A compliance lint for your code.
Lint your app against the law it answers to. Free.
Claude Code, Codex, or any other coding agent declares what the app does and where it operates. That declaration is the whole input: no source code, schema, or data is uploaded. LexLint returns findings: which obligations apply in each jurisdiction, with citations and freshness dates. It catches the basics early. It is not legal review.
Some agents will not fetch a page, or will not act on one they fetched. and paste that instead.
You need LexLint if
- Your code or your AI agent crawls, trains on, or republishes content from sites you don't own.
- AI writes any content your users see.
- Your app holds personal data, voices, or faces.
- Under-18s can reach your app, or you check that they can't.
- Your app has users in more than one country.
An account keeps your runs and your declaration in one place. The lint itself works without one.
AI Agents and the Law, on two pages
The terms the handbook uses, the law first and then the agent, with every term a link. Click a page to read it at full size.
Open the sheet → Download the two-page PDF → Version 1.17 · 2026-09-20, revised 2026-09-21
The same deal your linter makes.
A linter catches the bugs that are cheap to find and expensive to ship. It does not prove your program correct, and nobody mistakes a clean run for a QA sign-off. LexLint offers the same bargain about law.
What it is
- An early warning on the basics, while the code is still cheap to change
- Jurisdiction-aware: the same app profile lints differently in the US, the EU, and South Korea
- Cited: a finding on an instrument carries its source and an as-of date
- A handoff to counsel: where we keep a note on that instrument, the citation links to a law note you can hand a lawyer
What it is not
- Not legal advice, and not a substitute for qualified counsel
- Not a certification: the passing state is "no basic issues found," never "compliant"
- Not an authorization to crawl or access any system
- Not exhaustive: it lints the basics, the way a code linter catches common mistakes
Your code and data are not visible to us.
The whole input to a lint is two lists: what your app does, and where it operates. That is the entire request.
LexLint is never sent your source code, your schema, your data,
your prompts, or your git history. They are not discarded on
arrival, they are never part of the call. The lint runs from inside
Claude Code or Codex, the agent that already has your repository,
and the findings come back into a lexlint.yml you
commit and review like any other file.
One thing leaves, at the close of a run that found anything: the lint's own output. Your agent shows you the exact contents first and uploads on your approval of that call, so the run is kept on the LexLint portal where you can read it again and compare it with the next one. What goes is our findings against the declaration you wrote, which is not your data in the sense above.
Not risk-free, and we will not say it is. Two lists still describe an app, and they travel with the key that identifies the run. What LexLint keeps, and what it never writes down, is set out in full on the about page.
Sent
Not sent
Sent on your approval
The data underneath
Findings come from the UnGovr software-law corpus, which covers AI, scraping, privacy, cybersecurity, age-gating, and news-aggregation law. AI and scraping law are tracked across every country, US states, and the EU, maintained continuously. Privacy, cybersecurity, age-gating and news-aggregation law are researched jurisdiction by jurisdiction, on the same research waves. LexLint consumes the corpus through the same public API any developer can use, and adds nothing on top of its meter. A finding on an instrument carries its citation and an as-of date, and where we keep a note on that instrument it links to a LexLint law note you can hand to counsel.
There is nothing to arrange first: access is settled inside the session, at the point the lint needs it, with a free UnGovr account or a trial key that needs no account at all. See the documentation to connect Claude Code, Codex, or any MCP-compatible agent.
How current is this
LexLint is only worth using if it knows today's law, so it tells you how current it is rather than asking you to assume. Three things are true, and they are three different things.
What is not true: that a person re-reads every law every day. Research runs in waves, and the range in the footer of this page includes the oldest review date in the corpus, which is the number that tells you something.
- The wire is swept every day. Across every jurisdiction in the corpus. When a story outruns what we hold, it opens a research request rather than sitting in a feed.
- The corpus is rebuilt and republished every day. What the tool reads is what the database says, within a day.
- Every law carries the date it was last checked against its sources. Not a site-wide badge, a date on the law. Findings carry it too, and a finding whose entry is older than the corpus's 30-day review window is flagged stale in the output.
Powered by
UnGovr is a nonprofit transparency platform. It builds and runs LexLint, and its software-law corpus is what the lint reads. About UnGovr →
UnGovr is an Associate Member of
The Agentic AI Foundation is the Linux Foundation initiative behind the Model Context Protocol, the standard LexLint speaks. The Open Secure AI Alliance is the Linux Foundation fund on the security of AI agents and the systems they reach. The memberships are UnGovr's own: none of the three reviews, certifies, or endorses LexLint or its findings.