Skip to main content
Build trusted data with Ethyca.

Subject to Ethyca’s Privacy Policy, you agree to allow Ethyca to contact you via the email provided for scheduling and marketing purposes.

OneTrust reports.Ethyca governs.

In the Al era, questionnaire and spreadsheet management tools like OneTrust can't keep up. Ethyca is the choice of forward-thinking governance, risk, and privacy teams in the world's best companies.

Night and day. Ethyca turned our data governance from a hottleneck into a strategic enabler for scale.

Michael Razee, Privacy Counsel @ Ramp
The slice table is missing

SurveyMonkey replaced OneTrust with Ethyca. These were the results.

SurveyMonkey's implementation began by stabilizing their most fragile process: data subject access requests. Ethyca configured DSAR fulfillment workflows to integrate directly with their unique SQL Server environment, delivering consistent, policy-driven responses within 48 hours - down from seven-day manual coordination cycles.

7 days -> 48 hours

Data subject request response time.

4 PB

Volume of data governed by Ethyca

40m users

Protected by Ethyca

Govern and comply in a single layer

Govern and comply in a single layer

01Data Inventory MappingDetect your data

Discover personal and sensitive data across your infrastructure, websites, and third-party apps, or enrich existing DSPM and catalogs. The result is a unified source of data intelligence, risk, and insight to support governance obligations.

Warehouse
SNOWFLAKE · BIGQUERY
Websites
COOKIES · TAGS · SDKS
Infrastructure
AWS · IDP
Scan + classify
AUTOMATED DETECTION
PII
Financial data
Biometric data
CLASSIFIER OUTPUT
SENSITIVE DATA
42%
GAP REPORT
38need a data steward
12PCI-DSS datasets
GOVERNED
98%
02Continuous Risk AssessmentAssess risk in real time

Replace forms and template maintenance with continuous risk assessments. Astralis, made by Ethyca, knows the internal and external policies you must follow, and continually analyzes risk across your data, purpose, and vendor inventories.

RISKS · OPENRE-EVALUATED NIGHTLY
17vendors without DPA
22systems missing lawful basis
12cross-border transfers
31AI use cases unassessed
AGENTIC ASSESSMENT
You're onboarding two new AI products that handle sensitive data. Should I draft DPAs for every state you operate in?
Data catalog
3,412 DATASETS MAPPED
ROPA + vendors
87 PROCESSORS
Regulations
GDPR · EU AI ACT · CPRA
REPORT
PA-2026-014
MITIGATIONS
Route GPC to ad server
Add DPA for vendor
Gate model on consent
RISK REGISTER
AI USES · 31
DPA · 17
BASIS · 22
XFER · 12
03Purpose Based Access ControlGovern access through purpose

Purpose based access control monitors and enforces data access across AI agents, teams, and data projects. Policies provide a governance framework that proves how data is used, not just who accesses it, ready for audit.

PURPOSES TAXONOMY
operational.support
essential.service
analytics.reporting
marketing.segmentation
ai.training
personalize.content
disclosure.third_party
ASTRALISMCP GATEWAY · POLICY-CHECKED
DK
Build a list of customers from recent credit scores and risk profiles, for our next campaign.
Here's your list. It would have pulled in demographic details we don't allow for marketing, so I left those out and used credit thresholds instead.
INFERRED PURPOSEmarketing.segmentationquery rewritten
Policy check
MCP GATEWAY · EVERY CALL
POLICY · NO PROTECTED-CLASS PROFILING
Access is granted by purpose, not just identity — every agent call is checked before it runs.
04Consent & Lawful BasisCapture lawful basis everywhere

Fine-grained, high-performance consent and preference management. Model any consent or preference framework, from GDPR to CCPA, and respect user choice wherever data is accessed - models and agents included.

CONSENT · PER USE
Automated profiling
Data sharing
Marketing
CONTRACT OBLIGATIONS
CLAUSE 12.1 · DPA
"Any secondary use — including profiling — requires the customer's documented consent."
MODELED AS POLICY
CUSTOMER BASE
2.1M
1.52M · 72%
ANALYZABLE
628K · 28%
EXCLUDED · NEVER TOUCHED
I can analyze only customers who permit automated profiling — 1.52M of 2.1M. Of those, 83% show high propensity.
72%
PERMIT PROFILING
83%
HIGH PROPENSITY
628K
EXCLUDED · NO CONSENT
05Rights & De-identificationModify data on request

A flexible, policy-based data access and de-identification engine enables targeted, scaled data rights enforcement across your infrastructure, integrating with databases, warehouses, and third-parties to meet data obligations.

Deletion
process
DELETEDSR-4412 · IN PROGRESS
NAMESEMAILBIOMETRICADDRESSGOVERNMENT IDPHONEIP ADDRESSDEVICE ID
ENFORCED ACROSS 104 SYSTEMS
RETAINLAWFUL BASIS HELD
ACCOUNT NUMBERTRANSACTION HISTORY
Basis: regulatory reporting — retained 7 years, de-identified after closure.
01Original data asset
PERSONAL IDENTIFIERS · REMOVED
02Post-deletion asset
DE-IDENTIFIED · TOKENIZED
06Open-Source FoundationBuilt in the open

Ethyca's platform is built on Fides, the world's most used open-source taxonomy for data governance and privacy. It lets you consistently describe the data you process, its purposes, and ownership for consistent enforcement.

FIDESLANG · THE OPEN TAXONOMY FOR DATA GOVERNANCE
DATA CATEGORIES
DATA USES
user.contact
user.biometrics
user.demographic
user.government_id
user.health
essential.service
analytics.reporting
personalize
advertising.marketing
disclosure
CUSTOM EXTENSIONS
+ sensitivity · special_category
+ risk · high
FAQ

Frequently Asked Questions

For most teams it replaces the Al governance layer, and it can replace the wider privacy program too - SurveyMonkey moved off OneTrust entirely. Where a OneTrust deployment is entrenched, Astralis runs alongside it and supplies the enforcement and evidence that the program record can't produce on its own.

Test

Test