We reviewed the most expensive enforcement cases, looked at the legal tests different jurisdictions used, and operationalized that into one Universal Test — so coverage isn't a law-by-law list we chase. The engine runs the standard these regimes are built on; the jurisdictional specifics are added by configuration, not a roadmap wait — just as is any new regulation you want to cover.
GDPR · UK GDPR · EU AI Act · EU AI Act Art. 5 · DORA · NIS2 · DSA · DMA · Data Act · Data Governance Act (DGA)
SEC Cyber Rules · SOX · FTC GLBA · HIPAA · KOSA · COPPA · COPPA 2.0 · Federal Telecom Act · Executive Order 14117
CCPA/CPRA · CAADCA · VAADCA · NY SAFE for Kids · Florida DBOR · Texas SCOPE · Utah SOMA · Maryland AADC — with stronger deltas in CA, FL & NH — and 15+ more
PIPEDA · Quebec Law 25
Australia Privacy Act · APP 11 · UK Online Safety Act · Ireland OSMRA
The minors' laws above — CAADCA, NY SAFE, Utah SOMA, KOSA, COPPA 2.0, UK OSA, EU AI Act Art. 5 — sit inside these groups, and power the dedicated Minors Safety & Child Welfare application below.
Brazil (LGPD) · India (DPDP) · Singapore (PDPA) · South Korea (PIPA) · Japan (APPI) — and other reasonableness / adequacy regimes. Each applies the same underlying reasoning as the Universal Test, with real jurisdictional distinctions — Singapore's PDPC, for example, has held that a published policy alone does not satisfy its Accountability Obligation without matching internal practice. Adding a new jurisdiction to the OS is a configuration step, not a rebuild — but the underlying legal nuance in each regime still gets its own mapping, not a copy-paste of another jurisdiction's rules.
ISO 27001 / 27701 / 42001 / 31000, NIST AI RMF, CIS, CMMC, DoCRA — all mapped.
Plus regulatory guidelines, executive orders, and imminent laws — available as optional best-practice views. Add or subtract anything by configuration.
Minors Safety & Child Welfare · Gaming · Social Media · EdTech
For twenty years, protecting minors online meant privacy — COPPA, California's child-privacy rules, GDPR Art. 8: who may collect a child's data, and with whose consent. That layer still applies. But a second, newer body of law has arrived that has nothing to do with data privacy: psychological-welfare laws that regulate the design of the software itself — and its effect on a child's mental health, sleep, attention, and behavior.
This is the layer nobody else governs: feed defaults, notification windows, curfew hours, dark patterns, algorithmic amplification, behavioral profiling, and manipulative AI aimed at vulnerable users. Vermont's duty-of-care code, NY SAFE for Kids, Utah's curfew law, the UK Online Safety Act, and EU AI Act Article 5 regulate these mechanics directly. We built Psychological Welfare & Harmful Design as a discipline distinct from privacy and security — governance for the design mechanics themselves, not just the data behind them.
20 child-related laws out of the box — plus two significant imminent laws, KOSA and COPPA 2.0, included as best-practice.
The first four describe what a platform must build. The fifth describes what it must be able to prove.
$1.2B+ in fines
Epic Games (Fortnite) $275M + $245M refunds · Instagram €405M · TikTok €345M, plus £12.7M in the UK · YouTube $170M · Genshin Impact $20M. The most sophisticated operators on the internet, with deep legal and compliance teams. The fines happened anyway.
The next wave isn't privacy — it's harm. In January 2025, the FTC settled with Cognosphere (HoYoverse), maker of Genshin Impact, for $20M over loot-box monetization mechanics the agency called unfair and deceptive to children and teens — one of the first federal actions to treat manipulative product design itself, not just data handling, as the governance failure. That is a duty-of-care standard — the same one Vermont, the UK OSA, and the EU are writing into statute.
Maps each obligation to the named accountable executive, by jurisdiction. Returns a binary DEFENSIBLE / NOT DEFENSIBLE posture per law. Enforces the Pre-Release Gate — the risk assessment must be completed and sealed before a feature or game ships, with the seal timestamp as the legal artifact; post-launch assessment carries no protection. Court Mode stress-tests your posture against FTC/KOSA, Ofcom, the EU AI Office, and the eSafety Commissioner.
KOSA and COPPA 2.0 aren't law yet — they're built in now as optional best-practice frameworks that flip to compliance mode the day either is enacted, with no rework.
A binary DEFENSIBLE / NOT DEFENSIBLE posture for each governance area and each applicable law — with the evidence required to close every gap.
The question has moved from "did you comply?" to "can you show your leadership weighed the foreseeable harm to a child before it reached them?"
Request Pre-Release AccessFree to a limited number of companies in exchange for feedback.
The Legal Defensibility OS
The regulations differ — and so do the legal tests behind them, each with its own thresholds, definitions, and jurisdictional nuance. What stays constant is the exposure: wherever the law can hold a leader or a company accountable, leadership eventually has to show it met its governance obligations, acted reasonably — and can prove it. Our mission is to make that proactive legal defense possible wherever executive and organizational liability exists — and we're building the operating system to produce it.
Today · Available now
Cyber, privacy, AI, and minors' safety — delivered through our first two applications, Defensible Governance and Minors Safety & Child Welfare.
Next · Same engine
The same legal-defensibility engine extends to physical, environmental, food, and drug safety — wherever foreseeable harm, reasonable care, and documentation-before-the-fact decide liability.
One operating system — built to turn reasonable, documented judgment into a defense you can prove, wherever the law holds leaders and their companies accountable.