Legal and privacy
Region-aware checks for wherever you launch, including Indonesia and Southeast Asia.
- UU PDP
- GDPR
- CCPA
- PDPA
Findings to review with a professional. Not legal advice.
Paste a GitHub link for one plain-language report on security, testing, code quality and legal risk. Or paste your website address for a quick look from the outside.
Drop in a public GitHub link or your website address. There is nothing to install and nothing to configure.
Proven open-source scanners read your code and dependencies. Your app is never run.
Get one report ranked by what could hurt you first, with a fix prompt for every issue.
Most scanners stop at security. Signoffly also looks at the parts that sink launches quietly: missing tests, messy code and privacy rules.
Region-aware checks for wherever you launch, including Indonesia and Southeast Asia.
Findings to review with a professional. Not legal advice.
The mistakes AI assistants repeat, found before a stranger finds them.
Does the code that matters have tests? Payments, sign-in and anything that changes data are checked first.
Copied code, very long files and loose typing, explained without jargon.
Sample report
Scanned 4 Oct 2026
Blocks sign-off
Anyone who can see this repo can charge and refund on your account. Rotate the key now, then remove it from git history.
.env.example:4
Remove the Stripe secret key from .env.example and replace it with a placeholder. Read it from process.env.STRIPE_SECRET_KEY instead, add .env to .gitignore, and list the exact steps to rotate the key in the Stripe dashboard and clean it out of git history.
The signup form stores personal data. Privacy laws in several regions expect a clear notice before you collect it.
app/signup/page.tsx
Applies under: UU PDP (Indonesia) and GDPR (EU). A finding to review, not legal advice.
Add a /privacy page that explains what personal data this app collects (email, phone number), why, how long it is kept, and how a user can ask for deletion. Link it from the signup form and add an unchecked consent checkbox before submit. Keep the wording plain and mark anything that needs a lawyer to review.
Blocks sign-off
The profiles table has no row level security, so anyone holding your public key can read every user's email.
supabase/migrations/002_profiles.sql:1
Enable row level security on the profiles table and add policies so a signed-in user can only select and update their own row (auth.uid() = id). Show me the migration SQL and a test that proves another user cannot read it.
One of your dependencies has a published vulnerability. A newer version fixes it.
package-lock.json
List the dependencies with known vulnerabilities in this project, upgrade each to the lowest version that fixes it, run the tests, and tell me about any breaking change.
Google Analytics can follow visitors from page to page. Some laws expect people to agree first, for example visitors from Europe.
app/layout.tsx:14
Applies under: GDPR (EU). A finding to review, not legal advice.
Add a consent banner so Google Analytics only loads after a visitor agrees, with accept and reject buttons of equal weight and a way to change the choice later. Mark anything that needs a lawyer to review.
Your app handles payments, and none of its tests mention payments, checkout or webhooks. A silent bug here costs you customers or money. This is judged from file names and what the tests mention, not from measured coverage.
app/api/checkout/route.ts
Write tests for the payment code: a successful payment, a declined card, a duplicate submit, a webhook that arrives twice, and a request from a signed-out visitor. Use the test runner already in this project and mock the payment provider.
About 86 lines across 3 files look copied from each other. A fix in one place does not reach the others, and the copies slowly drift apart.
lib/orders.ts:6
Move the shared logic in lib/orders.ts, lib/invoices.ts and app/cart/page.tsx into one function, make each place use it, and delete the copies. Do not change behavior.
This can be fine if you handle requests by email. If so, say so in your privacy policy and make sure someone answers.
Applies under: UU PDP (Indonesia) and GDPR (EU). A finding to review, not legal advice.
Add a way for signed-in users to delete their account and download their data, or describe in the privacy policy how to ask for it by email. Make deletion remove the user's rows in every table.
No subscription to forget about. Scan a few times a day for free, and unlock everything for one repository when you need the full picture.
$0
One repository for 14 days
No. Legal findings are automated flags for you to review, ideally with a lawyer. They tell you where to look, not what the law requires of you.
No. It reads your repository as text and never starts your app, so nothing of yours executes on our side. For a website it only opens the page the way a browser does, and never tries to get in.
Public GitHub repositories get the full check. You can also paste the address of a live website for a quick look at what a visitor's browser sees: the secure connection, protective headers, cookies, keys visible in the page and privacy basics. A website check cannot see your code, so it can never be signed off. Private repos come later.
Security scanners stop at security. Signoffly also checks privacy rules by region, explains everything in plain language, and writes a fix prompt for every finding.