# Capabilities in Depth

## AI Security and Governance

Agents, models, RAG pipelines, and MCP servers create paths to customer data that nobody can enumerate by hand. Relyance splits the problem in two: Classification & AI Governance finds and fixes risk before the code ships, and AI Runtime Security & Enforcement keeps AI within bounds in production.

### Classification & AI Governance

Relyance classifies data, maps data flows, fixes risky flows and unsafe access, and automates AI governance.

| Features | Use cases |
|---|---|
| Inventory of every AI agent, model, RAG pipeline, and MCP server | Answer, with evidence, which AI paths can reach customer data |
| Permission reach and data provenance computed per component | Know what each agent can touch before you approve it |
| Context-aware classification of structured and unstructured data at petabyte scale | Build an accurate picture of the sensitive data you hold |
| End-to-end lineage from code to cloud to third party | Find and fix risky data flows and unsafe access |
| Detection at merge in CI/CD | Catch an over-scoped agent before it ships |
| Impact analysis and fix linked to each finding | Cut a risky path knowing exactly what depends on it |

### AI Runtime Security & Enforcement

Relyance stops an AI feature from taking an action or leaking data outside the rules set by your company and the app developer.

| Features | Use cases |
|---|---|
| Blocking of unapproved AI actions | Ship AI features that stay inside the rules and policies you set |
| Runtime blocking of over-scoped AI | Contain an over-scoped agent in production |
| Monitoring of classified data in motion, with blocking of misuse and leaks | Block, mask, or escalate a sensitive data leak before it leaves your environment |

## Privacy Automation

Five modules automate privacy operations.

### Universal ROPA

Most ROPAs describe systems as they were at the last review; this one regenerates from live flows.

| Features | Use cases |
|---|---|
| Records self-update from live data flows | Survive a 48-hour GDPR Article 30 audit |
| Multi-jurisdiction coverage | Pass privacy diligence during M&A without a scramble |
| Lawful basis and retention tracked per activity | Run a current ROPA without a team maintaining it by hand |

### Data Mapping

Data Mapping builds the map from your systems themselves.

| Features | Use cases |
|---|---|
| Automated mapping | Track data inventory, usage, and flow without manual upkeep |
| Multidimensional classification | Know your crown-jewel data, who's data it is, what state it is in, where it lives, and how long you retain it |
| Drift detection | Catch data misuse when a flow changes |

### DSR Automation

A data subject request is a distributed systems problem: the requester's data sits across SaaS tools, databases, and internal APIs, and the clock starts when the request lands.

| Features | Use cases |
|---|---|
| Unified request portal with identity verification | Verify who is asking before you move any data |
| Autonomous fulfillment across SaaS, databases, and APIs | Meet GDPR and CCPA deadlines through a spike in requests, without hiring |
| Audit log per request | Show a regulator exactly what you did, and when |

### Assessments

Regulators add assessment obligations faster than privacy teams add headcount.

| Features | Use cases |
|---|---|
| Automated DPIAs, PIAs, and AI risk assessments | Finish DPIAs and AI risk reviews before launch |
| Live obligation-gap detection | Catch obligation gaps as the EU AI Act, NIST RMF, ISO 42001, and new state laws in Texas, Colorado, and Florida take effect |
| Risk scoring | Cover thousands of assessments with a small team |

### Consent Management

A correct cookie banner cannot cover trackers you do not know are running.

| Features | Use cases |
|---|---|
| Tracker discovery and governance | Catch a tracker sending health data before it becomes an incident |
| Consent provenance | Prove what a user consented to, and when |
| Audit-ready consent vault | Walk into a cookie audit with the evidence already filed |

## How it fits together

Close an unsafe flow and the graph updates: the ROPA reflects the change, and the related assessment gap closes. For the mechanics, read [How Relyance AI Works](/docs/introduction-to-relyance-ai/how-relyance-ai-works/).
