
One right. Three laws. One thing to actually do.
Everything below is real data from the crosswalk, rendered live on this page — not a screenshot and not an example we wrote for the occasion. It follows the single most universal right in privacy law: delete my data. California calls it the right to delete, the EU calls it erasure, Virginia calls it something else again — and all three resolve to one internal mandate, which resolves to the exact policy paragraph telling your team how to answer the request.
California, USA
California state technology statutes — the California Consumer Privacy Act, the first and most prescriptive of the US state consumer-privacy laws, plus real enacted coverage in breach notification (the nation's first, and the template nearly every other state statute this library surveys was modeled on), the original SOPIPA student-data statute, a genetic-privacy statute (GIPA), an all-party-consent wiretapping statute (CIPA) with an active website-tracking-litigation profile, the original state IoT-security law (SB-327), the Delete Act's centralized data-broker deletion platform (DROP), three enacted AI statutes spanning frontier-model safety disclosure through bot disclosure, a right-to-repair statute, and one of the oldest state medical-records confidentiality statutes in the country (CMIA), predating HIPAA by over a decade.
European Union
The European Union as a supranational jurisdiction — home to the General Data Protection Regulation, the most influential and most-copied data protection statute in the world, binding across all EU/EEA member states and extending extraterritorially to any organization that offers goods or services to, or monitors the behavior of, individuals in the Union.
Virginia, USA
Virginia state technology statutes. Virginia's flagship statute is the Virginia Consumer Data Protection Act (VCDPA), the original "Virginia model" comprehensive privacy law that Colorado, Connecticut, Texas, and most subsequent state statutes were patterned after. Virginia also has real, enacted coverage in breach notification (a harm-triggered statute unusually paired with a narrow direct-economic-damages private remedy), a layered pair of SOPIPA-style/data-security student-data statutes, a direct-to-consumer genetic-privacy statute requiring itemized per-use consent, a one-party-consent wiretapping statute distinctively paired with a civil cause of action and liquidated damages, a 2020 adoption of the NAIC Insurance Data Security Model Law with an annual compliance-certification duty, a HIPAA-adjacent health-records-privacy and medical-breach-notification pairing, and two narrow but real AI-generated-content criminal statutes (deepfake nonconsensual imagery, computer-generated CSAM) — notwithstanding the Governor's March 2025 veto of Virginia's would-be comprehensive AI statute.
California Consumer Privacy Act (CCPA)
California privacy statute establishing consumer rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and receive notice at collection, together with CPPA governance, rulemaking, and enforcement provisions.
General Data Protection Regulation (EU) 2016/679
The European Union's comprehensive data protection regulation, directly applicable across all EU/EEA member states since May 25, 2018. It establishes the core principles governing any processing of personal data, enumerates the data subject rights (access, rectification, erasure, portability, and more) that give individuals control over their own information, sets out the distinct obligations of controllers and processors, and backs all of it with breach-notification duties and administrative fines that can reach 4% of global annual turnover. Its extraterritorial reach — Article 3 — means it applies to any organization, anywhere, that offers goods or services to individuals in the EU or monitors their behavior, which is why it is treated as the de facto global baseline for privacy programs.
Virginia Consumer Data Protection Act (VCDPA)
Virginia privacy statute establishing consumer rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, sale, and certain profiling, together with controller obligations for purpose limitation, data minimization, and data protection assessments, enforced exclusively by the Virginia Attorney General with no private right of action.
1798.105 - Right to Delete
Consumers have the right to request deletion of personal information collected from them.
