Compliance guides and free tools,
and what to open first.
Everything we publish, arranged by the situation you are in rather than by what kind of document it is. The free tools need no account and send nothing to us; the guides are written to be useful rather than to rank, and are reviewed as the rules change.
A customer just asked for our privacy policy
Name your processors in it. "Trusted third parties" is the single most common finding in a privacy review, and the fix costs nothing at drafting time.
A cookie audit found trackers firing before consent
Scan first so the policy describes what the site does rather than what you remember. The scan output feeds the generator directly.
We have a DPDP deadline and no programme
Read the build order before the law. The obligations arrive in a sequence, and starting with policies because they are quick to write is how these programmes stall.
Someone asked whether the EU AI Act applies to us
Check the dates first: the Digital Omnibus moved standalone high-risk obligations to 2 December 2027, and a great deal of published guidance still says August 2026.
An enterprise deal is stuck in security review
The readiness check will tell you in five minutes which area the questionnaire is going to expose. Usually data mapping.
We need to know what non-compliance would cost
Note the structural difference: DPDP sets fixed rupee maxima, the AI Act scales with turnover, and for SMEs the AI Act applies the lower of the two figures rather than the higher.
We are adding a second framework
Ask what the delta actually is before committing to a date. Companies holding SOC 2 usually find most of ISO 27001 already evidenced and almost none of DPDP's notice and consent work.
We had a security incident and the clock is running
CERT-In's six hours usually expires first, often before the facts are known. Report what you know, then complete it; the DPDP 72-hour report comes later and needs the detail.
A customer asked for our SOC 2 report
If there is no report yet, say so and share a readiness summary and a date. A bridge letter only covers the gap after a report exists.
We are an AI start-up and buyers want proof
Security questions usually come first, so SOC 2 tends to lead; ISO 42001 answers the AI governance question when buyers start asking it.
We run a SaaS product with users in Europe or India
For customer data you are usually a processor, so most duties arrive through customers' contracts. For your own sign-ups and website you are the controller or fiduciary.
We do not know if we need a cookie banner
Anything beyond strictly necessary, such as analytics or ad pixels, needs consent before it loads for EU, UK and Indian visitors. California asks for an opt-out instead.
We are not sure the DPDP Act applies to us
It almost certainly does if you process digital personal data of people in India. The exemptions are narrower than most teams assume.
We are choosing a compliance tool or setting up a programme
Pick the tool after you know the frameworks, the evidence they need and who owns each control. Most of the cost is the work, not the software.
We sell to US customers
California sets the bar, and a dozen states now require honouring opt-out signals such as GPC. HIPAA applies only if you handle protected health information for a covered entity.
We sell into the EU or UK
For most SaaS companies GDPR arrives through customer DPAs and transfer clauses. NIS2 and DORA reach you if you are in scope yourself or supply someone who is.
We sell in Australia or the UAE
Australia's 2024 reforms added a statutory privacy tort and new transparency duties. In the UAE, which law applies depends on whether you sit inside a financial free zone.
An enterprise or public-sector buyer wants a VPAT, an SLA or proof of performance
Procurement asks the same things every time: security evidence, a DPA, an accessibility report and reliability evidence. Start with the readiness list.
A customer or auditor is asking about our vendors
SOC 2, ISO 27001, GDPR, DORA, NIS2 and APRA CPS 230 all ask the same core question: which suppliers touch your data or your service, and how you checked them. Tier by access, not spend.
We are doing a DPIA or building a risk register
A DPIA assesses risk to individuals from one processing activity; a risk register scores risk to the organisation. Findings from the first should feed the second, linked back.
How this material is maintained
Two things are worth knowing about anything you read here, because they determine how much weight to put on it.
Dates are verified, and dated. Regulatory timelines in this area move: the EU AI Act's high-risk deadline shifted by sixteen months in July 2026, and a large share of published guidance still quotes the old date. Where a page states a date it also states when that was last checked, so you can judge whether to re-verify.
None of it is legal advice, and the generators are starting points. A generated policy describes what you tell it you do. Whether your systems actually behave that way is the thing an auditor tests and the thing no document can establish. Have counsel review anything you publish.
What each kind of page is for
| Answers | Good for | |
|---|---|---|
| Guides/dpdp, /eu-ai-act, penalties pages | What the law requires, and when | Understanding an obligation, briefing a colleague, checking a date |
| Solutions/solutions/* | What you do about it, in what order, and who owns each step | Planning a programme, scoping the work, assigning it |
| Free tools/tools/*, /scan | Your own situation, specifically | Producing a document or a score today, with no account |
| Product pages/platform, /consent, /risk | How the platform does it | Evaluating whether to buy, and what it would replace |
The split between a guide and a solutions page is deliberate: one carries the law, the other the work.
The things people ask us
Are the free tools really free?
Yes. No account, no email gate, no trial period. Four of the five run entirely in your browser and transmit nothing; the cookie scanner runs on our infrastructure because loading your site is the only way to observe what it does, and it asks for nothing but the URL.
What is the difference between a guide and a solutions page?
A guide explains what the law requires: obligations, tiers, dates, penalties. A solutions page explains what you do about it: the order of operations, which team owns each step, and what each step produces. They are written for different moments and deliberately do not repeat each other.
How current are the regulatory dates?
Each page states when its dates were last verified. This matters more than usual right now: the EU AI Act's standalone high-risk deadline moved from 2 August 2026 to 2 December 2027 under Regulation (EU) 2026/1744 in July 2026, and much published guidance has not been updated.
Can we use the generated documents commercially?
Yes, on your own site and under your own name, with no attribution required. They are starting points written to be edited, and should be reviewed by counsel against how your organisation actually processes data before you publish them.
Do you publish results from the cookie scanner?
Only in aggregate and anonymised. Results for a named company go to that company, privately.
When the reading is done, see it running.
We connect one account live and show real evidence landing in the ledger before the call ends.