Data breach notification software

Data breach notification in every state, handled in an afternoon.

When you have a breach, notification duties can land in dozens of states at once, each with its own deadline, letter format, and attorney general filing. BreachCompass takes your incident facts and returns which of the 54 US jurisdictions are triggered, a compliant letter for each, every attorney general filing packet, and a calendar of every deadline, with the statute cited behind each answer.

54US jurisdictions covered
37AG and regulator regimes
22hard numeric deadlines
30 daysthe new floor in 6 states
A single breach can put you on the clock in dozens of states at once. Six now require notice within 30 days, California gives the attorney general just 15, and the letter rules and reporting thresholds differ in every one. The 50 state chart most teams keep bookmarked is a static PDF that already trails the 2026 changes.
How it works

Four steps, one defensible work product.

STEP 01

Enter the facts

Data elements, discovery date, and affected residents by state, pasted or tallied from a CSV in your browser. No individual PII is ever uploaded.

STEP 02

See the obligations

A deterministic engine flags each jurisdiction as triggered, a judgment call, or clear, with the statute, threshold, and computed deadline for each.

STEP 03

Generate the documents

Letters formatted for each state, AG filing packets with every required field already filled in, and a deadline calendar you can export.

STEP 04

Review, then file

You, the licensed professional, review, attest, and file. BreachCompass never files for you and never gives legal advice.

Why not a PDF chart

The chart tells you the law. We do the work.

The free 50 state charts from the big firms are excellent references, and completely static. They don't compute your deadlines from your discovery date, they don't know that Massachusetts forbids describing the breach while California prescribes exact headings, and they don't fill out the Texas portal form you can't save. BreachCompass turns the same primary law into the actual deliverable.

See our sources and method →
CapabilityPDF chartsBreachCompass
Which states are triggeredyou read itcomputed
Deadlines from your datesnocalendared
Letters formatted per statenogenerated
AG filing packetsnoassembled
Federal overlays (HIPAA, FTC, DFS)separateincluded
Updated when the law changesquarterlywithin days
Who it's for

Built for the people who run the response.

BreachCompass isn't a substitute for legal judgment. It's the mechanical layer beneath it. The hours of checking 54 jurisdictions and formatting each letter become minutes. The decision always stays with a professional.

vCISOs and MSSPs

You are the first call when a client is breached. Instead of only referring out and waiting on counsel, give a defensible read the same day, handle the notification prep, and add a breach readiness line to your services. This is the piece your vCISO stack is missing.

For vCISOs →

Privacy counsel

You already know how to run a breach. Turn the 4 to 8 hours of chart checking and Word drafting per matter into 30 minutes of review, then bill the judgment, not the grind. Priced per matter, with no enterprise contract.

For law firms →
Had a breach, and no lawyer?

A breach isn't a place to rely on software alone.

Start with the free calculator to understand your exposure in minutes, then we'll connect you with a vetted attorney who runs breach response on BreachCompass. We're not a law firm, and the legal call belongs to a lawyer.

Start with the calculator. It's free, and it's the fastest way to see what you're facing.