GDPR · ePrivacy · EU AI Act · WCAG · NIS2

Know if your business complies — before regulators do.

Scan your website, SaaS or AI system and instantly discover compliance risks across multiple regulations. No consultants, no questionnaires, no six-week audit cycle.

No registration required. Free summary in under 60 seconds. Results are never published.
WebsitesSaaSWeb appsAPIsChatbotsAI agentsMarketplacesFintech
reginspector.com/scan
Idle
Regulatory coverage

One scan, every framework that applies to you.

Ten rule packs, each versioned and shipping independently. Several are scored only where they genuinely apply — DSA to intermediary services, CRA to software products, DORA to financial entities — and every report states which packs ran and why any were skipped. A score never overstates what was actually checked.

GDPRLive

Information duties, lawful basis, transfers, rights, security of processing.

ePrivacyLive

Pre-consent cookies, tracker gating, consent platform, cookie policy.

EU AI ActLive

Art. 50 transparency, AI disclosure, provider disclosure, Annex III signals.

WCAG 2.2 AALive

Language, text alternatives, control names, zoom, structure, bypass blocks.

NIS2Beta

Transport security, headers, framing, vulnerability disclosure channel.

DSABeta

Terms, contact point, notice and action, ad and recommender transparency. Platforms only.

CRABeta

Disclosure policy, SBOM, support period, advisories. Software products only.

DORABeta

ICT risk framework, incident reporting, third-party register, exit terms. Financial entities only.

ISO/IEC 27001Beta

Readiness signals: security policy, disclosure channel, crypto, suppliers, incidents.

ISO/IEC 42001Beta

AI policy, impact assessment, human oversight, model inventory, training data.

ISO/IEC 27701Q1 2027

Privacy information management, extending the ISO 27001 pack.

Your frameworkOn request

Enterprise customers can commission private rule packs for sector rules.

What happens when you press scan

Four stages. Under a minute.

Nothing is guessed from a domain name. We fetch the asset, observe how it behaves on first load, run it through the rule engine, and score only the regulations that actually apply.

Stage 01

We read the asset

We request the target, follow every redirect, and record what it serves and what it sets before you have agreed to anything.

technologiesAI usagecookiesprivacy chatbotsformspoliciesheaders contenttrackerspublic signals
Stage 02

The rule engine runs

Deterministic rules from every active pack execute against the captured evidence. Each rule maps to a specific article — no rule fires without a citation attached.

deterministicarticle-mappedversioned
Stage 03

Applicability is resolved

Rules only count when the regulation genuinely applies. A company with no AI system is never penalised on AI Act rules, and the report says why the pack was skipped.

contextapplicabilityno false penalties
Stage 04

Your score is issued

Findings are weighted by severity into one score, plus a verdict per regulation you can defend in a meeting.

weightedper-regulationreproducible
Analysis surface

What a single scan looks at.

Each domain of evidence feeds rules from several regulations at once — a consent banner is an ePrivacy question and a GDPR question and, on an AI product, an AI Act question.

AI transparency

Whether users are told they are talking to a machine, at the first interaction.

AI Act Art. 50

Privacy

All eight Art. 13 information elements, checked against the text of your notice.

GDPR Art. 13

Cookies

Every cookie set on first load, classified and timed against the consent state.

ePrivacy Art. 5(3)

Consent

Whether a consent platform exists and whether tags are gated behind it.

ePrivacy · GDPR

Accessibility

Language, alt text, control names, zoom, headings and bypass mechanisms.

WCAG 2.2 AA

Security headers

HSTS, CSP, framing protection, referrer and permissions policy, TLS enforcement.

NIS2 · CRA

Forms

What each field collects, where it posts, and whether the notice arrives in time.

GDPR Art. 13

Tracking

Third-party pixels and analytics, with the destination country of each flow.

ePrivacy · GDPR Art. 44

AI chatbots

Conversational surfaces, whether they are AI-driven, and whether they say so.

