AI governance and data posture management

Know and govern your entire AI footprint and the data it touches

Get an always-current inventory of every AI system, the data it uses, and where that data goes, so you can secure, govern, and comply without chasing teams for answers in an endless loop.

Use cases13Models408Agents7MCP30Vendors3
high risk
3 of 13
sensitive data
77%
registered
38%
ucKYC identity verificationaccounting · 3 models · 1 vendorGovernment IDFace scan+2new
ucWorkspace knowledge assistantemail, api keys, +1 data typesEmailAPI keys+1classified
ucCustomer support assistantsupport · reads tickets and order historyOrder historyAddress+3unregistered
ucCode review AI assistantengineering · reads system promptsSecretsAccess tokenshigh risk
ucRefund agentowner: Nishant ShahBank accountOrder history+4assigned
A new AI use case shows up the day it ships, not at audit time.
The data types it touches are listed on the same row.
Use cases nobody registered are flagged for review.
Risk comes from the data it reads and what it can do.
Every use case gets an owner and a department.
third party
93.6%
sensitive data
4.7%
unregistered
18
mdlclaude-sonnet-4-5anthropic · globalEmailFull name+5unregistered
mdlgpt-4oopenai · united statesChat logsregistered
mdlclaude-3.5-sonnet-v2aws bedrock · ap-southeast-1Card numberAddress+2registered
mdlclaude-haiku-4-5anthropic · global · customer dataEmailPhone+3unregistered
mdlgemini-2.5-provertex ai · europe-west4Location+1new
Models called straight from code are found even when nobody filed them.
Each model is listed with its provider and where it processes data.
Cloud-hosted models are tied to the account that runs them.
A model that reads sensitive data without review is flagged.
A new model shows up the day the first request is made.
autonomous uses
4
sends data out
3
registered
2 of 7
agtRefund agentlangchain · 11 toolsBank accountOrder history+6unregistered
agtWorkspace agentvertex ai · read onlyDocumentsregistered
agtBFP geniesnowflake cortex · first seen todayBank accountSalary+2new
agtPatient intake agentreads EHR records · sends referralsHealth recordsDate of birth+3autonomous
agtUser feedback agentowner: Jessica PateEmailFeedbackassigned
Each agent is found in the repo with the framework it runs on.
Its tools are sorted into what it reads, changes, and sends.
Agents built on data platforms are picked up too.
An agent that acts without a person in the loop is marked for review.
Each agent has an owner who signs off on how it is used.
tools exposed
214
write access
11
registered
21 of 30
mcpcrm-mcp14 tools · customers.writeEmailPhone+4write access
mcpgithub-mcp22 tools · read onlySource codeSecretsregistered
mcpjira-mcpfound in a developer configFull name+1new
mcpfilesystem-mcpreads the home directorySSH keysDocuments+2over-scoped
mcpslack-mcpowner: platform teamMessagesEmail+1assigned
MCP servers are listed with every tool they expose.
Read-only servers are cleared once and tracked for changes.
Servers wired up on a laptop are found through the config that loads them.
A server that can reach more than its job needs is flagged.
Each server has an owner and a record of which agents use it.
with customer data
2
unapproved
1
dpa on file
2 of 3
saasOpenAIapi.openai.com · customer emailEmailChat logs+2approved
saasHubSpot AIcustomers.email · no reviewEmailFull name+1unapproved
saasFullstorybehavioral data · eu → usSession replayIP address+3transfer
Every outside AI vendor is found in traffic, not in a questionnaire.
A vendor receiving customer data without approval is flagged.
Data leaving the region is caught with the transfer it needs.
Every decision above is driven by our
Discovery & classification
Agent blueprints
Policy engine

What you get

Know every AI system in production. Catch shadow AI.

Agents, models, RAG pipelines, and MCP servers inventoried by source and traffic, with the customer data each one touches. The answer exists before the board, auditor, or regulator asks.

