Method
Deterministic by construction, cited without exception, versioned so an assessment can be replayed. Everything below is checked by the build rather than promised here.
One wizard, many instruments #
The questions ask about your solution, never about a regulation: nobody should need to know that screening job applicants is Annex III point 4 before being told so. There are 32 facts, in 6 sections.
Each pack declares which facts it reads, and a gate fails the build if a pack reads a fact the wizard never asks, or if the wizard asks a fact no pack reads. That gate found two real faults the first time it ran.
How a finding is reached #
Each rule is a plain condition over the facts, inspectable and arguable. There is no model, no score and no ranking. The same answers always produce the same findings, which a gate verifies across 768 fact profiles on every build.
Findings are ordered by severity and then by date: prohibited practices first, because nothing else matters until they are resolved, then classification, then obligations, cautions and notes.
What it refuses to do #
It does not advise. A finding states what a provision requires and when it binds. The judgement stays with you and your advisers.
It does not assert national law. A directive binds through each Member State's transposing law. Where an instrument is a directive, this service states the directive's requirements and raises a caution rather than asserting a national obligation it cannot verify. Transposition also remains uneven across the Union.
It does not present proposals as law. Amendments still in negotiation are carried as watch items, marked proposed. Nothing proposed binds anyone today. The integrity gate rejects any watch item not marked as such.
Sharing an assessment #
An assessment can be copied as a link. The link carries the answers, the ruleset version and a digest of what was found, encoded in the fragment: the part of an address after the hash, which a browser never sends to a server. Nothing is uploaded, no record is created here, and there is nothing to delete afterwards.
Opening someone else's link recomputes the assessment from their answers under whatever ruleset is current, then reports what changed against what the link recorded. Two links opened together compare the two solutions instead: which answers differ, which findings they share, and which belong to only one of them.
A link that has been damaged in transit is refused rather than half-read, because a half-read link produces a confident wrong answer. A link written by a later version says so instead of being misinterpreted.
If you store an assessment #
Assessing a solution needs no account and stores nothing. Keeping a record of one, so that it can be replayed when the law moves, is a separate service on a separate address. It is built and it is not open. It will accept accounts once a legal review and indemnity cover are in place, and not before, and until then every route on it refuses with an explanation rather than quietly working.
When it opens, accounts will be by invitation and offered to businesses rather than to consumers, which is how the operator knows who holds records and why.
The design decision worth stating now, because it constrains everything else: a stored assessment is encrypted in your browser before it is sent, under a passphrase you choose, and cannot be read by the operator. A compliance assessment is a list of the places an organisation may be breaking the law. The operator has no business being able to read that, and being unable to read it removes most of what a breach could cost either party.
What that costs, said plainly rather than in a footnote: a forgotten passphrase means the record is unrecoverable, and no intervention can change that.
What the service can still do without reading anything: list your records by the name you gave them, replay one against a later ruleset to report whether it still holds, and compare two that you have opened in your own browser.
Signing in uses a code sent to your address and then a second factor from an authenticator app, which is required rather than offered. A correct code alone reaches nothing. Every action on an account is written to a chained log, so an entry cannot be altered or removed without leaving a break that anyone with a copy can find, and you can export or delete everything yourself.
Losing the authenticator does not lose the account. Eight recovery codes are issued once when the factor is confirmed, each usable once. Losing those as well starts a reset that takes effect after 72 hours and can be stopped from the moment it is requested, so somebody who has taken over an address cannot use it quietly. A completed reset retires every remembered device.
Watching the sources #
A scheduled job asks the Publications Office of the European Union, twice a week, which consolidated version of each instrument is current, and compares the answer against the one recorded last time. It asks through the machine service the publisher provides for automated clients rather than by reading the human website, which is both the route that works and the one the publisher asks for. What changes when an amending act takes effect is the consolidated document identifier, and that identifier is what the watch compares.
