SOC2 is a 6-month death march. This is a 30-second scan.

ComplianceLite checks the basics — security headers, TLS, privacy policy presence, cookie consent, common misconfigs — and gives you the exact config snippets to fix what's broken. Built for indie SaaS at <$1M ARR.

Start 14-day trial What it scans No card · Cancel anytime · Auditor-pleasing report

What gets scanned

Security headers

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy. We tell you which to add and the exact value.

TLS & redirects

HTTPS enforcement, redirect loops, mixed content. Catches the basics auditors flag in week one.

Policies & consent

Privacy policy, terms, security page, DPA — published or not. Cookie consent presence. GDPR-friendly footer signals.

Form hardening

POST forms without CSP. Login flows over HTTP (yes, still happens). Common XSS sinks.

Remediation prose

For each finding, the exact nginx/Caddy/Cloudflare snippet to fix it. Written by Claude, reviewed by a human.

Re-scan & alerts

Daily on Growth/Pro. Slack alert on regressions. CSV export.

Pricing

Starter

$39/mo
  • 1 site
  • Weekly scan
  • Markdown report
  • 14-day free trial
Start

Pro

$249/mo
  • Unlimited sites
  • Hourly scans
  • Auto-remediation PRs (GitHub)
  • White-glove onboarding
Start