Borneo
Data security and privacy scanning that finds sensitive data and tracks remediation.
Locates where personal data is sitting, flags what is exposed, and follows a remediation item through to closure.
Use Borneo with Snow
Snow is a personal AI assistant that builds real apps for you, and they can put Borneo to work.
What Snow can do with Borneo
These are the Borneo operations Snow and the apps you build with it can run. Sign in to choose which ones Snow may run without asking.
Reads86
Look at your data without changing it.
- Access scan iteration by id
Retrieves detailed information about a specific scan iteration in the Borneo integration platform. This endpoint allows users to fetch the current status, results, and metadata associated with a particular scan iteration. It should be used when monitoring the progress of a scan, analyzing results, or troubleshooting integration workflows. The endpoint provides a snapshot of the scan iteration at the time of the request and may not reflect real-time updates if the scan is still in progress. It's particularly useful for auditing, reporting, and maintaining a history of scan operations within Borneo's automation and integration processes.
- Download dashboard report
The DownloadDashboardReport endpoint allows users to download specific types of dashboard reports from the Borneo integration platform. This POST endpoint is designed to generate and retrieve comprehensive reports related to privacy operations, data discovery, and data flow within an organization's systems. It should be used when detailed insights into data management, privacy compliance, or data flow visualizations are required. The endpoint is particularly useful for privacy officers, data analysts, or system administrators who need to review or present aggregated data on the organization's data handling practices. Note that the report generation process may take some time depending on the complexity and amount of data being analyzed, so users should be prepared for a potential delay before receiving the downloaded report.
- Download dashboard report edition
Downloads a specific dashboard report edition from the Borneo integration platform. This endpoint allows users to retrieve a particular version or iteration of a dashboard report by providing its unique identifier. It should be used when a user needs to access or save a specific report edition, perhaps for archival purposes, offline analysis, or to compare different versions of a report. The endpoint accepts a POST request with a JSON payload containing the report edition ID. It's important to note that this tool only handles the download process and does not provide functionalities for listing available reports, creating new reports, or modifying existing ones. Users should ensure they have the correct reportEditionId before making the request, as the schema does not specify any error handling for invalid IDs.
- Export filtered leaf resources
The listLeafResources endpoint exports a comprehensive list of leaf resources in the Borneo integration platform, allowing for extensive filtering, sorting, and detailed information retrieval. It's designed to facilitate data discovery, classification, and management across various cloud providers and services. This endpoint is particularly useful for conducting audits, managing data governance, or preparing reports on resource usage and sensitive data distribution across the organization's digital landscape. The function supports a wide range of filtering options, enabling precise querying based on resource attributes, metadata, and detected sensitive information. Users can customize the output by sorting results and requesting detailed column-level information on detected infotypes. While powerful, users should be mindful of potential performance impacts when requesting detailed information or using complex filters on large datasets.
- Export insight page using scanid
The ExportPageInsight endpoint allows users to export filtered inspection results from a specific scan in the Borneo integration platform. This tool is particularly useful for retrieving and analyzing detailed information about scanned pages, resources, and detected info types. It provides extensive filtering capabilities to customize the exported data according to various criteria such as resource types, user associations, file types, and detection confidence levels. The endpoint should be used when a comprehensive export of scan results is needed, especially for further analysis or reporting purposes. It's important to note that while the filtering options are extensive, the performance may be affected when exporting large datasets with multiple complex filters applied simultaneously.
- Export inventory resource list
Exports a filtered and sorted list of inventory resources from the Borneo integration platform. This endpoint allows for extensive customization of the exported data, including pagination, field selection, sorting, and filtering based on various criteria such as account, region, resource type, and tags. It also provides options to include aggregated statistics from child resources, violation metrics, and framework exception counts. Use this endpoint when you need to retrieve a comprehensive, customized view of your inventory resources for analysis, reporting, or integration with other systems. The exported data can be further processed or used for compliance, resource management, or security auditing purposes. Note that the response may be paginated for large result sets, requiring multiple API calls to retrieve all data.
