCode auditsWebsitesVendorsCookies
Consent
Billing
Settings
Getting started
Help
AMAlex Morgan

Audit

All audits

Search auditsAll statuses
AuditTypeStatusOutcomeStarted
inth/dashboardEntire repository · mainFull auditCompleted6 findingsToday, 14:08View audit
inth.commarketing-siteWeb auditCompleted3 vendorsToday, 12:42View audit
inth/checkoutPull request · feature/checkoutPR auditFailedScan failedToday, 10:17View audit
app.inth.comdashboardWeb auditCompletedNo changesYesterday, 18:31View audit
inth/apiBranch · mainFull auditCompleted2 findingsYesterday, 16:04View audit

5 audits

Code review alone cannot see everything reaching production

Inth reviews your website for what users receive and compares behavior with your consent, policy and vendor records.

  1. 01

    Observe production

    Capture scripts, requests, vendors, domains, storage, and consent signals.

  2. 02

    Compare the rules

    Check what loaded against region, consent state, vendor record, and policy.

  3. 03

    Open the review

    Create a reviewable signal with the page, request, timing, and mismatch attached.

02 / Capabilities

Catch what code review and vendor dashboards miss

Runtime monitoring catches changes that are not visible in a pull request or vendor dashboard.

  • 01 / Capability

    Script and domain monitoring

    See third-party scripts and destinations as soon as they appear.

  • 02 / Capability

    Vendor discovery

    Connect observed domains to vendor records and ownership.

  • 03 / Capability

    Consent enforcement

    Verify categories and vendors stay blocked until allowed.

  • 04 / Capability

    Policy drift alerts

    Surface when production stops matching controls and disclosures.

03 / Evidence

Prove what the product did, not what it was meant to do

Each signal preserves enough runtime context to reproduce the issue and verify the fix.

Runtime
Page, script, request, domain, and observation time
Consent
Visitor region, category, and consent state
Evidence
Observed behavior, review history, and resolution

Run a free scan and find your privacy gaps

Find the change, get it reviewed and keep the decision with the code of production event that caused it.

Run a free scanTalk to us
Inbox - Inth
Inbox

Open

9 items

Reviewing evidence
  • PII in request logs

    4m

    api-gateway forwards email addresses to the logging vendor.

    P0Code scan·Project finding
  • Script calls new domain

    22m

    cdn.thirdparty.io detected in production before consent.

    P1Website activity·Project finding
  • New tracker: pixel.js

    1h

    Marketing category script added without a vendor record.

    P1Website activity·Project finding
Inbox - Inth
INInthPro
Search⌘ K

Products

Inbox
OpenResolvedDismissedAccepted risk
Agent
Audit
Consent
Billing
Settings
Getting started
Help
AMAlex Morgan

Open

9 items

  • PII in request logs

    4m

    api-gateway forwards email addresses to the logging vendor.

    P0Code scan·Project finding
  • Script calls new domain

    22m

    cdn.thirdparty.io detected in production before consent.

    P1Website activity·Project finding
  • New tracker: pixel.js

    1h

    Marketing category script added without a vendor record.

    P1Website activity·Project finding
  • New SDK: analytics-node@4

    5h

    Adds a data flow to Segment. Policy v9 has no match.

    P2Code scan·Project finding
P0Code scan·Open

PII in request logs

Summary

The API gateway forwards email addresses to a logging vendor without an approved data flow.

Evidence

Open scan report →
src/logging/request.ts:42-44
42
43
44
logger.info({
  email: request.user.email,
});

Recommended action

Remove the email field or replace it with a non-identifying internal user ID.
Inbox item resolved

New agent

Privacy agent

Research privacy requirements and turn guidance into practical next steps.

Ask anything about privacy…
Research

Legal information grounded in curated guidance, not legal advice.

Notes from building privacy into the product

Notes from building Inth. Sent occasionally.

Inth connects what your company promised to what engineers just shipped.

Platform

  • Code audit
  • Website audit
  • Inth Agent
  • Consent banner
  • Pricing

Use Cases

  • Privacy Impact Review
  • AI Feature Reviews

Company

  • About
  • Blog
  • Open source
  • Contact

Resources

  • Documentation
  • GitHub
  • Cookiebench
  • Status

© 2026 Inth. All rights reserved.

  • Contact us
  • Privacy
  • Cookies
  • Terms