Three agents, a privacy toolkit, and a GRC workspace.
A handful of capabilities over one GRC workspace, not a swarm of bots. Three agents do the work, a rules-based toolkit checks your privacy posture, and the workspace holds your registers, risk matrix, controls, and reviews. Each one below is labelled for what it is. Click a card to jump to the deep dive.
Regulatory monitoring + drafting
AgentWatcher
Scans the regulators that touch you and drafts the response.
Watcher runs every week across the regulator sources we monitor (around 60 regulator feeds and legislative trackers). It scores each change against your profile, keeps only what is material to you, writes a plain-language digest of what changed and why it matters, and - where a change touches a policy you have published - produces a Word redline with track changes. Citations are re-checked before anything reaches you.
- Weekly material-change digest, each item source-linked
- Month-in-Review monthly roll-up
- Word redlines with track changes on your published policies
- Tamper-evident record of every item
Included from the Foundation tier and above.
- FCA: operational resilience updatesource
- ICO: age-assurance guidancesource
- EUR-Lex: DORA secondary RTSsource
- + 47 informational, filtered out
Policy gap analysis
AgentAssessor
Scores your policies against the law and shows the gaps.
Assessor reads each policy against the relevant legal baselines, scores it, and lists exactly what is covered, partial, or missing, with a suggested redline for each gap. The UK Data (Use and Access) Act 2025 obligation pack (15 dated obligations) is built in, so UK policies are assessed against the reform as each provision commences. This is draft intelligence for your team to review, not legal advice. Today it assesses privacy and cookie policies; more policy types are on the roadmap.
- Per-policy score with covered / partial / missing findings
- Suggested redline for each gap
- DUAA 2025-aware (15 dated UK obligations built in)
- Powers the portal's Gap analysis page
Included from the Foundation tier and above.
- Lawful basis statedCovered
- Retention periodsPartial
- DUAA 2025 ADM rightsMissing
Onboarding + profile research
AgentProfiler
Builds your compliance profile from your website.
Profiler reads your corporate website (respecting the site's access rules), sorts the policies it finds by type, and proposes a structured compliance profile, with a quoted excerpt backing each field it fills in. You review and edit before it becomes your official profile, and Profiler proposes refreshes over time.
- Reads only your own website and saves a dated copy of each page as evidence
- Policy classification across the common document types
- Evidence-backed, editable profile fields
- Gap callouts (e.g. 'no DPA found')
Included from the Foundation tier and above.
- Privacy noticeFound · 0.94
- Cookie policyFound · 0.92
- Data processing addendumGap
- Acceptable useFound · 0.81
Vendor, policy + data-flow analysis
ToolkitPrivacy Inspector
Finds the gaps across your vendors, policies, and data flows.
Privacy Inspector is a rules-based check (it mostly does not use AI) across your vendor, processing-activity, asset, and cookie registers. It scores each vendor against a transparent rule set (country adequacy, missing DPA, SCC fit, audit recency, contract expiry), reconciles your privacy and cookie policies against what your registers actually say, and draws your data-flow map. Because the rules are explicit, you can always see exactly why something flagged.
- Per-vendor risk score with a transparent rule set
- Privacy-policy claimed-vs-actual findings
- Live data-flow map (subjects to activities to assets to vendors to countries)
- DPIA + cookie cross-checks against your registers
- · Fixed rules-based analysis tools, not an autonomous AI agent
Included from the Foundation tier and above.
- Acme Analytics72 · missing DPA
- DataPipe Inc48 · no SCCs
Policy vs registers: Twilio used, not named in notice
Registers, controls + review workflow
WorkspaceGRC Workspace
Your registers, risk matrix, controls, and review workflow in one place.
The GRC Workspace is where your governance lives: a 5x5 risk register with tamper-evident history and spreadsheet (CSV) export, a controls library linked Law -> Policy -> Control, an org directory (CSV / SCIM / HRIS), recurring review cycles that materialise tickets, and an executive dashboard. One scheduler turns review schedules into reminders and dispatches them across your channels. It is the platform workspace, not an AI agent.
- 5x5 risk register (inherent + residual) with tamper-evident history + spreadsheet (CSV) export
- Controls library with Law -> Policy -> Control mapping
- Org directory (CSV / SCIM / HRIS) with role-based ownership
- Review cycles + tickets + reminders; executive dashboard
- · The registers + workflow surface, not an autonomous agent
Included from the Foundation tier and above.
L4 x I4 = 16 · High · review ticket raised
Not sure which tier fits your stack?
30-minute discovery call: we walk through your current GRC tools, your owner accountability, and your audit cadence, then recommend Foundation, Compliance Pro, or Compliance Suite. We quote on the call.