Data breach notification in every state, handled in an afternoon.
When you have a breach, notification duties can land in dozens of states at once, each with its own deadline, letter format, and attorney general filing. BreachCompass takes your incident facts and returns which of the 54 US jurisdictions are triggered, a compliant letter for each, every attorney general filing packet, and a calendar of every deadline, with the statute cited behind each answer.
Four steps, one defensible work product.
Enter the facts
Data elements, discovery date, and affected residents by state, pasted or tallied from a CSV in your browser. No individual PII is ever uploaded.
See the obligations
A deterministic engine flags each jurisdiction as triggered, a judgment call, or clear, with the statute, threshold, and computed deadline for each.
Generate the documents
Letters formatted for each state, AG filing packets with every required field already filled in, and a deadline calendar you can export.
Review, then file
You, the licensed professional, review, attest, and file. BreachCompass never files for you and never gives legal advice.
The chart tells you the law. We do the work.
The free 50 state charts from the big firms are excellent references, and completely static. They don't compute your deadlines from your discovery date, they don't know that Massachusetts forbids describing the breach while California prescribes exact headings, and they don't fill out the Texas portal form you can't save. BreachCompass turns the same primary law into the actual deliverable.
See our sources and method →| Capability | PDF charts | BreachCompass |
|---|---|---|
| Which states are triggered | you read it | computed |
| Deadlines from your dates | no | calendared |
| Letters formatted per state | no | generated |
| AG filing packets | no | assembled |
| Federal overlays (HIPAA, FTC, DFS) | separate | included |
| Updated when the law changes | quarterly | within days |
Built for the people who run the response.
BreachCompass isn't a substitute for legal judgment. It's the mechanical layer beneath it. The hours of checking 54 jurisdictions and formatting each letter become minutes. The decision always stays with a professional.
vCISOs and MSSPs
You are the first call when a client is breached. Instead of only referring out and waiting on counsel, give a defensible read the same day, handle the notification prep, and add a breach readiness line to your services. This is the piece your vCISO stack is missing.
For vCISOs →Privacy counsel
You already know how to run a breach. Turn the 4 to 8 hours of chart checking and Word drafting per matter into 30 minutes of review, then bill the judgment, not the grind. Priced per matter, with no enterprise contract.
For law firms →A breach isn't a place to rely on software alone.
Start with the free calculator to understand your exposure in minutes, then we'll connect you with a vetted attorney who runs breach response on BreachCompass. We're not a law firm, and the legal call belongs to a lawyer.