Data Flow Map
Knowing where sensitive data lives and how it moves is the groundwork for a sound risk analysis. The Data Flow Map keeps two linked inventories: the systems and data assets that hold sensitive data, and the flows that move data between them.
The Data Flow Map is included in Premium and Enterprise, and it works
during the demo too. Exporting it comes with a plan.
This module is being reworked for AI governance, toward the lineage of the
data your AI systems use; until then it works as described below.
Data assets
An asset is a system or platform that stores or processes data. Each records its type (training data store, feature store, model endpoint, SaaS AI tool, database, file storage, messaging or collaboration, device, or Other for anything that does not fit), a data classification (personal / sensitive, de-identified, administrative, or public; a new asset starts at administrative, so choose personal / sensitive when it holds personal data), the personal data elements it stores or processes (name, date of birth, address, phone, email, government ID, financial, biometric, or other), an optional data custodian, and a retention period in days.
Data flows
A flow documents data moving from one place to another. Give it a label, a source and destination (pick from your assets or type a free-text endpoint), and a flow type (internal, external, third party, cloud, API, or manual). Flags record whether personal or sensitive data is transmitted and whether it is encrypted in transit and at rest. The page counts unencrypted sensitive flows so you can see exposure at a glance.
Who can do what
Org admins add and edit assets and flows. Contributors view them read-only. Read-only auditor accounts are refused this register entirely, on the page and on the CSV export alike: the map names where sensitive data lives and moves, and data flows are not one of the scopes an auditor link can grant. There are no due dates or recurrence here. The map is a living inventory you update as systems change.