Respect the user — and be able to prove it.
Free & open · no signup · read-only — every stage ends by asking · nothing leaves your machine
The operational-privacy layer regulators actually check: honest consent, real data-subject rights, encryption and key management, and a trustworthy audit trail.
The conductor fetches each brief in turn and writes its report before moving on — later briefs can build on earlier findings. Or copy any single stage to run it alone.
4 reports in reports/, plus the run's own INDEX.md: CONSENT.md, DSAR.md, ENCRYPTION.md, AUDITLOG.md. Feed them to the optional Studio to turn findings into commits, or run 28 · Roadmap Synthesis to merge them into one plan.
Copy the conductor into your agent inside the repo you want checked. It runs each Goal Prompt in sequence, honoring each one's ask-first rule.
Whether the product collects consent honestly and honors it — the cookies, trackers, and data collection that fire before or despite the user's choice.
Whether the product can honor the rights users have over their data — access, export, correction, and deletion — operationally, not just in the privacy policy.
How the product protects data with encryption — in transit, at rest, and at the field level — and whether the keys that unlock it are managed safely.
Whether the system keeps a trustworthy record of who did what — the audit trail that compliance, incident response, and forensics all depend on.