Privado: Mapping the Secret Life of Your Data
How a graph-based static analysis engine turns "Privacy by Design" from a legal slogan into a verifiable build step.
- Privado uses a Code Property Graph to map how sensitive data flows from API sources to external sinks.
- The engine automatically generates GDPR compliance reports and app store privacy labels directly from source code.
- A local-first architecture allows teams to scan for privacy leaks without uploading proprietary code to the cloud.
- The tool shifts privacy from manual legal questionnaires to a verifiable step in the CI/CD pipeline.
The Ghost in the Logs
The most dangerous privacy violations rarely look like malicious hacks. They look like a tired developer typing console.log(user) to debug a timing issue, inadvertently sending thousands of plaintext passwords and location coordinates to a third-party logging aggregator. Lawyers write comprehensive privacy policies, but code dictates reality. When the two drift apart, companies face massive fines and broken trust.
Privado bridges this gap by treating privacy as a data-flow problem. Instead of relying on manual questionnaires or surface-level keyword scans, it analyzes the actual source code to map exactly where Personally Identifiable Information (PII) enters an application and where it ultimately exits.
Tainting the Stream: How it Works
Traditional Static Application Security Testing (SAST) tools look for structural vulnerabilities like SQL injection or buffer overflows. Privado flips the model: it looks for data provenance. By building a Code Property Graph (CPG) using the Joern/Ocular framework, it transforms the codebase into a queryable map of data movement.
The engine identifies over 110 specific "Sources" (such as a GPS API call or an email input field) and tracks that data as it moves through variables, functions, and transformations. If a variable tagged as LOCATION_COORDINATES eventually touches a "Sink" (like a database, an external SDK, or an unencrypted file), Privado flags it. In security parlance, this is known as taint analysis, but applied specifically to privacy mandates.
From AST to Article 30
The brilliance of Privado lies in its outputs. A technical scan of an Abstract Syntax Tree (AST) is useful for engineers, but Privado translates these findings into the language of compliance. It automatically generates the Records of Processing Activities (RoPA) required by GDPR Article 30, proving exactly what user data is processed and why.
Furthermore, it maps these code-level flows directly to the specific categories required for Google Play Store "Data Safety" labels and Apple App Store Privacy Manifests. When a developer adds a new analytics SDK, the build fails if the privacy label isn't updated to match the new code reality.
"Mental healthcare is one of the domains where privacy is super important for everybody, including our patients, user members, and clinicians and coaches. Everybody in the company is highly aware and sensitive about preserving privacy."
Privacy Without the Upload
The paradox of cloud-based security tools is that you often have to upload your most sensitive asset—your source code—to a third party to verify it's secure. Privado elegantly sidesteps this "SaaS trust" issue with a local-first architecture.
The core scanning engine runs entirely locally via Docker. The heavy lifting of building the Code Property Graph and executing the YAML-based rules engine happens on the developer's machine or within the internal CI/CD runner. Only the resulting JSON metadata—the abstract map of the data flows, devoid of proprietary code logic—is synced to the cloud for reporting and visualization.
| Tool Type | Primary Focus | Depth | Deployment |
|---|---|---|---|
| Privado | Data Flow & Privacy | Code-level CPG | Local CLI / Docker |
| Traditional SAST (e.g., Semgrep) | Vulnerabilities (Injection) | AST / Regex | Various |
| Privacy Management (e.g., OneTrust) | Legal Compliance | Questionnaires | SaaS Cloud |
By bringing privacy engineering into the IDE and the pull request, Privado ensures that compliance is no longer a post-release audit, but an inherent property of the software delivery lifecycle.
Sources: Privado GitHub Repository; Headspace Health Case Study.