Skip to content
Legiscope
Menu

About Legiscope

Every part of this product started as a job somebody was doing by hand.

Legiscope has been sold as software since 2017 — the second attempt. The first build was deleted in 2016, because the team behind it had not implemented the security controls the product exists to enforce. Everything since was added when a recurring job proved worth simplifying, and kept because it still removes work.

First prototype
2014
Rebuilt from zero
2016
Sold as software
2017
§ 1  What accumulated
20142026 · 20 capabilities still in the product

Each layer removed a different kind of customer work.

Guidance reduced dependence on specialist interpretation. Shared records reduced reconstruction. Relationships preserved context, evidence supported the answer, and review controls kept the final decision with the customer.

Before the productTwo starts — the first one deleted

Angular prototypes built inside client engagements

2014

First platform build — deleted after a security failure

2016
RecordsKeep the compliance record ready to show

Register of processing activities

2017

Guided compliance workflows

2017

Processor and subprocessor records

2017

50 documented standard activities

2017

Reusable process templates and audits

2022

Automated register building

2025
RelationshipsSee how records, vendors and teams connect

Accounts, groups and subscriptions

2022

Documents and assisted work

2024

Multi-controller workflows

2024

Applications and vendor enrichment

2025
EvidenceKeep the source behind every conclusion

Article 28 assessment, done by hand

2017

AI-supported compliance evaluation

2023

Recorded justifications

2023

Document ingestion

2025

DPA discovery and assessment

2025

Product-security analysis

2025
DecisionsReview what automation prepares and retain authority

Validation steps and controlled usage

2023

Structured DPIAs

2026

Article 28 contract work

2026

Transfers, incidents and rights requests

2026
One bar ends. The 2016 build was deleted in full, and everything after it accumulates because later workflows reuse the records, relationships and evidence created earlier. Each bar starts the year that capability entered the product.

What that buys — the same job, before and after

A register of processing activities

  1. Before 20175 weeksEvery processing activity written from a blank page.
  2. From 20172 daysFifty fully documented standard activities, added with a button.
  3. From 20255 minutesThe register drafted by the system, then corrected by a reviewer.

An Article 28 assessment of a processor

  1. By hand5 hoursOne DPA, read clause by clause against Article 28.
  2. With AI3 minutesPaste the DPA in and read the assessment.
  3. In version 520 at onceName the processors. The system finds each DPA online and assesses them in minutes.
§ 2  The build record
Eight turns, two starts

The eight moments that changed what the software could do.

  1. 2014–15Make GDPR actionable

    Teams could begin without turning every task into a legal consultation.

    During a GDPR implementation for a CAC 40 company, Angular prototypes turned legal requirements into guided assessments. Project leaders could collect the right facts, see what needed attention and move work forward without first becoming privacy specialists.

  2. 2016Start again, properly

    The first platform was deleted rather than shipped.

    The team building it had not implemented proper IT security controls. The team was let go, the entire codebase was deleted, and Legiscope started again from nothing rather than sell a privacy product that could not meet its own standard.

  3. 2017Run compliance in one place

    Five weeks of register work became two days. Article 28 assessments were in the product from the same release, read clause by clause at about five hours per processor.

    Legiscope began selling its rebuilt Angular-based cloud service. Fifty fully documented standard activities meant a register was assembled by selecting what an organisation actually did, instead of writing every entry from a blank page — five weeks of work became two days.

  4. 2022Connect the core programme

    Records, vendor relationships and access controls became one workspace.

    The current repository opens during the move from Angular to React 17 and React 18. Processing records, audits, reusable templates, processor and subprocessor records, accounts and groups reduced duplicate work and kept access beside the records it governed.

  5. 2023Explain the assessment

    Customers received an evaluation they could understand and challenge.

    The React interface moved into Next.js as Legiscope added AI-supported evaluations. Recorded justifications and validation steps helped teams identify possible gaps earlier, inspect the reasoning and decide what should be accepted. A processor DPA pasted into the assessment came back in three minutes instead of five hours.

  6. 2024Bring context to the work

    Documents, tasks and controller boundaries stopped living outside the record.

    Automated processing creation and field-level audits reduced blank-form work. Document processing and assisted updates reduced re-entry, while tasks and multi-controller permissions put follow-up with the right people without losing organisational boundaries.

  7. 2025Turn evidence into structured work

    The register that took two days took five minutes.

    Legiscope built the first automated register: the system drafts the processing activities and the reviewer corrects them, taking the same register from two days to five minutes. Background jobs, document ingestion, application enrichment, product-security analysis, DPA discovery and modular audits prepared the rest of the context so reviewers could focus on exceptions.

  8. 2026Reach review-ready decisions

    Customers can move from evidence to accountable decisions without losing the links between them.

    Article 28 assessment stopped needing the document: name twenty processors and the system finds each DPA online and assesses them in minutes. Structured DPIAs, transfers, incidents and rights requests reuse existing programme context. Source evidence, reassessment, acceptance, dismissal and versioned decisions keep automation useful while the customer retains accountable judgment.

The chronology comes from the earlier Legiscope site and the current code history. The first product generation used Angular; React 17 and 18 appear in the 2022 repository transfer, followed by the Next.js interface in 2023.

§ 3  Who builds it
Doctor of law · SGDN/DCSSI · 25 years
Dr. Thiébaut Devergranne, founder of Legiscope

The automation is new. The judgment behind it is 25 years old.

Legiscope was founded by Dr. Thiébaut Devergranne — a doctor of law and former legal counsel in the French Prime Minister’s SGDN/DCSSI services, now ANSSI, the French national cybersecurity agency. The assessments the product runs are the ones he spent 25 years running for organisations by hand, which is why they are written as rules that survive contact with real records rather than as generic guidance.

Legal research
Ph.D., Université Paris II Panthéon-Assas, 2007Très honorable avec les félicitations du jury et autorisation de publication — the highest distinction awarded.
Public service
Six years at SGDN/DCSSI, now ANSSIThe French national cybersecurity agency.
Practice
25 years across data protection and cybersecurity

Bring one recurring privacy task.

We will show you how twelve years of iteration handles it — the record it creates, the evidence it keeps, and the decision it leaves for you to sign.

Book a tailored demo