EuroComply
EU regulatory compliance platform aimed at European SMEs under 250 staff, covering the AI Act, GDPR, NIS2 and DORA. It paired a 30-second URL scan with an evidence workspace on EU-resident infrastructure, free of charge. Now offline.
What is EuroComply?
EuroComply was a European regulatory compliance platform aimed at SMEs with fewer than 250 employees, operated by RMB Ventures, a single-shareholder company under Portuguese law based in Porto. The service is no longer reachable: as of 1 September 2026 the domain returns a registrar parking page, so everything described here reflects the site as archived on 13 July 2026. The product was organised around three blocks. Scan took a pasted URL and analysed public HTML, HTTP headers, schema.org markup and Set-Cookie responses to flag third-party AI tools (14+ vendor fingerprints), pre-consent trackers, missing legal pages, country and language signals and a sector index, in roughly thirty seconds and without signup. Comply turned those findings into artefacts: a ROPA, DPIAs and transfer impact assessments, NIS2 measures, a DORA Article 28 register and Pay Transparency reporting. Watch covered the moving parts, with an 'Intel' feed, a fines tracker and enforcement actions pulled from supervisory authority RSS feeds including the CNIL, Garante, ICO, AEPD, BfDI, EDPB, ESMA, EBA, EIOPA, the CJEU, BSI and ANSSI. A set of free diagnostic tools sat in front of the workspace: EU Compliance Checker, NIS2 Compliance Checker, EU AI Act Compliance Checker, AI X-Ray, Fine Risk Calculator, Pay Transparency Checker, Market Entry Mapper, AI Readiness and a ROPA Generator. Announced coverage ran to 20+ regulatory areas, among them GDPR, the AI Act, NIS2, DORA, the CRA, the Data Act, the DMA, the DSA, MiCA, eIDAS 2, CSRD and Pay Transparency. Technically, inference ran on EU endpoints with Mistral Small 3.1 (around 80%) and Mistral Medium 3 (around 20%), the compliance chat working as retrieval-augmented generation over regulatory texts. Editorial content was sourced to EUR-Lex and signed collectively as 'EuroComply Team'. The platform also published an MCP server at /api/mcp (JSON-RPC 2.0) exposing four tools, namely regulation_lookup, list_regulations, upcoming_deadlines and get_enforcement_actions, alongside an open dataset under CC BY 4.0 with CSV export. Its stated position was the 0 to 1,499 EUR band that Vanta, Drata and Secureframe do not serve.
What it does
- Scan a website URL and see its exposure across 20+ EU regulations in about 30 seconds
- Classify an AI system under the AI Act (Annex III, Article 5, Article 6) and track the Article 9 to 27 obligations
- Build a record of processing activities (ROPA, Article 30) and run data protection impact assessments
- Complete NIS2 and DORA self-assessments, including the DORA Article 28 register of information
- Track regulatory deadlines across regulations and receive national transposition alerts
- Produce versioned, review-ready exports of every compliance artefact
- Query EU regulatory texts through a retrieval-augmented compliance chat or the public MCP server
When to use EuroComply / When not to
A quick filter to help you decide if EuroComply is the right fit.
When to use EuroComply
- European SMEs with fewer than 250 employees and no dedicated compliance team
- Data protection officers and in-house counsel mapping several overlapping EU regulations at once
- CTOs and IT directors who need an AI Act inventory of the SaaS and AI tools already in their stack
- Procurement and vendor managers assembling a documented EU sovereignty posture for a tender
- Compliance officers building a first ROPA, DPIA or NIS2 self-assessment on a zero budget
When not to use EuroComply
- Consumers and private individuals: the service was strictly business-to-business, with an 18-year minimum age
- Anyone seeking legal advice: the terms explicitly excluded legal advice, audit work and legal opinions
- Teams that need outputs carrying evidential weight before a supervisory authority or a notified body
- Large enterprises already running a full GRC suite such as OneTrust
- Organisations handling confidential material that must never reach model training, given the Mistral 'Experiment' plan in use
How to use EuroComply
A typical end-to-end flow, from setup to results.
