Inth
Also known as: c15t
Privacy change management: scans pull requests and live websites for privacy issues, answers privacy questions with cited evidence, and hosts consent for the open source c15t SDK.
Inth sells privacy change management for software teams that ship fast. It checks each product change against what the company has promised about data. Code Audit scans every pull request, through the Inth GitHub App, for new data flows, trackers, SDKs, logging and vendor calls, including personal data sent to AI services, and proposes code fixes.
Website Audit loads the customer's live pages in chosen regions and compares the scripts, cookies and vendors that load with the consent state and published policies. Inth Agent answers privacy and compliance questions from the product's own scans, consent records and policies, with citations to that evidence and to privacy law, and leaves legal judgment to people. Inth also hosts the consent backend for c15t, its open source (Apache 2.0) consent management SDK for React, Next.js and JavaScript apps.
Findings land in an Inbox for review, with the decision kept beside the change. The platform has a public REST API, a CLI and an MCP endpoint, runs consent projects in a region the customer chooses, and can be self hosted under a BYOC license. Its SOC 2 audits are in progress.
Inth grew out of c15t and is Y Combinator backed.
Vendor details
Canonical URL
https://inth.com
Category
Enterprise operations agent
Subcategory
Privacy change management
Funding status
Pre-Seed; Y Combinator backed, per the Y Combinator listing and Crunchbase.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Inth GitHub App for repository and pull request scans, with findings opened as GitHub issues; Website Audit of the customer's public site; c15t consent integrations for analytics tags and pixels; a REST API with an OpenAPI specification, the Inth CLI and an MCP endpoint.
In practice
A product team connects its repository so every pull request that adds a tracker or sends personal data to a vendor is flagged before merge
A privacy lead checks whether scripts on the checkout page still load only after marketing consent in the EU
A security reviewer asks Inth Agent which vendors receive checkout data and gets an answer citing the scans and the policy
Sources & related URLs
Related / legacy domains
Agentic Index coverage score
6.5 / 14 capabilities · 46%
| Integrations & Tool Calling | Partial |
|---|---|
|
Inth acts in one ecosystem class. Code Audit connects through the Inth GitHub App to read repositories and pull requests, Inbox findings can open GitHub issues, and autofixes propose code changes. Website Audit reads the customer's public site. The c15t integrations (analytics tags and pixels) gate third party scripts behind consent in the customer's app; they are not tools an agent calls. The surface is deep but stays inside GitHub. SourceInth, inth.com/docs llms-full.txt (Code Audit, Inbox, REST API) and c15t.com docsread 2026-09-25 |
|
| Workflow Orchestration | Not documented |
|
No workflow the customer builds or runs. Findings land in an Inbox with statuses and can be routed to a reviewer, which is a review queue, not multi step or multi agent execution. The YC listing mentions code native workflows for consent and data subject requests; the docs describe hosted consent projects and audits, not a workflow model. SourceInth, inth.com/docs llms-full.txt (Inbox, Code Audit, Consent)read 2026-09-25 |
|
| Knowledge Grounding & RAG | Partial |
|
Inth Agent grounds each answer in the customer's own product record: scans, runtime signals, consent configuration and history, decisions, and the policy pages (privacy policy, cookie policy, terms) the customer connects to a project, with citations to that evidence and to privacy law. The context is assembled per question from those records; no maintained index, graph or embeddings layer over the customer's documents is described. SourceInth, inth.com/agent and inth.com/docs llms-full.txt (Inth Agent, Code Audit); inth.com/agent.mdread 2026-09-25 |
|
| Human Oversight & Guardrails | Partial |
|
Decisions are reserved to people, with no approval gate of Inth's own. Code Audit findings are evidence for review, not final legal conclusions; the Agent's answers go to the person reviewing the change and preserve human judgment; findings are routed and the decision is kept beside the change. Autofixes are proposed code changes that land through the customer's own pull request review, a gate the customer already owns. SourceInth, inth.com/agent, /code-audit and /docs llms-full.txt (Code Audit); inth.com/agent.mdread 2026-09-25 |
|
| Security, Identity & Governance | Partial |
|
Access controls are documented, while the compliance attestations are still pending. The REST API names an access model: owner, admin and member roles, with admin or owner required to create projects or manage API keys, OAuth scopes per capability (for example members.write, code-audit.write), and organization API keys carrying a fixed read scoped set. The trust center (Comp AI, trust.inth.com) lists SOC 2 Type 1 and SOC 2 Type 2 as in progress, alongside 25 policies, 35 controls and 3 subprocessors. Neither attestation is complete yet, and privacy governance is what the product sells rather than a statement of its own security posture. SourceInth, trust.inth.com and api.inth.com/openapi.json (securitySchemes)read 2026-09-25 |
|
| Observability & Auditability | Partial |
|
The agent's output carries provenance, not a run trace. Each Code Audit finding keeps cited evidence excerpts and the repository, branch, commit and directory scanned, and Agent answers cite the records behind each claim. No per run view of the steps taken or tools called is described. The consent records and Website Audit runtime signals are the customer's operational estate (end user consent and site behavior), not the agent's activity. SourceInth, inth.com/docs llms-full.txt (Code Audit, Consent records, Inth Agent)read 2026-09-25 |
|
| Memory & State Persistence | Not documented |
|
No memory layer. Inth Agent is organization scoped and answers from the product record, but that record (scans, findings, decisions, consent history) is the application's data model, not memory the agent retains. Consent records stored for end users belong to the consent product. SourceInth, inth.com/docs llms-full.txt (Inth Agent, Consent records)read 2026-09-25 |
|
| Deployment & Data Residency | Full |
