GEODI scans more than 200 systems, reads what is inside scanned documents and images, labels what it finds by sensitivity, then masks or removes the exposure.
Available across Canada, the United States and Mexico. Deploy on your own servers or in a cloud region you choose.
See what it finds in systems you already run, where the software can be deployed, and how licensing works.
Carry a data security product with an established install base and a defined channel process behind it.
Every team can name the databases they run. Almost none can name the scanned contract on a share drive with a client account number inside it.
Structured data is the part organizations already track. The exposure tends to sit somewhere else: in email attachments, in exports nobody deleted, in folders inherited through a migration, and in paper that was scanned to PDF and never read again by anything.
GEODI treats those the same as a database table. Optical character recognition turns scanned pages into text, so a credit card number printed on a 2019 invoice is found the same way as one sitting in a column.
Point GEODI at a source with read access. Folders, mail, databases, cloud storage and collaboration tools.
Prebuilt recognizers detect card numbers, national identifiers, health numbers and financial values.
Findings are labelled Confidential, PII, Restricted or Unclassified against rules you control.
Values are masked or anonymized per user group, so analysts work without seeing the originals.
Permissions decide who sees what, and every change is attributable to an account.
One query, run twice against the same PCI DSS project. The second run is the anonymize profile: card numbers and financial values are swapped for realistic substitutes, so the dataset keeps its shape for testing while the originals stay protected.
A scanner that reaches half your systems produces a false sense of completeness. GEODI connects to file shares, mail, databases, and the cloud services teams adopt without telling anyone.
GEODI supports the work these rules require: knowing what personal data you hold, limiting who can reach it, and producing evidence. Certification of your organization stays your own program.
| Market | Rules that drive the work | What GEODI contributes |
|---|---|---|
| Canada | PIPEDA, Quebec Law 25, PHIPA, FIPPA and MFIPPA | Inventory of personal data, access requests answered from the index, anonymization for retention limits |
| United States | HIPAA, CCPA and CPRA, GLBA, SOX, state privacy statutes | Locate protected health and financial data, restrict access, evidence for audit |
| Mexico | LFPDPPP | Identify personal data, apply masking, document the controls in place |
| Cross-border | PCI DSS, GDPR where applicable | Cardholder data discovery and scope reduction, subject access response |
A scoped session on representative data tells you more than any specification sheet. We connect one source, run discovery, and walk through what surfaces.