- Export processing activities list
This endpoint exports a filtered list of processing activities in specified formats and languages. It allows users to retrieve data about various data processing activities, which can be customized using multiple filter criteria. The export can be generated in CSV, PDF, or DOC formats, supporting multiple languages for localization. This tool is particularly useful for generating reports, conducting audits, or sharing processing activity information with stakeholders in their preferred format and language. Note that at least one export format and a language must be specified for a successful request.
- Export recipients list with filter
The ExportRecipientsList endpoint generates and exports a list of recipients based on specified criteria. It allows for flexible data extraction in multiple formats (CSV, PDF, or DOC) with extensive filtering options. This endpoint is ideal for generating reports, performing data analysis, or creating backups of recipient information. It can handle complex queries to narrow down the recipient list based on various attributes such as categories, roles, processing activities, and more. However, it does not provide real-time updates and should be used for point-in-time exports rather than live data access. The endpoint is particularly useful for compliance reporting, auditing, or transferring recipient data to other systems.
- Fetch dashboard report by id
Retrieves a specific dashboard report from the Borneo integration platform. This endpoint allows users to access detailed analytics and reporting data for a particular dashboard, providing insights into data exchange, workflow automation, and potentially sensitive data breach information. It should be used when a user needs to view or analyze a specific report's contents, such as performance metrics, data sharing statistics, or privacy incident details. The endpoint is particularly useful for generating up-to-date reports for monitoring and decision-making purposes. Note that this endpoint only retrieves existing reports and does not generate new ones or modify report data.
- Fetch data breach evaluation
Retrieves detailed information about a specific evaluated data breach incident. This endpoint should be used when you need to access comprehensive details about a particular data breach that has been assessed within the Borneo platform. It provides insights into the nature, scope, and potential impact of the breach, which can be crucial for incident response, compliance reporting, and risk assessment. The tool is particularly useful for security teams, compliance officers, and data protection officers who need to review or report on specific data breach incidents. Note that this endpoint only provides information about breaches that have already been evaluated and recorded in the system; it cannot be used to report new breaches or assess ongoing incidents.
Creates17
Add something new to your account.
- Create new asset
Creates a new asset in the Borneo integration platform. This endpoint allows users to add various types of assets to their inventory, ranging from hardware and software applications to office furniture and documentation. It's primarily used when onboarding new resources or updating the asset registry. The endpoint captures essential information about each asset, including its type, location, and associated identifiers. It's particularly useful for organizations managing diverse asset portfolios across multiple locations. Note that while creating an asset, only the name and type are required, allowing for flexible asset management workflows.
- Add discovered recipients
Adds multiple discovered recipients to the system as confirmed recipients. This endpoint should be used when you have a list of previously discovered recipient IDs that you want to officially add to your recipient database. It's particularly useful for bulk operations where multiple recipients need to be added simultaneously. The endpoint accepts an array of unique UUIDs, allowing for efficient processing of multiple recipients in a single API call. Note that this endpoint only adds recipients; it does not provide any information about the recipients or perform any other actions beyond adding them to the system.
- Create and schedule cloud resource scan
The createScan endpoint initiates a new scan operation in the Borneo integration platform, allowing users to configure and schedule data scans across various cloud resources. This powerful tool enables users to set up both one-time and recurring scans, with extensive customization options for resource selection, data inspection policies, and scan limits. It's particularly useful for compliance checks, sensitive data discovery, and regular security audits across cloud environments. The endpoint supports a wide range of resource types and provides flexible scheduling options, from immediate execution to complex cron-based recurring scans. Users should carefully consider the scan configuration to balance thoroughness with resource utilization, especially for large-scale environments. While highly versatile, users should note that some features may be resource-type dependent, and should refer to Borneo's documentation for specific connector and filter support.
- Create department with translations
Creates a new department in the Borneo integration platform. This endpoint allows you to add a department to the system with support for multilingual information. It's particularly useful when setting up the organizational structure within Borneo or when expanding to new regions requiring localized department names. The endpoint should be used when you need to establish a new department entity that other parts of the system can reference. It's important to note that this endpoint only creates the department and does not associate it with any specific workflows or integrations - those would need to be set up separately.
