Cleo Labs logo
Gov Legal · Legal Assistants

Cleo Labs

Cleo Labs is an AI regulatory intelligence platform that maps every product in a catalog to the rules that apply in each market. It tracks 25,000+ regulations across 106 countries and flags obligations before they enter into force.

Active GDPR compliant Free plan Contact Sales API available Verified by Guidaio
Overview

What is Cleo Labs?

Cleo Labs sells regulatory intelligence to brands that ship physical goods across borders. Its engine, MARIA — Multi-Agent Regulatory Intelligence Architecture — is a multi-agent system in which specialised agents read regulatory texts and return structured obligations. The company's research paper describes 19 regions, 8 languages and more than 30 LLM calls per run, executed on frontier models including Claude with a proprietary regulatory fine-tune on top.

The starting point is deliberately light: a catalog CSV, or simply a domain name. From there the platform extracts ingredients, claims and certificates, then ties each SKU to the texts that govern it, market by market. The homepage claims 106 countries, 25,000+ active regulations, 19,000+ indexed authorities and 3,700+ official sources; the separate Coverage Atlas reports 158 markets, 14,225 regulations, 4,658 authorities and 68% of consumer-product rules under live monitoring. The site never reconciles the two sets of figures.

Five views organise the work — Products, Signals, Markets, Laws and Authorities. Every regulatory signal gets a risk score from 0 to 100 and a level of Critical, High, Medium or Low, weighing severity, relevance to the business, deadline proximity and financial exposure. Alerts arrive before a rule takes effect, naming the products caught by it. Each finding cites the official text it came from, which is the vendor's stated answer to opaque compliance tooling: no black boxes in compliance, with human experts left to validate and decide.

Eight industries are covered — retail, cosmetics, electronics, food and beverage, pet care, sporting goods, medical devices, and drugs and pharmaceuticals — against named regimes including GPSR, REACH, RoHS, CE marking, ESPR and the Digital Product Passport, CPSIA, MoCRA, FCC Part 15, Japan's PSE mark, California Prop 65, CSRD, AGEC, the EU AI Act, DORA and NIS2. A separate module screens third parties for sanctions, PEP exposure and adverse media.

Everything is exposed to machines too: two v2 REST APIs, signed webhooks, and an MCP server publishing 35 tools to clients such as Claude Desktop and Cursor. Data sits in the EU, on Scaleway's Paris region, and never trains the models.

What it does

  • Map a company's entire regulatory perimeter from a domain name or a catalog CSV
  • Link every SKU to the regulations that apply in each market, with effective dates and local exceptions
  • Score each regulatory signal from 0 to 100 and rank it Critical, High, Medium or Low
  • Raise alerts before a rule enters into force, naming the SKUs affected and the revenue at stake
  • Produce executive briefings and audit-ready reports, timestamped and traceable back to the official source
  • Classify a product by HS code and compute duties, VAT, excise and landed cost through the API
  • Screen third parties against sanctions lists, PEP databases, adverse media and court records
Audience

When to use Cleo Labs / When not to

A quick filter to help you decide if Cleo Labs is the right fit.

When to use Cleo Labs

  • Product compliance teams at international retail and consumer-goods brands, the profile behind the Decathlon proof of concept quoted on the site
  • Regulatory affairs managers who have to keep CE marking, REACH, ESPR, GPSR, CSRD, AGEC and the Digital Product Passport straight at the same time
  • Importers and distributors who need an HS code, duties, certifications and a dual-use check settled before goods reach customs
  • Marketplaces policing listing eligibility and per-market sanctions across a catalog they do not own
  • Procurement and third-party risk teams running due diligence against sanctions lists, PEP databases, adverse media and court records

When not to use Cleo Labs

  • Individuals and hobbyists: there is no consumer offer, and every route on the site ends at a booked demo
  • Buyers who need to compare prices before talking to anyone: no rates are published, and /en/pricing simply redirects to the demo booking page
  • Teams that expect to sign up and start alone: even an API key requires a twenty-minute call with the vendor
  • Anyone looking for legal advice: the terms state plainly that the service does not constitute it and guarantee neither completeness nor accuracy
  • Mobile-first users and teams working in a third language: there is no iOS or Android app, and the interface exists in English and French only
Get started

How to use Cleo Labs

A typical end-to-end flow, from setup to results.

