Cleo Labs
Cleo Labs is an AI regulatory intelligence platform that maps every product in a catalog to the rules that apply in each market. It tracks 25,000+ regulations across 106 countries and flags obligations before they enter into force.
What is Cleo Labs?
Cleo Labs sells regulatory intelligence to brands that ship physical goods across borders. Its engine, MARIA — Multi-Agent Regulatory Intelligence Architecture — is a multi-agent system in which specialised agents read regulatory texts and return structured obligations. The company's research paper describes 19 regions, 8 languages and more than 30 LLM calls per run, executed on frontier models including Claude with a proprietary regulatory fine-tune on top.
The starting point is deliberately light: a catalog CSV, or simply a domain name. From there the platform extracts ingredients, claims and certificates, then ties each SKU to the texts that govern it, market by market. The homepage claims 106 countries, 25,000+ active regulations, 19,000+ indexed authorities and 3,700+ official sources; the separate Coverage Atlas reports 158 markets, 14,225 regulations, 4,658 authorities and 68% of consumer-product rules under live monitoring. The site never reconciles the two sets of figures.
Five views organise the work — Products, Signals, Markets, Laws and Authorities. Every regulatory signal gets a risk score from 0 to 100 and a level of Critical, High, Medium or Low, weighing severity, relevance to the business, deadline proximity and financial exposure. Alerts arrive before a rule takes effect, naming the products caught by it. Each finding cites the official text it came from, which is the vendor's stated answer to opaque compliance tooling: no black boxes in compliance, with human experts left to validate and decide.
Eight industries are covered — retail, cosmetics, electronics, food and beverage, pet care, sporting goods, medical devices, and drugs and pharmaceuticals — against named regimes including GPSR, REACH, RoHS, CE marking, ESPR and the Digital Product Passport, CPSIA, MoCRA, FCC Part 15, Japan's PSE mark, California Prop 65, CSRD, AGEC, the EU AI Act, DORA and NIS2. A separate module screens third parties for sanctions, PEP exposure and adverse media.
Everything is exposed to machines too: two v2 REST APIs, signed webhooks, and an MCP server publishing 35 tools to clients such as Claude Desktop and Cursor. Data sits in the EU, on Scaleway's Paris region, and never trains the models.
What it does
- Map a company's entire regulatory perimeter from a domain name or a catalog CSV
- Link every SKU to the regulations that apply in each market, with effective dates and local exceptions
- Score each regulatory signal from 0 to 100 and rank it Critical, High, Medium or Low
- Raise alerts before a rule enters into force, naming the SKUs affected and the revenue at stake
- Produce executive briefings and audit-ready reports, timestamped and traceable back to the official source
- Classify a product by HS code and compute duties, VAT, excise and landed cost through the API
- Screen third parties against sanctions lists, PEP databases, adverse media and court records
When to use Cleo Labs / When not to
A quick filter to help you decide if Cleo Labs is the right fit.
When to use Cleo Labs
- Product compliance teams at international retail and consumer-goods brands, the profile behind the Decathlon proof of concept quoted on the site
- Regulatory affairs managers who have to keep CE marking, REACH, ESPR, GPSR, CSRD, AGEC and the Digital Product Passport straight at the same time
- Importers and distributors who need an HS code, duties, certifications and a dual-use check settled before goods reach customs
- Marketplaces policing listing eligibility and per-market sanctions across a catalog they do not own
- Procurement and third-party risk teams running due diligence against sanctions lists, PEP databases, adverse media and court records
When not to use Cleo Labs
- Individuals and hobbyists: there is no consumer offer, and every route on the site ends at a booked demo
- Buyers who need to compare prices before talking to anyone: no rates are published, and /en/pricing simply redirects to the demo booking page
- Teams that expect to sign up and start alone: even an API key requires a twenty-minute call with the vendor
- Anyone looking for legal advice: the terms state plainly that the service does not constitute it and guarantee neither completeness nor accuracy
- Mobile-first users and teams working in a third language: there is no iOS or Android app, and the interface exists in English and French only
How to use Cleo Labs
A typical end-to-end flow, from setup to results.