Article 17 - Right to Erasure ('Right to be Forgotten')
Article 17 is the most recognized provision of the GDPR outside privacy-professional circles — the "right to be forgotten." It gives individuals the right to have their personal data erased without undue delay when one of several grounds applies: the data is no longer necessary for the purpose it was collected for, consent has been withdrawn and there's no other lawful basis, the individual objects and there's no overriding legitimate ground, the data was processed unlawfully, or erasure is required to comply with a legal obligation. The right is not absolute — Article 17(3) preserves processing where necessary for freedom of expression, legal compliance, public interest archiving, or the establishment/defense of legal claims — but where it applies, "without undue delay" sets a real operational clock, generally understood within the same one-month window as other data subject rights under Article 12. Critically, if the data has been made public, the controller must also take reasonable steps, including technical measures, to inform other controllers processing that data that the erasure has been requested. For an employee, this is where privacy stops being an abstract right and becomes an operational chain: a verified deletion request has to actually propagate through every system, backup, and downstream processor holding that individual's data, using a defined, auditable, secure-disposal method — not just a soft delete that leaves the record recoverable. This is precisely the kind of request that requires a documented Data Retention & Secure Disposal Policy so that "erase it" has one clear, repeatable meaning across the organization rather than being improvised system by system. Ultimately, Article 17 is why "right to delete" has become the shorthand the public uses for data privacy generally — it is the right most closely tied to the felt sense of control over one's own digital footprint, and the one whose mishandling generates the most reputational damage when a company claims to have deleted data and later turns out not to have.
59.1-577 - Right to Access, Correct, Delete, and Port Data
Section 59.1-577 bundles together the core set of consumer rights that most people think of when they picture "modern privacy law": the right to confirm whether a controller is processing your personal data and to access that data, the right to correct inaccuracies, the right to delete personal data you provided or that a controller obtained about you, and the right to obtain a portable copy of your data in a readily usable format so you can take it elsewhere. Together these four rights form the operational backbone of the statute. What distinguishes Virginia's approach is its restraint relative to California's original CCPA text. There is no separate "right to know specific pieces of information collected over the past twelve months" style of granular disclosure obligation layered on top; the rights are more consolidated and, in practice, somewhat less operationally granular for the controller to fulfill, though no less real for the consumer exercising them. For an employee, this section means building (or buying) a rights-fulfillment pipeline capable of authenticating a requester, locating their data across every system that touches it, executing the requested action, and responding within 45 days (with one 45-day extension available when reasonably necessary). If a request is denied, the controller must explain why and describe the appeal process described elsewhere in the statute. Ultimately, this section operationalizes the basic premise that data belongs, in a meaningful sense, to the person it describes. A controller is a steward, not an owner, and these four rights are the mechanism by which that stewardship is kept honest and answerable to the individual on the other end of the record.
P4 - Use, Retention, and Disposal
The entity limits the use of personal information to the purposes identified in the notice and for which the data subject has provided implicit or explicit consent, retains personal information for only as long as necessary to fulfill the stated purposes or as required by law or regulation, and disposes of, destroys, or de-identifies personal information when no longer needed.
American Institute of CPAs (AICPA)
The American Institute of CPAs, publisher of the SOC family of attestation frameworks — including the SOC 2 Trust Services Criteria — that independent CPA firms use to examine and report on a service organization's controls over security, availability, processing integrity, confidentiality, privacy, cybersecurity risk management, and supply chain risk management.
SOC 2 - AICPA Trust Services Criteria
A voluntary attestation framework administered by the American Institute of Certified Public Accountants (AICPA) under which an independent CPA firm examines and reports on the suitability of design and operating effectiveness of an entity's controls relevant to one or more Trust Services Categories: Security (the mandatory Common Criteria present in every report), Availability, Processing Integrity, Confidentiality, and Privacy. Unlike a prescriptive regulatory checklist, SOC 2 is criteria-based — the entity designs its own controls to meet the Trust Services Criteria and the resulting Type I (point-in-time) or Type II (operating effectiveness over a review period) report is typically shared under NDA with customers and prospects as evidence of a mature control environment.
Data Retention & Secure Disposal Policy
Defines how long specific categories of data (customer data, CUI, financial records, logs) must be retained to meet legal/contractual obligations, and the secure disposal methods required once that period expires. Distinct from the Document Control & Retention Policy in that it governs raw data and datasets rather than controlled documents; satisfies NIST SP 800-171 3.8.3 and ISO 27001 Annex A 8.10.
Fulfilling Deletion & Erasure Requests
The operational procedure for handling a verified consumer deletion/erasure request end to end: identity verification, timeline, propagation across systems and processors, and the secure-disposal method used, satisfying CCPA §1798.105 and GDPR Article 17.
Today you get to pick your poison.
Every organization that suddenly owes someone a real, evidenced answer ends up choosing between the same three options — and all three ask you to give something up.
The spreadsheet
Free, yours, and completely unverifiable. It works right up until someone asks how you know it's current, and nobody can answer — including you.
