How it works

How it works.

A short walk through the methodology, the primary legal sources we rely on, the update cadence, and where humans review the output before it reaches a customer.

01 · Methodology

Two passes, with humans reviewing the second.

Each scan runs in two passes. The first pass is deterministic. We parse your code, read your dependency manifests, and check your product surfaces for specific patterns: a cookie banner that sets non-essential cookies before consent, a checkout button without the required wording, a missing cancellation flow. The output is a list of factual observations about what the code does.

The second pass uses a language model, but in a narrow way. For each structured requirement, we pass a small set of relevant code snippets and ask a single question with a fixed answer space (yes, no, or insufficient context). The model works against the testable form of the requirement and returns a finding only when it can cite the article and paragraph it relates to.

Every finding has a confidence score. High confidence comes from a deterministic match and goes straight to the board. Medium confidence is reviewed by an analyst on our team before delivery. Low confidence is held back and only released after a human upgrades or discards it.

High confidence

Deterministic match against a structured requirement. Auto-published to the board.

Medium confidence

AI-assisted reasoning with a clear primary source. Reviewed by an analyst before delivery.

Low confidence

Ambiguous signal or insufficient context. Held back until verified or discarded.

02 · Sources

Primary legal sources. Browsable. Public.

Every regulation we track is listed here with a link to the primary source: EUR-Lex, the national gazette, or the official government publication. Not blog posts. Not LLM training data. Not secondary summaries.

This list is fully public. If you're evaluating us, copy it, send it to your counsel, and verify any entry directly at the source.