- Try the public demo first: enter an email or sign in with Google and a magic link opens a dashboard built on a real consumer-goods catalog, 186 regulations across 32 markets, with no account created
- Book a slot on the demo page for a live scan of your own company, run in under twenty minutes
- Hand over a domain name or a catalog CSV so the platform can map your regulatory perimeter automatically
- Expect the first regulatory scan to complete in under five minutes
- Refine the perimeter during onboarding — industry, jurisdictions, products, data processing activities — and adjust it whenever it drifts
- Work through the five views: Products, Signals, Markets, Laws and Authorities
- Assign obligations to named owners and invite the rest of the team, which is not capped
- Route real-time regulatory alerts into Slack
- Export the product-regulation matrix as CSV or JSON for reporting and audit
- For machine access, book twenty minutes to activate an API key, then call the v2 endpoints with an Authorization: Bearer header, or install the MCP server through npx
Pros & Cons
Pros
- Traceability is the product's backbone: every finding cites the official text, and the vendor makes a point of it — no black boxes in compliance
- Customer data is hosted entirely in the EU, on Scaleway's Paris region, with no transatlantic transfers claimed
- Models are never trained on customer data, stated independently on the homepage, the security page and the privacy policy
- Genuinely wide scope: 106 countries, eight industries, and regimes ranging from the EU's GPSR to California's Prop 65
- Full machine access, which is rare in this category: two documented APIs, signed webhooks and an MCP server for AI agents
- Security is documented rather than asserted — AES-256 at rest, TLS 1.3 in transit, role-based access, MFA on production, encrypted backups
- Reversibility is written into the terms: a full JSON or CSV export of your data within 30 days of asking
Cons
- No published pricing at all: /en/pricing redirects to the demo booking page, and the sitemap holds no pricing page for the terms to point at
- Nothing is self-service — even an API key is gated behind a twenty-minute call with the team
- The footer badge advertises SOC 2 Type II and ISO 27001 on every page while the security page states both are still in progress
- A very young vendor: a EUR 1.5M pre-seed, a declared headcount of two to ten, and a domain only registered on 26/11/2025
- The domain has no Wayback Machine capture at all, so there is no independent web history to check the company's track record against
- Coverage figures differ between pages — 106 countries and 25,000+ regulations on the homepage, 158 markets and 14,225 in the Coverage Atlas — with no explanation
- No mobile app, and the interface is limited to English and French
Pricing & Plans
No price is published. The pricing page referenced by the terms of service does not exist: /en/pricing redirects to the demo booking page, and none of the 499 URLs in the sitemap points to one. What the terms do state is that access to premium features requires a paid subscription, that prices are quoted in euros (EUR) excluding tax, that billing is monthly or annual at the customer's choice, and that rates may change with 30 days' notice. Two free entry points exist alongside it: a free regulatory scan, with no credit card and subject to fair-use limits, and a free personalised demo with no commitment. The API documentation names a Pro tier at 300 requests per minute and an Enterprise tier at 600, with negotiable volumes and a contractual SLA, but attaches no figure to either. A prospective buyer therefore has to contact sales to learn the cost.
- Free regulatory scan — no credit card
- subject to fair-use limits
- a summary analysis of the regulations applicable to a given company domain
- Paid subscription — amount not published
- quoted in EUR excluding tax
- billed monthly or annually
- cancellable at any time with access running to the end of the current period
- Legal Data API
- Pro — 300 requests per minute on a sliding one-minute window
- price not published
- Legal Data API
- Enterprise — 600 requests per minute
- negotiable volumes and a contractual SLA
- price not published
- Enterprise security options — SAML SSO
- exportable audit logs
- IP allow-listing
- configurable data lifecycle and a dedicated support channel
- price not published
Data, GDPR & hosting
A consolidated view of how Cleo Labs handles your data.
GDPR overview
The commitments are concrete rather than decorative. Cleo Labs states compliance with the GDPR and specifically with Article 28 on processing: it keeps records of processing activities, runs Data Protection Impact Assessments, has appointed a data protection lead — Anaelle Guez, reachable at contact@cleolabs.co — and answers data subject requests within 30 days. A DPA is available for download. The privacy policy, effective 24 February 2026, lists the legal bases used (contract, legitimate interest, consent, legal obligation) and the seven rights available, and names the CNIL as the supervisory authority. Breaches are notified to affected users and the CNIL within 72 hours. Transfers outside the EU rely on Standard Contractual Clauses. Compliance with the ePrivacy Directive, the CCPA and the LGPD is claimed as well. No Article 27 representative is designated, and none is required: the company is established in France.
Who owns the data?
The terms split ownership in two. You keep the data you send: you retain ownership of the data you provide to us, a point the privacy policy repeats. Cleo Corp SAS keeps the AI-generated reports and analyses, and grants you a non-exclusive, non-transferable licence to use them for internal compliance purposes only. The platform itself — software, design, AI models and methodologies — remains the vendor's exclusive property. Personal data is not sold. It is shared only with named service providers, with legal authorities where the law requires it, and with an acquirer in the event of a merger or sale of assets, every provider being contractually bound to process it solely on Cleo's instructions.
