See it in action.
Nine real screens from the product — what privacy operations look like when AI drafts the routine work, your team signs off, and every step lands in an append-only trail with proof a regulator can check for themselves.
The whole privacy program, on one screen.
Open the app and immediately see what needs attention: open DSARs ticking down to their deadline, escalations waiting for review, vendor reviews coming due, and the month's Q&A volume.
- Color-coded DSAR tile turns red when something is ≤ 7 days from deadline.
- Latest three escalations preview right on the home screen.
- Trial banner + onboarding checklist for fresh workspaces.
Latest escalations
Grounded answers, with receipts.
Type a privacy question. The assistant retrieves the relevant paragraphs from your uploaded policies and approved-vendor inventory, drafts an answer, and shows you exactly which sources it leaned on.
- Composite confidence (retrieval × LLM self-confidence × citation validity).
- Low-confidence or out-of-policy questions escalate to your privacy team automatically.
- Built-in prompt-injection and conflicting-intent detection.
Drew on: 4 chunks from your documents · 3 cited
Yes, with the existing DPA on file. Acme Analytics is listed as an approved processor for product-usage telemetry under your Vendor Privacy Policy (last reviewed Jan 2026).
- Data residency: EU only. Confirm your Acme tenant is in the eu-central-1 region.
- Retention: 13 months, per your retention schedule.
- Special categories: not permitted.
Review, edit, approve — one click.
When the AI isn’t confident or detects a conflicting intent, the question lands in your inbox with a draft answer pre-written. Review the source citations, edit if needed, and approve.
- Intent chips flag prompt-injection, conflicting requests, hard-blocks.
- Independent judge model verifies every draft — its note appears below.
- Markdown-rendered draft so structured AI output reads cleanly.
AI draft answer
You have two conflicting requirements here — the right of erasure (GDPR Art. 17) and a statutory retention obligation (typically 6–7 years for tax records). Both can co-exist:
- Erase personal identifiers (name, email, address) from the customer record.
- Retain the order history with the personal identifiers redacted (a pseudonymous customer ID is fine).
- Document the legal basis for retention in your Records of Processing under "tax compliance".
Article 35 in ten minutes, not ten hours.
Describe a new processing activity in plain language. The AI drafts an Article 35-defensible DPIA with screening, scored risks, and mitigations. You review and approve.
- 3×3 likelihood × severity heatmap with numbered chips that jump to the matching risk row.
- Inline editing on every field.
- Approved DPIAs sync into your RoPA (Records of Processing) automatically.
Customer support AI assistant — DPIA
DPIA required: Yes · Residual risk: Medium · Status: Approved
Risk heatmap
| # | Risk | L | S | Status |
|---|---|---|---|---|
| 1 | Stored chat logs include incidental PII | Low | Low | Mitigated |
| 2 | LLM provider data residency outside EU | Med | Med | Owner |
| 5 | Prompt injection extracts other tenants' data | High | High | Active |
Onboard a vendor by URL. Score the risk. Keep it current.
Paste a vendor’s website and the AI reads their public privacy, trust, and DPA pages, then pre-fills the record with quoted, sourced suggestions — you review every one before it saves. Each vendor lands with an explainable risk tier and a review date that nudges you when it comes due.
- Deterministic High / Medium / Low score with a “why” breakdown — no black box.
- Review reminders feed the weekly digest and the home dashboard automatically.
- Send a hosted due-diligence questionnaire; concerning answers get flagged for you.
Approved-vendor inventory
23 vendors · 3 reviews due · 1 questionnaire awaiting response
| Vendor | Risk | DPA | Review |
|---|---|---|---|
| Acme Analytics sensitive data · sub-processors |
Medium · 53 | Signed | Due 14d |
| MailBlast EU transfer · no DPA on file |
High · 78 | Missing | — |
| Databricks SOC 2 · EU region |
Low · 8 | Signed | Apr 2027 |
“Cloudflare processes personal information on behalf of its customers under a Data Processing Addendum.”
