# The Data Classification Taxonomy

![Screenshot](https://assets.relyanceuat.xyz/images/docs/47531623552781/47531623541261.png)
Relyance AI's **data class taxonomy** is the structured vocabulary we use to describe the sensitive data your organization holds. Every field, document, log line, prompt, and dataset that Relyance discovers across your systems is matched to a **data class** - a single, named type of data such as *AI / LLM Provider Credential*, *Payment Card Number*, or*Medical History*.

| **Hundreds** **DATA CLASSES**| **20+** **CATEGORIES**| **50+** **JURISDICTIONS**| **Fully** **CUSTOMIZABLE**| **Quarterly** **REFRESH** |
| --- | --- | --- | --- | --- |

What makes it more than a dictionary is the connection to **obligations**- the real-world laws and compliance frameworks that govern each type of data within your organization. Because every class is linked to the rules that apply to it, classifying your data instantly tells you what you must protect and why. And, just as important, the taxonomy is completely **contextual**: you only ever see the classes and obligations that are actually relevant to your business based on the jurisdictions you operate in and compliance frameworks you choose.

![Screenshot](https://assets.relyanceuat.xyz/images/docs/47531623552781/47531639749901.png)

*How one piece of data becomes a governed, relevant finding.*

**The building blocks**

You can explore the whole taxonomy yourself in your Relyance workspace under **Settings → Data Classification**.

A handful of simple concepts make it up, and on that screen each one appears as a column you can read at a glance - searchable, and grouped by category.

| **CONCEPT**| **WHAT IT MEANS** |
| --- | --- |
| **Data class** | A single, named type of data - the atomic unit of the taxonomy, shown as one row. Example: AI / LLM Provider Credential. |
| **Category** | The group a class belongs to, so related data stays together. Classes are organized into more than 20 categories, such as AI, ML & Model Data. |
| **Context** | The set of “lenses” that describe why a class matters - for example AI / ML Data, AI System Data, Personal Data, or AI Transparency. Context is what links a class to the obligations that apply to it. |
| **Obligation** | A rule that governs the class - in two forms: binding regulations like the EU AI Act, CCPA, or California SB-53, and voluntary frameworks and standards like ISO 42001, NIST AI RMF, or SOC 2. Each carries the jurisdiction or standards body behind it. |
| **Sensitivity**| How sensitive the class is, at a glance: **Critical**, **High**, or **Medium**. |
| **Findings** | How many real instances of this class Relyance has actually been discovered in your systems. |
| **Status** | Whether Relyance is actively classifying this class for you - a simple on / off switch. |

| **REGULATIONS + FRAMEWORKS** Obligations come in two flavors, and the taxonomy maps your data to both:      **binding regulations** you must follow (GDPR, CCPA, the EU AI Act); and   **voluntary frameworks and standards** you certify against (ISO 42001, NIST AI RMF, SOC 2, OWASP).      Classifying a single class can surface a legal duty and an audit-scope requirement at the same time. |
| --- |

**Reading a row: a worked example**

Here is a single real row - the **AI / LLM Provider Credential** class - read column by column. It shows how detection, meaning, and compliance come together in one place.

| **COLUMN**| **WHAT YOU SEE**| **WHAT IT MEANS** |
| --- | --- | --- |
| **Name** | AI / LLM Provider Credential | The data class: API keys and tokens for third-party AI providers such as OpenAI, Anthropic, or Azure OpenAI. |
| **Category** | AI, ML & Model Data | Grouped with the other data types produced and consumed by AI systems. |
| **Context** | AI / ML Data · AI System Data · … (+ more) | The lenses that make this class both sensitive and regulated - several apply at once. |
| **Obligations** | EU AI Act · ISO 42001 · … (+ more) | The laws and frameworks that govern it - here the EU AI Act (regulation) and the ISO 42001 AI-management standard (framework), among others. |
| **Findings** | A running count | How many real instances of this credential Relyance has discovered across your estate. |
| **Sensitivity**| **Critical** | The highest tier - leakage could enable unauthorized model access and data exfiltration. |
| **Status**| **On** | This class is switched on, so Relyance is actively watching for it. |

**The key idea: you only see what's relevant to you**

The taxonomy is deliberately **comprehensive** - hundreds of data classes and dozens of laws spanning more than fifty jurisdictions. But no single organization is subject to all of it, and showing everything would just be noise. So what actually surfaces for you is filtered three ways:

![Screenshot](https://assets.relyanceuat.xyz/images/docs/47531623552781/47531623543437.png)

- **By jurisdiction.** Obligations appear when they apply to the places you do business. A company operating only in the US isn't shown EU AI Act duties it isn't subject to; a company active in the EU is.
- **By what you've turned on.** You can enable or disable classes to match your risk posture and program, so the taxonomy reflects the way your organization actually works.
- **By what's actually in your data.** A class becomes real when Relyance discovers instances of it - that's the Findings count. Classes with nothing to match stay quiet.

| **THE PAYOFF** Instead of a generic checklist of every class multiplied by every law on the books, you see **your data, governed by your obligations**. The taxonomy adapts to your business - not the other way around. |
| --- |

**Turning classes on and off**

Every class carries a simple **Status** switch. Relyance ships a curated default set already switched on - the near-universally sensitive, high-confidence classes such as validated identifiers, secrets and credentials, and core AI-exposure data - and the rest stay off until they become relevant to you. Because every class is tied to its obligations, you can also let the laws and frameworks you answer to guide what you turn on.

**Making it yours: customizing the taxonomy**

The built-in library is a starting point, not a straitjacket - you can extend it with data classes unique to your business and fine-tune the ones that ship with it. Anything you create is a **first-class citizen**: a custom class carries context, obligations, sensitivity, findings, and an on / off switch exactly like the classes Relyance provides.

**Adding your own data classes**

Some of your most sensitive data is specific to you - an internal customer token, a proprietary record type, a contract identifier, a product-specific document. From the same **Classification Settings** screen you can add a class for any of it with **Create Data Element**. Creating one comes down to describing the data and teaching Relyance how to recognize it:

![Screenshot](https://assets.relyanceuat.xyz/images/docs/47531623552781/47531623545613.png)

You give Relyance the signals that reveal the data - a handful of example terms or field names typed in, or many **imported at once from a CSV in the backend with the help of your** ***forward-deployed engineer***- and choose how strictly to match: **exact** for precise identifiers, or **fuzzy** to catch spelling variations. You pick which connected systems it is scanned in, **map the obligations it falls under** so it inherits the same jurisdiction-aware behavior as the built-in library, and set its sensitivity. Before it goes live, you can **test it against sample data**, and optionally let Relyance's AI-assisted review filter out likely false positives.

**Tuning what's already there**

Customization isn't only about new classes. Every built-in class is adjustable: raise or lower its **sensitivity** to match your risk appetite, turn it **on or off**, and refine how it is detected. If a class is too broad or too narrow for your environment, you shape it - so the taxonomy bends to your reality instead of forcing a one-size-fits-all default. The result is a taxonomy that starts out comprehensive and becomes precisely yours.

**Spotlight: AI, ML & Model Data**

AI created entirely new kinds of sensitive data that traditional catalogs never accounted for. The taxonomy treats them as **first-class data classes**, each with its own meaning and its own obligations. A few examples from the category:

- **AI / LLM Provider Credential -** API keys and tokens for AI providers (Critical).
- **AI Conversation History -** stored transcripts between users and AI assistants (High).
- **AI Agent Memory / State -** persistent memory kept by autonomous agents across sessions (High).
- **AI governance records -** Model Cards, AI Bill of Materials (AIBOM), and Conformity / Impact Assessments (FRIA).
- **AI operations data -** inference / telemetry logs, evaluation and benchmark data, content-moderation labels, and safety / red-team findings.

Each already maps to the emerging AI rulebook built into the taxonomy - both the regulations (**EU AI Act**, **CCPA**, California's **SB-53** and **AB-2013**) and the frameworks teams are measured against (**ISO 42001**, **NIST AI RMF**, **OWASP**, **MITRE ATLAS**). Enable AI classes, and the obligations that govern them come with them.

**Always current**

Regulation and technology move fast - especially around AI. Relyance curates the taxonomy and **refreshes it roughly every quarter or as laws and frameworks change**: adding new data classes, mapping new laws and frameworks as they land, and retiring what's obsolete. Your library keeps growing with the regulatory landscape - and every custom class and setting you've added rides along untouched through each refresh.

| **IN ONE SENTENCE**   The data class taxonomy turns “we think we have sensitive data somewhere” into “here is exactly what we have, why it's sensitive, which laws govern it, and where it lives” - kept current automatically, and filtered to what actually matters to your business. |
| --- |