Catch the risky path in the release, not the incident.

Every code merge is checked for new routes from untrusted input to a privileged tool or dataset. The finding points to the line of code that caused it.

Risk, drift, and policy violation monitoring continuously, not in a quarterly review.

New agents, tools, permissions, and vendors appear the day they ship. You review a diff and proactively manage risk without chasing spreadsheets or outdated documents.

CAPABILITIES

Discover AI. Classify data. Map lineage.

We scan your code, cloud, and traffic once. You get a list of every AI tool and where its data goes.

Inventoried from source

We find every AI tool by reading your code and watching real traffic. Nobody has to fill out a form.

Classified everywhere

We label sensitive data, like card numbers or health records, the same way everywhere it shows up.

Lineage across every data hop

We follow each piece of data from where it starts to every AI tool and vendor it reaches.

inventory · use casesrelyance · live
Each use case is listed with the models, agents, and data behind it, and whether anyone registered it.
13
use cases
77%
touch sensitive data
38%
registered
KYC identity verificationaccounting · 3 models · 1 vendorchecking…classified
Workspace knowledge assistantenablement · 2 models · 1 agentchecking…registered
Customer support assistantsupport · gpt-4o · orders.historychecking…unregistered
Code review AI assistantengineering · reads system promptschecking…high risk
8 unregistered · 10 touch sensitive datasynced from 6 sources
inventory · modelsrelyance · live
Every model in use is listed with its provider, where it runs, and whether anyone registered it.
408
models found
93.6%
third party
4.7%
touch sensitive data
claude-sonnet-4-5Anthropic · Globalchecking…unregistered
gpt-4oOpenAI · United Stateschecking…registered
claude-3.5-sonnet-v2AWS Bedrock · Singaporechecking…registered
claude-haiku-4-5Anthropic · Global · customer datachecking…unregistered
18 unregistered · 19 with sensitive data accesssynced from 6 accounts
inventory · agentsrelyance · live
Every agent is listed with its framework, its tools, and whether anyone registered it.
7
agents found
4
autonomous uses
3
send data out
Refund agentLangChain · 11 toolschecking…unregistered
Workspace agentVertex AI · read onlychecking…registered
Patient intake agentreads EHR records · sends referralschecking…autonomous
User feedback agentowner: Jessica Patechecking…registered
5 unregistered · 3 send data outfound in 4 repos
inventory · mcp serversrelyance · live
Every MCP server is listed with the tools it exposes, what they can write, and whether anyone registered it.
30
servers found
214
tools exposed
11
can write
crm-mcp14 tools · customers.writechecking…write access
github-mcp22 tools · read onlychecking…registered
jira-mcpfound in a developer configchecking…new
filesystem-mcpreads the home directorychecking…over-scoped
9 unregistered · 11 can writefound in 12 configs
inventory · vendorsrelyance · live
Every outside AI vendor is found in traffic and listed with the data it receives and the paperwork on file.
3
AI vendors
2
receive customer data
2 of 3
DPA on file
OpenAIapi.openai.com · customer emailchecking…approved
HubSpot AIapi.hubspot.com · customers.emailchecking…unapproved
Fullstorybehavioral data · EU → USchecking…transfer
1 unapproved · 1 transfer needs SCCsfound in live traffic
review · customer support assistantrelyance · live
