A regulator. An auditor. A client's legal team. A journalist.

At that moment, the question isn't whether you're compliant. The question is whether you can prove it.

Most organisations can't. Not because they've done something wrong, but because nobody was watching the right things.

A one-time assessment of your AI-related risk exposure based on publicly available signals.

Your website, privacy documentation, security configuration, and AI usage, are mapped against GDPR, NIS2, the EU AI Act, and DORA. You get a factual report of what's visible, what's missing, and what it means for your risk position.

No installation. No access to internal systems required.

Who this is for

Organisations that use AI and haven't formally assessed what that exposes them to. Risk, legal, and compliance leads preparing for an audit or regulatory conversation. Boards that need a starting position before committing to a larger programme.

What you get

A timestamped audit report with a maturity score per regulatory pillar, a risk matrix with deadlines and priorities, and a top-3 action list with clear ownership criteria. Delivered within five working days.

Investment

Starting at €2,500. One-time.

The scan operates exclusively on publicly observable data. No credentials, no internal access, no agents installed.

Open-source intelligence across your primary domain — privacy documentation, cookie configuration, security.txt, HTTP headers, certificate validity, AI policy publication, and public-facing AI system behaviour.

A deterministic rule register maps each observation to applicable regulatory requirements. The same observations always produce the same outcome. No LLM judgment in the evaluation phase.

Every finding is logged in an append-only SHA-256 hash chain. Each conclusion is traceable to its source observation and independently verifiable.

GDPR, NIS2, EU AI Act, DORA, ePrivacy.

Two structured reports — an audit report (findings, maturity scores, risk matrix, MTL trace) and an advisory report (top-3 actions, quick wins, compliance roadmap at quarter level).

This scan covers publicly visible signals only. Internal processes, authenticated environments, and infrastructure configuration are outside scope. Sentinel Lite and Sentinel Complete address those layers.

One scan. A factual baseline. The starting point for everything that follows.

 

Request your scanWhat does the report look like?