Every Regulatory Signals product, in one place.

Scan-driven evidence — not policy templates — across GDPR, CCPA, EU AI Act, HIPAA, DORA, and OWASP LLM Top 10. 9 products. One subscription.

Comply with a regulation

Free scan → report → audit pack → continuous monitor, mapped to the regulations that apply to you.

EU AI Act Compliance

EU AI Act risk checks, reports, audit pack, and policies — one program.

EU AI Act
EU AI Act Readiness CheckFree
AI System Risk ScanIncluded in Starter ($49/mo)
AI System Report$39 one-time
EU AI Act Audit Pack$39 one-time
AI Policy GeneratorIncluded in Starter ($49/mo)
Free readiness check, plans from $39View product
HIPAA Compliance

HIPAA Audit Pack and Continuous Monitor for healthtech AI vendors.

HIPAAHHS OCR
HIPAA Audit Pack$9,990 one-time
HIPAA Continuous Monitor$1,990/quarter
$9,990 one-time, monitor from $1,990/quarterView product
DORA Compliance

DORA FinTech Audit Pack and Continuous Monitor for EU/UK financial firms.

DORAFCABaFinAMF
DORA FinTech Audit Pack€4,990 one-time
DORA Continuous Monitor$499/month
€4,990 one-time, monitor from $499/monthView product
Website Privacy

Free website compliance scan, paid report, and daily regulatory feed.

GDPRCCPAePrivacy
Website Compliance ScanFree
Website Report$29 one-time
Daily Regulatory FeedIncluded in Professional ($249/mo)
Free scan, report from $29View product

Audit an AI artifact

Independent security and compliance audits for codebases, MCP servers, extensions, and AI agents.

Codebase Audit

AI-generated codebase audit — Claude, Codex, Gemini, Cursor, Copilot, Lovable.

OWASPGDPR
Free ScanFree
Codebase Audit$99 one-time
Re-Scan Monitor$49/month
Free scan, then $99 audit or $49/mo monitorView product
MCP Server Audit

10 MCP-specific security rules. Signed cert. Public registry listing.

OWASP LLM Top 10CWE
MCP Server Audit$499 one-time
Continuous Monitoring$99/month
$499 one-time, monitor from $99/monthView product
Extension Audit

Browser extension security and privacy audit — permissions and data flows.

GDPRCCPA
Extension Audit$299 one-time
Annual Registry Listing$499/year
$299 one-time, listing from $499/yearView product
Agent Evaluation

Independent eval of AI agents — behaviour, safety, and regulatory readiness.

EU AI Act
$4,990 one-timeView product

Trust Registries

Searchable, publicly verifiable registries of audited MCP servers, extensions, and AI agents.

Trust Registries

Searchable registry of audited MCP servers, extensions, and AI agents.

EU AI ActGDPR
Free listingView product

Frequently asked questions

What regulations does Regulatory Signals cover?

GDPR, CCPA, ePrivacy, EU AI Act, HIPAA, DORA (FCA/BaFin/AMF), OWASP LLM Top 10, CWE, CFPB, and SEC regulations. Coverage depends on the product — each product page lists its regulation scope.

What is the difference between a scanner and an audit pack?

Scanners generate live evidence from your code, site, or repo. Audit packs take that evidence and produce regulator-ready documents (risk assessments, incident protocols, policy binders) that satisfy enterprise procurement questionnaires and regulatory inquiries.

Do I need all products, or can I buy one at a time?

You can start with any single product. Most teams start with the free Website Compliance Scan, then add the EU AI Act Audit Pack when they face a procurement questionnaire. A Professional subscription includes all scanners, audit packs, and monitoring.

What are the MCP and Extension Trust Registries?

Public, searchable registries of MCP servers and browser extensions that have passed an independent Regulatory Signals security audit. Enterprise security teams use these registries to build approved allowlists for their Claude and Anthropic deployments.

How is Regulatory Signals different from a policy generator or questionnaire-based platform?

Policy generators produce template documents. Questionnaire-based platforms collect self-reported evidence. Regulatory Signals runs live code and site scans and generates evidence from what your system actually does — not from what you claim it does. The difference matters when a regulator or enterprise buyer asks for technical evidence, not just a policy document.