AI Act

Model transparency

Which model providers you rely on, and whether users and buyers are told.

AI Act · ISO 42001

Risk classification

Public signals that your AI system may fall under Annex III high-risk use cases.

AI Act Art. 6

Legal & terms

Legal notice, terms, cookie policy, sub-processors and disclosure channels.

DSA · GDPR · CRA
The engine

Keyword search finds the word “cookie”. It doesn’t find the violation.

A page can carry a perfect privacy policy and still break the law in its first response header. Compliance lives in behaviour, not vocabulary — so we score behaviour.

Structure
How the asset is built

Redirect chain, response headers, embedded third parties, script origins and load order.

Content
What the asset claims

Policy pages are fetched and read for the specific information the law requires.

Behaviour
What it does before you agree

Cookies written and trackers embedded on the very first request, before any interaction.

Technology
What is actually running

Frameworks, consent platforms, analytics, chat widgets, AI agents and model SDKs.

Evidence
Proof, attached to every claim

The exact cookie, header, element or sentence that triggered the rule. A finding you cannot evidence is not shipped.

Input Captured evidence
Response headersRedirect chainCookie ledger Policy textFormsScripts & SDKsAccessibility tree
Layer 1 Deterministic rule packs
Loading rule packs…

Same input, same output, every time. Versioned and auditable — you can prove why a rule fired six months later.

Layer 2 Applicability & severity
Scope resolutionFalse-positive suppressionSeverity weightingRemediation drafting

The interpretation layer never invents a finding. It can only keep, downgrade or explain what the rules already proved.

/100

Compliance Score
Weighted by severity across the regulations that apply to you — not by how many rules happened to run.

Professional report

The document you hand to legal, or to the board.

Generated the moment you unlock it, written to be read by someone who was not in the room when it was produced.

Executive summary

Score, risk band and what to do first, in a paragraph a director can act on.

Every finding

All of them, with severity, status and the rule id that produced each one.

Evidence

The exact cookie, header, element or sentence that triggered the rule.

Articles affected

Citations down to the article and paragraph, per finding.

Recommendations

Ordered by priority, with concrete steps rather than “review your approach”.

Copy-ready text

Wording your team can paste straight into a banner, a form or a policy.

Implementation checklist

One line per action, ready to become tickets.

Compliance roadmap

This week, this quarter, ongoing — with the scope and limits stated plainly.

Pricing

Start free. Pay when you need the proof.

The scan and the score cost nothing. You pay for the evidence, the citations and the remediation work you would otherwise buy by the hour.

Free
€0no account

Scan any asset and see exactly where you stand.

Full scan across every applicable pack
Compliance Score and risk band
Verdict per regulation
Preview of your top findings
Run a free scan
Report
€3.99one-off

Every finding on the asset, with the proof behind it.

All findings, none withheld
Evidence captured for each one
Article-level citations
Recommended actions, in priority order
Technical appendix, printable to PDF
Scan, then unlock
Most popular
Report + templates
€9.99one-off

The report, plus the material that turns findings into fixes.

Everything in Report
Copy-ready wording for each fix
Implementation checklist
90-day compliance roadmap
Scan, then unlock
How it works

From URL to defensible evidence, in six steps.

Most people run their first scan before they finish reading this page. The paid report is a decision you make after you have already seen your score.

1

Enter a URL

A website, SaaS product, web app, API endpoint, chatbot or AI agent. No account, no credit card, no sales call.

2

We scan it automatically

The asset is fetched and observed under real conditions. Every signal we use is captured and stored as evidence.

3

We calculate your Compliance Score

Rules run, applicability is resolved, and one number lands — with a per-regulation verdict behind it.

4

You review the free summary

Score, status per regulation and your three highest-priority issues. Enough to know whether you have a problem today.

5

You unlock the professional report

Every finding, its evidence, the article breached, its priority, and the text to fix it.