When a source moves, the detection is committed and published on the verification page the same day, before anybody has read the amendment. That is deliberate. A reader relying on a finding is entitled to know that the ground under it has shifted, rather than learning it from a release some weeks later.
The watch cannot change a rule. It writes only its own records, it cannot reach a pack, and it cannot cut a release, all of which a build gate enforces by reading its source. Deciding what an amendment means to a provision is a reading, and a reading is recorded by a person in the log with what they read. An instrument whose rules could be rewritten by a scheduled job would have no verification record worth the name.
Versions and replay #
Every assessment records the ruleset it was made under, and every release publishes an immutable, checksummed snapshot. When the law moves, an assessment can be replayed to show what changed for this solution: which findings appeared, which vanished, which dates moved.
That is what makes replay honest. Given the same answers and a later ruleset, the engine reports what changed for that solution: which findings appeared, which disappeared, which dates moved. The AI Act moved four dates and added two prohibitions six days before enforcement began, and nothing told the people who had assessed their systems that spring.
Published rulesets: v0.1.0 · v0.2.0 · v0.2.1 · v0.3.0 · v0.4.0 · v0.5.0 · v0.6.0 · v0.6.1 · v0.7.0 · v0.7.1 · v0.7.2 · v0.7.3 · v0.7.4 · v0.7.5 · v0.7.6 · v0.8.0 · v0.8.1 · v0.8.2 · v0.8.3 · v0.8.4 · v0.8.5 · v0.9.0
What the build checks #
| Gate | What it refuses |
|---|---|
| Integrity | A rule without a provision, a date, a severity or a check record; a watch item not marked proposed |
| Facts coverage | A pack reading an undeclared fact; a question no pack consumes |
| Engine cases | Sixteen worked examples, including the deferred dates and the derogation |
| Invariants | 768 fact profiles: every finding cited, dated and attributable; determinism |
| Snapshot | Any edit to a ruleset already published |
| Replay parity | A snapshot that no longer reproduces the live ruleset, rule for rule and condition for condition |
| Design | A colour outside the token module; contrast below AA in either theme; a page that is not responsive |
| Site | A third-party script in the built pages; an analytics beacon that could read the fragment, the query or the full address; a beacon that does not refuse the assessment page; a wizard that does not reach an assessment; a configuration that gains server code |
| Accessibility | A page without a single first-level heading or named landmarks; a heading level skipped; a control with no accessible name; a wizard that cannot be completed by keyboard |
| Performance | A first visit heavier than its ceiling, measured gzipped, so that growth is noticed rather than discovered |
| House style | An em dash, an American spelling, a curly quote, or any wording that reads as advice rather than as a report |
| Brand | The name spelled more than one way; a page not stating its build; an address in harvestable form; a canonical tag pointing elsewhere |
| Documentation | The repository's verification document drifting from the records it is generated from |
| Compliance package | A retention period claimed in the record of processing that no statement enforces; an outbound call the sub-processor list does not account for; a Worker route that can decrypt a record while the agreement says it cannot |
| Registry plane | A dormant plane that stores anything or creates an account; an authenticated route reachable without a session; a session usable before the second factor is complete; one reader able to reach another's record; an unencrypted record accepted; a recovery code that works twice or is stored readably; a reset that completes early or survives cancellation; an audit chain that does not verify or that omits an action |
| Registry foundations | A stored record readable without its passphrase; an audit entry that can be altered, deleted or reordered without leaving a break; a token that can be forged, stretched or presented for the wrong purpose; a schema that states no retention |
| Source watch | An encoded instrument nobody watches; a watcher that could write to a rule; a moved source reported without naming what depends on it; a page it cannot parse treated as unchanged |
| Links and playback | An answer lost in encoding; a link that decodes when damaged; a digest that reports change where there is none; a payload placed in a query string |
| Restore drill | A guarantee named on this page that no longer exists, runs, or matches the figure it quotes |