Every Regulatory Signals product, in one place.
Scan-driven evidence — not policy templates — across GDPR, CCPA, EU AI Act, HIPAA, DORA, and OWASP LLM Top 10. 9 products. One subscription.
What do you ship? Go straight to your product.
Comply with a regulation
Free scan → report → audit pack → continuous monitor, mapped to the regulations that apply to you.
EU AI Act risk checks, reports, audit pack, and policies — one program.
HIPAA Audit Pack and Continuous Monitor for healthtech AI vendors.
DORA FinTech Audit Pack and Continuous Monitor for EU/UK financial firms.
Free website compliance scan, paid report, and daily regulatory feed.
Audit an AI artifact
Independent security and compliance audits for codebases, MCP servers, extensions, and AI agents.
AI-generated codebase audit — Claude, Codex, Gemini, Cursor, Copilot, Lovable.
10 MCP-specific security rules. Signed cert. Public registry listing.
Browser extension security and privacy audit — permissions and data flows.
Independent eval of AI agents — behaviour, safety, and regulatory readiness.
Trust Registries
Searchable, publicly verifiable registries of audited MCP servers, extensions, and AI agents.
Searchable registry of audited MCP servers, extensions, and AI agents.
Frequently asked questions
What regulations does Regulatory Signals cover?
GDPR, CCPA, ePrivacy, EU AI Act, HIPAA, DORA (FCA/BaFin/AMF), OWASP LLM Top 10, CWE, CFPB, and SEC regulations. Coverage depends on the product — each product page lists its regulation scope.
What is the difference between a scanner and an audit pack?
Scanners generate live evidence from your code, site, or repo. Audit packs take that evidence and produce regulator-ready documents (risk assessments, incident protocols, policy binders) that satisfy enterprise procurement questionnaires and regulatory inquiries.
Do I need all products, or can I buy one at a time?
You can start with any single product. Most teams start with the free Website Compliance Scan, then add the EU AI Act Audit Pack when they face a procurement questionnaire. A Professional subscription includes all scanners, audit packs, and monitoring.
What are the MCP and Extension Trust Registries?
Public, searchable registries of MCP servers and browser extensions that have passed an independent Regulatory Signals security audit. Enterprise security teams use these registries to build approved allowlists for their Claude and Anthropic deployments.
How is Regulatory Signals different from a policy generator or questionnaire-based platform?
Policy generators produce template documents. Questionnaire-based platforms collect self-reported evidence. Regulatory Signals runs live code and site scans and generates evidence from what your system actually does — not from what you claim it does. The difference matters when a regulator or enterprise buyer asks for technical evidence, not just a policy document.
Not sure where to start? Read how the scans work or compare plans and pricing.
Start with a free scan