6

You fix, re-scan and prove the improvement

Re-scan whenever you like. The dated record becomes your evidence that the issue was found and closed.

Why teams run it

An audit cycle, compressed into a coffee break.

01Save weeks of manual audit

What a consultant bills three weeks to assemble, the scan produces while you are still on the call.

02Find it before they do

Regulators, enterprise buyers and security questionnaires all check the same public surfaces. See what they see first.

03Prioritise by real risk

Severity weighting puts the issues that actually get companies fined at the top of the list.

04Recommendations you can act on

Not “review your consent mechanism” — the specific element, the specific fix, the specific wording.

05Keep a defensible history

Every report is dated and retained. Demonstrating diligence over time is itself a compliance argument.

06Catch regressions

Re-scan after each deployment and see immediately when something that used to pass no longer does.

Who it’s for

Anyone who has to answer for a digital asset.

Compliance stopped being a legal-department problem the moment it started depending on what your frontend does in its first second.

EnterprisesStartupsSaaS companiesConsultanciesLaw firms Legal teamsCompliance teamsCISOsDPOsCTOs Product teamsAgenciesCompanies shipping AIPublic sector suppliers
Questions

Before you scan.

What exactly does it analyse?
Any digital asset reachable from a URL: websites, SaaS products, web applications, public API endpoints, chatbots and AI agents. Within that asset we look at response headers and transport security, cookies set before consent, tracking technologies and where they send data, consent platforms, privacy and cookie policies (fetched and read, not just linked), legal notices, forms and what they collect, accessibility structure, conversational and AI surfaces, and model SDKs. Document, internal-policy and authenticated-area analysis are on the roadmap.
Is it fully automatic?
Yes. You provide a URL and nothing else — no questionnaire, no evidence upload, no interview.
How long does a scan take?
Typically 5 to 30 seconds, depending on how fast the target responds and how many policy pages we need to read. Slow assets can take up to a minute.
How is the Compliance Score calculated?
Every rule carries a severity weight — high counts 5, medium 3, low 1. A passing rule earns its full weight, a warning earns half, a failure earns nothing. Scores are computed per regulation, then combined into the headline number using each pack's weighting. Rules that do not apply to your asset are excluded entirely, so a company with no AI system is never penalised on AI Act rules. Every report lists which packs ran, at which version.
Who writes the recommendations?
Each rule ships with remediation written alongside it, referencing the article it enforces. RegInspector is an analysis tool, not a law firm — the report does not constitute legal advice.
Do you store my data?
We store the scan evidence needed to produce and later defend your report, which is why the report link works when you come back to it. Free scans are deleted automatically after 30 days. We scan only publicly accessible surfaces, we never publish results, and we do not sell or share them.
Which regulations are supported?
Ten packs are implemented and scored today: GDPR, ePrivacy, the EU AI Act and WCAG 2.2 AA are live; NIS2, DSA, CRA, DORA, ISO/IEC 27001 and ISO/IEC 42001 ship as beta. Four of them are conditional by design — the AI Act and ISO 42001 are scored only where a real AI system is detected, the DSA only where the terms confirm the service hosts user content, the CRA only where software is distributed, and DORA only where financial activity is present. A company outside those scopes is never penalised for them, and the report says exactly why a pack was skipped. ISO/IEC 27701 and the rendered-page accessibility criteria are on the roadmap.
Can I scan a site I don’t own?
A scan only requests publicly available pages, exactly as any visitor or search engine would — it does not test for vulnerabilities, attempt access or place load on the target. That said, the report is written for the people who can act on it, so it is most useful on assets you are responsible for.
Can I re-scan after making changes?
Yes, and you should — after any deployment that touches consent, forms, tracking or your AI assistant. Each scan produces its own dated report so you can show exactly when a finding was closed.
Free scan · No registration

You already know the URL. Find out what it says about you.

One minute now, or a formal request for information later. Both start with the same page.