The fines are real
Up to €20M or 4% of global turnover for breaches of principles, data-subject rights and transfers (Art. 83 GDPR).
Gen AI · GDPR & ePrivacy compliance
Point AXIOMA at one URL. A real browser engine opens the site, accepts and rejects consent, intercepts network, cookies and storage — and checks everything against GDPR, ePrivacy and Chapter V. You get a score, the violations and the evidence.
The problem
Up to €20M or 4% of global turnover for breaches of principles, data-subject rights and transfers (Art. 83 GDPR).
A lawyer needs days per site: policy, consent banner, cookies before consent, trackers, security headers.
Trackers and fingerprinting fire before consent, cookies live for years, data leaves for third countries — none of it visible to the naked eye.
EU supervisory authorities actively fine cookies-without-consent and opaque policies. You need continuous checking, not a one-off review.
Coverage · 46 automated checks
Completeness against Art. 13/14 — the 13 mandatory disclosures; presence of privacy & cookie policies; legal basis, retention periods and data-subject rights.
Consent banner / CMP quality, cookies and trackers before consent, pre-ticked boxes, whether "Reject all" is actually honored, declared vs actually-set cookies, excessive lifetimes.
Transfers outside the EEA, recipient geolocation and cross-domain submission of personal data.
TLS / HTTPS and handshake quality, HSTS, mixed content, transport depth, security headers, CSP, SRI and insecure transport of personal data.
Canvas / WebGL / Audio fingerprinting, session replay, pixels and third-party iframes before consent, social plugins, analytics IP anonymization.
A single compliance score, a ranked list of violations and the evidence behind each one — every finding mapped to the exact GDPR or ePrivacy article.
Technology core
A proprietary RAG engine checks the policy against the 13 mandatory Art. 13/14 disclosures: precise regex across 25+ languages plus local semantic embeddings (ONNX). Client data never leaves the server.
Regex coverage for the 13 Art. 13/14 requirements across 19+ EU languages, including Baltic, Greek and Czech.
Semantic accuracy measured on 897 real ground-truth EU-site policies across 9 eval-loop iterations, checked for zero regression on every update.
Semantic matching runs on-server (fastembed / ONNX) — no client data is ever sent to an external AI service.
A Playwright / Chromium engine opens the site, simulates accept / reject and intercepts network, cookies and storage — it sees what a real visitor's browser sees.
How it works
Point AXIOMA at your domain. It crawls pages, intercepts network traffic and inspects the consent banner — accepting and rejecting like a real user.
Findings are classified by GDPR / ePrivacy article with a risk tier and remediation guidance — every claim backed by evidence.
Export the report, fix the gaps and re-scan continuously to keep evidence ready for the supervisory authority.
Why AXIOMA
Policy analysis runs locally (regex + local embeddings) — client data never goes to an external AI service. Essential for a data-protection product.
Infrastructure on an EU server — processing and storage within the EEA, no transfer to third countries.
Every finding cites a source article and shows the evidence. No invented numbers, no hand-waving — built to stand up to a regulator.
On-Premise · Box Edition
Fully self-contained GDPR / ePrivacy auditing for banks, public sector and EU healthcare — where data must never leave the boundary.
Single-tenant deployment in your network with zero outbound cloud calls during scans; runs in fully isolated environments (images via docker save/load).
Policy analysis via regex + local embeddings (fastembed / ONNX) — client data never leaves your servers. 19 EU languages tested.
Art. 13/14 policy, consent & cookies, Chapter V transfers, Art. 9 special categories, Art. 8 children, Art. 32 security, AI Act transparency and fingerprinting.
Ed25519-signed offline activation (no call-home). Branded PDF reports, scoring and continuous monitoring included.
Download the installer for your OS, run it — Docker check, auto-deploy, demo opens in your browser. Demo mode: 1 domain, no commitment. Native-compiled core (anti-reconstruction), signed image, host-bound license.
Try it now
Enter a URL and AXIOMA checks it live — trackers and cookies firing before consent, missing consent banner, cross-border transfers, security headers, TLS and policy pages — each finding mapped to the exact GDPR or ePrivacy article.
Instant, free check · we don't store your URL · the scan runs from the EU
Tell us about your stack and we'll run AXIOMA on your own site.
info@axiomagdpr.comWe usually reply within one business day.