Scans · Legal
Know your legal exposure before someone else does.
Keelen's Legal scan is an automated engineering review. It reads your repo and maps what the code does, covering what the code collects, stores, sends and shows. That work ties those facts to commonly cited legal obligations. The laws it covers include GDPR, CCPA/CPRA, COPPA and TCPA, among others. It is not legal advice. It never says you are compliant, and never says you are in breach. What you get is a ranked, cited list for you and your lawyer. Each item shows where your code and an obligation plausibly meet.
Scope comes from a short profile you save first. It sets your jurisdictions, audience and data practices. So a B2B tool in one market is not graded like a consumer app in fifty. Every finding cites its source. Every registry entry records the date its citation was last checked.
Updated
- Findings stay at the level of observation. They set what the code does against what a cited authority is commonly read to require. Yet they never say “you broke the law” and never say “you are in the clear”.
- Ranked by the shape of the exposure. How cheaply can an outsider see it? Can a private person sue, and how do damages multiply? There is no single fake score.
- Scoped to your profile. A duty applies only where it fits. Your declared jurisdictions, audience and data practices set that scope.
- Send a selected code finding to the loop. It becomes a tracked remediation Request. Any pull request that follows uses the project's review, check and merge settings.
- Reruns reconcile. A finding closes on its own only when its detector ran again. The evidence must back it up. Silence never closes anything.
How the registry works
Each entry in the obligation registry checks your profile first. Next it maps one code observation to one commonly cited duty. It cites the authority for that duty. It also records when the citation was last checked. That check is against a primary source. The registry is versioned. Every report names the version it ran under. So two runs are comparable. When counsel has reviewed an entry, that is a fact. It is never inferred.
Ranked by exposure
Findings are ordered by the shape of the exposure. How cheaply can somebody outside the company see the behavior? Does it carry a private right of action? How do the damages multiply? They multiply per user, per message, per violation. The findings never add up to one number. A score would claim a precision the law does not have.
Built to hand to your lawyer
The output is shaped for a lawyer. Each finding pairs one code observation with one cited obligation. So the costly conversation starts from evidence. It does not start from a blank intake call. The disclaimer below appears on every surface this scan makes. That includes the tab and the report. The MCP output carries it too.
From finding to remediation Request
Send the findings that call for code changes into Keelen's development loop as Requests. Review the pull requests and checks that result. The project's merge settings govern them. Some findings need a policy decision. Some need a legal one. Others need an operational one. Those stay with the right people.
Run it on your cadence
Use the Run action on the project tab for a review on demand. For repeated reviews, set your own agent or scheduler to call run_legal_exposure_review for this project, for example each month, before a new market launch, or after a data model change. Keelen has no built in scan scheduler. Set up the project context and access first. Respect running reviews and limits. Read the result before you pick the next step.
Trigger it from any agent
claude mcp add --transport http keelen https://keelen.ai/mcp
Then the run_legal_exposure_review MCP tool starts a run. It works from Claude Code, Cursor, a cron job, or any other tool that speaks MCP.
What it is not
This is an automated engineering review. It maps code observations to commonly cited legal obligations. It is not legal advice, and it is not a compliance certificate. It is not exhaustive: the absence of a finding is not evidence of compliance. A lawyer must review anything that matters.
Included on every paid plan
From $29 / month on Indie
FAQ
Can an AI tell me if my app is GDPR compliant?
No. Be suspicious of any tool that says yes. Compliance is a legal judgment about your whole business. It is not a property of a repo. Keelen's Legal scan can read your code and find the places where what the code does plausibly meets a commonly cited obligation under GDPR or other laws. From there it cites the authority and ranks the exposure. That gives you a real, cited start for the talk with your lawyer.
What laws does the Legal scan know about?
The registry covers commonly cited duties. The list has GDPR, CCPA/CPRA, COPPA and TCPA. It has others too. Your profile sets which ones apply. Only jurisdictions that fit are used. Each entry carries its citation, and each records when it was last checked. The registry version is stamped on every report.
Is this legal advice?
No. It is an automated engineering review. It maps code observations to commonly cited legal obligations. This is not legal advice. It is not a compliance certificate. The absence of a finding is not evidence of compliance. Its job is to help the talk with your lawyer start from cited evidence. It should not start from zero.
How are findings prioritized?
By the shape of the exposure, on three axes. How cheaply can an outsider see it? Does the duty carry a private right of action? How do damages add up? They add up per user, per message, per violation. There is deliberately no single compliance score.
What happens to a finding after the scan?
You triage it. Dismiss is sticky and survives reruns. Send to loop turns it into a tracked remediation Request. Any pull request that follows uses the project's review, check and merge settings. On the next run, a finding closes only when its detector actually ran and the evidence supports it. Silence never closes anything.
Which plans include the Legal scan?
Included on every paid plan, from Indie at $29/month. CMMC Level 2 controls are an Enterprise feature.
Does Keelen include a scan scheduler?
No. Start a review from the dashboard. Or set up an external agent or scheduler to call the scan's MCP tool. Daily, weekly and release driven cadences are examples. You set those up outside Keelen.
Does every finding become an automatic fix?
No. Read the evidence first. Then send the code fixes you pick to the loop. Some findings need a policy decision. Some need an operational one. Others need a legal one. Development follows the project's normal approval and merge controls.