62 of 62
RegulationMarketDomainPrimary sourceLast reviewedStatus
General Data Protection Regulation
GDPR
EUData & privacyEUR-Lex 32016R06792026-05-12Enacted
ePrivacy Directive
2002/58/EC
EUTelecom & ePrivacyEUR-Lex 32002L00582026-04-30Enacted
Digital Services Act
DSA
EUPlatforms & contentEUR-Lex 32022R20652026-05-19Enacted
Digital Markets Act
DMA
EUPlatforms & contentEUR-Lex 32022R19252026-05-19Enacted
AI Act
Regulation (EU) 2024/1689
EUAI & algorithmsEUR-Lex 32024R16892026-05-20In force, phased
Data Act
Regulation (EU) 2023/2854
EUData & privacyEUR-Lex 32023R28542026-04-22Enacted
Data Governance Act
DGA
EUData & privacyEUR-Lex 32022R08682026-03-11Enacted
NIS2 Directive
2022/2555
EUData & privacyEUR-Lex 32022L25552026-04-08Enacted
Cyber Resilience Act
CRA
EUProduct safetyEUR-Lex 32024R28472026-05-02In force, phased
Consumer Rights Directive
CRD 2011/83/EU
EUConsumer protectionEUR-Lex 32011L00832026-02-26Enacted
Unfair Commercial Practices Directive
UCPD
EUConsumer protectionEUR-Lex 32005L00292026-02-26Enacted
Omnibus Directive
2019/2161
EUConsumer protectionEUR-Lex 32019L21612026-02-26Enacted
Sale of Goods Directive
2019/771
EUConsumer protectionEUR-Lex 32019L07712026-01-30Enacted
Digital Content Directive
2019/770
EUConsumer protectionEUR-Lex 32019L07702026-01-30Enacted
Geo-blocking Regulation
2018/302
EUConsumer protectionEUR-Lex 32018R03022026-02-04Enacted
European Accessibility Act
EAA 2019/882
EUAccessibilityEUR-Lex 32019L08822026-05-06In force, phased
Web Accessibility Directive
2016/2102
EUAccessibilityEUR-Lex 32016L21022026-03-18Enacted
PSD2
Payment Services Directive
EUPayments & financeEUR-Lex 32015L23662026-04-15Enacted
PSR / PSD3 (proposal)
EUPayments & financeEUR-Lex COM/2023/3672026-05-09In draft
MiCA
Markets in Crypto-Assets
EUPayments & financeEUR-Lex 32023R11142026-04-15Enacted
DORA
Digital Operational Resilience Act
EUPayments & financeEUR-Lex 32022R25542026-03-25Enacted
eIDAS 2
Regulation (EU) 2024/1183
EUData & privacyEUR-Lex 32024R11832026-04-02In force, phased
GPSR
General Product Safety Regulation 2023/988
EUProduct safetyEUR-Lex 32023R09882026-04-29Enacted
CLP Regulation
1272/2008
EUProduct safetyEUR-Lex 32008R12722026-01-22Enacted
REACH Regulation
1907/2006
EUProduct safetyEUR-Lex 32006R19072026-01-22Enacted
VAT Directive
2006/112/EC
EUTax & invoicingEUR-Lex 32006L01122026-03-04Enacted
ViDA package
VAT in the Digital Age
EUTax & invoicingEUR-Lex COM/2022/7012026-05-15In draft
CSRD
Corporate Sustainability Reporting Directive
EUSustainabilityEUR-Lex 32022L24642026-03-12Enacted
Green Claims Directive (proposal)
EUSustainabilityEUR-Lex COM/2023/1662026-05-09In draft
Empowering Consumers for the Green Transition
Directive (EU) 2024/825
EUSustainabilityEUR-Lex 32024L08252026-04-21Enacted
Right to Repair Directive
2024/1799
EUSustainabilityEUR-Lex 32024L17992026-04-21Enacted
Buttonlösung
§ 312j BGB
GermanyConsumer protectionGesetze im Internet · BGB § 312j2026-05-14Enacted
Kündigungsbutton
§ 312k BGB
GermanyConsumer protectionGesetze im Internet · BGB § 312k2026-05-14Enacted
Telekommunikation-Telemedien-Datenschutz-Gesetz
TTDSG / TDDDG
GermanyTelecom & ePrivacyBundesgesetzblatt · TTDSG2026-03-28Enacted
Bundesdatenschutzgesetz
BDSG
GermanyData & privacyGesetze im Internet · BDSG2026-03-28Enacted
Verpackungsgesetz
VerpackG
GermanySustainabilityGesetze im Internet · VerpackG2026-02-12Enacted
Loi Hamon
Loi n° 2014-344
FranceConsumer protectionLégifrance · Loi 2014-3442026-04-10Enacted
Loi Informatique et Libertés
FranceData & privacyLégifrance · Loi 78-172026-03-30Enacted
Loi AGEC
anti-gaspillage
FranceSustainabilityLégifrance · Loi 2020-1052026-02-18Enacted
Loi REEN
Réduction empreinte env. du numérique
FranceSustainabilityLégifrance · Loi 2021-14852026-02-18Enacted
Loi SREN
Sécuriser et réguler l'espace numérique
FrancePlatforms & contentLégifrance · Loi 2024-4492026-05-07Enacted
E-invoicing reform (Factur-X)
FranceTax & invoicingimpots.gouv.fr · facturation électronique2026-05-15In force, phased
Codice del Consumo
D.Lgs. 206/2005
ItalyConsumer protectionGazzetta Ufficiale · D.Lgs. 206/20052026-03-05Enacted
Codice Privacy
D.Lgs. 196/2003
ItalyData & privacyGarante Privacy · Codice2026-03-05Enacted
Fatturazione elettronica (SDI)
ItalyTax & invoicingAgenzia delle Entrate · SDI2026-04-18Enacted
LSSI-CE
Ley 34/2002
SpainTelecom & ePrivacyBOE · Ley 34/20022026-03-12Enacted
LOPDGDD
LO 3/2018
SpainData & privacyBOE · LO 3/20182026-03-12Enacted
Ley General para la Defensa de Consumidores
RDL 1/2007
SpainConsumer protectionBOE · RDL 1/20072026-03-12Enacted
Ley Crea y Crece (e-invoicing B2B)
Ley 18/2022
SpainTax & invoicingBOE · Ley 18/20222026-05-05In force, phased
Uitvoeringswet AVG
UAVG
NetherlandsData & privacyOverheid.nl · UAVG2026-02-20Enacted
Telecommunicatiewet (cookie rules)
NetherlandsTelecom & ePrivacyOverheid.nl · Telecommunicatiewet2026-02-20Enacted
Code de droit économique – Livre VI
BelgiumConsumer protectionMoniteur belge · CDE2026-02-08Enacted
Marknadsföringslagen
SFS 2008:486
SwedenConsumer protectionRiksdagen · SFS 2008:4862026-02-15Enacted
Markedsføringsloven
DenmarkConsumer protectionRetsinformation · LBK 866/20192026-02-15Enacted
Markkinointioikeus
Kuluttajansuojalaki
FinlandConsumer protectionFinlex · 38/19782026-02-15Enacted
UK GDPR + Data Protection Act 2018
United KingdomData & privacylegislation.gov.uk · DPA 20182026-04-02Enacted
PECR
Privacy and Electronic Communications Regulations
United KingdomTelecom & ePrivacylegislation.gov.uk · PECR 20032026-04-02Enacted
Online Safety Act 2023
United KingdomPlatforms & contentlegislation.gov.uk · OSA 20232026-05-08In force, phased
Digital Markets, Competition and Consumers Act 2024
DMCCA
United KingdomConsumer protectionlegislation.gov.uk · DMCCA 20242026-05-08In force, phased
Data Protection Act 2018
IrelandData & privacyIrish Statute Book · DPA 20182026-03-19Enacted
revFADP / nFADP
Federal Act on Data Protection
SwitzerlandData & privacyFedlex · SR 235.12026-03-25Enacted
Personopplysningsloven
NorwayData & privacyLovdata · LOV-2018-06-15-382026-02-28Enacted

