Give us the domain.
We’ll do the looking.
One field, no account, nothing installed. We read your legal pages, your DNS and mail records, your response headers, your consent tooling and any list you already keep — then a named reviewer works through the result before you see it.
Rather talk it through first? Book fifteen minutes with a reviewer
Six sources, because no single one is complete.
A legal page that hasn’t been touched in two years will not tell you what your engineering team switched on last quarter. Reading them separately is the point.
Your published pages
Sub-processor page, privacy notice, DPA and any annex. Read as structured entities, not scraped text.
MX, SPF, CNAME chain
Who actually carries your email, and which infrastructure sits in front of your domain.
Content-Security-Policy
A CSP frequently enumerates every third-party endpoint your product talks to. It is the most under-used source in this whole business.
Your vendor manifest
OneTrust, Cookiebot and similar publish a per-domain vendor list. If you run one, you have already done part of this work.
Spreadsheets and exports
A vendor list, a procurement export, a CSV someone maintains. Send it in any shape and we will reconcile it against everything we find.
DPAs and order forms
Optional, and the one that earns its keep later: we extract each notification clause so your objection windows come from your own contracts rather than a standard assumption.
Two columns, presented straight.
What your own pages declare, beside what we actually observed. They answer different questions and we do not pretend otherwise — the judgement stays with you.
Declared
named on your legal surface · 12 entities
Observed
detected on your public surface · 9 services
The part no scan can reach
Payroll, HR, data warehouses, anything internal. Paste them in and they are reconciled with everything else rather than living in a separate spreadsheet.
Your domain and someone else’s are treated differently.
We built this to be useful without being a weapon.
- Your own domain, verifiedYou can publish the result — on the register, your own site, or both.
- A domain you don’t controlStays private to your account. It is never published and never shown to that company.
- No accusations, everWe do not write “undisclosed” and we do not claim anyone is in breach. We record what we read and the date we read it.
- Corrections are welcomeEvery register page carries a way to correct it, and every correction is logged rather than silently applied.
Discovery is the start of the job, not the whole of it.
It gets published, properly
At your address or ours, with the source behind every entity and a dated history from day one.
See what you end up with →We re-read the whole stack
Changes come to you with the evidence attached, held until you decide. Your customers hear it from you.
How upkeep works →The same engine, aimed outward
Every vendor discovery found can be watched daily, with objection windows read from your own contracts.
See monitoring →Send the domain. See what we come back with.
Free, no account to start, and a named reviewer either way.