ComplianceSME

Compliance tools · Build and content filter agents · GATE-DEV

CSME Developer Build Compliance and Content Filter

For anyone who ships software. It works inside Claude.

You build with AI. This checks what you built, and what you are about to build, against the laws it has to meet before it ships.

Give it a plan and it tells you every duty the finished work will carry, before a line is written. Give it the build, a live page, or the source of an app, and it tells you which of those duties are met, which are missing, and which it cannot see. Every duty is quoted from the law with its article, and every answer names the file and the line.

It is for developers, agencies and product owners shipping websites, apps and services to customers in the EU or the UK.

£40 a month

The whole answer, every time you use it, per developer. The content filter agent comes with it.

Subscribe, £40 a month

Included in the Compliance Complete account.

What you get back

Give it a plan. A specification, a readme, a design note. It recognises the features the plan describes, taking payment, signing people in, analytics, cookies, user content, email marketing, subscriptions, reviews, connected hardware, an AI feature, selling across borders, and returns the duties each one brings. Every duty is marked PLANNED, because nothing exists yet to pass or fail.

Give it a build. The files as they sit in your publish folder. Cookie consent before any tracker fires, a privacy notice a reader can reach from every page, trader name and address, the total price before checkout, the steps of a subscription, a route to cancel online, labels on form fields, text on images, contrast a reader can see.

Give it a live page or an app. A live page is read at the address you give, with the headers and cookies it serves. For an app that is not a website it reads the words a user meets and what the dependency files reveal, a payment library, an analytics library, a Bluetooth library, each bringing its own duties.

Back comes each duty on one line with one of three answers. Pass, the proof is in the build. Fail, the duty applies and the thing it asks for is missing. Unknown, it cannot see the answer, so nothing is assumed. Then the law's own words, what it found, and the ComplianceSME toolkit that closes the gap.

Every check also reads the words a customer meets in your interface, your documentation and your error messages, and says where they read as if a machine wrote them.

What comes back is kept on your account. Ask for any part of it again later and it does not count as another check.

An example

A finished website for a small company trading across the UK and the EU, checked before it went live. Three of the failures it found:

FAIL     Consent before non-essential cookies
         ePrivacy Directive, as amended by Directive 2009/136/EC, Article 5(3),
         first sentence
         The page sets or loads 1 non-essential item and no consent mechanism
         was found.
         Found: Third-party script or frame: googletagmanager.com, at
         index.html line 8

FAIL     Consent taken before marketing by electronic mail
         The Privacy and Electronic Communications (EC Directive) Regulations
         2003 (SI 2003/2426), Regulation 22(2)
         The sign-up carries 1 consent box already ticked in the served page,
         so the notification comes from the trader and not from the recipient.
         Found: A marketing sign-up on the page: "newsletter", at index.html

FAIL     Trader information on the page
         Electronic Commerce (EC Directive) Regulations 2002, Regulation 6(1),
         opening words and sub-paragraphs (a) to (c)
         The page sells and does not carry a geographic address or a
         registration number.
         Found: Selling language on the page: "Add to basket", at
         index.html

Before the site was built, the same company's written plan went through. A plan has nothing to pass or fail yet, so every duty comes back marked PLANNED, which is what the finished work will owe, in the law's own words.

PLANNED  General Data Protection Regulation, Article 13(1), opening words and
         points (a) and (b)
         Carried by: Signing a person in, Tracking or analytics, Trading across
         borders, Holding personal data

Every answer names the file and the line.

How to connect it

  1. In Claude, open Settings, then Connectors, then Add custom connector. Paste this address and save. https://gate.compliancesme.com/developer/mcp
  2. Claude opens our sign-in page. Type your email, tick the box, press Send me the link.
  3. Open the email, press the link, press Connect on the page that opens. The developer filter agent now sits in your connectors.
  4. Start a new chat and type: “Read this plan and tell me what the work will carry.” or “Check these files before I ship them.”

What it does not do

It is not legal advice, and it never says a company is compliant. Where a matter is contested, take it to a qualified professional.

It reads what you give it. It cannot see a record you keep, a process you follow, a contract you signed or a conversation you had, so duties that turn on those are listed as not checked, with the count.

A plan carries no pass and no fail. An app's source has no served page and no headers, so those checks run on the live page instead.


The content filter agent reads what you publish: CSME Content Creator Compliance and Content Filter. All the toolkits: 116 agent toolkits.