🇺🇸 Built for US businesses

Spot your US privacy gaps
before a regulator does.

US privacy laws — the CCPA/CPRA in California and a fast-growing list of state laws — can apply to your site once you do business in a state and cross its thresholds, wherever your company is incorporated. Our free scan checks your site against CCPA/CPRA and VCDPA and shows you the observable gaps. Which laws ultimately apply depends on your business facts — we help you see where to look.

🇺🇸 CCPA / CPRA 🇺🇸 VCDPA 🇪🇺 GDPR 🇬🇧 UK GDPR 🇨🇦 PIPEDA + 8 more laws if you sell internationally

Is your website exposed?

Enter your URL — our AI checks it against CCPA/CPRA and VCDPA in seconds, for free.

A full report in 3 steps

No legal background required. Our AI does the reading so you don't have to.

1

Automatic detection

amalyon crawls your website: languages, currencies, hreflang tags, phone prefixes, cookie banners, legal notices. If nothing points elsewhere, we default to US law — the way your visitors' browsers do.

2

State-by-state legal analysis

Claude AI checks your site against CCPA/CPRA and VCDPA: score out of 100, 8 evaluated criteria (privacy notice, opt-out rights, do-not-sell signals, data retention…), maximum fine exposure.

3

Report delivered by email

Compliance score, fine exposure, and the top 3 fixes to make first — all in your inbox within the hour.

The two laws driving US enforcement today

CCPA/CPRA and VCDPA are the models most other state privacy laws are built on.

🇺🇸 CCPA / CPRAHigh priority
California Consumer Privacy Act (as amended by CPRA)
Max fine: $7,500 per intentional violation
🇺🇸 VCDPAPriority
Virginia Consumer Data Protection Act
Max fine: $7,500 per violation
What about Colorado, Connecticut, Utah, Texas, Oregon…? A dozen more states have passed privacy laws modeled closely on CCPA and VCDPA. Our automated report covers CCPA/CPRA and VCDPA directly — getting those two right resolves the substance of what the other state laws require, though we don't yet score each state law individually. We're adding more as enforcement data comes in.

SELLING BEYOND THE US? THE SAME SCAN ALSO CHECKS (see also our dedicated GDPR guide for US companies if the EU is your main growth market):

🇪🇺 GDPRHigh priority
General Data Protection Regulation
Max fine: €20M or 4% of global revenue
🇬🇧 UK GDPRPriority
UK General Data Protection Regulation
Max fine: £17.5M or 4% of global revenue
🇨🇦 PIPEDA / Law 25Priority
Personal Information Protection — Canada
Max fine: CAD $25M or 4% of revenue
🇧🇷 LGPDPriority
Lei Geral de Proteção de Dados
Max fine: R$50M or 2% of Brazil revenue
🇨🇭 nLPDPriority
New Federal Act on Data Protection
Max fine: CHF 250,000 (personal liability)
🇦🇺 Privacy ActStandard
Privacy Act 1988 — Australia
Max fine: AUD 50M

Choose your coverage

One-time payment, report delivered by email within the hour. No subscription.

Local

$49

1 jurisdiction (e.g. CCPA)

  • Full report for 1 law
  • Compliance score out of 100
  • 8 evaluated criteria
  • Top 3 urgent fixes
  • HTML report + email
Get started

Global

$299

All detected jurisdictions

  • US + international coverage
  • Per-law report + global score
  • Total fine exposure
  • Priority recommendations
  • Executive summary included
  • HTML report + email
Get started

Everything you need to know

My business isn't based in California — does the CCPA still apply to me?
Yes, if California residents visit your website and you collect their data (via Google Analytics, advertising cookies, forms…) and you meet the CCPA's revenue or data-volume thresholds. The law applies based on where your visitors are, not where your company is incorporated.
What's the difference between the CCPA and the CPRA?
The CPRA (2023) amended and expanded the original CCPA (2020): it added a dedicated enforcement agency (the CPPA), new rights (correction, limiting use of sensitive data), and stricter rules for data sharing. Our report evaluates your site against the current CPRA-amended CCPA.
Do you also check ADA/WCAG accessibility or FTC compliance?
Not in this specific report — this tool is focused on privacy-law compliance (CCPA/CPRA, VCDPA, and international equivalents). For a broader security and compliance review that also weighs in on accessibility and consumer-protection signals, see our full Website Audit.
How does amalyon detect which laws apply?
Our service crawls your website and analyzes 8 types of signals: the <html lang> attribute, hreflang attributes, the Content-Language header, displayed currencies, phone number prefixes, mentions of laws or countries in your legal pages, cookie banners (OneTrust, Cookiebot…), and meta geo.region tags. Sites with no international signals default to US coverage.
What exactly does the report contain?
For each detected law: 8 criteria evaluated from 0 to 10 (privacy notice, opt-out / do-not-sell mechanism, individual rights, business identity, data sale/sharing disclosures, retention periods, security measures, service-provider contracts). A global score out of 100 and the 3 urgent fixes to make. All in structured HTML format, delivered by email.
How long does it take to receive the report?
Usually less than 10 minutes. The time depends on the number of detected jurisdictions and server load. You receive an email notification as soon as the report is ready.
Does the report replace a privacy attorney?
No. This is an automated audit tool that identifies compliance gaps visible on your public website. For complex legal questions (data broker registration, vendor contracts, breach response), we recommend consulting a privacy attorney licensed in your state.