Each thing the use case does is listed with how much it acts on its own. Governance signs off per use.
Governance statusunregisteredregistered
Answer order questionsreads order history and ticketsassistiveneeds reviewapproved
Issue refundswrites to billingautonomousneeds reviewadd approval
Escalate to a personhands the ticket to an agentassistiveneeds reviewapproved
Refunds run without a person. Refunds over $200 get an approval step before the use case is registered.
Your policy · plain English
“Customer support AI must never send card numbers to a model outside the US.”
Customer support assistantcard data → gpt-4o1 match · flagged
Registered with 1 condition · @support-engevidence #uc-0413
review · claude-haiku-4-5relyance · live
Each caller is listed with the data it sends and how much it runs on its own. Governance signs off per use.
Governance statusunregisteredregistered
Ticket summariessupport · customer emailassistiveneeds reviewapproved
Code review commentsengineering · source codeassistiveneeds reviewapproved
Bulk customer exportsends 18k rows per runautonomousneeds reviewlimit fields
One caller sends full customer rows. It is limited to the fields it needs before the model is registered.
Your policy · plain English
“No model may process EU customer data outside the EU.”
claude-3.5-sonnet-v2ap-southeast-11 match · flagged
Registered with 1 condition · @ml-platformevidence #mdl-0408
capabilities context · claims processing agentrelyance · live
Each thing the agent does is listed with how much it acts on its own. Governance signs off per use.
Governance statusunregisteredregistered
Weekly claim narrativeswrites to the database and telemetry logautonomousneeds reviewadd approval
Claim status Q&Areads claims, notes, and claimant profilesassistiveneeds reviewapproved
Claimant email updatessends email with claim detailsautonomousneeds reviewadd approval
Two uses act without a person. Each gets an approval step before the agent is registered.
Your policy · plain English
“Any agent that can issue refunds needs a person to approve.”
Refund agentissue_refund · no approval1 match · flagged
Registered with 2 conditions · @claims-engevidence #ag-0916
review · filesystem-mcprelyance · live
Each tool is listed with what it touches and how much it acts on its own. Governance signs off per use.
Governance statusunregisteredregistered
Read source filescode review · ~/projectsassistiveneeds reviewapproved
Write patcheswrites to the working treeautonomousneeds reviewadd approval
Read home directoryincludes ~/.ssh and ~/.awsautonomousneeds reviewrescope
Two tools reach past the job. Writes get an approval step and reads are scoped to ~/projects before the server is registered.
Your policy · plain English
“MCP servers must not write to customer tables.”
crm-mcpcustomers.write1 match · flagged
Registered with 2 conditions · @dev-platformevidence #mcp-0030
review · hubspot airelyance · live
Each way the vendor is used is listed with the data it gets. Privacy and security sign off per use.
Vendor statusunapprovedapproved
Contact enrichmentsends customer email and nameautonomousneeds reviewneeds DPA
Lead scoringreads CRM fields onlyassistiveneeds reviewapproved
EU contact syncEU → US transferautonomousneeds reviewneeds SCCs
Two uses need paperwork first. A DPA and SCCs are signed before the vendor is approved.
Your policy · plain English
“Customer contact data only goes to vendors with a signed DPA.”
HubSpot AIemail and name · no DPA1 match · flagged
Approved with 2 conditions · @privacyevidence #vnd-0003