- Create domain with polling frequency
Creates a new domain within the Borneo integration platform, allowing for automatic polling and management of connected systems or applications. This endpoint is used to set up a new integration point with a specific name and polling frequency. It should be used when establishing a new connection or integration within the Borneo ecosystem. The endpoint is particularly useful for setting up automated data synchronization or workflow triggers between different business applications. It does not provide information about existing domains or modify existing ones; it is strictly for creating new domains.
- Create dpia for processing activity
Creates a new Data Protection Impact Assessment (DPIA) for a specific processing activity in the Borneo application. This endpoint allows users to comprehensively assess and document privacy risks associated with data processing, including confidentiality, integrity, and availability risks. It should be used when initiating a new DPIA process or updating an existing one with detailed risk assessments and mitigation measures. The tool provides a structured approach to evaluating privacy concerns and ensuring compliance with data protection regulations. However, it does not automatically implement any risk mitigation measures; it only facilitates the assessment and documentation process.
- Create employee with json payload
Creates a new employee record in the Borneo integration platform. This endpoint allows you to add an employee to the system with various details such as personal information, job-related data, and organizational structure. It's primarily used when onboarding new employees or updating the system with employee information from external sources. The endpoint captures both mandatory fields (name, surname, createdBy) and optional fields for a comprehensive employee profile. It's particularly useful for HR systems integration, allowing synchronization with external APIs through the referenceId field. Note that while it collects employment dates, it doesn't automatically handle employee status changes or departures; these would likely require separate API calls or processes.
- Create headquarter entry
Creates a new headquarters entry in the Borneo integration platform. This endpoint allows users to register the main office or primary location of a company or organization within the system. It captures essential information about the headquarters, including its name, address, and associated identifiers. Use this endpoint when setting up a new company profile or updating the primary business location. The endpoint ensures data consistency by enforcing specific formatting rules for each field. It's particularly useful for organizations managing multiple locations or integrating headquarters data with other business systems.
- Create legal document entry
Creates or uploads a new legal document in the Borneo integration platform with specified metadata. This endpoint allows users to add various types of legal documents, such as privacy policies or data processing agreements, to the system. It captures essential information about the document, including its location, type, applicable region, and discovery settings. Use this endpoint when you need to integrate new legal documents into your workflow or update existing ones with new versions. The tool is particularly useful for maintaining a centralized repository of legal documents across different regions and categories within your organization.
- Create new infotype category
Creates a new infotype category in the Borneo integration platform, allowing users to organize and group related sensitive data types. This endpoint is used to establish a structured hierarchy for managing various infotypes, such as PII, PFI, and PHI, enhancing data protection and compliance efforts. The created category serves as a container for specific infotypes, facilitating efficient data classification and management within the Borneo ecosystem.
Updates31
Change something that is already there.
- Create dashboard user
Creates a new dashboard user in the Borneo integration platform with specified roles, organizational access, and authentication settings. This endpoint allows for granular control over user permissions across different organizations and departments within the Borneo ecosystem. It supports integration with external identity providers (OKTA or GCP) for authentication. Use this endpoint when onboarding new users or updating existing user permissions. Note that while only the email is required, it's recommended to provide comprehensive role and organization information for proper access control.
- Enable dashboard user
Enables dashboard access for a specified user in the Borneo integration platform. This endpoint is used to grant or restore a user's ability to view and interact with dashboards within the system. It should be called when an administrator needs to activate a user's dashboard privileges, such as after initial account creation or if access was previously revoked. The endpoint only handles enabling access and does not provide information about the user's current access status or other account details. Note that this operation does not create a new user account; it assumes the specified username already exists in the system.
- Evaluate data breach impact
This endpoint allows users to evaluate and document details of a data breach incident. It is used to capture comprehensive information about a breach, including notifications made, affected parties, and an overall assessment. The endpoint supports saving evaluations as drafts, enabling users to revisit and complete the documentation process over multiple sessions if needed. The tool should be used when there's a need to record and assess the impact and response to a data breach, whether it's a new incident or an update to an existing evaluation. It's particularly useful for compliance purposes, helping organizations track their breach notification efforts and maintain detailed records of each incident. It's important to note that this endpoint does not automatically notify authorities or affected parties; it merely records whether such notifications have been made. Users should ensure they follow appropriate breach notification procedures separately from using this tool.