|
A documented selection surface and a customer environment option. Each consent project is created in a region the customer chooses (the REST API creates a project and its consent runtime in the chosen region, with a regions endpoint), and the docs tell customers to pick it for data residency. The BYOC license self hosts the entire Inth platform inside the customer's own infrastructure, keeping code and scan data within that boundary, and the open source c15t backend self hosts. SourceInth, inth.com/docs llms-full.txt (Create a consent project, REST API projects), inth.com/pricing and c15t.com self host docsread 2026-09-25 |
|
| Prebuilt Agents / Templates / Packs | Not documented |
|
No prebuilt agents or templates a buyer adopts. Near misses: c15t's consent banner, dialog and widget components are frontend code, and policy packs are region based consent settings the hosted runtime applies as rules. Neither is an agent or template that does work when selected. The YC listing also mentions workflow building blocks. SourceInth, inth.com/docs llms-full.txt (Policy packs) and c15t.com docs (components)read 2026-09-25 |
|
| Triggers & Channel Coverage | Full |
|
Work starts without a caller. Once a repository is linked, pull request automation scans each pull request's diff as it opens (the continuous option; scheduled full repository audits are not offered), and the Startup plan runs scheduled Website Audits. Both an event and a schedule can wake it. SourceInth, inth.com/docs llms-full.txt (Code Audit pull request scans, Pricing)read 2026-09-25 |
|
| Model Flexibility & Routing | Partial |
|
Vendor routed models, no customer choice. Code Audit investigations run AI models through Inth's own AI gateway to its model providers, under zero data retention agreements; the providers are not named and the customer does not select or route models. SourceInth, inth.com/docs llms-full.txt (Code Audit data handling)read 2026-09-25 |
|
| APIs / SDKs / MCP Extensibility | Full |
|
A documented public REST API for Inth's own platform, with an OpenAPI specification (25 paths covering organizations, projects and their consent runtimes, members, API keys, Code Audit scans and issues, Inbox findings and billing), bearer auth with API keys or scoped OAuth tokens, and a versioning and deprecation policy. The Inth CLI (npm @inth/cli, JSON output) and an MCP endpoint with user delegated OAuth 2.1 (api.inth.com/mcp) sit on the same surface. The YC listing also cites c15t npm downloads. SourceInth, api.inth.com/openapi.json and inth.com/docs llms-full.txt (REST API, CLI, Inth MCP)read 2026-09-25 |
|
| Testing, Debugging & Optimization | Not documented |
|
No surface tests or evaluates an agent. Code Audit and Website Audit evaluate the customer's own code and website for privacy issues, which is the product's function over the customer's artifact, not an evaluation of agent behavior; nothing scores or tests Inth Agent's answers or any customer agent. SourceInth, inth.com/docs llms-full.txt (Code Audit, Website Audit)read 2026-09-25 |
|
| Browser / Computer-use | Partial |
|
Website Audit visits the pages the customer lists (the homepage plus up to 20 more, in each chosen region) and records the scripts, cookies, vendors, consent state and Global Privacy Control handling that load, without a person driving it. That is page loading at run time, in the manner of web scraping or a headless fetch; nothing documents the audit clicking, filling or navigating an interface. SourceInth, inth.com/docs llms-full.txt (Website Audit)read 2026-09-25 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
$250/month (Startup)
Credits (10 Credits = $1) on a Free, Startup or Enterprise plan; one time reports quoted after a scan; a BYOC licence for self hosting.
What is public
The Startup price and Credit allowance, the Credit rate, Website Audit per page pricing, and the plan structure (Free, Startup, Enterprise, BYOC).
Billing mechanics
Monthly or annual Startup subscription carrying a Credit allowance (2,500 a month or 30,000 up front a year); audits and extra Credits draw on the balance.
Cost watchouts
Audits draw down Credits: a manual Website Audit costs 10 Credits per page per region, and a one time Code Audit report is quoted after the scan by repository size, domains and issues found. The subscription surfaces up to 30 issues at a time and covers one repository and one domain of typical size.
Variable cost rationale
Audits are metered in Credits on top of the plan's allowance, so spend rises with pages, regions and scans run; the Credit rate is published.
Additional watchouts
Unlimited autofixes and full Inth Agent access sit on the subscription; scheduled full repository audits are not offered, so pull request scans are the continuous option.
Sales call required
No, self serve available
Free / trial
Free workspace and Code Audit preview (issue counts and severity before paying); c15t is open source (Apache 2.0)
Lowest paid plan
Startup, $250/month or $3,000/year
Key ambiguities
One time report prices are set after the first scan, and repository or domain sizes beyond fair use move a customer to a custom plan.
Missing data
Enterprise and BYOC prices, one time report prices, and the full Credit cost per Code Audit scan.
Related vendors
- 11th Estate — Agentic platform whose AI engine scans markets, matches an…
- Adopt AI — AI CPA firm whose agents run reconciliations, close, AP and AR, and…
- Aera Technology — Decision intelligence platform where an always on agent executes…
- Akro AI — On premise operational intelligence that automates document heavy…
- alfred_ — AI executive assistant that triages the inbox overnight and scores…
- Alloy.ai — Commerce intelligence system for consumer brands that unifies four…
Alternatives to Inth
The closest documented capability profiles to Inth among enterprise operations agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Friendly5.0 / 14Adds documented Workflow Orchestration
- monday.com9.0 / 14Adds documented Workflow Orchestration and Prebuilt Agents, Templates & Packs
- ChipAgents4.5 / 14Adds documented Workflow Orchestration and Prebuilt Agents, Templates & Packs
- Hebbia5.5 / 14Adds documented Workflow Orchestration and Prebuilt Agents, Templates & Packs
- Novaworks3.5 / 14Adds documented Workflow Orchestration
- Pluto77.5 / 14Adds documented Workflow Orchestration and Prebuilt Agents, Templates & Packs
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded