Astrópalo
Sign in Pricing Compliance Partner login Become a partner Find a partner
Use cases by industry

The same rules,
different headaches depending on your business.

Compliance obligations do not look the same for an online store, a clinic, a company bidding for public contracts or a website subject to the European Accessibility Act. Here is what applies to each segment — and what Astrópalo checks for you.

Ecommerce

WooCommerce, PrestaShop, Tiendanube

You have a payment gateway, you process cards, you handle customer data. Three regulators are watching you and expect you to be able to prove it at any time.

  • The pain: skimmers at checkout, AEPD fines for cookie banners that block nothing, fraudulent emails spoofing your domain.
  • What Astrópalo does: in-depth monitoring (WooCommerce/PrestaShop/Tiendanube), checks HTTPS, cookies, SPF/DKIM/DMARC, active skimmers, plugin versions and LSSI legal compliance.

Real-world case

A WooCommerce store was fined EUR 45,000 by the AEPD because its cookie banner was purely decorative — it blocked nothing. It had been like that for 3 years. Astropalo would have detected it in the very first check.

Regulated SME

Data, healthcare, legal, advisory services

You handle sensitive data — clients, patients, case files. The GDPR applies in full force, and a breach can mean a fine, reputational damage and loss of trust from the clients who entrusted you with their data.

  • The pain: forms exposed without HTTPS, outdated privacy policies, cookies set before consent, your domain used to send phishing.
  • What Astrópalo does: continuous checks of HTTPS, headers, cookies, SPF/DKIM/DMARC and GDPR/LSSI legal compliance. Monthly report to demonstrate proactivity.

What the regulator expects

The GDPR does not forgive "I didn't know." It requires organizations to be able to demonstrate at any time that they have taken appropriate technical measures to protect data. A monitoring report is part of that evidence.

Public sector contracts

Companies bidding for public tenders

You sell SaaS, build websites or provide digital services to the public administration. Since Real Decreto 311/2022, the ENS clause in tender specifications is not optional — it is a filter. If you don't comply, you are disqualified.

  • The pain: you find out 3 days before the deadline that you don't comply. You lose the tender. You start from scratch.
  • What Astrópalo does: 16 automated ENS Basic controls (GEN-ENS-001 to GEN-ENS-016) verified from the outside, with a report you can submit as evidence of compliance.

What changes from 2026

Public bodies are stepping up enforcement of the ENS clause. Local councils that used to let it slide now use it as a knockout requirement. Having a monitoring report available makes the difference between winning and losing the tender.

European Accessibility Act (EAA)

Publicly accessible websites and digital services

Since June 2025, the European Accessibility Act (EAA) has been applicable. It affects companies providing digital services to consumers in the EU: ecommerce, SaaS, the public sector, financial services... If your website is not accessible, it is a legal risk — and a real exclusion.

  • The pain: a website that looks fine on screen can fail 40+ WCAG 2.1 AA criteria — and you won't know until a complaint or an inspection forces you to.
  • What Astrópalo does: full crawl with axe-core + LLM checks against WCAG 2.1 AA, sitemap-first, monthly report with remediation priorities.

Who is affected

Ecommerce, banks, insurers, transport, audiovisual, telecommunications, the public sector and any service from the above sectors delivered digitally. If you sell to consumers in the EU, you are on the list.

Not sure which modules apply to you?

Tell a partner which sector you work in and they will set up the modules that apply. No unnecessary complexity, no paying for things you don't need.

Find a partner Try for free