๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Data Flow Documentation

Know exactly what data moves where, and who touches it.

Most teams cannot say, on demand, which vendors process their data or where it flows between systems. Auditors ask, clients ask, and incident response depends on it. Lavawall® keeps an internal register of your data flows and subprocessors, auto-filled from the Data Flows module in your Business Impact Assessment, with retention and encryption expectations and a quarterly rhythm to keep it honest.

It uses data you already have, and it is written in plain language, so the register is something your whole team can read, not just your security lead.

Start with the GRC Wizard See the full GRC platform

Auto-filled from your BIA · subprocessor register · retention & encryption · quarterly reconciliation

A register that fills itself in

Two themes run through it

First, it uses data you already have. Lavawall reads the data flows and vendors in your Business Impact Assessment and drafts the register for you. Second, it is written in plain language, so anyone on your team can follow what moves where, without a security background.

Auto-filled from the BIA Data Flows module

Every flow you captured in the Business Impact Assessment (which system sends what to which system, and which vendor sits behind it) becomes a row in the register. The subprocessors are pulled from the same source, so the internal list stays consistent with the rest of your compliance records.

Retention expectations, on every flow

Each flow records how long the information is expected to be kept, so you can show a retention position instead of improvising one during an audit or a data request.

Encryption expectations, in and at rest

The register notes how information is expected to be protected in transit and at rest for each flow, giving you a single place to check that sensitive movement is covered.

Kept current, not left to rot

A data flow register is only useful if it matches reality. Lavawall builds a quarterly reconciliation into the document so it stays true without becoming a project.

Confirm what is still true

Each quarter, tick off the flows and subprocessors that still match how you operate.

Retire what you have dropped

Mark vendors and flows you no longer use so the register does not carry ghosts.

Add what is new

Fold in the tools and flows you picked up since last quarter, prompted by what Lavawall detects.

Leave a dated trail

Each reconciliation is timestamped, so you can show an auditor the register is maintained, not stale.

What it saves you from

The scramble when an auditor asks

“Show me your data flows and subprocessors” is a routine request. A living register answers it in minutes instead of a week of interviews.

The blind spot during an incident

When a vendor is breached, the first question is what data they hold and where it flows. The register tells you immediately which flows are affected.

The drift that makes documents worthless

Untended registers go stale within a quarter. The built-in reconciliation keeps yours matching the environment it describes.

Before you rely on it

This register is a starting draft generated from your records. The retention and encryption expectations it lists are defaults to review, not guarantees about your systems. Have your legal counsel or security advisor confirm the details before you rely on it as evidence or share it externally.

Part of the wider GRC platform

Business Impact Assessment

The Data Flows module that fills this register, captured once in plain language.

Learn more →

Foreign Processing Disclosure

The client-facing notice of where data is processed, drawn from the same flows.

Learn more →

Privacy Policy addendum

The public addendum that names subprocessors and international processing.

Learn more →

Common questions

What is data flow documentation?
An internal register that records what information moves between your systems, which vendors and subprocessors touch it, where it is processed, how long it is kept, and how it is encrypted. Lavawall builds yours automatically from the Data Flows module in your Business Impact Assessment, so it reflects your real environment instead of a template.
Where does the register get its data?
From data you already have. Lavawall reads the data flows and vendors captured in your Business Impact Assessment and fills the register in for you. You review and confirm rather than build it from memory.
How do I keep it accurate?
The register comes with quarterly reconciliation instructions. Each quarter you confirm the flows and subprocessors still match reality, retire anything you have stopped using, and add anything new. Because it is fed by your connected tools and BIA, most of the work is confirming, not typing.
Does it cover retention and encryption?
Yes. Each flow records how long the information is expected to be retained and how it is expected to be encrypted in transit and at rest. These are starting expectations to review with your advisors, not guarantees.

Start with the GRC Wizard →See the full GRC platform