Executive summary
Demo · Fictional companyCompany
Acme AI Inc. (fictional)
Sector
SaaS / Artificial intelligence
Declared markets
Canada, United States, European Union
2 critical or high-priority gaps to close before an enterprise sale.
We tell you what's missing. We never declare anyone compliant — including in this demo report.
Findings
Severity, jurisdiction, source, confidence, recommended action
No personal information protection officer identified
CriticalJurisdiction: Quebec
Source: Law 25 — general designation requirement
Confidence: High (primary source)
Recommended action: Designate an officer (by default, the most senior executive) and publish it on the site.
Insufficient transparency on user-facing generative AI systems
HighJurisdiction: European Union
Source: EU AI Act, Art. 50 — transparency obligations
Confidence: High (primary source)
Recommended action: Clearly disclose when a user is interacting with an AI system.
Incomplete HTTP security headers on the public site
MediumJurisdiction: All jurisdictions
Source: Cybersecurity best practice (OWASP)
Confidence: High (direct measurement)
Recommended action: Add the missing headers (CSP, HSTS, X-Content-Type-Options).
Privacy policy lacks explicit opt-out mention
MediumJurisdiction: California
Source: CCPA/CPRA — right to opt out of sale/sharing
Confidence: Moderate (guidance)
Recommended action: Add a visible opt-out mechanism and a dedicated clause.
No mention of a legal basis for processing or a data protection officer
HighJurisdiction: European Union
Source: GDPR — Art. 6 (lawfulness) and Art. 37 (DPO)
Confidence: High (primary source)
Recommended action: Document the legal basis per purpose; appoint a DPO if the threshold applies.