Gen AI · GDPR & ePrivacy compliance

GDPR breaches on your site —
found in minutes, not days.

Point AXIOMA at one URL. A real browser engine opens the site, accepts and rejects consent, intercepts network, cookies and storage — and checks everything against GDPR, ePrivacy and Chapter V. You get a score, the violations and the evidence.

46
automated checks
5
compliance domains
19
EU languages — policy analysis
0.91–0.97
F1 on real EU-site policies
EU
hosted · data never leaves the server

The problem

GDPR compliance is costly, slow and easy to miss

The fines are real

Up to €20M or 4% of global turnover for breaches of principles, data-subject rights and transfers (Art. 83 GDPR).

Manual audits don't scale

A lawyer needs days per site: policy, consent banner, cookies before consent, trackers, security headers.

Violations are invisible

Trackers and fingerprinting fire before consent, cookies live for years, data leaves for third countries — none of it visible to the naked eye.

Regulators are watching

EU supervisory authorities actively fine cookies-without-consent and opaque policies. You need continuous checking, not a one-off review.

Coverage · 46 automated checks

Five compliance domains — from policy to trackers

01

Privacy policy

Completeness against Art. 13/14 — the 13 mandatory disclosures; presence of privacy & cookie policies; legal basis, retention periods and data-subject rights.

02

Consent & cookies

Consent banner / CMP quality, cookies and trackers before consent, pre-ticked boxes, whether "Reject all" is actually honored, declared vs actually-set cookies, excessive lifetimes.

03

Data transfers · Chapter V

Transfers outside the EEA, recipient geolocation and cross-domain submission of personal data.

04

Security of processing · Art. 32

TLS / HTTPS and handshake quality, HSTS, mixed content, transport depth, security headers, CSP, SRI and insecure transport of personal data.

05

Tracking & fingerprinting

Canvas / WebGL / Audio fingerprinting, session replay, pixels and third-party iframes before consent, social plugins, analytics IP anonymization.

06

Score & evidence

A single compliance score, a ranked list of violations and the evidence behind each one — every finding mapped to the exact GDPR or ePrivacy article.

Technology core

Policy-text analysis — with no external AI

A proprietary RAG engine checks the policy against the 13 mandatory Art. 13/14 disclosures: precise regex across 25+ languages plus local semantic embeddings (ONNX). Client data never leaves the server.

1500+ multilingual patterns

Regex coverage for the 13 Art. 13/14 requirements across 19+ EU languages, including Baltic, Greek and Czech.

0.91–0.97 F1 accuracy

Semantic accuracy measured on 897 real ground-truth EU-site policies across 9 eval-loop iterations, checked for zero regression on every update.

Local embeddings

Semantic matching runs on-server (fastembed / ONNX) — no client data is ever sent to an external AI service.

Real-browser engine

A Playwright / Chromium engine opens the site, simulates accept / reject and intercepts network, cookies and storage — it sees what a real visitor's browser sees.

How it works

From scan to audit-ready in three steps

  1. 1

    Scan

    Point AXIOMA at your domain. It crawls pages, intercepts network traffic and inspects the consent banner — accepting and rejecting like a real user.

  2. 2

    Map & assess

    Findings are classified by GDPR / ePrivacy article with a risk tier and remediation guidance — every claim backed by evidence.

  3. 3

    Operate

    Export the report, fix the gaps and re-scan continuously to keep evidence ready for the supervisory authority.

Why AXIOMA

Why AXIOMA — not a cloud AI service

01

Privacy by design

Policy analysis runs locally (regex + local embeddings) — client data never goes to an external AI service. Essential for a data-protection product.

02

Data stays in the EU

Infrastructure on an EU server — processing and storage within the EEA, no transfer to third countries.

03

Evidence, not opinions

Every finding cites a source article and shows the evidence. No invented numbers, no hand-waving — built to stand up to a regulator.

On-Premise · Box Edition

Run AXIOMA inside your own perimeter

Fully self-contained GDPR / ePrivacy auditing for banks, public sector and EU healthcare — where data must never leave the boundary.

On-premise & air-gapped

Single-tenant deployment in your network with zero outbound cloud calls during scans; runs in fully isolated environments (images via docker save/load).

No external AI

Policy analysis via regex + local embeddings (fastembed / ONNX) — client data never leaves your servers. 19 EU languages tested.

46 automated checks

Art. 13/14 policy, consent & cookies, Chapter V transfers, Art. 9 special categories, Art. 8 children, Art. 32 security, AI Act transparency and fingerprinting.

Offline licensing

Ed25519-signed offline activation (no call-home). Branded PDF reports, scoring and continuous monitoring included.

Demo in minutes

Download the installer for your OS, run it — Docker check, auto-deploy, demo opens in your browser. Demo mode: 1 domain, no commitment. Native-compiled core (anti-reconstruction), signed image, host-bound license.

Windows · macOS · Linux

Try it now

Scan your website for GDPR & ePrivacy issues

Enter a URL and AXIOMA checks it live — trackers and cookies firing before consent, missing consent banner, cross-border transfers, security headers, TLS and policy pages — each finding mapped to the exact GDPR or ePrivacy article.

Instant, free check · we don't store your URL · the scan runs from the EU

Make GDPR compliance continuous

Tell us about your stack and we'll run AXIOMA on your own site.

info@axiomagdpr.com

We usually reply within one business day.