Draft policy wording checks: free pre-scan and optional paid early-access report. Findings need review. Public uploads must contain no patient data or other restricted information.
Draft checks you can use today
Draft policy checks
FTC Safeguards + Disposal
58 checks · +$0.25 per page
Organizations within the confirmed FTC Safeguards scope. Disposal checks are included; their consumer-report and jurisdiction facts are assessed separately.
US scope only. Applicability answers may exclude checks or leave them unresolved.
Whether the organization is a person over which the FTC has jurisdiction. This legal conclusion requires human confirmation.
Qualified Individual arrangement
One of INTERNAL, AFFILIATE, or SERVICE_PROVIDER.
Subject to FTC Safeguards Rule
Whether Part 314 applies to the organization.
Uses covered externally developed applications
Whether externally developed applications transmit, access, or store customer information.
Unknown answers stay unresolved. Document detection does not answer these questions for you.
A fictional example to explore
These sample policies contain intentional gaps. Use them to try the quote and pre-scan flow; they are not adopted policies or complete compliance templates.
PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.
Regulations and frameworks to explore
These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.
Draft policy checks available
FTC Safeguards Rule
16 CFR Part 314
Organizations within the confirmed FTC Safeguards scope. Disposal checks are included; their consumer-report and jurisdiction facts are assessed separately.
Jurisdictions: US-FEDERAL
Research applicability questions
Whether the organization maintains or possesses consumer information, as defined in § 682.1, for a business purpose.
Number of consumers whose customer information the institution maintains; used only for the limited 16 CFR 314.6 exceptions.
Whether the institution develops applications used to transmit, access, or store customer information.
Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.
Jurisdictions: GLOBAL
Research applicability questions
Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?