Reuse rights
Reuse is deliberately narrow. The licence on Cleo's reports is non-exclusive, non-transferable and limited to your own internal compliance work, so republishing or reselling an analysis is outside what the terms allow. Scraping or systematically extracting data from the platform without authorisation is forbidden, as is reverse-engineering it, sharing credentials, or using the output to produce misleading or fraudulent compliance documentation. Within those limits the data you put in stays yours and stays portable: on request Cleo exports everything in a structured, machine-readable format — JSON or CSV — within 30 days, during the subscription or on the way out, and the GDPR right to portability applies on top.
Data retention & training
Hosting summary
All customer data is stored and processed on servers located in the European Union, specifically Scaleway's Paris region, under European jurisdiction. The vendor states there are no transatlantic transfers of customer data. Encryption is AES-256 at rest and TLS 1.3 in transit, database backups are encrypted, and secrets are held in a vault; the infrastructure is designed for high availability with redundancy across several EU availability zones. Subprocessors are named: Scaleway for hosting in the EU, PostHog for analytics in the EU, Resend for email delivery in the US under Standard Contractual Clauses, and Stripe for payments in the US under the same clauses. Any transfer outside the EU relies on Commission-approved Standard Contractual Clauses. One technical caveat: the public site resolves to 76.76.21.21, an anycast CDN node geolocated in the United States. That is the delivery of the marketing site, not the storage of customer data.
Things to keep in mind
Risks and trade-offs to weigh before adopting Cleo Labs.
- A 0 to 100 score makes risk feel settled when it is an estimate; the vendor itself insists that experts validate every compliance-critical decision
- The terms state the service is not legal advice and guarantee neither completeness nor accuracy, yet the output looks authoritative enough to be treated as both
- Liability is capped at what you paid over the previous twelve months, which is unlikely to cover the cost of a missed obligation
- Coverage can breed false confidence: the Coverage Atlas puts live monitoring at 68% of consumer-product rules, with 480 sources still in progress and 349 only planned
- AI-generated reports belong to the vendor, not to you; your licence covers internal compliance use only
- Certification badges in the footer outrun reality, since SOC 2 Type II and ISO 27001 are described elsewhere on the same site as in progress
- Two different deletion windows coexist — 90 days after account closure in the privacy policy and terms, 30 days on the security page — so confirm which one binds your contract
Setup & Integrations
Technical difficulty
Low for the user. There is nothing to install: the product is a web dashboard, and the public demo opens through a magic link with no account created. A first regulatory scan runs in under five minutes from a domain name, and full onboarding — team setup, custom alerts, connecting existing tools — is quoted at under one day. Technical work is optional and standard: REST endpoints with an Authorization: Bearer header, no proprietary SDK, an MCP server installed through npx. The friction is commercial rather than technical: an API key is issued only after a call with the team.
Deployment
Integrations
Supported languages
Behind Cleo Labs
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does Cleo Labs actually do?
What is MARIA?
How much does it cost?
Is there anything free?
Where is the data hosted, and is it used for training?
Is there an API?
Which industries and regulations are covered?
Who is behind Cleo Labs and is it certified?
Should you pick Cleo Labs?
Cleo Labs is a narrow tool that goes deep. It is not a general assistant with a compliance skin: it exists to answer one question — what applies to this product, in this market, by when — and it answers it with sourcing that survives scrutiny. Every finding points back at the official text, the audit trail is timestamped, and the vendor is explicit that its role is to accelerate detection while human experts validate and decide. For a compliance team that has to defend a position in front of an authority, that design choice matters more than any feature list.
The infrastructure commitments are unusually clear for a company this young. Customer data stays on EU servers in Scaleway's Paris region, encryption and access controls are documented rather than gestured at, subprocessors are named with their countries and safeguards, and the promise never to train on customer data is repeated in three independent places. Reversibility is written into the terms: a full JSON or CSV export within 30 days of asking.
The reservations are real. Nothing is priced in public, and nothing is self-service — even an API key requires a call. The footer advertises SOC 2 Type II and ISO 27001 on every page while the security page says both are still in progress. Coverage figures differ between the homepage and the Coverage Atlas without explanation, and the Atlas puts live monitoring at 68% of consumer-product rules, a more honest number than the headline. The company is pre-seed, two to ten people, on a domain registered in late 2025 with no web archive behind it.
Worth a demo if you carry multi-market product compliance. Ask about certification timelines, the gap between the two coverage counts, and pricing, before anything else.
- Choosing a selection results in a full page refresh.
- Opens in a new window.