1. Enter the domain
BlindSpot crawls the public website and common support, search, policy, and widget paths.
Compliance guide
BlindSpot is not a legal opinion. It is an evidence pack for CTOs, DPOs, security leads, and product owners who need to see which AI compliance controls were checked, what passed, what failed, and who should fix it.
1. Enter the domain
BlindSpot crawls the public website and common support, search, policy, and widget paths.
2. Review discovered AI surfaces
SCAN-Agent lists chatbots, AI search, generated content, API chat endpoints, and third-party AI widgets.
3. Open Compliance reports
Each regulation shows area, article, goal, checked evidence, pass/fail/review status, owner, and remediation.
4. Export the evidence pack
The PDF includes the same regulation reports, findings, query ledger, certificate, and next steps.
Coverage
AI transparency and risk classification
Usage: A public user interacts with an AI system, sees AI-generated content, or is affected by AI-assisted decisions.
Articles
BlindSpot checks
Evidence returned
Personal data notice, security, DPIA, and breach readiness
Usage: The AI surface collects, processes, stores, infers, or exposes personal data from EU users.
Articles
BlindSpot checks
Evidence returned
Cybersecurity risk management and incident reporting
Usage: The company is an essential or important entity, or the AI surface creates supplier, logging, or incident-response exposure.
Articles
BlindSpot checks
Evidence returned
Consent before terminal access, cookies, widgets, and communications processing
Usage: A chat widget, AI widget, tracker, cookie, or third-party script loads before consent or reads user-device information.
Articles
BlindSpot checks
Evidence returned
Financial-sector ICT third-party and operational resilience risk
Usage: The audited company is a financial entity or uses AI vendors as part of regulated ICT services.
Articles
BlindSpot checks
Evidence returned
Result states
Pass
The check returned the expected safe result or no mapped breach was detected.
Fail
The returned result failed the control, exposed a mapped issue, or produced a critical finding.
Review
The result is incomplete, ambiguous, sector-dependent, or requires DPO/legal/security confirmation.
N/A
The framework does not apply to the detected sector or available evidence. DORA is usually N/A outside financial services.
How the compliance report should be used
Official references