Open Source MIT License

Scan any website for compliance issues in 60 seconds

47 rules across GDPR, WCAG 2.2, security, and transparency. One command. HTML, JSON, CSV, and SARIF reports. Built for CI/CD.

$ npx complytest scan https://your-site.com

47 rules across 4 compliance categories

Every rule includes rationale, evidence collection, and remediation hints. Built on real regulatory requirements.

Consent & Privacy

11 rules

GDPR Article 7 consent, cookie enforcement, banner validation, Google Consent Mode v2, and consent withdrawal mechanisms.

GDPR ePrivacy EDPB TCF 2.2

Accessibility

16 rules

WCAG 2.2 Level AA coverage: color contrast, ARIA validation, keyboard navigation, focus management, target size, and accessible authentication.

WCAG 2.2 EAA ADA

Security

14 rules

CSP headers and quality, HSTS, HTTPS enforcement, secure cookies, Subresource Integrity, COOP/COEP, and Permissions-Policy.

OWASP PCI DSS CSP

Transparency

6 rules

Privacy policy presence, terms of service, data controller identification, contact information, complaint mechanisms, and ad disclosure.

DSA GDPR Art 13 FTC

Reports in every format you need

Generate compliance reports for your team, CI/CD pipeline, or regulatory filings.

HTML

Interactive dashboard with charts and drill-downs

JSON

Machine-readable for CI/CD and API integrations

CSV

Spreadsheet-ready for compliance teams

SARIF

GitHub Security tab integration

How it works

1

Install

No configuration needed. Run directly with npx or install globally.

2

Scan

Real browser testing with Playwright. Detects cookies, consent banners, accessibility issues, and security headers.

3

Report

Get a detailed compliance score with category breakdowns, failing rules, and remediation hints.

$ npx complytest scan https://example.com
 
Results for https://example.com
Scanned in 4.2s
 
  Score: 68% (32/47 rules passed)
  consent          WARN  7/11
  accessibility    PASS  14/16
  security         FAIL  8/14
  transparency     PASS  6/6
  15 failing rules:
    - consent.cookies_before_consent: 8 non-essential cookies
    - security.hsts: Missing Strict-Transport-Security header
    ...

Need continuous monitoring?

Complicer is the managed platform built on ComplyTest. Automated daily scans, team routing, SLO monitoring, Jira integration, and legal-grade audit trails.