Lexiscript audits the scripts your website actually loads, maps each one to the privacy laws that apply to your visitors, generates the right notice per region, and enforces consent at the edge — so you can see what your store loads, and what each law expects, without becoming a privacy lawyer.
Every storefront quietly loads analytics, ad pixels, chat widgets and payment scripts — each one a potential data transfer a regulator can ask you to justify. Modern laws apply the moment you collect data from someone in that jurisdiction, wherever your business is based.
GDPR, UK GDPR, CCPA/CPRA and Africa's fast-moving laws — Kenya's DPA 2019, Nigeria's NDPA 2023, South Africa's POPIA — all apply at once for a cross-border merchant.
Kenya's DPA gives one of the tightest breach/response windows of the eight. Getting consent and notices right up front is far cheaper than explaining later.
A single tracker that fires before consent is given is all it takes. Most teams don't have a privacy lawyer on staff, so it's done once and never revisited.
Four purpose-built components working as one pipeline — each stage isolated, and every step leaves a record you can point to behind a published notice.
A headless Chromium browser visits your live storefront and records exactly what fires — every cookie, script and pixel, before and after consent.
Each detected tracker is bound to reviewed legal templates for the regions you sell into — GDPR, CCPA, DPA and more.
Notices and consent configuration are generated per region — opt-in, opt-out or notice-only, exactly as each law requires.
A single edge widget (under 5KB, served from the network edge) blocks non-essential scripts by region until a visitor consents.
Nothing is guessed; everything is observed. The scanner records what your site truly loads, so findings are evidence, not assumptions.
The model's only job is classifying unknown domains — every sentence of legal text comes from a fixed, reviewed template, never generated prose.
See every check we ran, and which ones failed — with the findings behind them, the generated notice for each region, full scan history and version control.
A scan doesn't just produce a pass/fail badge. Every finding is graded by severity, tied to the exact regimes it affects, and paired with what was observed and what to do about it.
Critical, High, Medium, Low and Info — findings are triaged by real-world exposure, not a generic checklist, so you fix what matters first.
Every finding shows what was observed on the live page and the specific fix — and names the exact law it touches, with a citation where one applies.
Lexiscript tells you what to fix next. It is never presented to your customers as a guarantee, and every generated notice is a draft for your own sign-off.
Select the regions your visitors come from, and Lexiscript generates the matching notice and consent behaviour for each — opt-in where the law requires affirmative consent, opt-out where it doesn't, and plain notice where that's all that's needed.
| Region | Law | Consent model |
|---|---|---|
| European Union | GDPR | Opt-in |
| United Kingdom | UK GDPR | Opt-in |
| California, USA | CCPA / CPRA | Opt-out |
| Kenya | Data Protection Act 2019 | Opt-in |
| Nigeria | NDPA 2023 | Opt-in |
| South Africa | POPIA | Notice-only |
| Brazil | LGPD | Opt-in |
| Canada | PIPEDA | Notice-only |
The scanner runs as its own service, so a heavy Chromium workload can never slow down or crash the dashboard your team relies on.
Sign-in uses short-lived, httpOnly session cookies that page JavaScript can't read — a scripting bug on your site can't leak a merchant's session.
Every request is checked against real ownership, not just a valid login — one merchant can never read another's scans, even by guessing an ID.
Published notices are versioned, never overwritten. If a notice is ever questioned, you can show exactly what was live, when, and the scan evidence behind it.
Sources: Africa e-commerce market — IMARC Group; global data-privacy software market — Fortune Business Insights; countries with data-protection law — IAPP. Third-party figures, included for context.
Scan your storefront and read the full report. No card required. Upgrade to PRO when you want ongoing monitoring.
No card required
· billed in KES · cancel anytime
All charges are in Kenya Shillings (KES). Amounts in other currencies are shown for guidance only; if you pay with a foreign card, your bank converts the KES charge at its own rate, which may differ. Free scan results appear in your Lexiscript dashboard, usually within minutes. PRO access is activated immediately on confirmed payment. PRO renews monthly and can be cancelled anytime; no refunds on the current billing period, and approved refunds are processed within 7 working days. See the Lexiscript Terms of Service and Refund & Cancellation Policy.
Lexiscript is sold and operated by JAYDEE INNOVATION HUB, Heshima Road, Nairobi, Kenya.
Lexiscript scans your online storefront for cookies, trackers and pixels, maps each one to the privacy laws that apply to your visitors, generates the correct notice and consent configuration for each region, and enforces consent at the edge with a lightweight widget.
Most free banners show the same message to every visitor and rely on you to list your trackers yourself. Lexiscript starts from what your store actually loads: it scans the live page, records every cookie, script and pixel before and after consent, and sets opt-in, opt-out or notice-only behaviour for each region you sell into. Run a free scan and compare the report with what your current banner covers.
No. Lexiscript is a triage tool. It shows what your store loads and which laws each tracker touches, and it generates starting drafts of notices from fixed templates. Have notices signed off by qualified counsel for your jurisdiction before you rely on them.
GDPR (EU), UK GDPR, CCPA/CPRA (California), Kenya Data Protection Act 2019, Nigeria NDPA 2023, South Africa POPIA, Brazil LGPD and Canada PIPEDA — with the opt-in, opt-out or notice-only consent model each one requires.
The consent widget is under 5KB and is served from the network edge, so it adds very little to page load. The scan itself is a single visit to your storefront by our scanner, much like one visitor loading the page.
Notice text is template-bound, not freeform. The AI only classifies unrecognised third-party domains into a category; it never writes the legal language itself, and low-confidence cases are routed to manual review. Generated notices are starting drafts for your own sign-off, not legal advice and not a substitute for legal counsel.
Yes, during launch. Create an account, scan your storefront and read the full report with no card required. PRO is KES 2,500 per month, billed in Kenya Shillings, for automatic monthly re-scans with the report emailed, published notices, the consent widget and an audit trail. Cancel anytime.
Add your website, run a scan, then review and publish the generated notice and paste one lightweight tag into your site. You can create an account and run your first scan at lexiscript.jaytechkenya.com.
Create an account and paste your storefront URL into the dashboard.
Lexiscript audits the live page and drafts your notices for the regions you choose.
Review the generated notice, publish it, and drop the widget script into your theme.
Lexiscript is built by Jaydee Innovation Hub, led by Judah Mneni Mwatee — 15+ years leading security and IT programs across international hospitality and national-scale government digital infrastructure, and author of The Security Executive: Leading, Influencing, and Protecting in the Age of Cyber Risk. Its constant-time authentication, token-reuse detection and audit-grade policy history reflect that background directly.
Add your site, run a scan, and see every tracker mapped to the regimes it touches. Then publish a notice you can stand behind.
Lexiscript generates starting drafts, not legal advice. Notices should be signed off by qualified counsel for your jurisdiction before you rely on them.