This is a real WatchSuit audit, anonymized. Every section, every citation, every evidence snippet — exactly what lands in your inbox 48 hours after purchase.
Real findings from a real scan. Company name anonymized. All citations, evidence snippets, and remediation steps are accurate.
Example Corp's public-facing website presents significant compliance risk across three of five audited frameworks. The most urgent exposures are in GDPR (missing lawful basis disclosures and incomplete data subject rights) and HIPAA (no Business Associate Agreement references despite visible health intake forms). These gaps represent enforceable violations — not aspirational best practices — and should be addressed before any EU or US regulatory engagement.
The site's EU AI Act posture is acceptable: no high-risk AI system signals were detected on the homepage or feature pages. CCPA performance is moderate; a Do Not Sell link exists but the data categories list is incomplete under Cal. Civ. Code §1798.110. SOC 2 readiness is the weakest area — there is no trust center, no security.txt, and no reference to an audit report or certification, which will materially affect enterprise sales cycles.
Of the 11 violations identified, 2 are Critical severity (potential regulatory fines exceeding $20M under GDPR Art. 83), 4 are High (reportable to regulators within 72 hours of breach discovery under GDPR Art. 33), and 5 are Medium (material compliance gaps requiring remediation within 30 days). No violations were found in 14 of the 25 checks performed.
Address Critical issues within 72 hours. High within 14 days. Medium within 30 days.
| Violation | Severity | Framework | Regulation | Effort | Action |
|---|---|---|---|---|---|
| Lawful Basis Not Disclosed | CRITICAL | GDPR | Art. 13(1)(c) | 2–4 hrs | Add lawful basis table to privacy policy |
| Data Subject Rights Incomplete | CRITICAL | GDPR | Art. 15–22 | 3–6 hrs | Add all 6 rights with exercise mechanism |
| BAA Not Referenced | HIGH | HIPAA | 45 CFR §164.504(e) | 1–2 days | Execute BAAs with Google, HubSpot, Segment |
| NPP Incomplete (3 sections) | HIGH | HIPAA | 45 CFR §164.520 | 4–8 hrs | Revise NPP using HHS model template |
| DPO Contact Missing | HIGH | GDPR | Art. 13(1)(b), Art. 37 | 1 hr | Add dpo@ contact to privacy policy + footer |
| No Trust Center / SOC 2 Reference | HIGH | SOC 2 | TSC CC6.1, CC9.2 | 2–5 days | Create /security page, reference audit status |
| Breach Notification Undocumented | MEDIUM | HIPAA | 45 CFR §§164.400–414 | 2–4 hrs | Add breach notification section to NPP |
| CCPA Data Categories Incomplete | MEDIUM | CCPA | Cal. Civ. Code §1798.110 | 2–3 hrs | Enumerate all 11 CCPA data categories collected |
| No Incident Response Policy | MEDIUM | SOC 2 | TSC A1.3, CC7.4 | 1–3 days | Publish incident response procedure page |
| security.txt Missing | MEDIUM | SOC 2 | RFC 9116, TSC CC7.1 | 30 min | Add /.well-known/security.txt with contact |
| No Subprocessor List | MEDIUM | SOC 2 | TSC CC9.2 | 1–2 hrs | Publish /subprocessors with vendor list |
The free scanner is a fast signal check. The Premium Report is a deliverable you can take to your legal team, your board, and your auditor.
48-hour turnaround. Exact citations. Actionable remediation steps. Everything you just saw — for your domain.
Order Premium Report →About this sample: The company shown above is anonymized. All findings, citations, and evidence excerpts are based on a real WatchSuit scan. WatchSuit is not a law firm and nothing in this report constitutes legal advice. Compliance requirements are fact-specific to your organization. Consult qualified counsel for regulatory guidance. Last updated: May 2026.