Audit module

Legal & Trust Pages Check (Not a Compliance Audit)

Does Audityxe do GDPR, SOC 2, HIPAA, or PCI-DSS compliance audits?

No — Audityxe does not audit or certify compliance with GDPR, SOC 2, HIPAA, or PCI-DSS; it only checks whether legal and trust pages (such as privacy policy, terms, and cookie policy) are present and discoverable, plus trust signals like security.txt.

Presence of a privacy policy is a basic trust and E-E-A-T signal, not evidence of legal compliance. Compliance determinations require qualified legal and security professionals.

What is checked

Legal & Trust Pages

Whether common legal and trust pages exist, ranked necessary / recommended / skippable for the detected site type.

  • Detected site type (with a confidence level) used to rank which legal pages are expected
  • Each legal page found via navigation/footer links or conventional URLs, or reported missing
  • Privacy policy, terms, and cookie-policy presence

Trust Signals

Disclosure and branding signals.

  • security.txt vulnerability disclosure policy
  • Favicon
  • Web app manifest
  • Safari pinned-tab icon

Cookies & Redirects

Cookie flags and redirect hygiene.

  • Secure, HttpOnly, and SameSite flags
  • Redirect chain and hop count
  • HTTP→HTTPS upgrade

How to run it

Web app: Paste a URL and open the Legal & Trust Pages module.

Command line (see the CLI guide):

npx audityxe-cli https://example.com

Frequently asked questions

Is Audityxe a GDPR compliance scanner?

No. Audityxe checks whether privacy and cookie pages exist, not whether your data practices comply with GDPR.

Can Audityxe produce a SOC 2 or HIPAA report?

No. Audityxe does not generate SOC 2, HIPAA, or PCI-DSS reports or evidence.

Last reviewed against the Audityxe source code. Product names mentioned are trademarks of their respective owners; Audityxe is not affiliated with them.