Coverage grows weekly. Missing a regulation that matters to you? Tell us and we'll prioritize it.

03 · Update cadence

Daily monitoring. Weekly review. Monthly horizon scan.

Daily. Automated polling of regulatory databases and gazettes for new publications, amendments, and implementing acts. Diffs are queued for analyst triage within the same day.

Weekly. Our team reviews every diff, classifies the change, updates affected structured requirements, and re-evaluates rules that depend on them.

Monthly. A deep review of upcoming regulations, trilogues, draft acts, and regulator guidance. This is what feeds the 12-month forward-looking horizon you see on the board.

When something changes, customers on monitoring plans get a notification with the specific impact on their product, not a generic "the regulation moved" email.

EUR-Lex

EU primary law

Légifrance

France

Bundesgesetzblatt

Germany

Gazzetta Ufficiale

Italy

BOE

Spain

Overheid.nl

Netherlands

legislation.gov.uk

United Kingdom

Lovdata · Fedlex

Norway · Switzerland

04 · Structured requirements

From legal prose to testable rules.

We decompose every regulation into machine-readable requirements with a clear pass/fail condition. That is what the scanner evaluates. Not the prose. Not a summary.

Here is what that looks like for one well-known example: the German Buttonlösung (§ 312j BGB), which requires that any button on a paid order page makes the payment obligation unambiguous to the user.

Source · § 312j BGB

"Die Schaltfläche muss gut lesbar mit nichts anderem als den Wörtern 'zahlungspflichtig bestellen'oder mit einer entsprechenden eindeutigen Formulierung beschriftet sein."

The button must be legibly labeled with nothing other than "order with obligation to pay" or an equivalent, unambiguous formulation.

Structured requirement

id: DE-BGB-312j-3
market: DE
source: gesetze-im-internet.de/bgb/__312j.html
appliesTo: checkout.submitButton
test:
  buttonLabel:
    matches:
      - "zahlungspflichtig bestellen"
      - "kostenpflichtig bestellen"
      - "kaufen"
    rejects:
      - "weiter"
      - "bestellen"
      - "jetzt anmelden"
severity: high

Failing example

<button type="submit" onClick={pay}>
  Weiter
</button>

Label is ambiguous about the payment obligation. Scanner flags as high.

Passing example

<button type="submit" onClick={pay}>
  Zahlungspflichtig bestellen
</button>

Label matches the statutory phrasing. Scanner passes the check and records the source line.

05 · Accuracy & feedback

We track our false positives. Out loud.

We are in early audits. The dataset is not yet big enough for a number we'd be comfortable publishing, and we'd rather say that than invent one. We will publish the aggregate false positive rate on this page the moment it becomes statistically meaningful.

Every disputed finding is reviewed by an analyst. If the dispute is right, the rule is refined, the structured requirement is updated, and the change ships into the next scan for every customer. The product gets sharper with every audit.

You can dispute a finding directly from the board. We respond within one business day with a verdict and, if we changed the rule, a diff of what changed and why.

06 · What we don't do

We are not a law firm.

We do not give legal opinions. We do not guarantee compliance. We do not replace your lawyer, your DPO, or your local counsel.

We surface engineering-actionable findings traceable to primary legal sources, so your team can ship a product that stands a fair chance of passing the audit your lawyer eventually runs.

For formal legal opinions, retain qualified counsel in the jurisdiction. We can recommend several we trust.