  1. Try the public demo first: enter an email or sign in with Google and a magic link opens a dashboard built on a real consumer-goods catalog, 186 regulations across 32 markets, with no account created
  2. Book a slot on the demo page for a live scan of your own company, run in under twenty minutes
  3. Hand over a domain name or a catalog CSV so the platform can map your regulatory perimeter automatically
  4. Expect the first regulatory scan to complete in under five minutes
  5. Refine the perimeter during onboarding — industry, jurisdictions, products, data processing activities — and adjust it whenever it drifts
  6. Work through the five views: Products, Signals, Markets, Laws and Authorities
  7. Assign obligations to named owners and invite the rest of the team, which is not capped
  8. Route real-time regulatory alerts into Slack
  9. Export the product-regulation matrix as CSV or JSON for reporting and audit
  10. For machine access, book twenty minutes to activate an API key, then call the v2 endpoints with an Authorization: Bearer header, or install the MCP server through npx
Quick read

Pros & Cons

Pros

  • Traceability is the product's backbone: every finding cites the official text, and the vendor makes a point of it — no black boxes in compliance
  • Customer data is hosted entirely in the EU, on Scaleway's Paris region, with no transatlantic transfers claimed
  • Models are never trained on customer data, stated independently on the homepage, the security page and the privacy policy
  • Genuinely wide scope: 106 countries, eight industries, and regimes ranging from the EU's GPSR to California's Prop 65
  • Full machine access, which is rare in this category: two documented APIs, signed webhooks and an MCP server for AI agents
  • Security is documented rather than asserted — AES-256 at rest, TLS 1.3 in transit, role-based access, MFA on production, encrypted backups
  • Reversibility is written into the terms: a full JSON or CSV export of your data within 30 days of asking

Cons

  • No published pricing at all: /en/pricing redirects to the demo booking page, and the sitemap holds no pricing page for the terms to point at
  • Nothing is self-service — even an API key is gated behind a twenty-minute call with the team
  • The footer badge advertises SOC 2 Type II and ISO 27001 on every page while the security page states both are still in progress
  • A very young vendor: a EUR 1.5M pre-seed, a declared headcount of two to ten, and a domain only registered on 26/11/2025
  • The domain has no Wayback Machine capture at all, so there is no independent web history to check the company's track record against
  • Coverage figures differ between pages — 106 countries and 25,000+ regulations on the homepage, 158 markets and 14,225 in the Coverage Atlas — with no explanation
  • No mobile app, and the interface is limited to English and French
Pricing

Pricing & Plans

No price is published. The pricing page referenced by the terms of service does not exist: /en/pricing redirects to the demo booking page, and none of the 499 URLs in the sitemap points to one. What the terms do state is that access to premium features requires a paid subscription, that prices are quoted in euros (EUR) excluding tax, that billing is monthly or annual at the customer's choice, and that rates may change with 30 days' notice. Two free entry points exist alongside it: a free regulatory scan, with no credit card and subject to fair-use limits, and a free personalised demo with no commitment. The API documentation names a Pro tier at 300 requests per minute and an Enterprise tier at 600, with negotiable volumes and a contractual SLA, but attaches no figure to either. A prospective buyer therefore has to contact sales to learn the cost.

Plan 1
  • Free regulatory scan — no credit card
  • subject to fair-use limits
  • a summary analysis of the regulations applicable to a given company domain
Plan 3
  • Legal Data API
  • Pro — 300 requests per minute on a sliding one-minute window
  • price not published
Plan 4
  • Legal Data API
  • Enterprise — 600 requests per minute
  • negotiable volumes and a contractual SLA
  • price not published
Plan 5
  • Enterprise security options — SAML SSO
  • exportable audit logs
  • IP allow-listing
  • configurable data lifecycle and a dedicated support channel
  • price not published
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Cleo Labs handles your data.

GDPR overview

The commitments are concrete rather than decorative. Cleo Labs states compliance with the GDPR and specifically with Article 28 on processing: it keeps records of processing activities, runs Data Protection Impact Assessments, has appointed a data protection lead — Anaelle Guez, reachable at contact@cleolabs.co — and answers data subject requests within 30 days. A DPA is available for download. The privacy policy, effective 24 February 2026, lists the legal bases used (contract, legitimate interest, consent, legal obligation) and the seven rights available, and names the CNIL as the supervisory authority. Breaches are notified to affected users and the CNIL within 72 hours. Transfers outside the EU rely on Standard Contractual Clauses. Compliance with the ePrivacy Directive, the CCPA and the LGPD is claimed as well. No Article 27 representative is designated, and none is required: the company is established in France.

Who owns the data?

