🟢 Open source · MIT

Compliance scanning in your terminal.

eucomply-scan checks any URL for GDPR, NIS2, DORA and EAA technical gaps in seconds. Any CMS, any stack — one command.

Get started Try the web version

Install & run

Requires Node.js 18+. No sign-up, no API key, no tracking.

# Install globally
npm install -g eucomply-scan

# Scan any site
eucomply-scan https://yourdomain.com

Example output (real scan of webflow.com):

$ eucomply-scan https://webflow.com
╔══ EUComply Scan ═══ webflow.com (696ms)
║  Score:  67%   4/6 checks  ·  Platform: Webflow
║  🔒  HTTPS + HSTS OK                     PASS
║  🍪  No consent banner detected          CHECK MANUALLY
║  📋  Forms present, privacy policy linked PASS
║  📄  Legal pages linked                  PASS
║  🛡️  3/4 security headers present        PASS
║  •  No DORA / resilience disclosures     CHECK MANUALLY
╚══════════════════════════════════════════════════

What it checks

Six automated technical checks against EU requirements:

🔒

HTTPS + HSTS

TLS encryption and Strict-Transport-Security header (GDPR Art. 32).

🍪

Cookie consent

Detects 15+ consent platforms (Cookiebot, OneTrust, CookieYes…). ePrivacy Directive.

📋

Forms & privacy link

Forms without a visible privacy-policy link are a top enforcement target (Art. 13).

📄

Legal pages

Privacy policy, imprint, terms and EAA statement linked from the homepage.

🛡️

Security headers

CSP, X-Content-Type-Options, Referrer-Policy — OWASP baseline, NIS2 Art. 21.

🔍

DORA disclosures

Operational-resilience information financial entities must publish under DORA.

Why a CLI?

Need auditor-ready proof?

The CLI is free forever. For documented deliverables — PDF audit reports, DPA documents, NIS2 clauses and EAA statements — upgrade to EUComply Pro.

See Pro — $79/year →