Average GDPR fine: €1.2M · EU AI Act Annex III enforcement: December 2027 (phased)
One platform for GDPR, CCPA, and EU AI Act. Scan, document, monitor, and export audit packs — without a legal retainer.
One-time packs
No recurring charge. Full pricing and scope on each pack's page.
Vibe-Coded Audit
Free scan · from $99
Get the audit →EU AI Act Audit Pack
From $39
What's in the pack →HIPAA Audit Pack
See pricing
See the HIPAA Pack →DORA FinTech Audit Pack
See pricing
See the DORA Pack →AI Agent Evaluation
See pricing
See the evaluation →One-time packs are non-refundable once the deliverable is issued. Exceptions apply for material defects — Terms of Service §5.
Framework add-ons
Add framework-specific monitoring on top of any plan — regulatory change alerts, policy drift detection, and auditor-ready evidence bundles for the frameworks your business is actually subject to.
EU AI Act
$49/moProfessional's bundled monitoring tracks Federal Register filings for your industry (CFPB/SEC, CMS/FDA, or USDA) — it doesn't cover EU AI Act obligations. This add-on layers dedicated alerts on Annex III obligations, GPAI rules, and enforcement deadlines, auto-flagging drift in your AI system policies after each update.
GDPR + CCPA
$49/moProfessional's bundled monitoring tracks Federal Register filings for your industry (CFPB/SEC, CMS/FDA, or USDA) — it doesn't cover GDPR or CCPA. This add-on layers DPA guidance updates, consent management drift alerts, and cross-border transfer rule changes, with a weekly re-scan against your live privacy policy.
HIPAA
$99/moOCR enforcement bulletins and lightweight drift alerts between full re-scans. For the complete quarterly re-scan + refreshed documentation, see the HIPAA Continuous Monitor.
Not yet available — join the waitlist to be notified. Will require an active Starter or Professional subscription.
| Feature | Free | Starter | Professional | Enterprise |
|---|---|---|---|---|
| Website scans / mo | 1 | 10 | 50 | 500 |
| AI system scans / mo | 1 preview | 3 | 15 | 50 |
| GDPR/CCPA document generation | — | |||
| EU AI Act policy generation | — | |||
| All 5 EU AI Act policy types | — | — | ||
| Scan history | — | |||
| Continuous monitoring + alerts | — | — | ||
| Live scan evidence export | — | — | ||
| One-time report purchase | $29 / $39 | $29 / $39 | Included | Included |
| Priority support | — | Priority | Dedicated | |
| API access | — | — | 10,000/mo | Unlimited |
Professional and Enterprise plans include REST API access. Read the API docs
Not ready for a subscription?
One-time Compliance Report — $29 (website) or $39 (AI system)
Scan a single URL or AI system and get a full compliance PDF: all findings, risk flags, and remediation steps. No subscription, no recurring charge. Buy 2 and you're already at Starter territory.
Run a scan to get your reportProfessional and Enterprise plans export a structured JSON/markdown bundle from your live AI system scans — every finding linked to its scan, every policy to its validation status, all timestamped for review.Looking for a one-time EU AI Act compliance binder? See the EU AI Act Audit Pack →
For each included scan: repo URL, EU AI Act Article 6 risk classification (minimal/limited/high/unacceptable), Claude-generated summary, and completion timestamp.
Every detected gap from the scan: category, finding text, severity, raw evidence excerpt from your code or site, and the recommended remediation. Each finding is linked back to the scan that produced it.
Privacy Policy, Cookie Notice, Terms of Service, and EU AI Act policies you generated and approved — only policies in 'passed' or 'approved' state are included; flagged or rejected policies block export until reviewed.
Title, status, creation timestamp, and expiry date — auditable identifiers your DPO or external auditor can reference. Exports as JSON; convert to PDF or DOCX through your in-house tooling as needed.
EU AI Act enforcement is phased: prohibited practices since Feb 2025; GPAI obligations since Aug 2025; high-risk system (Annex III) obligations begin December 2027
All plans include AI system scanning. Starter+ includes full EU AI Act gap analysis and policy generation.
Yes. Cancel at any time and retain access until the end of your billing period.
We offer a 14-day money-back guarantee for new monthly and annual subscriptions. All one-time pack and report purchases are non-refundable once the deliverable is issued, except for material defects as described in our Terms of Service.
All major credit cards via Stripe. Billing is processed in USD, except the DORA FinTech Pack which is billed in EUR.
Website scans analyze your live site for cookies, trackers, third-party services, and legal page coverage (GDPR/CCPA). AI system scans analyze your GitHub repository for EU AI Act compliance — AI model usage, risk classification, transparency obligations, and policy gaps.
Need a custom arrangement or have compliance-specific questions?
Regulatory Signals provides compliance monitoring and evidence collection tools. Generated documents are informational drafts, not legal advice. All output should be reviewed and approved by qualified legal counsel before use. Scans do not constitute certification or guarantee of regulatory compliance. Read our methodology and full disclaimer.