- Paste your website URL into the scan page: the report came back in about 30 seconds, with no signup and no card
- Read the flagged items: third-party AI tools, pre-consent trackers, missing legal pages, country and language signals
- Work through the free diagnostic tools in the tools catalogue, each result answering what matters, what to do, what evidence to keep and by when
- Create a free account only when you want to save your AI inventory, ROPA, assessments and exports
- Import the scan findings into the dashboard to turn the plan into tracked work
- Classify your AI systems under the AI Act and record the obligations that follow
- Build the ROPA, the DPIAs and the NIS2 or DORA self-assessments in the workspace
- Consult the regulation hubs and the glossary for the legal context behind each obligation
- Export the artefacts in open formats and have them reviewed by qualified counsel
- For machine-to-machine use, connect to the MCP server published at /api/mcp
Pros & Cons
Pros
- Entirely free, with no card required and no paid tier
- EU data residency documented service by service: Supabase in Frankfurt, Vercel in the EU, Mistral inference in Paris
- Subprocessor list published with the country and the data type for each entry
- Unusually candid disclosure that compliance inputs could be used to improve AI models
- Multi-regulation coverage that is rare at this price point, from the AI Act to CSRD
- Public MCP server and an open dataset released under CC BY 4.0
- Dense legal documentation, consistently sourced to EUR-Lex
Cons
- The service is offline: as of 1 September 2026 the domain serves a Namecheap parking page, so nothing described here can be used today
- Compliance inputs could feed Mistral's model training under the 'Experiment' plan, which sits awkwardly with the sovereignty pitch
- No training opt-out was available, the publisher describing one only as under evaluation
- Inconsistent legal identity: RMB Ventures in the imprint, EuroComply Lda on the About pages and in the structured data
- No postal address, no company registration number and no Portuguese tax number published anywhere
- Contradictory usage figures: 1,200+ companies scanned on the home page against 24+ elsewhere and zero in the open dataset
- Pricing contradicted itself across pages, and outputs were explicitly stated to carry no legal or evidential value
Pricing & Plans
The product was presented as entirely free. The pricing page stated 'no credit card, no time limit, no paid tiers', the refund policy dated 10 July 2026 confirmed that 'there are no subscriptions, paid plans, or one-time purchases, and we never collect payment or card details', and the imprint stated that the platform did not process payments or operate paid subscriptions at that time. There is therefore no entry price point to report. The publisher said it funded the service by referring users to European sovereign vendors and through a consent-based insurance referral. One reservation must be recorded: the site contradicted itself on money. The About page mentioned paid tiers, the home page displayed reports at 149, 199 and 299 EUR as one-off purchases while the pricing page gave the same reports away, and the structured data declared a Starter offer at 49 EUR per month and a Pro offer at 149 EUR per month. None of these amounts is reproduced here as a starting price: they contradict one another and the publisher's own statement that no payment was processed.
- AI Act classification
- GDPR ROPA
- DPIA and TIA
- NIS2 and DORA self-assessments
- sovereignty audit
- deadline tracker
- compliance chat and exports
- A free account was required to save and export artefacts
- and the terms limited each legal entity to a single free account
- the amounts appearing in the site's structured data and on the home page were contradicted by the pricing page
- the imprint and the refund policy
Data, GDPR & hosting
A consolidated view of how EuroComply handles your data.
GDPR overview
GDPR implementation was documented in unusual detail. The site claimed outright to be 'a GDPR-compliant compliance SaaS hosted in Frankfurt, Germany'. RMB Ventures, a company under Portuguese law, acts as controller, with the Portuguese CNPD (Av. D. Carlos I, 134, 1.o, 1200-651 Lisbon) as lead authority. Rights under Articles 15 to 21 are set out, with a 30-day response deadline under Article 12(3), extendable by two months. A DPA incorporating the EU controller-to-processor standard contractual clauses is available on request, transfers outside the EEA rely on SCCs under Article 46(2)(c) together with transfer impact assessments referencing Schrems II (C-311/18), and breaches are notified to the CNPD within 72 hours under Article 33. No Article 27 representative is designated, the publisher being established in the EU. The privacy policy is dated 30 March 2026.
Who owns the data?
Under the terms, the customer remains the data controller for any personal data submitted through the platform, such as ROPA entries, DPIA records and incident logs, while RMB Ventures acts only as a processor under Article 28 GDPR and processes solely on the customer's documented instructions. Compliance artefacts, including the ROPA, DPIAs, mappings and evidence items, can be exported in machine-readable form on request. The publisher aligned its exit terms with the Data Act: 30 days of egress, no exit fees and no lock-in. Article 20 portability is offered as a JSON download from Settings > Data. Ownership of the submitted content therefore stays with the customer, not with the platform.
Reuse rights
Purposes and legal bases were tabulated: Article 6(1)(b) contract for the account, AI system records, ROPA and chat; Article 6(1)(a) consent for the newsletter; Article 6(1)(f) legitimate interest for analytics. No special categories under Article 9 were processed, and no automated decision-making within the meaning of Article 22 took place. Data was not sold and not shared for advertising, and partner clicks were logged through an in-house redirect carrying no personal identifier. The decisive caveat concerns AI inference. The publisher ran on Mistral AI's 'Experiment (API)' plan, under which API requests, including prompts and responses, may be used by Mistral to improve its models. Compliance queries, AI system descriptions and classification inputs could therefore end up in model training data. Names, email addresses and direct identifiers were stated as never being sent in prompts, and no opt-out mechanism was in place.
