Free & Open Source | 25 COPPA rules | View on GitHub
Direct violations of existing and upcoming COPPA 2.0 standards found across open-source and public mobile codebases.
Potential statutory penalties based on the FTC's maximum per-violation rate applied to active user cohorts.
npx runhalo scan . — No signup. No config. Results in under two minutes.
Every finding includes the regulation cited, severity level, developmental context, and a fix suggestion.
Add Halo to your CI/CD pipeline. GitHub Action runs on every PR.
Static analysis, AI-powered review, and compliance tracking. One CLI.
npx runhalo scan . — scans any codebase for children's privacy violations. Supports JavaScript, TypeScript, Python, Ruby, Go, Java, Swift, and more. Results in seconds, runs locally.
One YAML block in your pipeline. Compliance checks run on every pull request. Non-compliant code gets flagged before it merges.
Privacy violations highlighted in your editor as you work. Available on the VS Code Marketplace.
Each finding is assessed by Halo's AI that filters false positives and provides fix suggestions with regulatory context. Free tier: 2 reviews/day.
Select jurisdictions, set severity thresholds, exclude paths, and tune detection sensitivity. One config file: .halorc.json.
Generate compliance scorecards with A-F grading. JSON export included. PDF, SARIF, and HTML reports.
Updated regularly by our compliance engineering team. One scan, global coverage.
25 rules
15 rules
10 rules
15 rules
12 rules
6 rules
8 rules
6 rules
5 rules
15 rules
10 rules
6 rules
5 rules
12 rules
10 rules
8 rules
12 rules
New rules ship regularly. One scan, global coverage.
Children spend more time inside software than they do in classrooms. The apps they use every day are built by engineers who rarely see the regulatory landscape they're shipping into.
We built Halo because we believe the gap between what the law requires and what engineering teams actually know is the single biggest risk to children online. Not malice. Blind spots.
COPPA was written in 1998. The 2.0 update extends protections to kids under 17, with penalties up to $53,088 per violation per day. Most engineering teams have never read it. Most codebases have never been audited against it.
Halo is preventive mental health infrastructure at the code level. We scan source code the way a regulator would, looking for dark patterns, unauthorized data collection, missing consent flows, and age verification gaps. Teams fix issues before they ship, not after an enforcement action.
Built by Mindful Media in Santa Monica, California 🌴😎
Start scanning for free. Upgrade when you need more.
For individual developers and open source projects.
For teams building products children use.
For teams that need compliance attestation and audit readiness.
All plans include the open-source CLI. Cancel anytime.
Two minutes. Free. Before the FTC finds out for you.