Automate AI governance and data posture management.

Posture becomes a check that runs on every merge, with the customer commitment it protects.

Risks flagged continuously with remediation attached

Relyance watches every AI system all the time and flags a new risk the moment it appears, with the rule it breaks.

Your policies and controls, in plain English

Write a rule the way you would say it. Relyance turns it into a check and monitors every AI system for it.

Evidence, not policy text

Audit-ready records are generated on demand, each with commit and owner attached.

Fix risky flows. Remove unsafe access.

We check what each AI actually does with its access, not just what it is allowed to do.

See who used what data

Every time sensitive data is read or changed, you see which person or AI did it and why.

Remove access nobody needs

We find shared or unused passwords and keys, show how they are used, and suggest a fix you can approve.

Break risky combinations

Some risks only appear when two things combine, like reading customer data and sending email. We cut the link so the risk goes away and the app keeps working.

use case map · customer support assistantrelyance · live
Each use case is mapped to what starts it, what it reads, what it can change, and where its output goes.
Customer support assistant
use case · support · gpt-4o
Triggers1
zendesk.ticket.created
Knowledge2
orders.history
customers.profile
Capabilities2
issue_refund
update_ticket
Outputs2
reply_to_customer
api.openai.com
Order history leaves for an outside model. Names and addresses go to the model provider unmasked. Mask them or route to an approved model.
1 model · 1 agent · 1 vendorowner @support-eng
model map · claude-haiku-4-5relyance · live
Each model is mapped to the use cases that call it, the data they send, the keys they use, and where it processes.
claude-haiku-4-5
model · anthropic · third party
Called by2
Customer support assistant
Code review AI assistant
Data sent2
customers.email
orders.history
Credentials1
shared api key · 3 services
Processes in2
Global
EU data · no region pin
EU customer data is processed outside the EU. Pin the model to an EU region or route EU traffic to an approved endpoint.
2 use cases · 1 shared keyanthropic::claude-haiku-4-5
agent map · claims processing agentrelyance · live
Each agent is mapped to what starts it, what it can read, what it can change, and where its output goes.
Refund Agent
first party · langchain · claude-sonnet-4-5
Triggers1
POST /chat
Knowledge3
get_order
get_customer_profile
+4 more
Capabilities2
write_narrative
append_telemetry
Outputs2
post_on_slack_thread
send_email
Customer profiles can leave by email. The agent reads customer records and can send_email with no approval step. Remove send_email or add a review.
11 tools · 0 downstream agentsRelyance/boutique-v2
server map · filesystem-mcprelyance · live
Each server is mapped to the agents that use it, the tools it exposes, and the paths those tools can reach.
filesystem-mcp
mcp server · local · 8 tools
Used by2
Code review AI assistant
Workspace agent
Tools3
read_file
write_file
+6 more
Scope1
~/ (home directory)
Reaches2
~/projects
~/.aws/credentials
The server can read cloud credentials. Scope it to the project folder. The agents that use it only need source files.
2 agents · 8 tools.cursor/mcp.json
vendor map · hubspot airelyance · live
Each vendor is mapped to the services that send to it, the data it gets, the contract behind it, and where the data lands.
HubSpot AI
vendor · api.hubspot.com
Sent by1
sync.py · growth-eng
Data2
customers.email
customers.name
Contract1
no DPA on file
Lands in2
United States
EU customer records
Customer emails go to an unapproved vendor. No DPA covers this and EU records leave the region. Block the sync or finish vendor review.
1 service · 2 fieldssync.py:88 · @growth-eng
HOW IT WORKS

Six surfaces. One graph. Updated on every release.

Read-only connectors pull code structure, runtime metadata, and identity configuration — never payloads. The graph joins them so a finding carries the data, the identity, the path, and the owner together.

1
Code and CI: agents, prompts, tools, and the data they reference
2
Runtime traffic and model providers: what actually gets called
3
Data stores and cloud accounts: what is held, where, and how sensitive
4
Identities and permissions: who each agent really runs as
graph finding · payments-svc · 09:14:22
findingPII reaches an external LLM
pathcustomers.db → refund-agent → api.openai.com
dataemail, card_last4 ← classification: PII / PCI
identitysvc-refund-agent (inherits: billing-admin)
severityHIGH · toxic combination
violatesno-pii-to-external-llm
fixscope identity to refunds.write;
mask card_last4 before egress (PR #412 drafted)
evidencecommit 3f9c2a1 · owner @payments-team
Deployment options
How it connects

Read-only connectors for Git, CI, cloud accounts, warehouses, model providers, and identity providers. Nothing is installed in your data path.

What it reads

Code structure, runtime metadata, and configuration. Relyance stores the graph and findings, not your data or your prompts.

Where findings go

Routed to the owning team as a PR comment, Jira ticket, or Slack message, each with commit, path, and the commitment at stake.

See your own exposure map before you decide anything.

Connect one repo and one cloud account in the demo. You leave with the AI inventory, the lineage graph, and the first three risky flows — whether or not you buy.

Free exposure map
Read-only connectors, nothing installed
Results in the same session
Export stays with you
Get a Demo