Skip to content

Product

The Privacy Graph.

Anchor reviews, findings, drift, and evidence to the workloads they belong to.

Follow a workload from discovery to review.

Group related resources into workloads, then keep each workload’s reviews, findings, and changes together.

orders-service privacy workflow

  1. 1InventoryWorkloads, resources, data stores, and integrations
  2. 2ReviewScan results and answers from the workload team
  3. 3FindingsRisks and obligations tied to specific systems
  4. 4DriftInfrastructure changes compared against reviewed state
  5. 5DocumentsRoPAs, DPIAs, LIAs, and TIAs
1

Map resources to workloads

Truspecta scans cloud resources and groups related infrastructure into workloads.

  • Record the resources in each workload.
  • Visualize data flows and integrations.
  • Collect resource details from cloud scans.
A workload, mappedExample

orders-service

Workload boundary
  1. API Gateway

    /orders/v1

    Receives requests
    Invokes
  2. Lambda

    order-processor

    Processes orders

Branches to

DynamoDB

tbl-orders-prod

Stores records

S3

orders-exports

Keeps exports

Resources and relationships give each privacy review a system boundary.

2

Start reviews with evidence

Privacy reviews start with cloud scan results. Your team supplies context such as purpose and lawful basis.

Provided by infrastructure

  • Resources
  • Data stores
  • Regions
  • Integrations
  • Data flows

Provided by your team

  • Purpose
  • Lawful basis
  • Data subjects

Infrastructure evidence and team context complete each review.

3

Remediate privacy risks and obligations

Each finding ties back to specific workloads and resources.

  • Assign findings to accountable owners.
  • Track remediation status across workloads.
A finding with contextExample

DynamoDB

tbl-orders-prod

orders-service
DynamoDB resource → linked finding
Medium riskOpen finding

Retention period missing

Customer data is stored without a configured retention policy.

Accountable owner
Orders team
Next action
Define retention policy

Trace the issue to a resource, then keep ownership and remediation together.

4

Monitor workload drift

Truspecta monitors infrastructure to identify privacy-impacting drift as systems change.

  1. Workload detected

    4 weeks ago

  2. Review completed

    3 weeks ago

  3. Retention policy changed

    6 days ago

  4. Drift detected

    Today

5

Draft documents from privacy reviews

Draft RoPAs and DPIAs from scan results and privacy reviews.

Record of Processing Activities

RoPA

Data Protection Impact Assessment

DPIA

Legitimate Interests Assessment

LIA

Transfer Impact Assessment

TIA

Drafted from orders-service infrastructure and its privacy review.

6

Your privacy program, at a glance

See which workloads need a review or have open findings.

orders-service

Review status

Current
Status
Attention needed
Drift
High
Findings
3 open

billing-api

Review status

Current
Status
On track
Drift
None
Findings
0 open

growth-tools

Review status

Missing
Status
Needs review
Drift
Medium
Findings
6 open

Frequently asked questions

See your privacy program, workload by workload.

See which workloads need attention and the resources behind each finding.