The consultant
Real expertise, applied by hand. Slow, expensive, and when the engagement ends the understanding of your program leaves with them.
The platform with your keys
The fastest-growing option, and it works by asking for API keys, service accounts, and standing access into exactly the systems a security program exists to protect.
We built the fourth option.
The usual promise is "we won't look." Ours is that we can't.
This is not a policy we wrote down and hope to keep. It is the shape of the application, and it is enforced by the build.
Your evidence never reaches us
Every answer, upload, and attestation is created and stored client-side, in storage provisioned inside your organization's own Microsoft 365 tenant. We hold no copy, because there is no server here to hold one.
There is no secret to steal
The app authenticates with your signed-in user's own delegated Microsoft Entra ID token. We hold no service credential on your behalf, so there is nothing that could be leaked, subpoenaed, or misused later.
Enforced at build time, not by policy
Server-side actions and API routes are a hard lint error in this codebase — a future commit cannot quietly add a server that sees your data without failing the build first.
Walk away and keep everything
Your attestations live in your tenant, in your Microsoft 365 subscription. If you stop paying us tomorrow, you keep every one of them. We never had the ability to hold them hostage.
See every Microsoft Graph permission the app asks for, and why
Map it. Examine it. Prove it.
Three questions most organizations can't answer cleanly — what are we on the hook for, have we done anything about it, and can we show our work later.
Map what binds you
Choose the standards and jurisdictions you fall under. The crosswalk resolves them into the actual set of mandates you owe — deduplicated across every framework that happens to share one, so a requirement you already meet stops showing up as four separate jobs.
Run the exam
Structured exams walk your team through each mandate: what it asks for, who is accountable, and what counts as an answer. Ten today, including CMMC Level 2, DFARS CUI protection, the HIPAA Security Rule, SOX 404, FISMA, ISO/IEC 27001, and NIST CSF 2.0.
Keep the attestation
Each answer becomes a timestamped, attributable attestation, written to storage provisioned inside your own Microsoft 365 tenant. Not marked complete — evaluated, dated, and sourced.
Two kinds of teams arrive here, for opposite reasons.
One has been handed an obligation it never planned for. The other is choosing one, because a deal depends on it. Both need the same thing: a real answer, fast, without hiring a function they cannot afford.
You just got a flow-down clause
DFARS 252.204-7012 and CMMC obligations flow down contractually from a prime to every subcontractor that touches CUI, whether or not that subcontractor has ever run a security program. Losing eligibility to bid is not a theoretical risk — it is the next contract.
A deal is blocked on a certification
An enterprise buyer, an insurer, or a partner now wants an attested answer before signing. You have no in-house compliance function and no interest in building one to close a single deal.
You are answering the same question five times
A federal rule, a state privacy statute, an insurer questionnaire, and a customer DPA all asking for the same control in four different vocabularies — and no way to prove to yourself that the four answers agree.
The questions a careful buyer asks first.
Do you need access to our systems?
No. No API keys, no service accounts, no read access into your environment, no agent to install. You sign in with your own Microsoft identity, and the application runs in your browser against your own tenant using your own permissions.
Where does our evidence actually live?
In storage provisioned inside your organization's own Microsoft 365 tenant — the same place the rest of your organization's documents already live, under your existing retention, access, and eDiscovery controls. We never receive a copy.
What happens when a law changes?
We update the crosswalk and redeploy. Because one real-world requirement is stored once and recognized under every framework that references it, a statutory revision is a content change on our side, not a migration on yours.
What does it cost?
Not finalized yet, and we would rather say so than invent a number. Two models are already ruled out: per-seat pricing, because charging per person in a compliance tool just teaches an organization to involve fewer people, and per-framework pricing, because shared requirements are the entire point of a crosswalk. The intent is flat pricing per organization, scaled roughly to size.
Is it ready?
It is in closed alpha, and the honest version is that the content library grows continuously rather than ever being "done" — that is the nature of surveying live law. What exists today is real and is what you see rendered on this page, not a mockup.
See what you're actually on the hook for.
Sign in with your Microsoft work account to open the crosswalk against your own organization. Nothing is provisioned in your tenant until you ask for it, and nothing you enter is ever sent to us.