Sixteen questions, answered properly.
Sixteen questions answered at length: whether finding a problem makes it worse, whether this is legal advice, what is monitored, and what the audit covers.
Am I too late? My website has been up for years.
No. Regulators consistently weigh what you did once you knew. A business that finds its own issues, holds the evidence and fixes them on a documented timeline is in the strongest position available. The worst position is learning about a gap from a regulator's letter, a competitor's complaint or a claimant's demand, because someone else read your website first.
Who is Compliance Radar for?
Businesses whose public presence is policed by a named regulator: clinics, law firms, financial advisers, schools, hotels, restaurants, estate agencies, and their multi-location and multi-jurisdiction versions. If a single wrong claim, missing disclosure or misfiring pixel on your website costs more than a month of monitoring, you are who this was built for. In-house counsel and compliance teams use it as their evidence layer.
Is this legal advice?
No. The Radar produces evidence-backed findings mapped to published requirements: what was observed, which provision it concerns, what regulators have done in comparable cases, and how to fix it. Interpretation and decisions stay with you and your counsel. Many findings are deliberately tiered as indicators precisely because their legal conclusion needs a lawyer.
What happens after a risk is identified?
You are notified through your agreed channel (email, Slack, WhatsApp or a call) with the evidence, the exact act and section, the severity tier and a step-by-step fix with a suggested owner and deadline. We coordinate the remediation with your team, and when you say it is fixed, a fresh scan confirms it and the whole story is retained in the Evidence Vault.
I have one location. Is this overkill?
No, and it is priced for that case: one sector × one jurisdiction is the £1,200 base. A single-location clinic in England still carries a 29-requirement stack spanning the ICO, CQC, GDC, ASA and the CMA's new direct-fining powers. One location does not mean one regulator.
We operate in several countries and sectors. Does this scale?
Yes, that is what the Attachment Matrix is for. Each additional sector or jurisdiction adds £400/month and its full stack: 5,760 combinations are pre-mapped across the UK's four nations, US federal plus all 50 states, the EU and nine member states, UAE including DIFC, ADGM and DHCC, and Saudi Arabia. Capture runs from the market vantages you serve, so UK law is tested against UK evidence.
What exactly do you cover, and what do you not?
We cover your public digital presence: every public page, policy, form, cookie, script, booking and checkout flow, plus the law register that binds your combination. We do not cover internal systems, contracts, employment practices or anything behind a login unless separately agreed. And where a law depends on facts a website cannot prove, an employee threshold, a revenue test, the result says so instead of guessing.
How often do you scan?
Continuously, on a schedule agreed in your contract, with re-scans on demand around releases and fixes. We deliberately do not advertise a universal clock-speed: cadence is a contractual term, and a compliance company should not make timing claims on a marketing page that its contracts do not.
Can you guarantee we will be compliant?
No, and be wary of anyone who says yes. Compliance is a legal state that depends on facts, interpretation and things outside a website. What we guarantee is method: evidence captured and verified before anything is alleged, fail-closed applicability, tri-state honesty where "not assessed" never masquerades as "compliant", and a documented trail for everything.
What does "not assessed" mean in my results?
It means the law applies but the test could not run: a checkout that needs real payment, a threshold we could not verify, a page that blocked capture. We show it because hiding it would inflate your score. A report with zero "not assessed" entries across a complex site is a report you should distrust.
How is this different from a one-time audit or a site scanner?
Three ways. Scope: generic scanners check one rulebook; the Radar attaches your actual combination's stack, sector and sub-sector included. Evidence: findings only exist after artefacts are captured, hashed and independently re-verified: no artifact, no breach. Time: an audit is a snapshot; your website and the law both keep changing, and the Radar watches both sides.
What role does AI play, honestly?
A bounded one. AI classifies, extracts and proposes; it may never invent regulators, citations, penalties or enforcement, and it cannot upgrade an indicator into a breach. Citations are stored strings from a human-approved law catalogue. Quoted text is byte-matched against the captured page before it can support anything.
What happens when a law changes?
The law register is monitored like your website is: proposed, enacted, effective, amended, repealed. A change re-maps to every affected combination, re-scopes the tests and, where you are affected, you get notified with what it means for you. That is how clients heard about the CMA's DMCC powers going live and the EU AI Act's August 2026 transparency duties before the letters started.
Who sees my data, and what do you store?
We read your public pages, the same ones anyone can open. Captured artefacts are stored hashed and access-controlled as your evidence record, retained per contract. We do not resell data, and network captures are slimmed so personal data in response bodies is not needlessly retained.
Can my competitors really report me?
Yes. The ASA, CMA and FCA all accept complaints from competitors, and ASA rulings regularly open with "a competitor challenged whether…". Regulators also run their own automated monitoring: the ASA scanned nearly 60 million ads with AI in 2025, and the FCA assessed 480,000 new websites in a year. The question is not whether your site gets read, but who reads it first.
Where do your statistics come from?
Every figure on this site carries its source and period: regulator annual reports, official press releases, and named legal surveys. Where a number is not published, competitor-complaint splits, for example, we say so rather than invent one. Sample dashboards are always badged as sample data.
Still unanswered? Ask it on the audit form and we will reply with the provision, not a brochure.