Skip to main content
Best for: identifying which compliance regimes apply (CCPA, HIPAA, SOX, COPPA, BIPA, FedRAMP), dispatching the right checks, and rolling them up into a gap report. Describe your company and upload your compliance documents. An agent identifies the applicable regimes, launches the right child compliance workflows, waits for them, and produces a single gap report with immediate-action items.
This is one of three agentic workflows. Rather than running a fixed pipeline, it plans which checks to run based on your answers, then dispatches them as child runs. The child runs are visible from the parent run’s page.
Screenshot of the Compliance Scan Agent launcher showing its document slots and input form

The Compliance Scan Agent launcher: document slots, inputs, and what you get

What you need

Documents are optional: the agent can produce a regime-applicability analysis from your answers alone, though the gap findings get much sharper with documents attached.

Inputs

How it runs

1

Plan

The agent scopes the compliance surface from your answers and the uploaded documents, and decides which regime checks apply.
2

Launch children

Dispatches the planned compliance checks as child workflow runs.
3

Wait for children

Blocks until every child check completes. This is why the workflow runs on the long queue.
4

Synthesize

Aggregates the child findings into one prioritized gap picture.
5

Render

Writes the scan report.

What you get

Child runs remain individually inspectable from the parent run page, so you can drill from a summarized gap into the check that produced it.

What this will not do

  • Replace compliance counsel review for final remediation calls or breach-notification decisions.
  • Confirm regime applicability, such as HIPAA covered-entity status, SOX issuer status, or FedRAMP impact level, when the facts are ambiguous. Consult counsel.
  • Send regulatory notifications, file state breach notices, or respond to an FTC inquiry on your behalf.
  • Audit your actual data flows, vendor sub-processor chain, or technical controls beyond what is in the uploaded documents.
  • Run a technical security review: penetration testing, code audit, SOC 2 readiness assessment.

Privacy and Data Protection Audit

Deeper on privacy specifically, when you already know that is the regime.

Compliance check

The interactive single-check version.