System and method for automated compliance and risk assessment using ai
Patent Information
- Application Number
- PCT/CA2026/050440
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-21
- Filing Date
- 2026-03-20
- Publication Date
- 2026-09-24
Smart Images

Figure CA2026050440_24092026_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR AUTOMATED COMPLIANCE AND RISK ASSESSMENT USING AlCROSS REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to U.S. Provisional Application 63 / 775,942, filed March 21, 2025, the contents of which are incorporated herein by reference in their entirety.BACKGROUND
[0002] Digital properties, including websites, web applications, and software applications, are deployed across a wide range of industries and act as the primary interface between organizations and users. A digital property may include a collection of web pages operating under one or more domains, and may incorporate third-party scripts, cookies, application programming interfaces (APIs), and tracking technologies that are loaded and executed in a browser during a session. The behavior of a digital property may extend beyond the code of an organization, as third-party integrations introduce additional data flows involving external domains, advertisers, and analytics providers. Discovery mechanisms, including synthetic-user agents, sensor script tags, and domain-based analysis, may be used to observe the behaviors of a digital property by navigating authenticated and unauthenticated portions and recording the scripts, cookies, network calls, and third-party integrations that are active during a session. The artifact data produced by such discovery may describe the technologies, scripts, cookies, data transfers, domains, and component interactions present at the digital property.
[0003] Governance, risk, and compliance (GRC) frameworks define the legal and regulatory standards that organizations may be subject to with respect to the collection, processing, and transfer of user data. Examples of such frameworks include the General Data Protection Regulation (GDPR), the California Privacy Rights Act (CPRA), the Health Insurance Portability and Accountability Act (HIPAA), the Payment Card Industry Data Security Standard (PCI DSS), andvarious internal policies adopted by individual organizations. A GRC framework may specify requirements relating to lawful basis for data processing, user consent, data minimization, and the transfer of personal data to third parties. Compliance determinations under a GRC framework may involve assessing whether the observed behaviors of a digital property, including the presence of tracking technologies and data flows to external parties, are consistent with the applicable requirements. The scope of a compliance assessment may vary based on the frameworks selected, the pages or user flows evaluated, and the data elements of interest identified by the organization.SUMMARY
[0004] In general, in one or more aspects, the disclosure relates to a method for automated compliance and risk assessment using artificial intelligence. The method involves receiving a digital property and compliance input data. The method further involves collecting telemetry from the digital property to obtain artifact data describing the digital property. The method further involves constructing one or more prompts based at least in part on the digital property, the compliance input data, and the artifact data. The method further involves providing the prompts to a foundation model to produce assessment output data with respect to the compliance input data. The method further involves presenting the assessment output data.
[0005] In general, in one or more aspects, the disclosure relates to a system that includes a computer processor and an application that executes on the computer processor. Executing the application performs receiving a digital property and compliance input data. Executing the application further performs collecting telemetry from the digital property to obtain artifact data describing the digital property. Executing the application further performs constructing one or more prompts based at least in part on the digital property, the compliance input data, and the artifact data. Executing the application further performs providing theprompts to a foundation model to produce assessment output data with respect to the compliance input data. Executing the application further performs presenting the assessment output data.
[0006] In general, in one or more aspects, the disclosure relates to a non- transitory computer readable medium including instructions executable by at least one processor. Executing the instructions performs receiving a digital property and compliance input data. Executing the instructions further performs collecting telemetry from the digital property to obtain artifact data describing the digital property. Executing the instructions further performs constructing one or more prompts based at least in part on the digital property, the compliance input data, and the artifact data. Executing the instructions further performs providing the prompts to a foundation model to produce assessment output data with respect to the compliance input data. Executing the instructions further performs presenting the assessment output data.
[0007] Other aspects of one or more embodiments may be apparent from the following description and the appended claims.BRIEF DESCRIPTION OF DRAWINGS
[0008] FIG. 1 shows a diagram in accordance with the disclosure.
[0009] FIG. 2 shows a method in accordance with the disclosure.
[0010] FIG. 3 shows examples in accordance with the disclosure.
[0011] FIG. 4A and FIG. 4B show computing systems in accordance with the disclosure.
[0012] Similar elements in the various figures may be denoted by similar names and reference numerals. The details of features and elements described in one figure may extend to similarly named features and elements in different figures.DETAILED DESCRIPTION
[0013] Disclosed embodiments relate to automated compliance assessment of digital properties using foundation model-based analysis. A digital property (e.g., a website or web application) may incorporate a variety of third-party technologies that collect and transfer user data, and an organization operating a digital property may be subject to one or more governance, risk, and compliance (GRC) frameworks that impose requirements with respect to the collection, processing, and transfer of user data. Disclosed embodiments receive a digital property and compliance input data, collect telemetry from the digital property to obtain artifact data describing the behaviors of the digital property, construct prompts from the digital property, the compliance input data, and the artifact data, and provide the prompts to a foundation model to produce assessment output data.
[0014] Computer-based compliance tools have traditionally operated by executing sets of hardcoded rules that map specific observed behaviors to specific regulatory provisions. A rule-based approach produces compliance assessments that are limited to the specific scenarios anticipated at the time the rules were written, and may fail to account for novel data flows, newly introduced tracking technologies, or cross-framework interactions that were not anticipated in the rule set. Extending a rule-based compliance tool to address an additional regulatory framework or a new category of tracking technology involves authoring, testing, and maintaining a new rule set, which may be timeconsuming and error-prone.
[0015] Disclosed embodiments improve on rule-based compliance tools by replacing hardcoded rule sets with foundation model-based analysis. A foundation model may reason across multiple GRC frameworks from natural language compliance input data without relying on a pre-authored rule set for each framework, and may produce structured assessment output data in response to use-case-specific prompts that combine the digital property, the compliance input data, and the normalized artifact data. The foundation model-based approach may adapt to novel data flows, newly introduced tracking technologies, and newly applicable regulatory frameworks without modification to the underlying tool.
[0016] The digital property and compliance input data are received, and telemetry is collected from the digital property to obtain artifact data describing the digital property. One or more prompts are constructed based at least in part on the digital property, the compliance input data, and the artifact data, and the prompts are passed to a foundation model to produce assessment output data with respect to the compliance input data. The assessment output data is presented, and may include compliance determinations, risk identifications, remediation recommendations, and references to associated enforcement cases and penalties.
[0017] Turning to FIG. 1, a system for automated compliance assessment of digital properties is shown. The system of FIG. 1 may be implemented using one or more computing components, including those described in FIG. 4A and FIG. 4B, and may execute on one or more computer processors.
[0018] The assessment application (102) is a software application that receives one or more digital properties and compliance input data and produces assessment output data describing the compliance of the digital properties with respect to the compliance input data. The assessment application (102) includes a collection application (108), a prompt generator (115), and a foundation model (120) that operate in sequence to collect telemetry, construct prompts, and generate assessment output data.
[0019] The digital properties (105) are the websites, web applications, or software applications subject to compliance assessment. A digital property in the digital properties (105) may include one or more web pages operating under one or more domains and may incorporate third-party scripts, cookies, application programming interfaces (APIs), and tracking technologies that are loaded and executed in a browser during a session. A session is a period ofinteraction between a browser and a digital property during which page loads, script executions, network calls, and cookie operations are recorded. The digital properties (105) are received by the assessment application (102) and are passed to both the collection application (108) for telemetry collection and the prompt generator (115) for inclusion in the constructed prompts.
[0020] The collection application (108) is a software application that collects telemetry from the digital properties (105) to obtain artifact data (110) describing the digital properties (105). The collection application (108) may operate using one or more discovery mechanisms, including synthetic-user agents, sensor script tags, and domain-based analysis, to navigate authenticated and unauthenticated portions of the digital properties (105) and record the scripts, cookies, network calls, and third-party integrations that are active during a session.
[0021] The artifact data (110) is data describing the technologies, scripts, cookies, data transfers, domains, and component interactions present at the digital properties (105). The artifact data (110) may be normalized into a schema identifying JavaScript libraries, domains, IP addresses, and observed behaviors prior to processing by the prompt generator (115). The artifact data (110) may be stored in a structured text file, such as a JSON or CSV file, that records the observations collected during one or more sessions. The artifact data (110) is produced by the collection application (108) and is passed to the prompt generator (115) for inclusion in the constructed prompts (118).
[0022] The compliance input data (112) is data identifying one or more GRC frameworks, policies, or legal standards against which the digital properties (105) are to be assessed. The compliance input data (112) may identify frameworks including the General Data Protection Regulation (GDPR), the California Privacy Rights Act (CPRA), the Health Insurance Portability and Accountability Act (HIPAA), the Payment Card Industry Data Security Standard (PCI DSS), or an internal organizational policy. The compliance inputdata (112) is received by the assessment application (102) and is passed to the prompt generator (115) for inclusion in the constructed prompts (118).
[0023] The prompt generator (115) is a software component that constructs one or more prompts (118) based at least in part on the digital properties (105), the artifact data (110), and the compliance input data (112). The prompt generator (115) may construct use-case-specific prompts that frame compliance analysis tasks for the foundation model (120) by combining observations from the artifact data (110) with the applicable regulatory requirements identified in the compliance input data (112).
[0024] The prompts (118) are data representing one or more structured inputs constructed by the prompt generator (115) for the foundation model (120). A prompt in the prompts (118) may describe a digital property context, a set of artifact observations, a set of applicable compliance requirements, and one or more analytical tasks to be performed by the foundation model (120).
[0025] The foundation model (120) is a machine learning model that receives the prompts (118) and produces the assessment output data (122). The foundation model (120) may reason across multiple GRC frameworks identified in the compliance input data (112) without relying on a hardcoded rule set, and may produce structured assessment output data (122) including compliance determinations, risk identifications, and recommended remediations in response to the prompts (118). In some embodiments, the foundation model (120) represents multiple distinct machine learning models, each receiving one or more of the prompts (118) and producing intermediate outputs, and the intermediate outputs may be aggregated into the assessment output data (122) by one of the models or by the assessment application (102).
[0026] The assessment output data (122) is data produced by the foundation model (120) describing the compliance of the digital properties (105) with respect to the compliance input data (112). The assessment output data (122) may include one or more of a compliance determination, a risk identification,a recommended remediation, a prioritized list of identified risks, and references to associated enforcement cases and penalties. The assessment output data (122) is presented to a user of the assessment application (102).
[0027] FIG. 2 shows a flowchart of a method for automated compliance assessment of a digital property. The method of FIG. 2 may be implemented using the systems described in the other figures, and one or more of the steps may be performed on, or received at, one or more computer processors. The system may include at least one processor and an application that, when executing on the at least one processor, performs the method. A non-transitory computer readable medium may include instructions that, when executed by one or more processors, perform the method. The outputs from various components (including models, functions, procedures, programs, processors, etc.) for performing the method may be generated by applying a transformation to inputs using the components to create the outputs without using mental processes or human activities.
[0028] Turning to FIG. 2, the method (200) shows steps for receiving a digital property and compliance input data, collecting telemetry from the digital property to obtain artifact data, constructing prompts from the digital property, the compliance input data, and the artifact data, and passing the prompts to a foundation model to produce and present assessment output data. The method (200) may include multiple steps (c.g., Block 202 through Block 212) that may execute on the components described in the other figures, including those of FIG. 1, FIG. 4 A, and FIG. 4B.
[0029] Block 202 involves receiving a digital property and compliance input data. The digital property may be received as one or more uniform resource locators (URLs), domain names, or application identifiers that identify the website, web application, or software application to be assessed. The compliance input data may be received as a selection of one or more GRC frameworks, policies, or legal standards against which the digital property is tobe assessed, and may further identify the scope of the assessment, including the pages or user flows to be evaluated and the data elements of interest.
[0030] The method (200) may involve receiving the digital property, including one or more of a website, web application, or software application. The digital property may be specified by a user of the assessment application or may be drawn from a preconfigured list of monitored properties. The digital property may be identified by one or more URLs, domain names, or application identifiers that are passed to the collection application for telemetry collection and to the prompt generator for inclusion in the constructed prompts.
[0031] The method (200) may involve receiving the compliance input data including one or more of a compliance framework, a policy, and a legal standard. The compliance input data may be specified by selecting from a library of supported GRC frameworks or by supplying natural language policy text describing the compliance requirements applicable to the digital property. The compliance input data may identify the scope of the assessment, including the pages or user flows to be evaluated and the categories of data elements of interest.
[0032] Block 205 involves collecting telemetry from the digital property to obtain artifact data describing the digital property. Telemetry may be collected by one or more discovery mechanisms that observe the runtime behavior of the digital property during one or more sessions, recording the scripts loaded, cookies set, network calls made, and third-party integrations active during each session. The artifact data obtained from telemetry collection may be aggregated across multiple sessions and normalized into a structured representation for use in prompt construction.
[0033] The method (200) may involve collecting the telemetry using one or more discovery mechanisms including synthetic-user interaction, sensor script tags, and domain-based analysis. Synthetic-user interaction may be performed by one or more automated agents that navigate the digital property in a mannerthat mimics a human user, traversing authenticated and unauthenticated flows and triggering dynamic script execution. Sensor script tags may be injected into pages of the digital property to record cookie operations and network calls as pages load, while domain-based analysis may identify third-party domains contacted during navigation without relying on page injection.
[0034] The method (200) may involve obtaining the artifact data describing technologies, scripts, cookies, data transfers, domains, and component interactions present at the digital property. The artifact data may be assembled from observations recorded across all discovery mechanisms and may include, for each observed element, a record of the type, origin domain, content or identifier, and the page or user flow during which the element was observed. The artifact data may further describe relationships among observed elements, such as a script loaded from one domain setting a cookie read by a network call to a second domain.
[0035] The method (200) may involve navigating, by one or more synthetic-user agents, authenticated and unauthenticated portions of the digital property to record scripts, cookies, network calls, and third-party integrations. Authenticated portions of the digital property may be accessed by supplying credentials to the synthetic-user agent, allowing observations to be collected from pages and flows that are not visible to unauthenticated visitors. The observations recorded during authenticated navigation may reveal tracking technologies and data transfers that differ from those present in unauthenticated portions of the digital property.
[0036] Block 208 involves constructing one or more prompts based at least in part on the digital property, the compliance input data, and the artifact data. A prompt may be constructed by combining a description of the digital property, a representation of the applicable compliance requirements drawn from the compliance input data, and a structured excerpt of the artifact data describing the observed behaviors of the digital property. Multiple prompts may be constructed to address different compliance frameworks, different pages or userflows, or different categories of risk, with each prompt framing a specific analytical task for the foundation model.
[0037] The method (200) may involve constructing the prompts using one or more compliance laws or standards including one or more of GDPR, CPRA, HIPAA, PCI DSS, and an internal policy. The applicable provisions of each compliance law or standard may be retrieved from a library of regulatory text and incorporated into the prompt as natural language context that frames the compliance determination task for the foundation model. Where multiple compliance laws or standards are identified in the compliance input data, separate prompts may be constructed for each framework, or a single prompt may be constructed that combines the applicable provisions of multiple frameworks.
[0038] The method (200) may involve normalizing the artifact data into a schema identifying JavaScript libraries, domains, IP addresses, and observed behaviors prior to processing by the foundation model. Normalization may involve deduplicating observations, resolving domain names to canonical forms, and categorizing observed scripts and cookies according to their functional purpose. The normalized artifact data may be formatted as a structured text representation that is compact enough to be incorporated into a prompt while preserving the information relevant to the compliance determination.
[0039] Block 210 involves providing the prompts to a foundation model to produce assessment output data with respect to the compliance input data. The prompts may be passed to the foundation model in sequence or in parallel, and the foundation model may process each prompt independently to produce an intermediate output. The intermediate outputs may be aggregated into a unified assessment output by one of the models or by the assessment application, combining compliance determinations, risk identifications, and recommended remediations from across all prompts into a single structured result.
[0040] The method (200) may involve producing the assessment output data including one or more of a compliance determination, a risk identification, and a recommended remediation responsive to the compliance input data. A compliance determination may indicate whether an observed behavior of the digital property is consistent with the applicable requirements of the GRC frameworks identified in the compliance input data, referencing the specific provisions implicated by the observed behavior. A risk identification may describe the nature and severity of a potential compliance exposure, and a recommended remediation may specify a technical or procedural action that, if taken, would bring the digital property into compliance.
[0041] The method (200) may involve generating, in the assessment output data, a prioritized list of identified risks together with references to associated enforcement cases and penalties. The prioritized list may rank identified risks by severity, with severity determined by factors including the sensitivity of the data involved, the specificity of the applicable regulatory provision, and the magnitude of penalties associated with similar violations in prior enforcement actions. References to associated enforcement cases and penalties may be drawn from a corpus of regulatory guidance and enforcement history incorporated into the foundation model during training or supplied as context in the prompts.
[0042] Block 212 involves presenting the assessment output data. The assessment output data may be presented in a report format that groups findings by compliance framework, by page or user flow, or by severity, and may include a narrative summary alongside structured data representations. The presented assessment output data may be delivered to a user of the assessment application through a dashboard, a downloadable report file, or an integration with a compliance management platform.
[0043] The method (200) may involve initiating an enforcement of a security or compliance policy at the digital property based on the assessment output data. An enforcement action may include blocking or restricting a third-party scriptor tracking technology at the digital property, updating content security policy rules, or suppressing data transfers to identified third-party domains until a remediation is confirmed. The enforcement action may be initiated automatically in response to a finding in the assessment output data that meets a configured severity threshold or may be initiated upon confirmation by a user of the assessment application.
[0044] The method (200) may involve triggering a remediation workflow based on one or more findings generated in the assessment output data. A remediation workflow may be triggered by passing one or more findings from the assessment output data to a task management or compliance management system, creating tracked action items that assign remediation responsibility and record completion status. The remediation workflow may track the progress of each action item and may trigger a rescan of the digital property upon completion to verify that the finding has been resolved.
[0045] Turning to FIG. 3, an example implementation of the assessment application (102) of FIG. 1 is shown, illustrating a data flow from a website (302) through a data source (305) and a reporting engine (308) to a GRC Al module (310). FIG. 3 depicts a concrete implementation of the components described in FIG. 1 and may be implemented using one or more computing components, including those described in FIG. 4 A and FIG. 4B.
[0046] The website (302) is a digital property subject to compliance assessment.The website (302) may include one or more web pages operating under one or more domains, and may incorporate third-party scripts, cookies, APIs, and tracking technologies that are loaded and executed in a browser during a session. In the example of FIG. 3, the website (302) is 'https : / / shop . example . com', a web application whose pages include ' / account', ' / login', and ' / checkout', and whose page at ' / account' loads a third-party analytics script from 'cdn. analytics- co . com' and executes an advertising partner initialization script thattransmits a user identifier to " trk . pixelpartner . io' upon login. The following sample illustrates the digital property input as received by the assessment application:URL : https : / / shop . example . com / accountPage Title : My Account - ShopExamplePage HTML (excerpt) :< script src=" https : / / cdn . analytics- co . com / analytics . j s " >< / script ><script>window . adPartner . init ( { userid: "abcl23" } ) ;< / script ><imgsrc="https : / / trk . pixelpartner . io / pixel . gif ?uid=abcl2 3&event=login" / >
[0047] The digital property sample identifies the URL of the page subject to assessment, includes an excerpt of the page HTML showing the third-party analytics script loaded from 'cdn . analytics-co . com', the advertising partner initialization script that passes a user identifier as a parameter, and the tracking pixel request transmitted to 'trk . pixelpartner . io ' upon login.
[0048] The data source (305) is a collection of discovery mechanisms that collect telemetry from the website (302) to obtain artifact data describing the website (302). The data source (305) may include one or more of an Inspector, a PageGuard, and a DomainGuard, each of which observes the runtime behavior of the website (302) using a different discovery mechanism. An Inspector mayobserve scripts, cookies, and network calls by monitoring browser activity during a session, a PageGuard may inject sensor script tags into pages of the website (302) to record cookie operations and data transfers as pages load, and a DomainGuard may perform domain-based analysis to identify third-party domains contacted during navigation. In the example of FIG. 3, the data source (305) collects telemetry from the website (302) using synthetic-user interaction across authenticated and unauthenticated flows, and records the following artifact data:Discovery Method: synthetic-user + sensor script tag Session ID: sess - 2026 - 03 - 16 - 1420 - 001Observed Scripts :cdn . analytics-co . com / analytics . j sinline script : window . adPartner . init ( { userid: "abcl23" } )Cookies :_ga (domain: . example . com; purpose : analytics) aid (domain: . pixelpartner . io ; purpose : advertising id)Network Calls :GEThttps : / / trk . pixelpartner . io / pixel . gif ?uid=abcl23 &eve nt=loginPOST https : / / api . analytics-co . com / collectThird-Party Domains :analytics-co . com, pixelpartner. ioBehavior Notes :Ad / marketing pixel fires on / account after login (no consent banner detected)Cross-domain identifier (uid=abcl23 ) transmitted to pixelpartner . io
[0049] The artifact data records the scripts loaded, the cookies set, the network calls made, and the third-party domains contacted during the session, and further notes that an advertising pixel fires on the authenticated " / account " page without a detected consent mechanism.
[0050] The reporting engine (308) is a software component that normalizes the artifact data received from the data source (305) and passes the normalized artifact data to the GRC Al module (310). The reporting engine (308) may deduplicate observations, resolve domain names to canonical forms, and format the artifact data as a structured text representation for inclusion in prompts. The reporting engine (308) also receives compliance input data identifying the GRC frameworks and policies applicable to the website (302), and passes the compliance input data to the GRC Al module (310), alongside the normalized artifact data. In the example of FIG. 3, the compliance input data received by the reporting engine (308) identifies the following frameworks and scope:Selected Frameworks :GDPR Arts . 5 (1) (a) , 6 , 7 (lawful basis and consent) CPRA Section 1798 .120 (right to opt-out of sharing and sale)Internal Policy: No third-party tracking on authenticated pages without explicit consent Assessment Scope :Pages : / , / login, / account , / checkoutData elements of interest : identifiers, cookies , cross-domain calls
[0051] The GRC Al module (310) is a software module that receives the normalized artifact data and the compliance input data from the reporting engine (308) and produces assessment output data describing the compliance of the website (302) with respect to the compliance input data. The GRC Al module (310) includes a GRC Al agent (312), a use-case specific prompt generation and foundation models component (315), and an output processing and compliance reporting component (318) that operate in sequence to construct prompts, invoke foundation models, and format assessment output data.
[0052] The GRC Al agent (312) is a software agent that coordinates the operation of the GRC Al module (310) by directing the use-case specific prompt generation and foundation models component (315) to construct and process prompts and directing the output processing and compliance reporting component (318) to format and present the resulting assessment output data. The GRC Al agent (312) may receive the normalized artifact data and the compliance input data from the reporting engine (308) and determine one or more use cases for which prompts are to be constructed, such as a compliance determination use case, a risk identification use case, and an enforcement mapping use case.
[0053] The use-case specific prompt generation and foundation models component (315) is a software component that constructs one or more prompts based on the digital property, the compliance input data, and the normalized artifact data, and passes the prompts to one or more foundation models to produce intermediate outputs. The use-case specific prompt generation and foundation models component (315) may construct separate prompts for each use case identified by the GRC Al agent (312), with each prompt combining adescription of the website (302), a representation of the applicable compliance requirements, and a structured excerpt of the normalized artifact data. In the example of FIG. 3, the use-case specific prompt generation and foundation models component (315) constructs a compliance determination prompt and a risk and enforcement mapping prompt. The compliance determination prompt frames the task of determining whether the observed third-party tracking on the authenticated ' / account' page is consistent with the identified GDPR, CPRA, and internal policy requirements, and includes the following content:System:You are a GRC Al agent . Evaluate website artifacts against GDPR, CPRA,and the internal policy below.User :Digital Property: https : / / shop . example . com / account (authenticated page)Compliance Inputs :GDPR Arts . 5 (1) (a) , 6 , 7 (lawful basis and consent) CPRA Section 1798 .120 (opt-out of sale and share) Internal Policy: No third-party tracking on authenticated pageswithout explicit consentArtifacts :Third parties : analytics-co . com, pixelpartner . io Cookie : aid (pixelpartner . io; advertising) Network: GET https : / / trk . pixelpartner . io / pixel . if ?uid=abcl23 &eve nt=login(fires post-login)No consent banner detected on / accountTask:Determine if third-party tracking on / account is compliant .Identify implicated provisions .Recommend remediations and classify severity (High / Med / Low) .Return JSON with findings , severity, and citations .
[0054] The risk and enforcement mapping prompt frames the task of mapping the identified findings to enforcement history and recommending policy actions, and includes the following content:System:Map findings to enforcement history and propose policy actions .User :Findings : Ad pixel firing on authenticated page without consent ;cross-domain identifier transmitted.Task:Identify relevant enforcement cases or regulator guidance .Recommend CSP and Tag Manager rules to block the behavior .Specify steps to implement consent gating before any tracking fires .
[0055] The output processing and compliance reporting component (318) is a software component that receives the intermediate outputs produced by the foundation models of the use-case specific prompt generation and foundation models component (315) and aggregates and formats the intermediate outputs into assessment output data for presentation. The output processing and compliance reporting component (318) may combine compliance determinations, risk identifications, recommended remediations, and enforcement references from across multiple intermediate outputs into a unified structured report. In the example of FIG. 3, the output processing and compliance reporting component (318) produces assessment output data including the following findings:" summary" : "Third-party advertising and analytics activity detected onauthenticated page without consent . " , " f indings" : [" id" : " F- 001" ," issue" : "Ad / marketing pixel f ired on / account after login" ," evidence" : " Request to trk . pixelpartner . io with uid=abcl23" ," implicated_rules" : ["GDPR Art . 5 ( 1 ) (a) " ,"GDPR Art . 6" ," CPRA Section 1798 . 120" ," Internal Policy : no third-party tracking on authenticated pages"] ," severity" : "High" ," risk" : " Potential unlawful processing and sharing of identif ierswithout consent or opt - out" ," recommended_remediation" : ["Gate all third-party tags behind af f irmative consent onauthenticated routes" ,"Block pixelpartner . io via content security policy :connect - src self analytics - co . com" ,"Configure tag manager rule : suppress marketing tags whenuser is authenticated and marketing consent is not recorded"]] ,"next_actions" : ["Remove or consent -gate ad pixel on / account" , "Re-scan after deployment to verify no crossdomain identifiers leak" ,"Update privacy notice to reflect tracking on authenticated pagesif retained with consent"]
[0056] The assessment output data identifies finding F-001, which records that an advertising pixel fires on the authenticated " / account " page after login. The pixel transmits a cross-domain user identifier to "trk . pixelpartner . io' without a detected consent mechanism, which implicates GDPR Articles 5(l)(a) and 6, CPRA Section 1798.120, and the applicable internal policy and is classified as high severity. The recommendation is to gate third-party tags behind affirmative consent, blocking 'pixelpartner . io' through the content security policy, and configuring a tag manager rule to suppress marketing tags on authenticated pages where marketing consent has not been recorded. The output processing andcompliance reporting component (318) may also produce a narrative report summarizing the findings in natural language for presentation to compliance personnel. In the example of FIG. 3, the narrative report produced by the output processing and compliance reporting component (318) reads as follows:Calls to pixelpartner . io and an advertising cookie were detected on the authenticated / account page without evidence of prior user consent . The observed behavior implicates GDPR lawful-basis requirements under Arts . 5 (1) (a) and 6 , CPRA opt-out rights under Section 1798.120 , and the applicable internal policy prohibiting third-party tracking on authenticated pages without explicit consent .Remediation is recommended: the advertising pixel on authenticated routes should be blocked or gated behind affirmative consent , content security policy rules should be updated to restrict connections to pixelpartner . io, and tag manager configuration should suppress marketing tags on authenticated pages where marketing consent has not been recorded. A rescan should be performed after remediation to confirm that no cross-domain identifiers are transmitted without consent .
[0057] The narrative report summarizes the finding that third-party tracking activity was detected on an authenticated page without consent, identifies the implicated regulatory provisions and internal policy, and presents the recommended remediation steps in plain language for review by compliance personnel.
[0058] The recommendations produced by the output processing and compliance reporting component (318) may be automatically executed at the website (302) without requiring manual intervention by a user of the assessment application that generated the report. Where a recommendation specifies a content security policy rule, the rule may be automatically pushed to the web server or content delivery network hosting the website (302) to block the identified third-party domain from receiving data transfers. Where a recommendation specifies a tag manager configuration change, the change may be automatically applied to the tag manager governing the website (302) to suppress the identified tracking technology on the applicable pages or user flows. Where a recommendation specifies a consent gating requirement, the assessment application may automatically configure the consent management platform of the website (302) to gate the identified third-party tags behind affirmative user consent before the tags are permitted to fire. The results of the automatic execution may be recorded in the assessment output data and a rescan of the website (302) may be initiated to confirm that the identified finding has been resolved.
[0059] One or more embodiments may be implemented on a computing system specifically designed to achieve an improved technological result. When implemented in a computing system, the features and elements of the disclosure may yield a technological advancement over computing systems that do not implement the features and elements of the disclosure. Any combination of mobile, desktop, server, router, switch, embedded device, or other types of hardware may be improved by including the features and elements described in the disclosure.
[0060] For example, as shown in FIG. 4 A, the computing system (400) may include one or more computer processor(s) (402), non-persistent storage device(s) (404), persistent storage device(s) (406), a communication interface (408) (e.g., Bluetooth interface, infrared interface, network interface, optical interface, etc.), and numerous other elements and functionalities that implement the features and elements of the disclosure. The computer processor(s) (402)may be an integrated circuit for processing instructions. The computer processor(s) (402) may be one or more cores, or micro-cores, of a processor. The computer processor(s) (402) includes one or more processors. The computer processor(s) (402) may include a central processing unit (CPU), a graphics processing unit (GPU), a tensor processing unit (TPU), combinations thereof, etc.
[0061] The input device(s) (410) may include a touchscreen, keyboard, mouse, microphone, touchpad, electronic pen, or any other type of input device. The input device(s) (410) may receive inputs from a user that are responsive to data and messages presented by the output device(s) (412). The inputs may include text input, audio input, video input, etc., which may be processed and transmitted by the computing system (400) in accordance with one or more embodiments. The communication interface (408) may include an integrated circuit for connecting the computing system (400) to a network (not shown) (e.g., a local area network (PAN), a wide area network (WAN), or any other type of network) or to another device, and combinations thereof.
[0062] Further, the output device(s) (412) may include a display device, a printer, external storage, or any other output device. One or more of the output device(s) (412) may be the same or different from the input device(s) (410). The input device(s) (410) and output device(s) (412) may be locally or remotely connected to the computer processor(s) (402). Many different types of computing systems exist, and the aforementioned input device(s) (410) and output device(s) (412) may take other forms. The output device(s) (412) may display data and messages that are transmitted and received by the computing system (400). The data and messages may include text, audio, video, etc., and include the data and messages described above in the other figures of the disclosure.
[0063] Software instructions in the form of computer readable program code to perform embodiments may be stored, in whole or in part, temporarily or permanently, on a non-transitory computer readable medium, such as a solidstate drive (SSD), compact disk (CD), digital video disk (DVD), storage device, a diskette, a tape, flash memory, physical memory, or any other computer readable storage medium. Specifically, the software instructions may correspond to computer readable program code that, when executed by the computer processor(s) (402), is configured to perform one or more embodiments, which may include transmitting, receiving, presenting, and displaying data and messages described in the other figures of the disclosure.
[0064] The computing system (400) in FIG. 4A may be connected to, or be a part of, a network. For example, as shown in FIG. 4B, the network (420) may include multiple nodes (e.g., node X (422) and node Y (424), as well as extant intervening nodes between node X (422) and node Y (424)). Each node may correspond to a computing system, such as the computing system shown in FIG. 4A, or a group of nodes combined may correspond to the computing system shown in FIG. 4A. By way of an example, embodiments may be implemented on a node of a distributed system that is connected to other nodes. By way of another example, embodiments may be implemented on a distributed computing system having multiple nodes, where each portion may be located on a different node within the distributed computing system. Further, one or more elements of the aforementioned computing system (400) may be located at a remote location and connected to the other elements over a network.
[0065] The nodes (e.g., node X (422) and node Y (424)) in the network (420) may be configured to perform operations for a client device (426). The operations may include receiving requests and transmitting responses to the client device (426). For example, the nodes may be part of a cloud computing system. The client device (426) may be a computing system, such as the computing system shown in FIG. 4A. Further, the client device (426) may include or perform one or more embodiments, in whole or in part.
[0066] The computing system of FIG. 4A may include functionality to present data (including raw data, processed data, and combinations thereof), such as assessment output data, compliance determinations, risk identifications, andremediation recommendations generated by the assessment application. For example, presenting data may be accomplished through various presenting methods. Specifically, data may be presented by being displayed in a user interface, transmitted to a different computing system, and stored. The user interface may include a graphical user interface (GUI) that displays information on a display device. The GUI may include various GUI widgets that organize what data is shown, as well as the presentation of data to a user. Furthermore, the GUI may present data directly to the user, e.g., data presented as actual data values through text, or rendered by the computing device into a visual representation of the data, such as through visualizing a data model.
[0067] As used herein, the term “connected to” contemplates multiple meanings.A connection may be direct or indirect (e.g, through another component or network). A connection may be wired or wireless. A connection may be a temporary, permanent, or a semi-permanent communication channel between two entities.
[0068] The various descriptions of the figures may be combined and may include, or be included within, the features described in the other figures of the application. The various elements, systems, components, and steps shown in the figures may be omitted, repeated, combined, or altered as shown in the figures. Accordingly, the scope of the present disclosure should not be considered limited to the specific arrangements shown in the figures.
[0069] In the application, ordinal numbers (e.g, first, second, third, etc.) may be used as an adjective for an element (z.e., any noun in the application). The use of ordinal numbers is not to imply or create any particular ordering of the elements, nor to limit any element to being a single element unless expressly disclosed, such as by the use of the terms “before,” “after,” “single,” and other such terminology. Rather, ordinal numbers distinguish between the elements. By way of an example, a first element is distinct from a second element, and the first element may encompass more than one element and succeed (or precede) the second element in an ordering of elements.
[0070] Further, unless expressly stated otherwise, the conjunction “or” is an inclusive “or” and, as such, automatically includes the conjunction “and,” unless expressly stated otherwise. Further, items joined by the conjunction “or” may include any combination of the items with any number of each item, unless expressly stated otherwise.
[0071] In the above description, numerous specific details are set forth in order to yield a more thorough understanding of the disclosure. However, one of ordinary skill in the art may practice the technology without some of the specific details. In other instances, well-known features have not been described in detail to avoid unnecessarily complicating the description. Further, other embodiments not explicitly described above may not depart from the scope of the claims as disclosed herein. Accordingly, the scope should be limited by the attached claims.
Claims
CLAIMSWhat is claimed is:
1. A method comprising:receiving a digital property and compliance input data;collecting telemetry from the digital property to obtain artifact data describing the digital property;constructing one or more prompts based at least in part on the digital property, the compliance input data, and the artifact data;providing the prompts to a foundation model to produce assessment output data with respect to the compliance input data; andpresenting the assessment output data.
2. The method of claim 1, further comprising:receiving the digital property including one or more of a website, web application, or software application; andreceiving the compliance input data including one or more of a compliance framework, a policy, and a legal standard.
3. The method of claim 1, further comprising:collecting the telemetry using one or more discovery mechanisms including synthetic-user interaction, sensor script tags, and domain-based analysis.
4. The method of claim 1, further comprising:obtaining the artifact data describing technologies, scripts, cookies, data transfers, domains, and component interactions present at the digital property.
5. The method of claim 1, further comprising:navigating, by one or more synthetic-user agents, authenticated and unauthenticated portions of the digital property to record scripts, cookies, network calls, and third-party integrations.
6. The method of claim 1, further comprising:producing the assessment output data including one or more of a compliance determination, a risk identification, and a recommended remediation responsive to the compliance input data.
7. The method of claim 1, further comprising:constructing the prompts using one or more compliance laws or standards including one or more of GDPR, CPRA, HIPAA, PCI DSS, and an internal policy.
8. The method of claim 1, further comprising:normalizing the artifact data into a schema identifying JavaScript libraries, domains, IP addresses, and observed behaviors prior to processing by the foundation model.
9. The method of claim 1, further comprising:generating, in the assessment output data, a prioritized list of identified risks together with references to associated enforcement cases and penalties.
10. The method of claim 1, further comprising:initiating an enforcement of a security or compliance policy at the digital property based on the assessment output data; andtriggering a remediation workflow based on one or more findings generated in the assessment output data.
11. A system comprising:a computer processor; andan application that, when executing on the computer processor, performs operations comprising:receiving a digital property and compliance input data,collecting telemetry from the digital property to obtain artifact data describing the digital property,constructing one or more prompts based at least in part on the digital property, the compliance input data, and the artifact data,providing the prompts to a foundation model to produce assessment output data with respect to the compliance input data, andpresenting the assessment output data.
12. The system of claim 11, wherein the operations further comprise:receiving the digital property including one or more of a website, web application, or software application; andreceiving the compliance input data including one or more of a compliance framework, a policy, and a legal standard.
13. The system of claim 11, wherein the operations further comprise:collecting the telemetry using one or more discovery mechanisms including synthetic-user interaction, sensor script tags, and domain-based analysis.
14. The system of claim 11, wherein the operations further comprise:obtaining the artifact data describing technologies, scripts, cookies, data transfers, domains, and component interactions present at the digital property.
15. The system of claim 11, wherein the operations further comprise:navigating, by one or more synthetic-user agents, authenticated and unauthenticated portions of the digital property to record scripts, cookies, network calls, and third-party integrations.
16. The system of claim 11, wherein the operations further comprise:producing the assessment output data including one or more of a compliance determination, a risk identification, and a recommended remediation responsive to the compliance input data.
17. The system of claim 11, wherein the operations further comprise: constructing the prompts using one or more compliance laws or standards including one or more of GDPR, CPRA, HIPAA, PCI DSS, and an internal policy.
18. The system of claim 11, wherein the operations further comprise:normalizing the artifact data into a schema identifying JavaScript libraries, domains, IP addresses, and observed behaviors prior to processing by the foundation model.
19. The system of claim 11, wherein the operations further comprise:generating, in the assessment output data, a prioritized list of identified risks together with references to associated enforcement cases and penalties.
20. A non-transitory computer readable medium comprising instructions executable by a computer processor to perform:receiving a digital property and compliance input data;collecting telemetry from the digital property to obtain artifact data describing the digital property;constructing one or more prompts based at least in part on the digital property, the compliance input data, and the artifact data;providing the prompts to a foundation model to produce assessment output data with respect to the compliance input data; andpresenting the assessment output data.