Source: cloudflare.com/dpa · processing role → ProcessorApplied 2 suggestions from 4 pages. Review before saving.
From inbound email to closed request, with the regulatory deadline enforced.
The AI classifies an inbound email as a deletion / access / portability / opt-out request and starts the verification flow. Once you verify the requester’s identity, every department that holds their data gets a tokenized link to confirm what they hold and take action.
- Five-step lifecycle stepper across every DSAR.
- Per-DSAR fan-out to your configured department contacts.
- Aggregate completion email back to the requester when every team has responded.
Deletion request — Sarah Kim
Department fan-out · 2 of 5 responded
The AI surfaces the tension. You sign it off.
When a DSAR has cross-jurisdictional friction — a deletion request meeting a litigation hold, a portability request running against an IRS retention rule — the AI drafts a flag: the relevant statutory texts, the customer-authored facts, and a verbatim line that the obligations interact and resolution is the human’s. It cites only from a closed, curated corpus of statutory text we maintain, scoped to your jurisdiction — the AI can pull references from it but cannot invent them — and a qualified human signs off before anyone acts on it.
- Schema-level guarantee: no signed-off determination can land without an authenticated user id and a non-empty citations array.
- Closed citation menu — the AI cannot invent a statute reference; the validator rejects any id not in the corpus.
- Every draft requires a qualified human’s sign-off (Invariant 12) before it can be acted on — it describes, it never concludes.
- Audit chain records the signing user, the draft it came from, and the prompt+hash that produced it.
Cross-jurisdictional conflict flag
Controlling texts
- GDPR Art. 17(3)(e) names a carve-out from the deletion right for legal claims.
- FRCP 37(e) creates preservation duties once litigation is reasonably anticipated.
Observed facts
- A litigation-hold marker is set on this subject (set 2026-04-12).
- Your retention policy cites IRS §6001 for related business records.
Classify your AI under the EU AI Act — and draft the paperwork.
Add an AI system you build or use. The AI classifies it against the EU AI Act, names the obligations that follow, and drafts the documents they require — seeded from your existing DPIAs, RoPA, and vendors, and editable in-app to a final version.
- Risk tier and triggered obligations, each cited to the Act — a human signs off before the classification counts.
- One click drafts Annex IV technical docs, Article 50 transparency notices, and Article 27 FRIAs.
- Record the models behind each system; if a model version or a vendor’s terms change, the classification is flagged for re-review.
Résumé screening assistant
Role: Deployer · Risk tier: High-risk (Annex III) · Signed off
Triggered obligations
- Annex IV technical documentation Drafted
- Article 50 transparency notice Draft
- Article 27 FRIA Drafted
Models
claude-opus-4-8 · Anthropic · v4.8
One click. A regulator can verify it without an account.
Close a DSAR — or approve a DPIA, seal a RoPA snapshot, or sign off an AI-system classification — and produce a sealed evidence record. Hand it to a regulator or auditor and they confirm it’s authentic and unaltered themselves, no account required. The same record prints to PDF for the binder.
- Public verifier — the regulator pastes the file in and gets a plain-language verdict: authentic, sealed on this date, for this controller.
- Tamper-evident: change one character and verification fails, so “this is the record we gave you” isn’t a matter of trust.
- Works for DSARs, DPIAs, RoPA snapshots, AI-system classifications, and point-in-time posture seals.
- Want the cryptographic details? They’re all on the engineering trust page.
Signed evidence packet
SealedA regulator-facing record of this DSAR — every step, the verification trace, and the completion proof. Verifiable by anyone you hand it to, no account needed.
“This record is authentic, sealed on 21 Jun 2026 for Acme Ltd.”
See it on your own data.
Sign up free, upload one privacy policy, ask the AI a question about your actual workflow. Takes about three minutes.
Start free 14-day trialNo credit card required · Drops to Free after, your data stays