- Mark scan false positives by id
Marks specified reports as false positives within a given scan in the Borneo platform. This endpoint is used to refine scan results by identifying and flagging reports that are determined to be false alarms. It helps in improving the accuracy of security scans and reducing noise in the results. The function takes a scan ID and a list of report UUIDs to be marked as false positives. It should be used when security analysts or automated systems have reviewed scan results and identified certain findings as non-issues or false alarms. This action helps in training the system and improving future scan accuracy. Note that this operation is likely irreversible, so care should be taken to ensure only genuinely false positive reports are marked.
- Pause scan by id
The PauseScan endpoint allows users to temporarily halt an ongoing scan process in the Borneo integration platform. This tool is used to pause the scanning and analysis of sensitive data within connected systems or data streams. It's particularly useful when you need to temporarily suspend data processing for maintenance, to manage system resources, or to address any issues that may have arisen during the scan. The endpoint should be used when there's a need to interrupt a scan without completely terminating it, allowing for later resumption. It's important to note that this action doesn't delete or reset the scan progress; it simply suspends further processing until explicitly resumed. The pause operation is immediate, but any in-progress data processing may complete before the pause takes full effect.
- Poll domain by id
This endpoint allows you to initiate a poll operation or submit data for a specific domain within the Borneo integration platform. It is used when you need to gather information, trigger a data collection process, or update the status of a particular domain identified by its unique domainId. The POST method suggests that you're sending data to the server, possibly to start a new poll, update an existing one, or submit responses to a poll. This endpoint should be used when interacting with domain-specific polling functionality in Borneo, such as collecting integration status updates or triggering scheduled data synchronizations. It's important to note that the exact behavior and data requirements may vary depending on the specific implementation and purpose of polling in your Borneo setup.
- Post discovered recipient by id
Updates or processes information for a specific discovered recipient user in the Borneo integration platform. This endpoint allows you to interact with user data that has been automatically discovered by the system, potentially as part of the integration process between different applications. Use this when you need to modify, confirm, or take action on a discovered user's information. The exact actions performed depend on the request body (not specified in the schema) but may include tasks such as confirming the user's identity, updating their details, or initiating further integration steps. This endpoint is specific to individual users and requires the unique discoveredRecipientId to target the correct record.
- Put tom status and note
Updates a specific Technical Operating Model (TOM) in the Borneo integration platform. This endpoint allows users to modify the implementation status of a TOM, add explanatory notes, and attach relevant documentation. It's primarily used for tracking and managing the lifecycle of TOMs within an organization's integration processes. The endpoint is particularly useful when the status of a TOM changes, when additional context needs to be provided, or when supporting documents need to be linked to the TOM. It should be used to keep TOM information up-to-date and to maintain a clear record of TOM progress and associated documentation.
- Reset dashboard user password
Initiates a password reset process for a specified dashboard user in the Borneo platform. This endpoint should be used when a user has forgotten their password or needs to change it for security reasons. It triggers the password reset mechanism, which typically involves sending a reset link or temporary password to the user's registered email address. This tool does not actually change the password but starts the secure reset process. It's important to note that this endpoint doesn't return the new password or reset token directly for security reasons.
- Resume scan by id
The ResumeDataScan endpoint allows users to resume a previously paused or interrupted data scan operation within the Borneo integration platform. This PUT request is used to continue the scanning process for privacy risks or data vulnerabilities that was halted earlier. The endpoint is particularly useful in scenarios where a scan was temporarily stopped due to system maintenance, network issues, or intentional pausing. It should be used when there's a need to complete an unfinished scan without starting the entire process from the beginning. This tool doesn't initiate new scans or modify the scan parameters; it simply continues the existing scan from where it left off.
Deletes19
Remove something. This often cannot be undone.
- Archive discovered recipient
Archives a specific discovered recipient in the Borneo platform. This endpoint is used to move a discovered recipient's data into an archived state, which may be useful for compliance, data retention, or organizational purposes. It should be called when you need to store historical data about a recipient that has been identified through Borneo's data visibility and privacy automation processes. The endpoint uses a POST method, suggesting it may trigger backend processes to properly archive the recipient's data. Note that this operation might affect the visibility or accessibility of the recipient's data in other parts of the system.
