Skip to content
ComplyMynt

Comprehensive risk assessment

Six domains. One evidence file. Every finding ships with a fix.

We assess the surfaces AI and SaaS companies actually get caught on — then hand your engineers reproducible evidence and a sequenced remediation plan. Technical assessment, not legal advice.

Get started

Choose how to engage

Start with a free scan, upload an existing report, or see the platform in action.

Free Website Scan

Run a read-only surface scan and get a high-level risk snapshot in minutes — no signup required.

Start free scan

Upload Report

Already have a scanner or prior audit output? Upload it and we'll triage the findings against our methodology.

Upload for review

Live Demo

See how a comprehensive assessment works on a real product surface with our team in a 30-minute walkthrough.

Book a demo

Coverage

What a comprehensive assessment covers

Run all six domains together, or start with the one your buyers keep asking about.

AI Governance & Transparency

How your models are used, disclosed, and governed — from training-data provenance to the words a user actually sees.

  • AI disclosure and automated-processing notices
  • Model and data-flow mapping across product surfaces
  • Training-data provenance and vendor licensing terms
  • Human-review and appeal paths for automated decisions
  • AI output labeling, provenance metadata, and hallucination disclaimers
  • EU AI Act transparency readiness posture

Accessibility

WCAG 2.2 AA testing that combines automated scanning with manual keyboard and screen-reader passes on real journeys.

  • WCAG 2.2 AA conformance testing (automated + manual)
  • Keyboard operability and focus-order review
  • Screen-reader traversal on signup, checkout, and support flows
  • Color contrast, target size, and motion-preference handling
  • Form labeling, error identification, and status messaging
  • Accessibility statement and feedback channel review

Security & Infrastructure

Externally observable posture only — headers, transport, and email authentication. No intrusive testing, ever.

  • Security headers review (CSP, X-Frame-Options, Referrer-Policy)
  • CSP and HSTS policy strength and preload posture
  • SSL/TLS configuration, cipher suites, and certificate hygiene
  • SPF, DKIM, and DMARC email authentication alignment
  • Public attack-surface and exposed-endpoint review
  • Responsible disclosure program and security.txt readiness

Technical Trust

The machine-readable signals that determine how search engines, AI crawlers, and enterprise buyers perceive you.

  • robots.txt directives and crawler/AI-agent handling
  • sitemap.xml completeness and technical SEO review
  • Structured data, canonical, and metadata integrity
  • Core Web Vitals and performance budget review
  • Public security disclosure and trust-page readiness
  • Vendor questionnaire and enterprise-readiness artifacts

Evidence-based findings

Every finding, with proof attached

Filter by severity, then open any finding for the captured evidence, affected URLs, business impact, and the engineering steps that close it.

Network trace evidence showing third-party tracker requests firing before the consent banner is answered
PRI-014CriticalPrivacy & Consent

Analytics and ad trackers fire before consent

/ , /pricing, /signup

Evidence captured

  • HAR trace of first paint showing six third-party requests before any banner interaction
  • Annotated screenshot of the banner in its pre-interaction state with identifiers already set
  • Reproduction steps against a clean EU session profile

Engineering-ready steps

  1. 1Move all vendor tags out of the base template into a consent-gated container
  2. 2Add a server-side guard that refuses tag injection without a stored consent record
  3. 3Ship a Playwright test asserting zero third-party requests before consent
  4. 4Backfill a consent audit log with timestamp, version, and choice

Business impact

Every European session creates a documented processing event without a lawful basis. This is the single most common trigger for supervisory-authority complaints and the first thing an enterprise buyer's privacy team tests.

Recommended fix. Gate every non-essential tag behind a server-verified consent signal and prove it in CI.

Estimated effort. 3–5 engineering days

Redacted from a real engagement. Technical assessment only — not legal advice.

Remediation roadmap

Sequenced so the riskiest thing gets fixed first

Findings are grouped into four delivery phases with owners, acceptance criteria, and regression tests in the full report.

Week 1

Immediate

Stop active exposure

  • Gate all non-essential tags behind verified consent
  • Publish AI disclosure on every model-influenced surface
  • Separate SMS consent capture and begin retaining proof
  • Correct any policy statement that contradicts observed behavior

Weeks 2–4

30-Day

Close material findings

  • Ship the accessible checkout dialog and keyboard path
  • Enforce CSP after a clean report-only window
  • Add HSTS, frame-ancestors, and Referrer-Policy at the edge
  • Stand up the consent and revocation audit log export

Months 2–3

60–90 Day

Systemize and document

  • Complete WCAG 2.2 AA remediation across remaining journeys
  • Move DMARC to enforcement with aligned senders
  • Generate the subprocessor list and sitemap from source of record
  • Document the human-review path and AI risk classification

Continuous

Ongoing Monitoring

Keep closed findings closed

  • Scheduled re-scans across all six assessment domains
  • CI guardrails blocking pre-consent requests and a11y regressions
  • Header, TLS, and DNS baseline drift alerting
  • Quarterly executive report with trended domain scores