Data governance stops at the database. Your data leaves through APIs.
Catalogs govern tables. Gateways manage traffic. Goava connects the two: it discovers every endpoint across your API gateways, traces each one back to the exact tables and columns behind it, inherits data classifications up to the API layer, and scores exposure risk — so the APIs serving your most sensitive data are governed, not invisible.
The Blind Spot
Catalogs govern tables. Gateways manage traffic. Nobody connects them.
A public endpoint serving personal data from a classified table is invisible to both sides: the data catalog doesn't know the API exists, and the API gateway doesn't know what data sits behind it. In Saudi Arabia, that gap is no longer just technical — it is regulatory.
- Your catalog knows the table is classified — but not that an API exposes it to the outside world.
- Your gateway sees every request — but not the sensitivity of the data behind the endpoint.
- The NDMO framework expects data sharing to be governed wherever it happens, including its Data Sharing and Interoperability domains — and APIs are exactly where sharing happens.
- PDPL, fully enforced since September 2024 with SDAIA actively enforcing it, makes ungoverned exposure of personal data a regulatory risk, not just an engineering oversight.
Native discovery for the gateways you already run
API-to-Data Lineage
Know exactly which tables power which endpoints
Goava extends end-to-end, column-level lineage past the warehouse and into the API layer. Endpoints are detected automatically from OpenAPI specifications and connected to the data assets that feed them — so 'what does this API actually expose?' becomes a question you can answer in seconds.
- Automatic endpoint detection from OpenAPI specs — no manual inventory to maintain.
- End-to-end lineage from source systems to endpoints, down to the individual column.
- A visual lineage editor plus ML-based suggestions to confirm or correct connections quickly.
- Impact analysis: before changing a column, see every endpoint that depends on it.
Inherited Classification
Tag a column as PII once. Every API that exposes it inherits the tag.
Classification work shouldn't be done twice. With tag inheritance between data and APIs, the sensitivity you record in the catalog flows automatically along the lineage to every endpoint that serves that data — keeping data and API layers consistent by design.
- Classifications and tags propagate automatically from tables and columns to the endpoints that serve them.
- Personal and financial data tags stay consistent across the data layer and the API layer — no duplicate tagging effort.
- Ownership and stewardship apply to APIs the same way they apply to tables, dashboards, and pipelines.
- Classification coverage you can evidence — supporting the classification controls of the NDMO framework.
API Exposure Dashboard
The screenshot you show your CISO — and your regulator
One risk-scored view of every endpoint in your organization: what it exposes, who owns it, and how sensitive the data behind it is. When the question is 'which of our public APIs serve personal data?', you answer with a dashboard, not a task force.
- Risk scoring that flags public APIs exposing personal or financial data.
- Filter by gateway, domain, classification, or owner to focus reviews where they matter.
- Drill down from a high-risk endpoint to the exact tables and columns behind it.
- Audit-friendly evidence supporting PDPL accountability and the NDMO framework's data sharing controls.
Frequently asked questions
Which API gateways does Goava support?
Goava natively discovers APIs from Kong, AWS API Gateway, Azure API Management, Google Cloud API Gateway, and Nginx. Endpoints are detected automatically from OpenAPI specifications, so your API inventory stays current without manual documentation.
How does API-to-data lineage actually work?
Goava connects to your gateways and to your data platforms through roughly 80 native connectors, then links endpoints to the tables and columns that feed them. ML-based suggestions propose lineage connections, and a visual lineage editor lets your team confirm or correct them — down to column level.
Does this help with NDMO and PDPL compliance?
Yes, with careful framing: Goava supports compliance work, it does not certify it. API discovery, API-to-data lineage, exposure dashboards, and inherited personal-data classifications help teams maintain reviewable evidence of where data is exposed and how related governance controls are applied. Regulatory claims should be checked against the approved source register before publication or assessment use.
Can we deploy inside Saudi Arabia?
Yes. Goava runs self-hosted on-premises or in the cloud inside Saudi Arabia. Enterprise controls include RBAC, SSO via OIDC, SAML 2.0, and LDAP, JWT support, and audit-friendly operation — with a natively bilingual Arabic and English interface.
Find your exposed endpoints in the first week
Connect your gateways and data sources, and walk into your next review with a risk-scored map of every API your organization exposes.