We read the asset
We request the target, follow every redirect, and record what it serves and what it sets before you have agreed to anything.
Scan your website, SaaS or AI system and instantly discover compliance risks across multiple regulations. No consultants, no questionnaires, no six-week audit cycle.
Ten rule packs, each versioned and shipping independently. Several are scored only where they genuinely apply — DSA to intermediary services, CRA to software products, DORA to financial entities — and every report states which packs ran and why any were skipped. A score never overstates what was actually checked.
Information duties, lawful basis, transfers, rights, security of processing.
Pre-consent cookies, tracker gating, consent platform, cookie policy.
Art. 50 transparency, AI disclosure, provider disclosure, Annex III signals.
Language, text alternatives, control names, zoom, structure, bypass blocks.
Transport security, headers, framing, vulnerability disclosure channel.
Terms, contact point, notice and action, ad and recommender transparency. Platforms only.
Disclosure policy, SBOM, support period, advisories. Software products only.
ICT risk framework, incident reporting, third-party register, exit terms. Financial entities only.
Readiness signals: security policy, disclosure channel, crypto, suppliers, incidents.
AI policy, impact assessment, human oversight, model inventory, training data.
Privacy information management, extending the ISO 27001 pack.
Enterprise customers can commission private rule packs for sector rules.
Nothing is guessed from a domain name. We fetch the asset, observe how it behaves on first load, run it through the rule engine, and score only the regulations that actually apply.
We request the target, follow every redirect, and record what it serves and what it sets before you have agreed to anything.
Deterministic rules from every active pack execute against the captured evidence. Each rule maps to a specific article — no rule fires without a citation attached.
Rules only count when the regulation genuinely applies. A company with no AI system is never penalised on AI Act rules, and the report says why the pack was skipped.
Findings are weighted by severity into one score, plus a verdict per regulation you can defend in a meeting.
Each domain of evidence feeds rules from several regulations at once — a consent banner is an ePrivacy question and a GDPR question and, on an AI product, an AI Act question.
Whether users are told they are talking to a machine, at the first interaction.
AI Act Art. 50All eight Art. 13 information elements, checked against the text of your notice.
GDPR Art. 13Every cookie set on first load, classified and timed against the consent state.
ePrivacy Art. 5(3)Whether a consent platform exists and whether tags are gated behind it.
ePrivacy · GDPRLanguage, alt text, control names, zoom, headings and bypass mechanisms.
WCAG 2.2 AAHSTS, CSP, framing protection, referrer and permissions policy, TLS enforcement.
NIS2 · CRAWhat each field collects, where it posts, and whether the notice arrives in time.
GDPR Art. 13Third-party pixels and analytics, with the destination country of each flow.
ePrivacy · GDPR Art. 44Conversational surfaces, whether they are AI-driven, and whether they say so.
AI ActWhich model providers you rely on, and whether users and buyers are told.
AI Act · ISO 42001Public signals that your AI system may fall under Annex III high-risk use cases.
AI Act Art. 6Legal notice, terms, cookie policy, sub-processors and disclosure channels.
DSA · GDPR · CRAA page can carry a perfect privacy policy and still break the law in its first response header. Compliance lives in behaviour, not vocabulary — so we score behaviour.
Redirect chain, response headers, embedded third parties, script origins and load order.
Policy pages are fetched and read for the specific information the law requires.
Cookies written and trackers embedded on the very first request, before any interaction.
Frameworks, consent platforms, analytics, chat widgets, AI agents and model SDKs.
The exact cookie, header, element or sentence that triggered the rule. A finding you cannot evidence is not shipped.
Same input, same output, every time. Versioned and auditable — you can prove why a rule fired six months later.
The interpretation layer never invents a finding. It can only keep, downgrade or explain what the rules already proved.
Compliance Score
Weighted by severity across the regulations that apply to you — not by how many rules happened to run.
Generated the moment you unlock it, written to be read by someone who was not in the room when it was produced.
Score, risk band and what to do first, in a paragraph a director can act on.
All of them, with severity, status and the rule id that produced each one.
The exact cookie, header, element or sentence that triggered the rule.
Citations down to the article and paragraph, per finding.
Ordered by priority, with concrete steps rather than “review your approach”.
Wording your team can paste straight into a banner, a form or a policy.
One line per action, ready to become tickets.
This week, this quarter, ongoing — with the scope and limits stated plainly.
The scan and the score cost nothing. You pay for the evidence, the citations and the remediation work you would otherwise buy by the hour.
Scan any asset and see exactly where you stand.
Every finding on the asset, with the proof behind it.
The report, plus the material that turns findings into fixes.
Most people run their first scan before they finish reading this page. The paid report is a decision you make after you have already seen your score.
A website, SaaS product, web app, API endpoint, chatbot or AI agent. No account, no credit card, no sales call.
The asset is fetched and observed under real conditions. Every signal we use is captured and stored as evidence.
Rules run, applicability is resolved, and one number lands — with a per-regulation verdict behind it.
Score, status per regulation and your three highest-priority issues. Enough to know whether you have a problem today.
Every finding, its evidence, the article breached, its priority, and the text to fix it.
Re-scan whenever you like. The dated record becomes your evidence that the issue was found and closed.
What a consultant bills three weeks to assemble, the scan produces while you are still on the call.
Regulators, enterprise buyers and security questionnaires all check the same public surfaces. See what they see first.
Severity weighting puts the issues that actually get companies fined at the top of the list.
Not “review your consent mechanism” — the specific element, the specific fix, the specific wording.
Every report is dated and retained. Demonstrating diligence over time is itself a compliance argument.
Re-scan after each deployment and see immediately when something that used to pass no longer does.
Compliance stopped being a legal-department problem the moment it started depending on what your frontend does in its first second.
One minute now, or a formal request for information later. Both start with the same page.