Skip to content
ComplyMynt

Services

Every risk surface an AI or SaaS company actually gets caught on.

Seven review domains, one methodology, one report. Run the full audit or start with a focused review.

AI Governance

End-to-end review of model usage, data flows, vendor terms, disclosures, and automated decision risk across your product surface.

  • Model & data flow mapping
  • Training-data and vendor terms
  • Disclosure gap analysis

Privacy Compliance

Tag, tracker, and consent-banner analysis mapped to GDPR, CPRA, and state privacy expectations — with evidence you can hand to counsel.

  • Tracker inventory
  • Consent banner behavior
  • Policy-to-practice mismatch

TCPA Compliance

Forms, SMS flows, call scripts, and lead-gen paths reviewed for express written consent, revocation, and record-keeping defects.

  • Form & disclosure capture
  • Opt-out handling
  • Lead vendor exposure

Accessibility (WCAG)

WCAG 2.2 AA testing combining automated scans with manual keyboard, screen-reader, and contrast validation on real user journeys.

  • Keyboard & AT testing
  • Contrast & semantics
  • Remediation backlog

Cybersecurity Review

Externally observable security posture: headers, exposure, authentication surfaces, and disclosure readiness — no intrusive testing.

  • Header & TLS posture
  • Exposed surface review
  • Disclosure program setup

Website Compliance

A full-site review of legal, privacy, accessibility, and technical signals that enterprise buyers and regulators evaluate first.

  • Policy consistency
  • Technical SEO & crawler directives
  • Form and disclosure language

Enterprise Audits

Board-ready, multi-domain assessments with procurement-friendly deliverables, vendor questionnaires, and quarterly re-verification.

  • Multi-domain assessment
  • Procurement packets
  • Quarterly exec reporting

In practice

Evidence, not checklists.

Every domain produces reproducible artifacts your engineers can act on the same day.

Consent management interface with granular category toggles

Consent & privacy

We replay your banner against real tag firing order, revocation, and record retention.

Accessibility testing view with focus outlines, keyboard path and contrast checks

Accessibility

Keyboard, screen reader, and contrast passes on the journeys that actually convert.

Security posture visualization with TLS certificate and HTTP header checks

Public security

Externally observable posture — headers, TLS, exposure — with zero intrusive testing.

Comprehensive risk assessment

Six domains, and every check inside them

A full assessment runs all six. Each domain can also be scoped and delivered on its own.

AI Governance & Transparency

How your models are used, disclosed, and governed — from training-data provenance to the words a user actually sees.

  • AI disclosure and automated-processing notices
  • Model and data-flow mapping across product surfaces
  • Training-data provenance and vendor licensing terms
  • Human-review and appeal paths for automated decisions
  • AI output labeling, provenance metadata, and hallucination disclaimers
  • EU AI Act transparency readiness posture

Accessibility

WCAG 2.2 AA testing that combines automated scanning with manual keyboard and screen-reader passes on real journeys.

  • WCAG 2.2 AA conformance testing (automated + manual)
  • Keyboard operability and focus-order review
  • Screen-reader traversal on signup, checkout, and support flows
  • Color contrast, target size, and motion-preference handling
  • Form labeling, error identification, and status messaging
  • Accessibility statement and feedback channel review

Security & Infrastructure

Externally observable posture only — headers, transport, and email authentication. No intrusive testing, ever.

  • Security headers review (CSP, X-Frame-Options, Referrer-Policy)
  • CSP and HSTS policy strength and preload posture
  • SSL/TLS configuration, cipher suites, and certificate hygiene
  • SPF, DKIM, and DMARC email authentication alignment
  • Public attack-surface and exposed-endpoint review
  • Responsible disclosure program and security.txt readiness

Technical Trust

The machine-readable signals that determine how search engines, AI crawlers, and enterprise buyers perceive you.

  • robots.txt directives and crawler/AI-agent handling
  • sitemap.xml completeness and technical SEO review
  • Structured data, canonical, and metadata integrity
  • Core Web Vitals and performance budget review
  • Public security disclosure and trust-page readiness
  • Vendor questionnaire and enterprise-readiness artifacts

Remediation roadmap

Findings arrive already sequenced

Immediate, 30-day, 60–90 day, and ongoing monitoring — so nobody has to argue about what to do first.

Week 1

Immediate

Stop active exposure

  • Gate all non-essential tags behind verified consent
  • Publish AI disclosure on every model-influenced surface
  • Separate SMS consent capture and begin retaining proof
  • Correct any policy statement that contradicts observed behavior

Weeks 2–4

30-Day

Close material findings

  • Ship the accessible checkout dialog and keyboard path
  • Enforce CSP after a clean report-only window
  • Add HSTS, frame-ancestors, and Referrer-Policy at the edge
  • Stand up the consent and revocation audit log export

Months 2–3

60–90 Day

Systemize and document

  • Complete WCAG 2.2 AA remediation across remaining journeys
  • Move DMARC to enforcement with aligned senders
  • Generate the subprocessor list and sitemap from source of record
  • Document the human-review path and AI risk classification

Continuous

Ongoing Monitoring

Keep closed findings closed

  • Scheduled re-scans across all six assessment domains
  • CI guardrails blocking pre-consent requests and a11y regressions
  • Header, TLS, and DNS baseline drift alerting
  • Quarterly executive report with trended domain scores