The map, not the treasure

Know what you owe. Prove you did it. Keep the proof.

RunDEETS links every statute and standard you're bound by into one graph, walks your team through structured exams against it, and writes timestamped attestations into storage inside your own Microsoft 365 tenant. Your evidence never touches our servers — structurally, it can't.

Jurisdictions52
Statutes404
Mandates1,317
Standards104
What that buys you
One rule, every name it has

California calls it the right to delete. The EU calls it erasure. Your policy calls it something else again. The crosswalk knows all three are the same obligation, so you satisfy it once instead of three times.

Evidence, not checkboxes

Every exam answer becomes a dated, attributable attestation that a requirement was actually evaluated — the thing an auditor asks for, rather than a green tick nobody can source.

Nothing to hand over

No API keys, no service accounts, no standing access into your environment. You sign in with your own Microsoft identity and the work happens in your browser.

Proof, not a promise

One right. Three laws. One thing to actually do.

Everything below is real data from the crosswalk, rendered live on this page — not a screenshot and not an example we wrote for the occasion. It follows the single most universal right in privacy law: delete my data. California calls it the right to delete, the EU calls it erasure, Virginia calls it something else again — and all three resolve to one internal mandate, which resolves to the exact policy paragraph telling your team how to answer the request.

View the crosswalk as a narrative walk or as a graph
Jurisdictions

California, USA

California state technology statutes — the California Consumer Privacy Act, the first and most prescriptive of the US state consumer-privacy laws, plus real enacted coverage in breach notification (the nation's first, and the template nearly every other state statute this library surveys was modeled on), the original SOPIPA student-data statute, a genetic-privacy statute (GIPA), an all-party-consent wiretapping statute (CIPA) with an active website-tracking-litigation profile, the original state IoT-security law (SB-327), the Delete Act's centralized data-broker deletion platform (DROP), three enacted AI statutes spanning frontier-model safety disclosure through bot disclosure, a right-to-repair statute, and one of the oldest state medical-records confidentiality statutes in the country (CMIA), predating HIPAA by over a decade.

European Union

The European Union as a supranational jurisdiction — home to the General Data Protection Regulation, the most influential and most-copied data protection statute in the world, binding across all EU/EEA member states and extending extraterritorially to any organization that offers goods or services to, or monitors the behavior of, individuals in the Union.

Virginia, USA

Virginia state technology statutes. Virginia's flagship statute is the Virginia Consumer Data Protection Act (VCDPA), the original "Virginia model" comprehensive privacy law that Colorado, Connecticut, Texas, and most subsequent state statutes were patterned after. Virginia also has real, enacted coverage in breach notification (a harm-triggered statute unusually paired with a narrow direct-economic-damages private remedy), a layered pair of SOPIPA-style/data-security student-data statutes, a direct-to-consumer genetic-privacy statute requiring itemized per-use consent, a one-party-consent wiretapping statute distinctively paired with a civil cause of action and liquidated damages, a 2020 adoption of the NAIC Insurance Data Security Model Law with an annual compliance-certification duty, a HIPAA-adjacent health-records-privacy and medical-breach-notification pairing, and two narrow but real AI-generated-content criminal statutes (deepfake nonconsensual imagery, computer-generated CSAM) — notwithstanding the Governor's March 2025 veto of Virginia's would-be comprehensive AI statute.

Statutes

California Consumer Privacy Act (CCPA)

California privacy statute establishing consumer rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and receive notice at collection, together with CPPA governance, rulemaking, and enforcement provisions.

General Data Protection Regulation (EU) 2016/679

The European Union's comprehensive data protection regulation, directly applicable across all EU/EEA member states since May 25, 2018. It establishes the core principles governing any processing of personal data, enumerates the data subject rights (access, rectification, erasure, portability, and more) that give individuals control over their own information, sets out the distinct obligations of controllers and processors, and backs all of it with breach-notification duties and administrative fines that can reach 4% of global annual turnover. Its extraterritorial reach — Article 3 — means it applies to any organization, anywhere, that offers goods or services to individuals in the EU or monitors their behavior, which is why it is treated as the de facto global baseline for privacy programs.

Virginia Consumer Data Protection Act (VCDPA)

Virginia privacy statute establishing consumer rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, sale, and certain profiling, together with controller obligations for purpose limitation, data minimization, and data protection assessments, enforced exclusively by the Virginia Attorney General with no private right of action.

Sections

1798.105 - Right to Delete

Consumers have the right to request deletion of personal information collected from them.

