Your real obligations — and an attestation your customer can verify themselves.
By starting a scan, you agree to our Terms of Service.
read.customer_record · personalWhy: Un mécanisme de transfert doit encadrer cette sortie de données.
cross_border_transfer_mechanism_required
Frameworks coveredRegulatory frameworks the assessment covers
read.customer_record · personalWhy: Un mécanisme de transfert doit encadrer cette sortie de données.
cross_border_transfer_mechanism_required
Built by a CISSP · 100% Canadian · Open specification
A customer, an investor or a tender asks where you stand — and you find out the answer by looking for it.
Acme AI — Assessment report
Canada (Quebec) · France · European Union
Transfer mechanism required for data leaving Québec
Your attestation carries an identifier and an Ed25519 signature. Whoever you send it to — customer, auditor, investor, regulator — enters it on our verification page and sees what was assessed, when, and over what scope. No account, nothing to ask you for.
Verify an attestationStructureClerk identifies exposure and provides the reasoning behind each finding. The legal judgment stays human.
Assessments, decisions and sources are preserved as you go. Six months later you can retrieve how things stood when you decided — not your recollection of it.
Your answers stay in your browser during the assessment. We keep only what you hand us: the email address for the report, and your assessments if you create an account. Saving is entirely optional, and there are no third-party advertising cookies.
Know what applied. Know what you did. Prove it later.
192 jurisdictions · 168 data protection laws in force · 18 AI governance frameworks · 5 cybersecurity
GDPR, AI Act, NIS2, UK GDPR, Swiss
POPIA, Nigeria NDPA, Morocco Law 09-08
PIPL, APPI, Privacy Act, PDPA
Law 25, PIPEDA, CCPA, LGPD
Saudi PDPL, Qatar, UAE, Bahrain
Most tools handle privacy and leave AI aside. Your obligations, however, arrive together.
GDPR, Law 25, PIPEDA, CCPA, LGPD, PIPL
EU AI Act, Law 25, ISO 42001, guidelines
NIS2, CIRCIA, ISO 27001, SOC 2, NIST
EU AI Act, Law 25, transparency, audit
There is nothing to fill in to get started. We begin with what your site already says.
Paste your website URL. Nothing else to prepare.
We read your pages, policies and headers — what a customer or a regulator would see.
Your list, sorted: what's urgent, what can wait, what doesn't apply to you.
The report says where you stand. What follows is for doing something about it.
Enterprise-grade document with cover page, domain scores, applicable laws and priority recommendations.
Create an account to save your assessments and track your progress over time. 100% opt-in.
Visualize your scores, progress over time, weak domains and receive proactive alerts.
Compare your score to your industry average. Anonymous and aggregated data.
Ask about Law 25, the GDPR or the EU AI Act and get a sourced answer, without re-reading three hundred pages.

Cybersecurity and AI governance architect. CISSP. Member of the ISC2 Exam Review Commission.
Author of the Three Zones Framework for classifying human/AI decision boundaries, published in L'Architecte Numérique, distributed by Hachette (2026).
StructureClerk was born from a simple observation: French-speaking SMEs and organizations don't have access to professional-grade compliance tools without a significant budget.
Doing it now takes a few minutes. Doing it under pressure, once the question lands, takes far longer — and it shows.
An equivalent engagement with a firm or consultant runs roughly $3,000 to $15,000 CAD.
The assessment is free and stays free. What you pay for is following it over time — see the plans.