The terms split ownership in two. You keep the data you send: you retain ownership of the data you provide to us, a point the privacy policy repeats. Cleo Corp SAS keeps the AI-generated reports and analyses, and grants you a non-exclusive, non-transferable licence to use them for internal compliance purposes only. The platform itself — software, design, AI models and methodologies — remains the vendor's exclusive property. Personal data is not sold. It is shared only with named service providers, with legal authorities where the law requires it, and with an acquirer in the event of a merger or sale of assets, every provider being contractually bound to process it solely on Cleo's instructions.

Reuse rights

Reuse is deliberately narrow. The licence on Cleo's reports is non-exclusive, non-transferable and limited to your own internal compliance work, so republishing or reselling an analysis is outside what the terms allow. Scraping or systematically extracting data from the platform without authorisation is forbidden, as is reverse-engineering it, sharing credentials, or using the output to produce misleading or fraudulent compliance documentation. Within those limits the data you put in stays yours and stays portable: on request Cleo exports everything in a structured, machine-readable format — JSON or CSV — within 30 days, during the subscription or on the way out, and the GDPR right to portability applies on top.

Data retention & training

Retention summary
Account data is kept for the life of the subscription and deleted within 90 days of the account being closed. Regulatory scan data is kept for 12 months unless you ask for it to be deleted sooner. The terms repeat the 90-day window for permanent deletion of all customer data, unless a longer period is required by law, and add that you can request a full export in JSON or CSV at any time, delivered within 30 days. Audit logs are retained for 12 months or more with tamper-proof timestamps. Enterprise customers can configure their own retention policies, with automatic purging of scans and reports afterwards. Note one inconsistency: the security page states full deletion on account closure within 30 days, where the privacy policy and terms both say 90.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

All customer data is stored and processed on servers located in the European Union, specifically Scaleway's Paris region, under European jurisdiction. The vendor states there are no transatlantic transfers of customer data. Encryption is AES-256 at rest and TLS 1.3 in transit, database backups are encrypted, and secrets are held in a vault; the infrastructure is designed for high availability with redundancy across several EU availability zones. Subprocessors are named: Scaleway for hosting in the EU, PostHog for analytics in the EU, Resend for email delivery in the US under Standard Contractual Clauses, and Stripe for payments in the US under the same clauses. Any transfer outside the EU relies on Commission-approved Standard Contractual Clauses. One technical caveat: the public site resolves to 76.76.21.21, an anycast CDN node geolocated in the United States. That is the delivery of the marketing site, not the storage of customer data.

Hosting countries
🇫🇷 France
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Cleo Labs.

  • A 0 to 100 score makes risk feel settled when it is an estimate; the vendor itself insists that experts validate every compliance-critical decision
  • The terms state the service is not legal advice and guarantee neither completeness nor accuracy, yet the output looks authoritative enough to be treated as both
  • Liability is capped at what you paid over the previous twelve months, which is unlikely to cover the cost of a missed obligation
  • Coverage can breed false confidence: the Coverage Atlas puts live monitoring at 68% of consumer-product rules, with 480 sources still in progress and 349 only planned
  • AI-generated reports belong to the vendor, not to you; your licence covers internal compliance use only
  • Certification badges in the footer outrun reality, since SOC 2 Type II and ISO 27001 are described elsewhere on the same site as in progress
  • Two different deletion windows coexist — 90 days after account closure in the privacy policy and terms, 30 days on the security page — so confirm which one binds your contract
Setup

Setup & Integrations

Technical difficulty

Low for the user. There is nothing to install: the product is a web dashboard, and the public demo opens through a magic link with no account created. A first regulatory scan runs in under five minutes from a domain name, and full onboarding — team setup, custom alerts, connecting existing tools — is quoted at under one day. Technical work is optional and standard: REST endpoints with an Authorization: Bearer header, no proprietary SDK, an MCP server installed through npx. The friction is commercial rather than technical: an API key is issued only after a call with the team.

Deployment

Web appAPI

Integrations

Slack Okta Azure AD Google Workspace Claude Desktop Cursor Cline Continue

Supported languages

EnglishFrench
Company

Behind Cleo Labs

Company name
Cleo Corp SAS
Founded
INFORMATION_NOT_FOUND
Country of origin
🇫🇷 France
Headquarters
17 rue Berteaux Dumas, 92200 Neuilly-sur-Seine, France
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇩🇩 Germany
Legal contact
Support contact