- Delete asset by id
The DeleteAsset endpoint removes a specific asset from the Borneo integration platform. This operation is used when an asset needs to be permanently deleted from the system, such as when it's no longer relevant or has been decommissioned. The deletion is irreversible, so it should be used with caution. This endpoint is particularly useful for maintaining an up-to-date asset inventory, cleaning up obsolete data, or managing system resources. It's important to note that deleting an asset may have implications on related data or integrations, so users should ensure that the asset is no longer needed before proceeding with deletion.
- Delete category by label
Deletes a specific category from the Borneo integration platform using its unique label. This endpoint should be used when you need to remove an entire category and all its associated data from the system. It's particularly useful for cleaning up outdated or unnecessary categories. Be cautious when using this endpoint, as the deletion is permanent and cannot be undone. This operation will fail if the specified category doesn't exist or if there are any dependencies preventing its deletion.
- Delete dashboard report by id
Deletes a specific dashboard report from the Borneo integration platform. This endpoint should be used when you need to permanently remove a dashboard report that is no longer needed or relevant. It's important to note that this action is irreversible, and once a report is deleted, it cannot be recovered. Use this endpoint with caution, ensuring that the report is no longer required before deletion. The endpoint does not return the deleted report data, so make sure to retrieve any necessary information before deletion if needed.
- Delete data breach by id
Deletes a specific data breach evaluation record from the Borneo system. This endpoint should be used when an organization needs to remove an evaluation record, typically in cases where the record is no longer relevant, contains errors, or needs to be purged for compliance reasons. The operation is irreversible, so it should be used with caution. This tool is part of Borneo's DataBreachManagement functionality, supporting the platform's data protection and privacy management capabilities. It helps maintain an accurate and up-to-date record of data breach evaluations, which is crucial for regulatory compliance and risk management.
- Delete department by id
Deletes a specific department from the Borneo platform using its unique identifier. This endpoint should be used when you need to remove a department that is no longer relevant or has been decommissioned. It's important to note that this operation is irreversible and will permanently remove all data associated with the specified department. Use this endpoint with caution, as it may impact resource management and organizational structure within the Borneo context. Before deletion, ensure that all necessary data has been backed up or transferred to other relevant departments if required.
- Delete domain by id
Deletes a specific domain from the Borneo integration platform. This endpoint permanently removes all data and configurations associated with the specified domain. Use this operation with caution, as it cannot be undone. It should be used when a domain is no longer needed or when cleaning up unused resources. This operation may have cascading effects on related integrations or workflows, so ensure all dependencies are considered before deletion. The API will likely require appropriate authentication and authorization to perform this sensitive operation.
- Delete dpia by id
Deletes a specific Data Protection Impact Assessment (DPIA) from the Borneo system. This endpoint should be used when a DPIA is no longer needed or relevant, such as when a project has been completed or cancelled, or when the assessment needs to be removed due to policy changes. The operation is irreversible, so it should be used with caution. Once deleted, the DPIA and its associated data cannot be recovered through the API. This endpoint is part of Borneo's data privacy management features, allowing organizations to maintain an up-to-date repository of their DPIAs.
- Delete employee by id
Deletes an employee record from the Borneo system using the specified employee ID. This endpoint should be used when an employee leaves the organization or when their record needs to be permanently removed from the system. Once deleted, the employee data cannot be recovered through the API, so use this endpoint with caution. It's recommended to archive or backup employee data before deletion if retention is required for compliance or record-keeping purposes. This operation is final and irreversible within the Borneo platform.
- Delete headquarters by id
Deletes a specific headquarters record from the Borneo system. This endpoint should be used when you need to permanently remove a headquarters entry from your organization's data. It's particularly useful for cleaning up obsolete or erroneous headquarters data. Exercise caution when using this endpoint, as the deletion is irreversible and will remove all associated data for the specified headquarters. Ensure you have the correct headquarterId before proceeding with the deletion to avoid unintended data loss. This operation may have cascading effects on related data, such as employee records or location-based configurations.
Related integrations
Ready to put Borneo to work?
Sign up free, build an app by chatting, and connect Borneo in minutes. No credit card required.