Skip to main content

Privacy compliance, verifiable on every deploy.

Syrcha continuously audits your sites for GDPR, CCPA, WCAG and AI Act issues. Real browser checks, signed reports, no marketing theatre.

Public beta: 50% off your first 3 months.

Frameworks
GDPR · CCPA · WCAG · AI Act (soon)
Rules
80
Hosting
EU
syrchascanacme.example.com
47.2s

Overall

86/100

GDPR

91/100

CCPA

74/100

  • TLS 1.3, HSTS preloadpass
  • Consent banner: reject equal weightpass
  • No pre-checked consent boxespass
  • Privacy policy reachable in 1 clickpass
  • Cookies set before consentwarn
  • "Do Not Sell" link missing (CCPA)fail
  • DSAR contact disclosedpass
  • AI chatbot disclosurewarn
signed · sha256:9c4a…d712last run · 14m ago

/ capabilities

What a privacy scan should look like.

Real Chrome, real DOM, real network. We don't grep your HTML; we interact with consent banners, reject tracking, and verify what still fires the way an auditor would.

01 - interact

Browser-driven, not regex-driven

A real Chrome instance loads the site, clicks reject on the consent banner, and watches what still gets stored, sent, or set after you decline. Static crawlers can't see this. Auditors do.

02 - stamp

Signed, hash-stamped reports

Every report carries an HMAC-SHA256 signature over the page state and rule set. Replayable, attributable, audit-ready.

03 - diff

Diff between scans

See exactly what changed between Tuesday's deploy and today's. Regressions surface before legal does.

04 - fix

Findings include the fix, not just the problem

Network and cookie violations link to the offending request and the responsible script, alongside a worked example of remediation. Engineers fix in minutes, not meetings.

/ coverage

Four regimes. One audit trail.

Every framework below carries its real status (live, beta, or not yet shipped) with the coverage it has today and the tier that unlocks it. We would rather show you the gaps than average them away.

  • GDPR

    EU · EEA · UK

    Live

    General Data Protection Regulation

    Full ruleset live. Consent, lawful basis, DSAR routes, transfer notices.

    • Privacy policy reachable in one click
    • Cookie banner: reject equal weight to accept
    • No cookies set before consent
    • Pre-checked consent boxes flagged
    • DSAR contact disclosed
    • HTTPS + HSTS enforced
    • Unsubscribe present in marketing email
    • International transfer notices verified
  • WCAG

    WCAG 2.1 / 2.2 · Section 508

    Live

    Web Content Accessibility Guidelines

    axe-core accessibility scanning live. 64 rules. Free covers 2.1 A; AA and 2.2 unlock on higher tiers, and each plan is scanned against the standards it includes. Section 508 conformance is reported from the WCAG 2.0 A+AA criteria it incorporates.

    • Images carry alt text
    • Colour contrast meets thresholds
    • Form fields have labels
    • Heading hierarchy is ordered
    • Links have discernible text
    • Page has a document language
    • ARIA roles used validly
    • Interactive elements reachable by keyboard
  • CCPA

    California · USA

    Beta

    California Consumer Privacy Act / CPRA

    Core ruleset in beta. "Do Not Sell" detection, consumer rights, sale disclosures.

    • "Do Not Sell or Share" link present
    • California-specific rights disclosure
    • Sensitive data category notices
    • Consumer request flow accessible
  • AI Act

    EU · phased through 2026

    Q3 2026

    EU Artificial Intelligence Act

    Transparency checks shipping Q3 2026. Chatbot disclosure, system docs, risk tier.

    • AI chatbot identifies itself
    • Generated-content disclosure
    • Risk-tier documentation reachable
    • Affected-user notice present

/ how it works

Three steps. The middle one does the work.

  1. Point at a domain

    Add a URL, verify DNS ownership, set a cadence. Free plan covers your first domain, no card needed.

  2. We run real Chrome

    Headless Chromium loads, clicks reject on consent banners, captures every request and storage write before and after, typically under a minute on a normal page.

  3. You get a signed report

    Findings, suggested fixes, diffs against the last run, and an HMAC-SHA256 signature over the rule set used. PDF, HTML, or webhook.

/ reportacme.example.com
14m ago

Overall

86 /100

GDPR

91 /100

CCPA

74 /100

WCAG

88 /100

  • TLS 1.3 · HSTS preloadgdpr
  • Consent banner: reject equal weightgdpr
  • Cookies set before consentgdpr
  • "Do Not Sell" link missingccpa
  • DSAR contact reachablegdpr
signed · sha256:9c4a…d71233,529 assertions
Run your first scan

no card · 1 domain · weekly scans

/ pricing

Honest pricing. Beta keeps it half-off.

Start free, no card. 50% off your first three months when you upgrade, while we finish the AI Act ruleset. Cancel any time. No "contact sales" tier hiding the real price.

Free

Kick the tyres, no card

$0forever

Free while you need it

  • 1 website
  • Weekly scans, 4 / month
  • Up to 5 pages per scan
  • WCAG 2.1 A accessibility rules
  • All 29 GDPR checks - score & issue count
  • HTML reports
  • No credit card required
Start for free

Starter

Solo sites & freelancers

$14.50/ month

$29 · first 3 months

  • 1 domain
  • Weekly scans, 30 / month
  • GDPR + CCPA rules, every finding named: duty, page, fix
  • HTML & PDF reports
  • Slack & email alerts
  • Email support
Start for free

Agency

Agencies & consultancies

$124.50/ month

$249 · first 3 months

  • 20 domains
  • Daily scans, 600 / month
  • White-label reports (coming soon)
  • Section 508 conformance statement on reports
  • API + webhook access
  • Historical trends
  • Dedicated channel
Start for free

Beta discount holds for three months from sign-up. After that, list price. Cancel from settings without sending an email.

/ ready

Stop hoping you're compliant. Know.

First scan in under a minute. No card. No call. You'll know what's broken before you finish your coffee.

  • no card required
  • cancel from settings
  • hosted in EU