Data you forgot you had
A support ticket with a password in the body. An export sitting in an analytics warehouse. Sensitive fields turn up in places nobody put them deliberately.
Gravitas Trust House builds data governance infrastructure for enterprises that need to know where their sensitive data lives, who can reach it, and whether they can prove it. Trust isn't claimed — it's evidenced.
The problem
Not because they're careless — because the answer is spread across a dozen systems nobody has looked at together. Sensitive data accumulates in places it was never meant to live, access is granted faster than it's revoked, and the evidence needed to prove any of it doesn't exist until someone asks for it.
A support ticket with a password in the body. An export sitting in an analytics warehouse. Sensitive fields turn up in places nobody put them deliberately.
Contractors who finished. Staff who moved teams. Admin rights granted for one migration and never taken back.
Readiness work starts when the audit is booked, so answers get reconstructed from memory rather than recorded as they happened.
What we do
Gravitas connects to the systems you already run, discovers what sensitive data is in them, and keeps a record of the decisions you make about it — so readiness is a state you're in, not a project you start.
Connect a database read-only. Gravitas introspects the schema, samples values in memory to classify them, and records the metadata — never the values themselves.
Every field is categorised — PII, Financial, Credentials, Health, Behavioral — and given a sensitivity level, with the reasoning attached.
Grants are assessed against which systems actually hold sensitive data. Each review is preserved as evidence: who decided what, and when.
An assessment against your framework — SOC 2, HIPAA, GDPR, or PCI-DSS — scaled to what's reasonable for a company your size.
Get in touch
If you're preparing for an audit — or you simply don't have a confident answer to where your sensitive data lives — we'd like to hear from you.