STILLWORKS
☕ Support

Attestly

Scans your codebase to auto-generate and keep privacy policies and AI-Act docs current.

Visit product ↗
Listed Sep 18, 2026

Attestly connects to your repo via read-only GitHub OAuth, statically scans for AI SDK calls, subprocessors, personal-data fields and OSS licenses with file-and-line citations, then generates five compliance documents — privacy policy, DPA and subprocessor list, OSS attributions, SOC 2 readiness, AI trust center — for you to review and publish. It re-scans on every PR so the documents track the code instead of going stale, and auto-notifies customers when a new subprocessor appears, per GDPR Art. 28(2).

What holds up

  • +Cites file and line for every AI SDK call, subprocessor and OSS license it finds, not a black-box scan.
  • +Re-scans on every PR, so the trust center doesn't fall behind a release the way a static PDF does.
  • +Auto-notifies customers of new subprocessors per GDPR Art. 28(2) instead of a manual update.
  • +Free for open-source projects, with a 14-day trial on paid plans and no credit card required.

Mind the limits

  • Only sees what static analysis can find in code — legal-entity facts still need a manual interview.
  • Generated documents need your review before publishing — not fully hands-off compliance.