See what your website exposes, then turn compliance gaps into reviewable work.
What customers, clients and regulators can see — and what they can’t. GuardianStack starts with a free public compliance and trust check for UK SMEs: every finding labelled detected, inferred or needs-confirmation, with fast outside-view results.
Cookie tools cover one obligation. GuardianStack is built to cover the wider trust stack: privacy notice, cookies, processor evidence, retention and accountability, with human review where the answer depends on internal facts.
Three layers, from public signals to continuous cover.
Start with what anyone can see from outside, connect the operating layer for what they can’t, then let it re-check as your business changes.
Outside view
Privacy notice, ICO registration, SSL/TLS, cookies, DNS/email auth, Companies House, processor coverage — what customers, clients and regulators can see from outside your business.
Operating layer
DPA coverage, marketing consent records, data retention, lawful-basis gating, privacy-notice completeness — internal evidence that needs your review before anything is relied on.
Continuous
Automated re-checks as your apps, processors, retention rules and policies change. Drift is caught early, so gaps do not reappear quietly between manual reviews.
Reviewable compliance workflows for work SMEs usually postpone.
The value is practical output with an audit trail: drafts, checks and flags that a responsible owner can review before relying on them.
DPA support
Article 28-aligned draft · betaDrafts reviewable data-processing agreements for common app and supplier relationships, with source logic visible before use.
Cookie review
PECR / ePrivacy · liveScans and classifies the cookies your site sets and highlights pre-consent risks.
Retention review
Article 5(1)(e) · rolling outFlags records and retention questions that need owner review before the business relies on them.
Policy review
Article 5(2) · betaReviews privacy-policy coverage with an audit trail so the reasoning can be checked.
Defensible by design.
Grounded in real enforcement
Risk signals draw on ICO enforcement patterns and precedent where available — not generic estimates.
Citation chain where enabled
Findings show which regulation and article they rest on, with reasoning you can inspect.
Glass-box, not black-box
See how each recommendation is reached, with decision logs — not opaque scoring.
GuardianStack is operated by MikaHari Labs Ltd (Company No. 14894353). It is not a law firm; generated documents are AI-assisted drafts for your review. For UK SMEs, founder-led — five ICO obligations, right-sized, not a full SOC 2 programme you do not need. Need buyer questionnaire reuse? See our Compliance Evidence Pack story — complementary to GuardianStack's trust stack.
Cheaper than stitching four point solutions together.
All prices in GBP as published on guardianstack.com. Cheaper than stitching four point solutions; a fraction of enterprise GRC. The free scan never expires.
Beta
Selected beta users get 30 days free from installation (Shopify-first). Limited places during beta. No credit card required.
- Free outside-view scan, every time
- Findings labelled detected / inferred / needs confirmation
- DPA, cookie, retention and review agents during beta
Pro
PopularPaid continuation after beta · single store. After beta closes, new merchants start on a 14-day free trial. Founding members lock launch pricing for life.
- Daily scans where enabled
- Reviewable DPA, cookie, retention and policy workflows (as each rolls out)
- Document generation with owner approval where enabled
- GuardianBot, email support
Business
Multi-store support · audit reports. Enterprise tier (full autonomous · API · white-label) also coming soon.
- Everything in Pro
- Multi-store support
- Audit reports
- Priority access to new agents
See what your website exposes.
No login for the outside-view scan. Open methodology. A free, shareable read of visible compliance and trust signals.