Responsibility boundary
Diagnostics are not a compliance certificate.
Plugin
Observable signals
Forms, cookies, scripts, endpoints, evidence, and coverage.
320px
Technical implementation
Data-flow map, consent UI, integrations, access, retention, and release checks under the agreed brief.
Controller / legal
Legal decisions
Grounds, texts, notification, internal documents, and the final legal view.
Sequence
Six steps from data map to handoff.
- Context: forms, accounts, analytics, CRM, mail, and processors.
- Evidence map: automated and manual engineering checks with unknowns.
- Responsibility split: code, documents, and controller decisions.
- Stage implementation: forms, scripts, storage, access, and operational controls.
- Verification: repeated scenarios, network capture, regression, and rollback.
- Handoff: data-flow map, settings, and open decisions.
Not automatic scope
Legal assessment and threat modelling are separate work.
- We do not confirm the legal ground or completeness of documents.
- We do not file a notification in place of the controller.
- We do not call a site compliant with 152-FZ from one technical scan.
Tell us what the site needs.
A goal, the current difficulty, and an optional website address are enough. Do not send passwords, keys, or private exports.