Skip to main content
API Governance

Data governance stops at the database. Your data leaves through APIs.

Catalogs govern tables. Gateways manage traffic. Goava connects the two: it discovers every endpoint across your API gateways, traces each one back to the exact tables and columns behind it, inherits data classifications up to the API layer, and scores exposure risk — so the APIs serving your most sensitive data are governed, not invisible.

The Blind Spot

Catalogs govern tables. Gateways manage traffic. Nobody connects them.

A public endpoint serving personal data from a classified table is invisible to both sides: the data catalog doesn't know the API exists, and the API gateway doesn't know what data sits behind it. In Saudi Arabia, that gap is no longer just technical — it is regulatory.

  • Your catalog knows the table is classified — but not that an API exposes it to the outside world.
  • Your gateway sees every request — but not the sensitivity of the data behind the endpoint.
  • The NDMO framework expects data sharing to be governed wherever it happens, including its Data Sharing and Interoperability domains — and APIs are exactly where sharing happens.
  • PDPL, fully enforced since September 2024 with SDAIA actively enforcing it, makes ungoverned exposure of personal data a regulatory risk, not just an engineering oversight.
/v1/customers · PUBLIC · PII ⚠
/v1/orders · partner · Financial
/v1/health · public · safe

Native discovery for the gateways you already run

KongAWS API GatewayAzure API ManagementGoogle Cloud API GatewayNginx

API-to-Data Lineage

Know exactly which tables power which endpoints

Goava extends end-to-end, column-level lineage past the warehouse and into the API layer. Endpoints are detected automatically from OpenAPI specifications and connected to the data assets that feed them — so 'what does this API actually expose?' becomes a question you can answer in seconds.

  • Automatic endpoint detection from OpenAPI specs — no manual inventory to maintain.
  • End-to-end lineage from source systems to endpoints, down to the individual column.
  • A visual lineage editor plus ML-based suggestions to confirm or correct connections quickly.
  • Impact analysis: before changing a column, see every endpoint that depends on it.
Explore Lineage
source_db → etl_orders → dwh.orders
dwh.orders → bi.sales_dash
dwh.orders → api:/v1/orders

Inherited Classification

Tag a column as PII once. Every API that exposes it inherits the tag.

Classification work shouldn't be done twice. With tag inheritance between data and APIs, the sensitivity you record in the catalog flows automatically along the lineage to every endpoint that serves that data — keeping data and API layers consistent by design.

  • Classifications and tags propagate automatically from tables and columns to the endpoints that serve them.
  • Personal and financial data tags stay consistent across the data layer and the API layer — no duplicate tagging effort.
  • Ownership and stewardship apply to APIs the same way they apply to tables, dashboards, and pipelines.
  • Classification coverage you can evidence — supporting the classification controls of the NDMO framework.
See Governance Capabilities
orders · data-team · PII
customers · analytics · Certified
revenue_daily · finance

API Exposure Dashboard

The screenshot you show your CISO — and your regulator

One risk-scored view of every endpoint in your organization: what it exposes, who owns it, and how sensitive the data behind it is. When the question is 'which of our public APIs serve personal data?', you answer with a dashboard, not a task force.

  • Risk scoring that flags public APIs exposing personal or financial data.
  • Filter by gateway, domain, classification, or owner to focus reviews where they matter.
  • Drill down from a high-risk endpoint to the exact tables and columns behind it.
  • Audit-friendly evidence supporting PDPL accountability and the NDMO framework's data sharing controls.
See It on Your APIs
/v1/customers · PUBLIC · PII ⚠
/v1/orders · partner · Financial
/v1/health · public · safe

Frequently asked questions

Which API gateways does Goava support?

Goava natively discovers APIs from Kong, AWS API Gateway, Azure API Management, Google Cloud API Gateway, and Nginx. Endpoints are detected automatically from OpenAPI specifications, so your API inventory stays current without manual documentation.

How does API-to-data lineage actually work?

Goava connects to your gateways and to your data platforms through roughly 80 native connectors, then links endpoints to the tables and columns that feed them. ML-based suggestions propose lineage connections, and a visual lineage editor lets your team confirm or correct them — down to column level.

Does this help with NDMO and PDPL compliance?

Yes, with careful framing: Goava supports compliance work, it does not certify it. API discovery, API-to-data lineage, exposure dashboards, and inherited personal-data classifications help teams maintain reviewable evidence of where data is exposed and how related governance controls are applied. Regulatory claims should be checked against the approved source register before publication or assessment use.

Can we deploy inside Saudi Arabia?

Yes. Goava runs self-hosted on-premises or in the cloud inside Saudi Arabia. Enterprise controls include RBAC, SSO via OIDC, SAML 2.0, and LDAP, JWT support, and audit-friendly operation — with a natively bilingual Arabic and English interface.

Find your exposed endpoints in the first week

Connect your gateways and data sources, and walk into your next review with a risk-scored map of every API your organization exposes.