StructureClerk

Tell us what you're building. We'll determine what applies.

Your real obligations — and an attestation your customer can verify themselves.

By starting a scan, you agree to our Terms of Service.

Your company
Regulatory intelligence
Decision
Live
1 / 7
FRRGPD + LIL
US_FED
read.customer_record · personal
Approveconfidence 0.00

Why: Un mécanisme de transfert doit encadrer cette sortie de données.

cross_border_transfer_mechanism_required

Frameworks coveredRegulatory frameworks the assessment covers

Loi 25 / Law 25PIPEDARGPD / GDPREU AI ActNIS2ISO 27001SOC 2

Built by a CISSP · 100% Canadian · Open specification

Example — what you get

The question always comes after the fact.

A customer, an investor or a tender asks where you stand — and you find out the answer by looking for it.

ExampleAcme AI · SaaS B2B · sells in Canada, France, the EU
7 obligations detected
3 high priority2 medium priority2 to monitor

Why it applies

Not a generic estimate — the exact article, the exact jurisdiction.

Acme AI — Assessment report

Canada (Quebec) · France · European Union

Illustrative example
Data protection82%
AI governance61%
Cybersecurity74%
Algorithmic compliance48%
High priority

Transfer mechanism required for data leaving Québec

Why
Law 25 recognises no default destination for personal information — every transfer out of Québec requires a prior assessment, including to the rest of Canada.
Source
Law 25 (CA_QC) — verified 2025-01-31
Action
Document the transfer mechanism before activating the US cloud vendor already under evaluation.

How we prove it

Built to be verified.

Your attestation carries an identifier and an Ed25519 signature. Whoever you send it to — customer, auditor, investor, regulator — enters it on our verification page and sees what was assessed, when, and over what scope. No account, nothing to ask you for.

Verify an attestation

We never declare compliance

StructureClerk identifies exposure and provides the reasoning behind each finding. The legal judgment stays human.

A record you can rely on

Assessments, decisions and sources are preserved as you go. Six months later you can retrieve how things stood when you decided — not your recollection of it.

We keep only what is needed

Your answers stay in your browser during the assessment. We keep only what you hand us: the email address for the report, and your assessments if you create an account. Saving is entirely optional, and there are no third-party advertising cookies.

Know what applied. Know what you did. Prove it later.

Global coverage

192 jurisdictions · 168 data protection laws in force · 18 AI governance frameworks · 5 cybersecurity

Europe

48

GDPR, AI Act, NIS2, UK GDPR, Swiss

Africa

42

POPIA, Nigeria NDPA, Morocco Law 09-08

Asia-Pacific

34

PIPL, APPI, Privacy Act, PDPA

Americas

51

Law 25, PIPEDA, CCPA, LGPD

Middle East

17

Saudi PDPL, Qatar, UAE, Bahrain

Four domains, one pass

Most tools handle privacy and leave AI aside. Your obligations, however, arrive together.

Data protection

GDPR, Law 25, PIPEDA, CCPA, LGPD, PIPL

AI governance

EU AI Act, Law 25, ISO 42001, guidelines

Cybersecurity

NIS2, CIRCIA, ISO 27001, SOC 2, NIST

Algorithmic compliance

EU AI Act, Law 25, transparency, audit

How it works

There is nothing to fill in to get started. We begin with what your site already says.

01

Your address

Paste your website URL. Nothing else to prepare.

02

What's public

We read your pages, policies and headers — what a customer or a regulator would see.

03

Your obligations

Your list, sorted: what's urgent, what can wait, what doesn't apply to you.

After the diagnosis

What you keep, once you've read the report

The report says where you stand. What follows is for doing something about it.

Professional PDF report

Enterprise-grade document with cover page, domain scores, applicable laws and priority recommendations.

Save & track

Create an account to save your assessments and track your progress over time. 100% opt-in.

Dashboard

Visualize your scores, progress over time, weak domains and receive proactive alerts.

Industry benchmarks

Compare your score to your industry average. Anonymous and aggregated data.

An assistant that knows the texts

Ask about Law 25, the GDPR or the EU AI Act and get a sourced answer, without re-reading three hundred pages.

Michel Fotsing

Created by Michel Fotsing

Cybersecurity and AI governance architect. CISSP. Member of the ISC2 Exam Review Commission.

Author of the Three Zones Framework for classifying human/AI decision boundaries, published in L'Architecte Numérique, distributed by Hachette (2026).

StructureClerk was born from a simple observation: French-speaking SMEs and organizations don't have access to professional-grade compliance tools without a significant budget.

The natural evolution

Once you know what applies, make it machine-readable.

The authority layer lets your systems — and your AI agents — check it themselves, before acting.

Next time someone asks, have the answer ready.

Doing it now takes a few minutes. Doing it under pressure, once the question lands, takes far longer — and it shows.

An equivalent engagement with a firm or consultant runs roughly $3,000 to $15,000 CAD.

The assessment is free and stays free. What you pay for is following it over time — see the plans.