Skip to content
regSpace
What you actually get

Three agents, a privacy toolkit, and a GRC workspace.

A handful of capabilities over one GRC workspace, not a swarm of bots. Three agents do the work, a rules-based toolkit checks your privacy posture, and the workspace holds your registers, risk matrix, controls, and reviews. Each one below is labelled for what it is. Click a card to jump to the deep dive.

Regulatory monitoring + drafting

Agent

Watcher

Scans the regulators that touch you and drafts the response.

Watcher runs every week across the regulator sources we monitor (around 60 regulator feeds and legislative trackers). It scores each change against your profile, keeps only what is material to you, writes a plain-language digest of what changed and why it matters, and - where a change touches a policy you have published - produces a Word redline with track changes. Citations are re-checked before anything reaches you.

What it delivers
  • Weekly material-change digest, each item source-linked
  • Month-in-Review monthly roll-up
  • Word redlines with track changes on your published policies
  • Tamper-evident record of every item

Included from the Foundation tier and above.

This week3 material
  • FCA: operational resilience updatesource
  • ICO: age-assurance guidancesource
  • EUR-Lex: DORA secondary RTSsource
  • + 47 informational, filtered out

Policy gap analysis

Agent

Assessor

Scores your policies against the law and shows the gaps.

Assessor reads each policy against the relevant legal baselines, scores it, and lists exactly what is covered, partial, or missing, with a suggested redline for each gap. The UK Data (Use and Access) Act 2025 obligation pack (15 dated obligations) is built in, so UK policies are assessed against the reform as each provision commences. This is draft intelligence for your team to review, not legal advice. Today it assesses privacy and cookie policies; more policy types are on the roadmap.

What it delivers
  • Per-policy score with covered / partial / missing findings
  • Suggested redline for each gap
  • DUAA 2025-aware (15 dated UK obligations built in)
  • Powers the portal's Gap analysis page

Included from the Foundation tier and above.

Privacy notice78/100
  • Lawful basis statedCovered
  • Retention periodsPartial
  • DUAA 2025 ADM rightsMissing

Onboarding + profile research

Agent

Profiler

Builds your compliance profile from your website.

Profiler reads your corporate website (respecting the site's access rules), sorts the policies it finds by type, and proposes a structured compliance profile, with a quoted excerpt backing each field it fills in. You review and edit before it becomes your official profile, and Profiler proposes refreshes over time.

What it delivers
  • Reads only your own website and saves a dated copy of each page as evidence
  • Policy classification across the common document types
  • Evidence-backed, editable profile fields
  • Gap callouts (e.g. 'no DPA found')

Included from the Foundation tier and above.

Profile draft · v1
  • Privacy noticeFound · 0.94
  • Cookie policyFound · 0.92
  • Data processing addendumGap
  • Acceptable useFound · 0.81

Vendor, policy + data-flow analysis

Toolkit

Privacy Inspector

Finds the gaps across your vendors, policies, and data flows.

Privacy Inspector is a rules-based check (it mostly does not use AI) across your vendor, processing-activity, asset, and cookie registers. It scores each vendor against a transparent rule set (country adequacy, missing DPA, SCC fit, audit recency, contract expiry), reconciles your privacy and cookie policies against what your registers actually say, and draws your data-flow map. Because the rules are explicit, you can always see exactly why something flagged.

What it delivers
  • Per-vendor risk score with a transparent rule set
  • Privacy-policy claimed-vs-actual findings
  • Live data-flow map (subjects to activities to assets to vendors to countries)
  • DPIA + cookie cross-checks against your registers
Good to know
  • · Fixed rules-based analysis tools, not an autonomous AI agent

Included from the Foundation tier and above.

Vendor riskrule-based
  • Acme Analytics72 · missing DPA
  • DataPipe Inc48 · no SCCs

Policy vs registers: Twilio used, not named in notice

Registers, controls + review workflow

Workspace

GRC Workspace

Your registers, risk matrix, controls, and review workflow in one place.

The GRC Workspace is where your governance lives: a 5x5 risk register with tamper-evident history and spreadsheet (CSV) export, a controls library linked Law -> Policy -> Control, an org directory (CSV / SCIM / HRIS), recurring review cycles that materialise tickets, and an executive dashboard. One scheduler turns review schedules into reminders and dispatches them across your channels. It is the platform workspace, not an AI agent.

What it delivers
  • 5x5 risk register (inherent + residual) with tamper-evident history + spreadsheet (CSV) export
  • Controls library with Law -> Policy -> Control mapping
  • Org directory (CSV / SCIM / HRIS) with role-based ownership
  • Review cycles + tickets + reminders; executive dashboard
Good to know
  • · The registers + workflow surface, not an autonomous agent

Included from the Foundation tier and above.

Residual heatmap · 5x5
5
10
15
20
25
4
8
12
16
20
3
6
9
12
15
2
4
6
8
10
1
2
3
4
5

L4 x I4 = 16 · High · review ticket raised

Not sure which tier fits your stack?

30-minute discovery call: we walk through your current GRC tools, your owner accountability, and your audit cadence, then recommend Foundation, Compliance Pro, or Compliance Suite. We quote on the call.