EU digital regulation arrived all at once: the EAA is enforced, alongside GDPR, the DSA, and NIS2. Most teams have no idea which clause their site is breaking, or how to fix it. ComplianceLayer scans a site, names the exact clause, and writes the remediation: evidence for an auditor, a patch for a developer. I ran the UX and shipped it as a live product.

The live product: scan a URL, get a scored compliance certificate.
The brief came from a real change: the European Accessibility Act moved from theory to enforcement in 2025, landing on top of GDPR, the DSA, and NIS2. To understand the pain rather than the statute, I traced the journey of a single compliance finding through an organisation and talked to the two people it lands on. They turned out to never share a language.
A compliance lead or founder is told they are non-compliant, with no way to translate a legal clause into an action a team can take.
An engineer or agency has to act, but the requirement arrives as prose, not as a patch they can paste and verify.
Between "you are non-compliant" and "here is the line that fixes it" sits expensive consulting. Closing that handoff, in one tool, was the whole opportunity.
Turn a regulation into a named clause and a written fix, for both the person who gets the letter and the person who ships the patch. Scope kept trying to widen into a full GRC suite; running each idea through these six questions is what kept it to one job done well.
Compliance leads and founders, plus the developers and agencies who fix it.
A scanner that names the clause and writes the remediation.
EU rules are enforceable now, but unreadable, and audits are expensive.
Before a regulator, a customer, or an RFP asks for proof.
Any public EU-facing website, scanned on demand.
One scan engine, two outputs, anchored to real articles.
The entire product is a single flow, and I designed it to prove value before asking for anything. You paste a URL, the scan runs, and you get a scored certificate, what passed, what is breaking, the article behind each finding, and the fix. The first scan is free with no signup, because the fastest way to earn trust is to let someone watch their own site get graded.

The operator dashboard: score, findings, monitors, and recent scans.
I structured the report around the four questions an auditor actually asks. That structure was also a guardrail: every finding has to cite a real article, propose a real fix, and stand up as evidence, or it does not ship.
Every finding points to the exact article behind it, such as a specific GDPR Article 13 disclosure gap. No invented severity scores.
A plain-language explanation and a copy-paste patch for the team's framework.
A verifiable, timestamped certificate at a permanent URL, for RFPs and audits.
Optional monitors re-scan on a schedule and email the team on a regression, not the regulator.

The second decision followed straight from discovery: refuse to pick one audience. The same scan produces two outputs, a clause-by-clause report for the person who gets the letter, and a developer-ready patch, branded as your own, for the agency that ships the fix. One engine, two surfaces, so neither reader has to translate the other's language.

Coverage is framed by consequence, not statute: the European Accessibility Act, data protection under GDPR, the Digital Services Act, and the NIS2 baseline, each explained by what it means for a site owner, including the real fines.

I built it as a live service rather than a spec, so every decision had to survive contact with a real scan instead of looking right in a deck.
A compliance buyer trusts a dated, verifiable record at a permanent URL, not a number on a landing page. So I designed the output to read like evidence an auditor would accept, down to the timestamp and the article reference, because that is the difference between a tool they cite and a tool they ignore.
The scanner uses models to read pages and draft fixes, but every finding is anchored to a named clause and a checkable patch. A reviewer can trace the claim, verify it, or throw it out, the machine proposes and the human disposes.
I moved from concept to a live, scanning product using AI build tools, treating prototyping in code as the design medium, not a step after it.
This was self-QA, not user research: I pointed the scanner at real production websites and read its output the way a sceptical auditor would read mine. The rule that emerged became the product's spine: if a finding could not be traced to a real article and turned into a checkable fix, it was cut. That is what keeps the report trustworthy instead of alarming.
Vague warnings were removed until every line cited an article a developer could verify.
Remediations were rewritten until they read as a patch, not advice.
ComplianceLayer is live and scanning today: a free first scan with no signup, a scored certificate at a permanent URL, and monitors that re-scan on a schedule. It collapses an expensive, lawyer-shaped process into a one-minute report two different readers can act on, and it shows the way I now work, research, design, and ship as one motion.