Data retention & training
Hosting summary
Hosting was documented service by service. The database and authentication ran on Supabase in Frankfurt, Germany (AWS eu-central-1), the application and routing on Vercel's EU region in Frankfurt, with a global CDN that includes US nodes for static assets, and AI inference with Mistral AI SAS in Paris, France. Analytics used Microsoft Clarity and Google Analytics 4 in Irish data centres, while transactional email went through SendPulse in the United States under standard contractual clauses. The publisher acknowledged that Supabase Inc., Vercel Inc., SendPulse Inc., Microsoft and Google are all incorporated in the United States and covered those relationships with SCCs, while claiming that regulated workspace data does not transit through the US subprocessors. The subprocessor list was published with the country and data type for each entry and last updated in June 2026. In short, an EU-resident core with US-incorporated suppliers at the edges, disclosed rather than hidden, but disclosed on a site that is now offline and can no longer be re-verified.
Things to keep in mind
Risks and trade-offs to weigh before adopting EuroComply.
- Service offline: as of 1 September 2026 eurocomply.app no longer answers over HTTPS and the www host serves a Namecheap parking page. Every fact in this entry is frozen at the Wayback capture of 13 July 2026 and has not been re-confirmed since.
- Contradictory legal identity: the imprint and the privacy policy name 'RMB Ventures', while the About pages, the founder page and the structured data legalName say 'EuroComply Lda', and a search engine result still mentions 'Code Tide Unipessoal LDA' on a page that was never archived. Three trading names for one publisher, and nothing on the site settles which is correct.
- No legal identifiers: the imprint explicitly declines to publish a registration number or a Portuguese tax number, even though the privacy policy points back to the imprint for exactly those details. Searches on nif.pt, racius.com and GLEIF returned nothing for either name, while control searches on the same registers worked as expected.
- Unreliable structured data: the JSON-LD declares a Starter offer at 49 EUR per month and a Pro offer at 149 EUR per month, contradicted by three separate pages, and its sameAs links to Wikidata and to three GitHub repositories all return genuine 404s.
- Inconsistent traction claims: the home page advertises 1,200+ companies scanned while the same page also states 24+ domains scanned, and the open dataset reports zero verified companies.
- Model training against the sovereignty argument: compliance inputs could feed Mistral's models under the Experiment plan, no opt-out was offered, and that sits uneasily with the EU sovereignty case the rest of the site builds.
- Anonymised founder, declared namesakes and unfinished pages: the site shows only the label 'EuroComply Founder', the name Rui Barreira appearing solely in a URL, a personal LinkedIn profile and a GitHub account. The site itself disclaims any link with EuroComply Dublin, eurocomply.eu, eurocomply.net and the academic EUROCOMPLY framework, while leftovers such as an empty bullet on the founder page and the Portuguese phrase 'Camada 2' inside an English llms.txt suggest unfinished editing.
Setup & Integrations
Technical difficulty
Very low. The scan required no signup, no card and no installation: you pasted a URL and read the report about 30 seconds later. A free account was needed only to save artefacts and export them. The publisher claimed self-service onboarding with no mandatory demo, and the product was a web application, so there was nothing to deploy or maintain. Only the machine-to-machine route raised the bar, since connecting to the MCP server over JSON-RPC 2.0 assumes a technical profile. None of this can be tried today, the service being offline.
Deployment
Supported languages
Behind EuroComply
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement EuroComply.
Frequently asked questions
Was EuroComply a paid product?
Where was the data hosted?
Were customer inputs used to train AI models?
Could you opt out of model training?
Did EuroComply provide legal advice?
What was the minimum age to use the service?
Was a data processing agreement available?
Which regulations were covered?
Was there an API?
Is the service still online?
Should you pick EuroComply?
EuroComply set out to do something genuinely rare: give European SMEs free, documented coverage of a dozen overlapping EU regulations, from the AI Act and GDPR to NIS2, DORA, the CRA, the Data Act, Pay Transparency and CSRD, with a sovereignty posture spelled out service by service, from a Frankfurt database to Paris-based inference. The legal documentation was dense, sourced to EUR-Lex, and unusually honest about its own weak points, including the admission that compliance inputs could be used to improve Mistral's models. The published subprocessor list, the CC BY 4.0 open dataset and the MCP server all pointed to a team that took transparency seriously. Two things temper that. First, the service is no longer available: as of 1 September 2026 eurocomply.app serves a registrar parking page, and everything above describes the site as archived on 13 July 2026, a few months after the domain was registered. Second, the publisher's own record does not hold together. The imprint names RMB Ventures while the About pages and the structured data name EuroComply Lda, no registration or tax number is published anywhere, the Portuguese registers consulted returned nothing under either name, usage figures contradict themselves from one paragraph to the next, and the pricing markup announces monthly amounts that three separate pages deny. The verdict is therefore a documentary one. As a reading of how EU regulatory obligations interlock, and as a template for what an EU-resident compliance stack can look like, EuroComply remains genuinely interesting. As a tool you could adopt, it has no observed operational availability, and anyone assessing it today should treat this entry as a record of what existed in July 2026 rather than a recommendation to sign up.
- Choosing a selection results in a full page refresh.
- Opens in a new window.