Article 17 - Right to Erasure ('Right to be Forgotten')

Article 17 is the most recognized provision of the GDPR outside privacy-professional circles — the "right to be forgotten." It gives individuals the right to have their personal data erased without undue delay when one of several grounds applies: the data is no longer necessary for the purpose it was collected for, consent has been withdrawn and there's no other lawful basis, the individual objects and there's no overriding legitimate ground, the data was processed unlawfully, or erasure is required to comply with a legal obligation. The right is not absolute — Article 17(3) preserves processing where necessary for freedom of expression, legal compliance, public interest archiving, or the establishment/defense of legal claims — but where it applies, "without undue delay" sets a real operational clock, generally understood within the same one-month window as other data subject rights under Article 12. Critically, if the data has been made public, the controller must also take reasonable steps, including technical measures, to inform other controllers processing that data that the erasure has been requested. For an employee, this is where privacy stops being an abstract right and becomes an operational chain: a verified deletion request has to actually propagate through every system, backup, and downstream processor holding that individual's data, using a defined, auditable, secure-disposal method — not just a soft delete that leaves the record recoverable. This is precisely the kind of request that requires a documented Data Retention & Secure Disposal Policy so that "erase it" has one clear, repeatable meaning across the organization rather than being improvised system by system. Ultimately, Article 17 is why "right to delete" has become the shorthand the public uses for data privacy generally — it is the right most closely tied to the felt sense of control over one's own digital footprint, and the one whose mishandling generates the most reputational damage when a company claims to have deleted data and later turns out not to have.

59.1-577 - Right to Access, Correct, Delete, and Port Data

Section 59.1-577 bundles together the core set of consumer rights that most people think of when they picture "modern privacy law": the right to confirm whether a controller is processing your personal data and to access that data, the right to correct inaccuracies, the right to delete personal data you provided or that a controller obtained about you, and the right to obtain a portable copy of your data in a readily usable format so you can take it elsewhere. Together these four rights form the operational backbone of the statute. What distinguishes Virginia's approach is its restraint relative to California's original CCPA text. There is no separate "right to know specific pieces of information collected over the past twelve months" style of granular disclosure obligation layered on top; the rights are more consolidated and, in practice, somewhat less operationally granular for the controller to fulfill, though no less real for the consumer exercising them. For an employee, this section means building (or buying) a rights-fulfillment pipeline capable of authenticating a requester, locating their data across every system that touches it, executing the requested action, and responding within 45 days (with one 45-day extension available when reasonably necessary). If a request is denied, the controller must explain why and describe the appeal process described elsewhere in the statute. Ultimately, this section operationalizes the basic premise that data belongs, in a meaningful sense, to the person it describes. A controller is a steward, not an owner, and these four rights are the mechanism by which that stewardship is kept honest and answerable to the individual on the other end of the record.

Mandate

P4 - Use, Retention, and Disposal

The entity limits the use of personal information to the purposes identified in the notice and for which the data subject has provided implicit or explicit consent, retains personal information for only as long as necessary to fulfill the stated purposes or as required by law or regulation, and disposes of, destroys, or de-identifies personal information when no longer needed.

Authority

American Institute of CPAs (AICPA)

The American Institute of CPAs, publisher of the SOC family of attestation frameworks — including the SOC 2 Trust Services Criteria — that independent CPA firms use to examine and report on a service organization's controls over security, availability, processing integrity, confidentiality, privacy, cybersecurity risk management, and supply chain risk management.

Standard

SOC 2 - AICPA Trust Services Criteria

A voluntary attestation framework administered by the American Institute of Certified Public Accountants (AICPA) under which an independent CPA firm examines and reports on the suitability of design and operating effectiveness of an entity's controls relevant to one or more Trust Services Categories: Security (the mandatory Common Criteria present in every report), Availability, Processing Integrity, Confidentiality, and Privacy. Unlike a prescriptive regulatory checklist, SOC 2 is criteria-based — the entity designs its own controls to meet the Trust Services Criteria and the resulting Type I (point-in-time) or Type II (operating effectiveness over a review period) report is typically shared under NDA with customers and prospects as evidence of a mature control environment.

Template

Data Retention & Secure Disposal Policy

Defines how long specific categories of data (customer data, CUI, financial records, logs) must be retained to meet legal/contractual obligations, and the secure disposal methods required once that period expires. Distinct from the Document Control & Retention Policy in that it governs raw data and datasets rather than controlled documents; satisfies NIST SP 800-171 3.8.3 and ISO 27001 Annex A 8.10.

Paragraph

Fulfilling Deletion & Erasure Requests

The operational procedure for handling a verified consumer deletion/erasure request end to end: identity verification, timeline, propagation across systems and processors, and the secure-disposal method used, satisfying CCPA §1798.105 and GDPR Article 17.

