How Relyance AI Works
Map: connect what you already run
Cloud connections are agentless.
| Category | Integrations |
|---|---|
| Source code | GitHub, GitLab, Bitbucket |
| Cloud (agentless) | AWS, GCP, Azure |
| Data platforms | Snowflake, Databricks, ClickHouse, and others |
| Identity | Okta, Entra ID |
| AI providers | OpenAI, Anthropic, Bedrock, Vertex, and others |
| SaaS | Salesforce, HubSpot, and hundreds more |
| Observability | Datadog, Splunk, New Relic, and others |
Each source adds edges the others lack: repos show what your code does with data, cloud and data platforms show where it lives, identity providers show who and what can reach it, AI provider integrations show the models and agents in the path, and SaaS integrations show where data leaves your boundary. Relyance joins all of it into one model. Connector-level detail lives in Integration Features.
Detect: what the graph computes
End-to-end lineage
Relyance derives lineage from the code that produces data, through the stores it lands in, to the third parties it leaves through.
Effective permissions
For every identity, Relyance resolves roles, scopes, and grants down to what that identity can reach. Service accounts and AI agents get the same treatment as people.
The AI surface
Relyance inventories every agent, model, RAG pipeline, and MCP server with its permission reach and its path to data.
Context-aware classification
The graph holds the code and business process around a field, so Relyance classifies with that context rather than string patterns in isolation. Classification covers structured and unstructured data and runs at petabyte scale. Relyance watches classified data in motion and blocks misuse and leaks at the enforcement points below.
The graph updates continuously as code merges and systems change. Findings carry the business process they belong to rather than a bare resource ID.
Where enforcement runs
At merge. Relyance runs checks in CI/CD that catch an over-scoped agent or a risky data flow before it ships.
At runtime. Relyance allows only approved AI actions and blocks risky flows of classified data.
Enforcement reads the same graph as detection, so every finding carries its blast radius: the data, identities, and paths on the affected route. Impact analysis and the fix are one click from the finding.
One graph, many consumers
The privacy modules run on Data Journeys, so ROPAs and data maps update from live flows instead of point-in-time surveys. When an auditor asks how you know, the answer is the same graph that did the blocking.
Deployment options
The same product ships three ways. Choose on architecture and data residency, not on features.
Full SaaS. Relyance-hosted and fully managed. Fastest to deploy — nothing to run or maintain — with automatic updates and managed scaling. Best when you are standardizing on SaaS.
Outpost. Runs inside your own cloud, so data and processing stay in your perimeter. For strict data-residency and isolation needs. You own the environment; Relyance operates it.
DirectConnect. Private connectivity to your systems: managed control plane, your data plane. The network path stays private with no public exposure — a balance of fast setup and tight control.