Privado: Mapping the Secret Life of Your Data

How a graph-based static analysis engine turns "Privacy by Design" from a legal slogan into a verifiable build step.

7 min read • View on GitHub • More from Privado-Inc

A complex plumbing system made of glass pipes showing data packets flowing, with one leaking into an external bucket.
Privado treats personal data like a physical substance, tracing its flow from collection to destination to catch invisible leaks before they ship.
Key Takeaways

The Ghost in the Logs

The most dangerous privacy violations rarely look like malicious hacks. They look like a tired developer typing console.log(user) to debug a timing issue, inadvertently sending thousands of plaintext passwords and location coordinates to a third-party logging aggregator. Lawyers write comprehensive privacy policies, but code dictates reality. When the two drift apart, companies face massive fines and broken trust.

Privado bridges this gap by treating privacy as a data-flow problem. Instead of relying on manual questionnaires or surface-level keyword scans, it analyzes the actual source code to map exactly where Personally Identifiable Information (PII) enters an application and where it ultimately exits.

Tainting the Stream: How it Works

Traditional Static Application Security Testing (SAST) tools look for structural vulnerabilities like SQL injection or buffer overflows. Privado flips the model: it looks for data provenance. By building a Code Property Graph (CPG) using the Joern/Ocular framework, it transforms the codebase into a queryable map of data movement.

The engine identifies over 110 specific "Sources" (such as a GPS API call or an email input field) and tracks that data as it moves through variables, functions, and transformations. If a variable tagged as LOCATION_COORDINATES eventually touches a "Sink" (like a database, an external SDK, or an unencrypted file), Privado flags it. In security parlance, this is known as taint analysis, but applied specifically to privacy mandates.

A data flow explorer showing a 'Source' node (User Email field) connecting through a 'Transformation' node (hashing function) to three 'Sinks' (Database

From AST to Article 30

The brilliance of Privado lies in its outputs. A technical scan of an Abstract Syntax Tree (AST) is useful for engineers, but Privado translates these findings into the language of compliance. It automatically generates the Records of Processing Activities (RoPA) required by GDPR Article 30, proving exactly what user data is processed and why.

Furthermore, it maps these code-level flows directly to the specific categories required for Google Play Store "Data Safety" labels and Apple App Store Privacy Manifests. When a developer adds a new analytics SDK, the build fails if the privacy label isn't updated to match the new code reality.

"Mental healthcare is one of the domains where privacy is super important for everybody, including our patients, user members, and clinicians and coaches. Everybody in the company is highly aware and sensitive about preserving privacy."

— Puneet Thapliyal, CISO, Headspace Health. Source

Privacy Without the Upload

The paradox of cloud-based security tools is that you often have to upload your most sensitive asset—your source code—to a third party to verify it's secure. Privado elegantly sidesteps this "SaaS trust" issue with a local-first architecture.

The core scanning engine runs entirely locally via Docker. The heavy lifting of building the Code Property Graph and executing the YAML-based rules engine happens on the developer's machine or within the internal CI/CD runner. Only the resulting JSON metadata—the abstract map of the data flows, devoid of proprietary code logic—is synced to the cloud for reporting and visualization.

Split screen showing a lawyer buried in paperwork versus a clean terminal window with a passing scan.
Replacing point-in-time manual privacy questionnaires with continuous, code-driven verification.
Tool Type Primary Focus Depth Deployment
Privado Data Flow & Privacy Code-level CPG Local CLI / Docker
Traditional SAST (e.g., Semgrep) Vulnerabilities (Injection) AST / Regex Various
Privacy Management (e.g., OneTrust) Legal Compliance Questionnaires SaaS Cloud

By bringing privacy engineering into the IDE and the pull request, Privado ensures that compliance is no longer a post-release audit, but an inherent property of the software delivery lifecycle.


Sources: Privado GitHub Repository; Headspace Health Case Study.