Platform Capabilities
Nine integrated tools.
One compliance posture.
Regulatory Signals covers the full evidence chain — from first scan to audit-ready evidence pack. Every output traces back to a detected signal, every policy to a validation outcome, every finding to the scan that produced it.
Deep Website Privacy Scan
What it does
A headless browser loads your site twice — once with consent accepted, once with consent declined — and fingerprints every cookie, tracker, third-party service, and form. Each detected signal is matched against a 60k+ tracker domain database (DDG Tracker Radar) and classified by category and confidence.
What it outputs
A scan report with: cookie inventory, tracker classification, third-party services list, legal page adequacy check (GDPR Art. 13 / CCPA disclosure), and a regulation-trigger list explaining why each obligation applies to your site.
AI System Risk Classification
What it does
Paste a GitHub repository URL. We analyse code, dependencies, and configuration for AI/ML model usage, then classify your system under EU AI Act Article 6 — minimal, limited, high, or unacceptable risk — with the documentation obligations each tier carries.
What it outputs
A risk-classified scan with finding-level evidence: model detection, training data signals, transparency obligation gaps, and human oversight requirements. Each finding links to a recommended remediation and policy template.
Vibe-Coded App Audit
What it does
Paste a GitHub repository URL and we pull dependencies, lockfiles, README, and architecture signals. Deterministic checks run first — rate limiting gaps, unchecked fetch() responses, webhook silent-success, broken button→route contracts, and non-Stripe payment handler verification — then Claude analyses for supply-chain risk, security posture, and compliance readiness.
What it outputs
A 0–100 score across security, dependency health, and compliance, with an architecture summary and prioritised remediation list. Free preview includes the headline score; the full report unlocks via one-time purchase.
Policy Document Generation
What it does
Generate Privacy Policy, Cookie Notice, Terms of Service, and the full EU AI Act policy bundle (Articles 9, 10, 11, 13, 14) from your scan output. Every clause traces back to a detected signal — no generic templates, no boilerplate that doesn't apply.
What it outputs
Each document is marked passed, flagged, or rejected. Flagged policies block audit-pack export until reviewed. Documents render in markdown ready for your CMS or legal review pipeline.
Audit Pack Export
What it does
Bundle completed scans, finding-level evidence, and validated policies into a timestamped evidence pack. Each pack carries a status, creation date, and expiry — a timestamped record your DPO or external auditor can reference.
What it outputs
A structured JSON/markdown bundle covering scan summaries, every finding (with severity, evidence, and recommendation), and approved policies. Flagged or rejected policies block export until human review unblocks them.
Compliance Monitor
What it does
Pick your industry — fintech, healthtech, or food — and we run a daily cron across the regulatory feeds for your sector (CFPB/SEC, CMS/FDA, or USDA). New rules, guidance documents, and enforcement actions surface in your dashboard within hours of publication.
What it outputs
Per-change cards with the original source link, a plain-English summary, and the specific actions required of your team. No more email triage, no more PDF parsing — just the changes that matter for your industry.
Audit Logs & Policy Review
What it does
Every AI interaction, every policy generation, and every validation outcome lands in an immutable audit log. Flagged policies are queued for human review — visible across all plans because governance is a baseline requirement, not a paid add-on.
What it outputs
A paginated log of AI interactions and policy events plus a flagged-policies review queue. Each entry links to the underlying scan or policy version for full traceability — what regulators expect when they ask 'how did this document get approved?'
REST API
What it does
Connect your CI/CD pipeline to Regulatory Signals. Log AI interaction events from build and deploy workflows for EU AI Act audit trails, retrieve scan findings — rate limiting gaps, unchecked fetch() responses, webhook silent-success, and broken button→route contracts — and route compliance signals into your governance dashboards. Versioned, API-key-authenticated.
What it outputs
Structured interaction logs (risk scores, human-oversight flags, intent categories) with cursor-based pagination; scan finding retrieval including all deterministic check results; API key management. Pro plans include 10,000 calls/month; Enterprise plans are unmetered.
MCP Audit Tool
What it does
Install @regulatorysignals/mcp and ask your AI assistant to audit any GitHub repo — no browser required. The MCP server connects directly to your Regulatory Signals API key and exposes two tools: audit_repository for full AI-powered analysis (score, dependency risks, security findings, compliance gaps) and check_repository for instant deterministic checks (rate limiting, webhook handling, button→route contracts) that consume no quota.
What it outputs
audit_repository returns a 0–100 score with prioritised findings and remediation recommendations — same output as the dashboard, delivered in-conversation. check_repository returns a pass/fail checklist in seconds. Both tools authenticate via your existing API key; full audits count against your plan's monthly scan quota.
Ready to map your compliance gaps?
Run a free scan now — no sign-up required for preview. Full results, policy generation, and audit packs unlock with a Starter or Pro plan.