You don't know what AI you've shipped.
Marketing turned on an assistant. Support added one inside the helpdesk. Someone in HR is running screening through a vendor. A full inventory of what's actually facing your customers — free, in minutes.
We read only public pages. See what the scan touches below.
What a scan finds — rendered honestly, not illustrated
| Ref | Surface | Type | Duty | Status |
|---|---|---|---|---|
| 000482 | /support | chat widget | provider | undisclosed |
| 000483 | /careers/apply | AI screening | deployer | undisclosed |
| 000484 | /campaigns/summer | generated image | provider | marked |
What a scan finds
Concrete surfaces, not a checklist of frameworks.
- Chat and voice assistants
- Support widgets, sales bots, phone systems — anything that talks to a customer and might not say what it is.
- AI-generated images, video and copy
- Campaign imagery, product photography, marketing copy — generated content published without a machine-readable mark.
- Screening and scoring tools
- Careers pages running CV screening through a vendor, support queues triaged automatically, anything that scores a person.
- Emotion or biometric detection
- Call-centre sentiment analysis, kiosk cameras estimating age or mood — systems that read a person, not just a form.
What comes back
An inventory of every surface we found, each one with evidence: what we saw, where, which rule it maps to, how confident we are, and when we captured it. Not a score. A record.
The artifact you hand upward
A signed PDF and JSON bundle — screenshot, cited rule, article reference, confidence, remediation — for a date range you choose. Regenerated from stored evidence, so it never changes after the fact.
Why now
- Article 50 of Regulation (EU) 2024/1689 applies from 2 August 2026.
- Penalties of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
The high-risk regime was deferred to December 2027. The transparency duties were not.
What the scan touches
Before you enter a domain, you should know exactly what happens.
Public pages only
We crawl what a visitor to your site can already see. Nothing behind a login.
robots.txt, respected
Our crawler reads and follows your robots.txt before it reads anything else.
Rate-limited and identified
One request per second by default, and our crawler names itself in the user agent on every request.
Proof of control required first
A DNS TXT record or a signed authorisation from someone at your company — before anything runs, every time.
Where data lives
Deployment is EU-only. You can see the configured region on our status page. Data is retained for the length of your subscription and deleted on request.
See your own inventory
The same scan, on your domain.