Fundraising

Pre-seed round of EUR 1.5M, announced at the end of April 2026, led by Larry Berger, founder of Amplify, with participation from La Financiere Saint-James and Kima Ventures
Stated use of proceeds: commercial deployment in Europe, then in the United States
Covered on 29 April 2026 by Tech.eu, EU-Startups, Vestbee, FinTech Global, RegTech Analyst and The Legal Wire
Winner of The Pitch by Deel at Station F, selected from more than 35,000 applications

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does Cleo Labs actually do?
It maps a company's products to the regulations that apply to them, market by market. You supply a catalog CSV or just a domain name; the platform extracts ingredients, claims and certificates, links each SKU to the applicable texts, scores the risk and alerts you before a rule enters into force. The homepage claims 106 countries and more than 25,000 active regulations.
What is MARIA?
MARIA, for Multi-Agent Regulatory Intelligence Architecture, is the company's proprietary agentic engine. Specialised agents read regulatory sources and turn them into structured impact analyses. The published research describes 19 regions, 8 languages and over 30 LLM calls per run, running on frontier models including Claude with a proprietary regulatory fine-tune.
How much does it cost?
That is not public. The terms of service refer to a pricing page, but /en/pricing redirects to the demo booking page and no pricing page exists in the sitemap. The terms do confirm that subscriptions are billed in euros excluding tax, monthly or annually, and that rates can change with 30 days' notice. Pricing has to be obtained from the vendor.
Is there anything free?
Yes, two things. A free regulatory scan gives a summary analysis of the regulations applicable to a company domain, needs no credit card and is capped by fair-use limits. And the personalised demo is free, with a live scan run on your own business and no commitment. Neither is a time-limited trial of the full product.
Where is the data hosted, and is it used for training?
All customer data sits on EU servers — Scaleway, Paris region — under European jurisdiction, with no transatlantic transfers claimed. It is encrypted with AES-256 at rest and TLS 1.3 in transit. Customer data is never used to train or fine-tune the models; the vendor states its models are trained exclusively on public regulatory sources.
Is there an API?
Yes. Two v2 APIs, documented against OpenAPI 3.1, cover product compliance (HS classification, duties, obligations, dual-use screening, landed cost) and legal data (hybrid semantic and lexical search, documents, amendments, coverage, translation). Signed webhooks and an MCP server exposing 35 tools to clients such as Claude Desktop and Cursor come with it. Getting a key means booking twenty minutes with the team.
Which industries and regulations are covered?
Eight industries: retail, cosmetics, electronics, food and beverage, pet care, sporting goods, medical devices, and drugs and pharmaceuticals. Named regimes include GPSR, REACH, RoHS, CE marking, ESPR and the Digital Product Passport, CPSIA, MoCRA, FCC Part 15, Japan's PSE mark, California Prop 65, CSRD, AGEC, the EU AI Act, DORA and NIS2.
Who is behind Cleo Labs and is it certified?
Cleo Corp SAS, based in Neuilly-sur-Seine, France, founded by Anaelle Guez and Naomie Halioua, with Alexandre Bloch as CTO. It raised EUR 1.5M in a pre-seed round led by Larry Berger, founder of Amplify, with La Financiere Saint-James and Kima Ventures. GDPR Article 28 compliance is claimed and a DPA is downloadable; SOC 2 Type II and ISO 27001 are described on the security page as still in progress.
Conclusion

Should you pick Cleo Labs?

Cleo Labs is a narrow tool that goes deep. It is not a general assistant with a compliance skin: it exists to answer one question — what applies to this product, in this market, by when — and it answers it with sourcing that survives scrutiny. Every finding points back at the official text, the audit trail is timestamped, and the vendor is explicit that its role is to accelerate detection while human experts validate and decide. For a compliance team that has to defend a position in front of an authority, that design choice matters more than any feature list.

The infrastructure commitments are unusually clear for a company this young. Customer data stays on EU servers in Scaleway's Paris region, encryption and access controls are documented rather than gestured at, subprocessors are named with their countries and safeguards, and the promise never to train on customer data is repeated in three independent places. Reversibility is written into the terms: a full JSON or CSV export within 30 days of asking.

The reservations are real. Nothing is priced in public, and nothing is self-service — even an API key requires a call. The footer advertises SOC 2 Type II and ISO 27001 on every page while the security page says both are still in progress. Coverage figures differ between the homepage and the Coverage Atlas without explanation, and the Atlas puts live monitoring at 68% of consumer-product rules, a more honest number than the headline. The company is pre-seed, two to ten people, on a domain registered in late 2025 with no web archive behind it.

Worth a demo if you carry multi-market product compliance. Ask about certification timelines, the gap between the two coverage counts, and pricing, before anything else.