What's Covered

We reviewed the most expensive enforcement cases, looked at the legal tests different jurisdictions used, and operationalized that into one Universal Test — so coverage isn't a law-by-law list we chase. The engine runs the standard these regimes are built on; the jurisdictional specifics are added by configuration, not a roadmap wait — just as is any new regulation you want to cover.

Mapped today — out of the box

European Union

GDPR · UK GDPR · EU AI Act · EU AI Act Art. 5 · DORA · NIS2 · DSA · DMA · Data Act · Data Governance Act (DGA)

United States — Federal

SEC Cyber Rules · SOX · FTC GLBA · HIPAA · KOSA · COPPA · COPPA 2.0 · Federal Telecom Act · Executive Order 14117

United States — State (20+)

CCPA/CPRA · CAADCA · VAADCA · NY SAFE for Kids · Florida DBOR · Texas SCOPE · Utah SOMA · Maryland AADC — with stronger deltas in CA, FL & NH — and 15+ more

Canada

PIPEDA · Quebec Law 25

Australia & UK

Australia Privacy Act · APP 11 · UK Online Safety Act · Ireland OSMRA

Child & Psychological Welfare

The minors' laws above — CAADCA, NY SAFE, Utah SOMA, KOSA, COPPA 2.0, UK OSA, EU AI Act Art. 5 — sit inside these groups, and power the dedicated Minors Safety & Child Welfare application below.

Same test — supported now, added by configuration

Brazil (LGPD) · India (DPDP) · Singapore (PDPA) · South Korea (PIPA) · Japan (APPI) — and other reasonableness / adequacy regimes. Each applies the same underlying reasoning as the Universal Test, with real jurisdictional distinctions — Singapore's PDPC, for example, has held that a published policy alone does not satisfy its Accountability Obligation without matching internal practice. Adding a new jurisdiction to the OS is a configuration step, not a rebuild — but the underlying legal nuance in each regime still gets its own mapping, not a copy-paste of another jurisdiction's rules.

Frameworks & Standards

ISO 27001 / 27701 / 42001 / 31000, NIST AI RMF, CIS, CMMC, DoCRA — all mapped.

Plus regulatory guidelines, executive orders, and imminent laws — available as optional best-practice views. Add or subtract anything by configuration.

Minors Safety & Child Welfare · Gaming · Social Media · EdTech

Two kinds of law now govern minors — and almost everyone is watching only one.

For twenty years, protecting minors online meant privacy — COPPA, California's child-privacy rules, GDPR Art. 8: who may collect a child's data, and with whose consent. That layer still applies. But a second, newer body of law has arrived that has nothing to do with data privacy: psychological-welfare laws that regulate the design of the software itself — and its effect on a child's mental health, sleep, attention, and behavior.

This is the layer nobody else governs: feed defaults, notification windows, curfew hours, dark patterns, algorithmic amplification, behavioral profiling, and manipulative AI aimed at vulnerable users. Vermont's duty-of-care code, NY SAFE for Kids, Utah's curfew law, the UK Online Safety Act, and EU AI Act Article 5 regulate these mechanics directly. We built Psychological Welfare & Harmful Design as a discipline distinct from privacy and security — governance for the design mechanics themselves, not just the data behind them.

The binding stack a U.S.-based global company is already inside

  • Federal — COPPA. Mandatory, and no longer sufficient: silent on teens 13–17 and on design harm.
  • State — design-code & duty-of-care laws (CAADCA, Vermont AADC) and platform-mechanics laws (NY SAFE for Kids, Utah SOMA curfew, FL HB 3, TX SCOPE).
  • EU — AI Act Art. 5 (no cure period; up to €35M or 7% of global turnover), the DSA, and GDPR.
  • UK — Online Safety Act: a documented children's risk assessment before launch, with senior-manager criminal liability.
  • Australia — Online Safety Act: under-16 account prohibition, with individual officer liability.

20 child-related laws out of the box — plus two significant imminent laws, KOSA and COPPA 2.0, included as best-practice.

Five obligations every regime is converging on

  • Privacy by default
  • Age assurance
  • Design accountability — no dark patterns or exploitative engagement loops
  • Psychological harm & compulsive use
  • Duty of care & evidence

The first four describe what a platform must build. The fifth describes what it must be able to prove.

$1.2B+ in fines

Every one tied to harm to minors — the exposure Minors Safety & Child Welfare is built to address

Epic Games (Fortnite) $275M + $245M refunds · Instagram €405M · TikTok €345M, plus £12.7M in the UK · YouTube $170M · Genshin Impact $20M. The most sophisticated operators on the internet, with deep legal and compliance teams. The fines happened anyway.

The next wave isn't privacy — it's harm. In January 2025, the FTC settled with Cognosphere (HoYoverse), maker of Genshin Impact, for $20M over loot-box monetization mechanics the agency called unfair and deceptive to children and teens — one of the first federal actions to treat manipulative product design itself, not just data handling, as the governance failure. That is a duty-of-care standard — the same one Vermont, the UK OSA, and the EU are writing into statute.

What the application does

Maps each obligation to the named accountable executive, by jurisdiction. Returns a binary DEFENSIBLE / NOT DEFENSIBLE posture per law. Enforces the Pre-Release Gate — the risk assessment must be completed and sealed before a feature or game ships, with the seal timestamp as the legal artifact; post-launch assessment carries no protection. Court Mode stress-tests your posture against FTC/KOSA, Ofcom, the EU AI Office, and the eSafety Commissioner.

KOSA and COPPA 2.0 aren't law yet — they're built in now as optional best-practice frameworks that flip to compliance mode the day either is enacted, with no rework.

Minors Safety Defensibility Dashboard

Minors Safety Defensibility Dashboard — binary DEFENSIBLE / NOT DEFENSIBLE posture across child-safety governance areas and applicable laws

A binary DEFENSIBLE / NOT DEFENSIBLE posture for each governance area and each applicable law — with the evidence required to close every gap.

The question has moved from "did you comply?" to "can you show your leadership weighed the foreseeable harm to a child before it reached them?"

Request Pre-Release Access

Free to a limited number of companies in exchange for feedback.

The Legal Defensibility OS

Built for wherever executives and organizations carry liability

The regulations differ — and so do the legal tests behind them, each with its own thresholds, definitions, and jurisdictional nuance. What stays constant is the exposure: wherever the law can hold a leader or a company accountable, leadership eventually has to show it met its governance obligations, acted reasonably — and can prove it. Our mission is to make that proactive legal defense possible wherever executive and organizational liability exists — and we're building the operating system to produce it.

Today · Available now

Digital Governance

Cyber, privacy, AI, and minors' safety — delivered through our first two applications, Defensible Governance and Minors Safety & Child Welfare.

Next · Same engine

Physical & Product Safety

The same legal-defensibility engine extends to physical, environmental, food, and drug safety — wherever foreseeable harm, reasonable care, and documentation-before-the-fact decide liability.

One operating system — built to turn reasonable, documented judgment into a defense you can prove, wherever the law holds leaders and their companies accountable.