The status quo

Today you get to pick your poison.

Every organization that suddenly owes someone a real, evidenced answer ends up choosing between the same three options — and all three ask you to give something up.

The spreadsheet

Free, yours, and completely unverifiable. It works right up until someone asks how you know it's current, and nobody can answer — including you.

The consultant

Real expertise, applied by hand. Slow, expensive, and when the engagement ends the understanding of your program leaves with them.

The platform with your keys

The fastest-growing option, and it works by asking for API keys, service accounts, and standing access into exactly the systems a security program exists to protect.

We built the fourth option.

The architecture is the promise

The usual promise is "we won't look." Ours is that we can't.

This is not a policy we wrote down and hope to keep. It is the shape of the application, and it is enforced by the build.

Your evidence never reaches us

Every answer, upload, and attestation is created and stored client-side, in storage provisioned inside your organization's own Microsoft 365 tenant. We hold no copy, because there is no server here to hold one.

There is no secret to steal

The app authenticates with your signed-in user's own delegated Microsoft Entra ID token. We hold no service credential on your behalf, so there is nothing that could be leaked, subpoenaed, or misused later.

Enforced at build time, not by policy

Server-side actions and API routes are a hard lint error in this codebase — a future commit cannot quietly add a server that sees your data without failing the build first.

Walk away and keep everything

Your attestations live in your tenant, in your Microsoft 365 subscription. If you stop paying us tomorrow, you keep every one of them. We never had the ability to hold them hostage.

See every Microsoft Graph permission the app asks for, and why

How it works

Map it. Examine it. Prove it.

Three questions most organizations can't answer cleanly — what are we on the hook for, have we done anything about it, and can we show our work later.

01

Map what binds you

Choose the standards and jurisdictions you fall under. The crosswalk resolves them into the actual set of mandates you owe — deduplicated across every framework that happens to share one, so a requirement you already meet stops showing up as four separate jobs.

02

Run the exam

Structured exams walk your team through each mandate: what it asks for, who is accountable, and what counts as an answer. Ten today, including CMMC Level 2, DFARS CUI protection, the HIPAA Security Rule, SOX 404, FISMA, ISO/IEC 27001, and NIST CSF 2.0.

03

Keep the attestation

Each answer becomes a timestamped, attributable attestation, written to storage provisioned inside your own Microsoft 365 tenant. Not marked complete — evaluated, dated, and sourced.

Who this is for

Two kinds of teams arrive here, for opposite reasons.

One has been handed an obligation it never planned for. The other is choosing one, because a deal depends on it. Both need the same thing: a real answer, fast, without hiring a function they cannot afford.

You just got a flow-down clause

DFARS 252.204-7012 and CMMC obligations flow down contractually from a prime to every subcontractor that touches CUI, whether or not that subcontractor has ever run a security program. Losing eligibility to bid is not a theoretical risk — it is the next contract.

A deal is blocked on a certification

An enterprise buyer, an insurer, or a partner now wants an attested answer before signing. You have no in-house compliance function and no interest in building one to close a single deal.

You are answering the same question five times

A federal rule, a state privacy statute, an insurer questionnaire, and a customer DPA all asking for the same control in four different vocabularies — and no way to prove to yourself that the four answers agree.

Straight answers

The questions a careful buyer asks first.

Do you need access to our systems?

No. No API keys, no service accounts, no read access into your environment, no agent to install. You sign in with your own Microsoft identity, and the application runs in your browser against your own tenant using your own permissions.

Where does our evidence actually live?

In storage provisioned inside your organization's own Microsoft 365 tenant — the same place the rest of your organization's documents already live, under your existing retention, access, and eDiscovery controls. We never receive a copy.

What happens when a law changes?

We update the crosswalk and redeploy. Because one real-world requirement is stored once and recognized under every framework that references it, a statutory revision is a content change on our side, not a migration on yours.

What does it cost?

Not finalized yet, and we would rather say so than invent a number. Two models are already ruled out: per-seat pricing, because charging per person in a compliance tool just teaches an organization to involve fewer people, and per-framework pricing, because shared requirements are the entire point of a crosswalk. The intent is flat pricing per organization, scaled roughly to size.

Is it ready?

It is in closed alpha, and the honest version is that the content library grows continuously rather than ever being "done" — that is the nature of surveying live law. What exists today is real and is what you see rendered on this page, not a mockup.

Closed alpha

See what you're actually on the hook for.

Sign in with your Microsoft work account to open the crosswalk against your own organization. Nothing is provisioned in your tenant until you ask for it, and nothing you enter is ever sent to us.

Read the full story