What it checks
Compliance Evidence collects security-contact and privacy/terms-page evidence, reviews cookie-consent mechanisms, DNSSEC configuration, WHOIS domain expiry, mail security (SPF/DKIM/DMARC), and mail/DNS hardening (MTA-STS, TLS-RPT, CAA).
It also checks availability status, blocklist and reputation signals, and GDPR/CCPA data-subject-rights indicators — no consent required, since none of these checks send anything beyond a standard DNS/HTTP lookup.
Built for audits, not just alerts
Each finding cites the exact record or page checked, so results can be attached directly to an audit trail or client compliance report rather than requiring a manual write-up.