The spreadsheet was heroic. It had taken six months, more than one hundred interviews and the concentrated patience of product managers and developers. Its cells described how personal data moved through an ecommerce company. By the time it was finished, it was also becoming a historical document. Product changes had continued. The map had not. There are less expensive ways to discover that software is alive, but few are quite as persuasive.
For Prashant Mahajan and his fellow founders, that assignment supplied the origin story for Privado AI. The problem was not that people had been careless. They had been painstaking. The problem was that the method depended on memory, meetings and a static file while the system it described kept changing. Privacy had been asked to take a group photograph of a moving train.
Mahajan knew something about moving trains. Before co-founding Privado in 2020 with Vaibhav Antil and Jasdeep Cheema, he had spent nine years at PubMatic, where his founder profile identifies him as employee number one. He eventually became a senior director of engineering. PubMatic's machinery belonged to advertising technology, an industry built around speed, distributed systems and the nimble passage of information. A company post describing his journey says those systems served billions of advertisements. His later work would ask a quieter question about similarly busy infrastructure: what, precisely, is in those pipes?
The builder meets the audit
Mahajan's career has the pleasing geometry of a return journey. First came the infrastructure that helped the commercial internet move data at great speed. Then came software designed to account for that movement. The first job prized scale. The second still requires scale, but adds provenance, context and proof. He has not abandoned the machine room for the courtroom. He is trying to give the courtroom an accurate window into the machine room.
That distinction matters because a privacy promise is written in language, while a product behaves in code. A notice may say that a category of data is collected for a particular purpose. The working product may touch an API, write to a log, call a third-party software kit and persist something in a database. Each move can be defensible. Each can also make the original sentence incomplete. Lawyers read the promise. Engineers can see the implementation. Privacy failures often rent the corridor between them.
“You can't govern what you can't see.”Privado's founding thesis
Privado's answer was to look at the software itself. Its scanners identify personal and sensitive data in source code, then inspect where the information is collected, used, shared or stored. APIs, forms, databases, logs and software kits become evidence rather than anecdotes. The resulting map can refresh as code changes. A privacy professional no longer has to ask an engineer to reconstruct six months of decisions from memory, an exercise roughly as delightful as finding a missing receipt during a tax audit.
How code becomes privacy evidence
The premise is usually described as “shifting privacy left,” a phrase that can sound like an instruction for rearranging office furniture. In engineering, left means earlier. A problem found while code is being written is cheaper to repair than one found after launch, after a complaint or after a regulator has developed an interest. Mahajan's 2022 essay on privacy as code argued against two familiar extremes: treating privacy as a blocker at the finish line, or issuing rules from above without enough product context. His preferred territory is continuous, close to the code and useful to the person who can still change it.
From interviews to instruments
By August 2022, the thesis had acquired financial weight. Privado announced $17.5 million in funding, including a $14 million Series A co-led by Insight Partners and Sequoia Capital India, now Peak XV Partners. The seed round earlier that year had been $3.5 million. TechCrunch reported that the company was already monitoring more than 600,000 code commits, had signed six-figure contracts and counted Here.com, Thrasio and Zego among its customers. Its price was tied to the repositories or products it scanned and monitored. Privacy, in other words, was being packaged as infrastructure.
The same year, Privado was named among the North America and Latin America finalists for the IAPP Innovation Awards. Awards are pleasant; operations are sterner. The more revealing measure is what the company kept adding. Code scanning expanded toward dynamic data maps, assessment automation, consent checks across websites and mobile apps, and privacy risk monitoring. The organizing idea remained visibility, but the surface area grew.
Mahajan's public work is strikingly consistent about where privacy becomes real. In a webinar, he spoke about shifting privacy left with code scanning. In his writing, he described classifying data, detecting its sources and destinations, and generating flows that improve as more engineers use the system. In a podcast conversation with Debbie Reynolds, the subject was proactive privacy and the limits of manual processes. The vocabulary changes; the engineering instinct does not. Find the state of the system. Trace what it does. Intervene before harm.
This is also how he now writes about AI governance. His recent public posts break large controversies into production questions. Where did training data enter? Which copy receives a deletion instruction? What happens to an embedding or another derived artifact? How does an age signal propagate from one service to the next? He treats policy as a claim that architecture must be able to prove. In one succinct formulation: “Policies describe intent. Systems determine whether the promise holds.”
An AI model needs context, not the whole kitchen
The arrival of generative AI could have tempted Privado toward the usual fog machine. Mahajan's published explanation of its RoPA automation is more restrained. A Record of Processing Activities is a formal account of how an organization uses personal data. Preparing one can require developers to review thousands of data points and explain the purpose behind them. Privado uses static analysis to narrow the relevant portions of code, then employs generative AI to help describe the processing activity.
The sequence is important. Mahajan wrote that the company does not need to send an entire application to a model. Static analysis first locates the areas of interest. The model receives less material, less often, while gaining the context needed to distinguish one use of data from another. His point is not that the model magically knows privacy law. It is that a careful pipeline can give the model a smaller, better-shaped job.
This context-first approach fits Mahajan's longer story. Advertising technology taught him about distributed systems and data at scale. The failed spreadsheet taught him about the half-life of manual knowledge. Privacy engineering offered a way to join those lessons. Software could watch software, leaving people to judge the cases where purpose, law and consequence cannot be reduced to a rule.
It also explains the sober tone beneath the company's sales language. Automation is not presented merely as a way to save time, although it can. It is presented as protection against omission. A questionnaire records what someone recalls. A scanner can reveal an SDK or data flow nobody thought to mention. Human recollection has many charms. Completeness is not reliably among them.
The second-order engineer
Mahajan is now based in the New York metropolitan area, while Privado describes a team spread across the United States, Europe and India. His education included computer science studies at Fergusson College, after earlier study at HAL College of Science and KTHM College. His public profile lists English, Hindi and Marathi. The geography is broad, but the career has stayed close to systems: Symantec, PubMatic, Privado.
He is connected to two co-founders with complementary roles. Antil leads Privado as chief executive. Cheema is the company's revenue chief. Mahajan owns the technical argument. Their founding story is collective, and so is the product. Privacy software must translate among engineers, lawyers, security leaders and executives, four groups capable of using the same noun to mean four subtly different emergencies.
The company has continued to widen those connections. In 2024, former Google, Uber and Meta privacy leader Nishant Bhajaria joined to build a Privacy Engineering Center of Excellence. In 2025, Privado announced a strategic partnership with KPMG in India as the country developed rules under its Digital Personal Data Protection framework. Mahajan remains CTO and co-founder, appearing in the company's public events and technical explanations.
The useful source of truth was never the spreadsheet. It was the changing system the spreadsheet was trying to remember.
There is a broader idea hiding inside this founder story. The internet's first great engineering challenge was to make information move. The next is to make its movement accountable. Those problems are not opposites. They share queues, services, databases, logs and fallible people. They also share the need for good instruments. Mahajan has worked on both sides of that history, first increasing the speed of the current, then trying to make every branch visible.
His aspiration is not mysterious. Privacy should become proactive, continuous and grounded in evidence. The work is less romantic than a grand promise to fix the internet. It consists of code paths, tickets, inventories and alerts, the bureaucratic furniture of responsible software. Yet this may be precisely why it matters. A principle becomes durable when it survives contact with a release schedule.
The heroic spreadsheet deserves a final word. It failed honestly. It exposed the mismatch between the speed of software and the tempo of compliance, then gave three founders a company to build. Somewhere, perhaps, it still exists: carefully formatted, impressively large and serenely unaware of everything that changed after row one.
Relevant links