Service and legal information

What this service does

You answer 10 questions about a product. A fixed ruleset turns those answers into an indicative classification, the provision each conclusion rests on, and the dates that follow from it.

The ruleset is deterministic and versioned. The same answers produce the same result, and every result shows the ruleset version and the date it was produced. No language model, no network call and no randomness takes part in producing a classification.

Every conclusion shown to you is displayed beside the answers it came from, so you can check the reasoning rather than take the result on trust.

What this service is not

This is not legal advice, and using it does not create a lawyer-client relationship. It is a scoping tool.

No person reviews your answers. There is no paid tier in which somebody does, and no promised timescale, at any price. Where your answers leave a point genuinely open, the classification is withheld and the result tells you what would settle it.

This service does not issue any certificate, badge, seal or mark, and it does not state that a product is compliant. Conformity is assessed under the procedures the Regulation itself sets out.

This service does not submit, transmit or pre-register anything to any authority on your behalf. The incident flow records what you did; you submit on the official portal yourself.

Nothing here guarantees an outcome. Using this service does not protect you against enforcement action.

The state of the ruleset

The annex category text is verified against the Official Journal, and every classification remains indicative.

The scoping and classification rules are deterministic and versioned against the published Regulation.

Monitoring in the workspace

The workspace matches the software bill of materials you upload against exploitation data loaded into it. The sources in use, and how recent that data is, are named in the workspace itself.

Matching is by component name and version. It is deliberately conservative: a component whose affected versions are unknown still raises an alert. It is not exhaustive: a vulnerability absent from the loaded sources, or a component absent from your bill of materials, will not appear.

An alert is a prompt to look, not a finding that your build is exploitable, and not a determination that any duty has been triggered.

What is stored

An assessment stores the answers you gave and the result produced from them. An assessment that is never purchased is deleted after thirty days.

A workspace stores the product details you enter, the status of each obligation, any evidence files you upload, incident records, and an append-only audit trail of those changes. Evidence files are stored on the server's own disk.

Signing in uses a single-use link sent to your email address; there is no password. Optional analytics can run only on the public marketing site when explicitly configured; it does not run in the signed-in application.

The audit trail is hash-chained, and entries are signed where a signing key is configured. That establishes internal consistency and authenticates signed entries against a trusted key. It does not prove that the stored history is original and complete.

Terms of service

The current Terms of Service are published at /terms and identify the operator, business-use restriction, purchase terms and liability provisions.

Privacy policy and data retention

The current Privacy Policy is published at /privacy and identifies the controller, processing purposes, providers, retention periods and individual rights.

Imprint and company details

Scopeward is operated by J. B. Nielsen T. Operator contact details are provided in the Terms of Service and Privacy Policy.

VAT and invoicing

Paddle is the merchant of record for paid purchases. Paddle presents applicable taxes and supplies the buyer's receipt or invoice at checkout.

Scopeward — EU Cyber Resilience Act compliance software