US privacy laws — the CCPA/CPRA in California and a fast-growing list of state laws — can apply to your site once you do business in a state and cross its thresholds, wherever your company is incorporated. Our free scan checks your site against CCPA/CPRA and VCDPA and shows you the observable gaps. Which laws ultimately apply depends on your business facts — we help you see where to look.
Enter your URL — our AI checks it against CCPA/CPRA and VCDPA in seconds, for free.
How it works
No legal background required. Our AI does the reading so you don't have to.
amalyon crawls your website: languages, currencies, hreflang tags, phone prefixes, cookie banners, legal notices. If nothing points elsewhere, we default to US law — the way your visitors' browsers do.
Claude AI checks your site against CCPA/CPRA and VCDPA: score out of 100, 8 evaluated criteria (privacy notice, opt-out rights, do-not-sell signals, data retention…), maximum fine exposure.
Compliance score, fine exposure, and the top 3 fixes to make first — all in your inbox within the hour.
Legal coverage
CCPA/CPRA and VCDPA are the models most other state privacy laws are built on.
SELLING BEYOND THE US? THE SAME SCAN ALSO CHECKS (see also our dedicated GDPR guide for US companies if the EU is your main growth market):
Pricing
One-time payment, report delivered by email within the hour. No subscription.
Local
1 jurisdiction (e.g. CCPA)
Regional
Up to 3 jurisdictions (e.g. CCPA + VCDPA)
Global
All detected jurisdictions
Frequently asked questions
<html lang> attribute, hreflang attributes, the Content-Language header, displayed currencies, phone number prefixes, mentions of laws or countries in your legal pages, cookie banners (OneTrust, Cookiebot…), and meta geo.region tags. Sites with no international signals default to US coverage.