Find compliance blind spots
before regulators do.

Scans your code against HIPAA, SOC2, PCI-DSS, GDPR, CCPA, and 5 more
Asks the exact questions regulators ask in investigations
Finds the evidence in specific files and line numbers
HIPAA fines averaged $9.48M per breach in 2024
45% of AI-generated code has security flaws — Veracode 2025
OpenDocket asks the questions an investigator would ask — and finds the evidence in your code
Use my API keys
Both keys are used only for this scan and never stored.
3 free scans per hour · No account required
--
repos scanned
--
lines analyzed
--
risks identified
--
judge reviews

How It Works

1

Point it at a repo

Give OpenDocket any public GitHub URL. It clones the repository, runs qualification gates, and detects which regulatory domains apply — healthcare, fintech, SaaS, payments, communications, and more.

2

It asks legal questions

Based on the domain, OpenDocket loads compliance frameworks — 10 frameworks, 94 questions from actual regulatory text. The questions a regulator would ask in a deposition or audit.

3

You get a legal brief

For each question, OpenDocket finds evidence in your code — specific files, line numbers, patterns. Gemini independently reviews every finding. You get a structured report with risk levels and remediation.

Compliance Intelligence Directory

Real compliance scans of open-source repositories.

RepositoryStarsDomainFrameworksConfirmedFindingsRiskReport
medplum/medplum4,200HealthcareHIPAA, SOC2, GDPR +31056ElevatedView
openemr/openemr2,900HealthcareHIPAA, SOC2, GDPR2330CriticalView
juspay/hyperswitch12,500FintechPCI-DSS, SOC2, GDPR +3356ModerateView
getprobo/probo200SaaSSOC2, GDPR1820CriticalView
supabase/supabase74,000SaaSSOC2, GDPR +4356ModerateView
formbricks/formbricks9,200SaaS9 frameworks6194CriticalView
hashicorp/vault31,000InfrastructureSOC2, GDPR +4656ModerateView
kelseyhightower/nocode60,000Did not qualifyGate

Compliance Frameworks

10 regulatory frameworks. 94 legal questions. Open source question libraries.

FrameworkApplies toMax PenaltyQuestions
HIPAAHealthcare apps, EHR systems, telemedicine$1.5M/year per category10
SOC 2SaaS platforms, cloud services, B2B softwareLoss of enterprise contracts10
PCI-DSSPayment processors, e-commerce, fintech$5K-$100K/month10
GDPRAny app with EU users, personal data processorsEUR 20M or 4% turnover10
TCPASMS marketing, automated calling, messaging apps$500-$1,500/violation8
SOXPublic company software, financial reportingCriminal penalties, delisting8
CCPA/CPRA NEWAny app with California users, SaaS$2,500-$7,500/violation10
COPPA NEWApps used by children under 13, educationUp to $51,744/violation8
FERPA NEWEd-tech, LMS, student information systemsLoss of federal funding8
GLBA NEWFintech, banking, insurance, financial advisors$100K/violation + criminal8
More frameworks coming — contribute on GitHub

Open Source

MIT License. Scan any public repo, contribute frameworks, or build on top of it.

View on GitHub Contribute