XCA for SME / SaaS / Enterprise - Patent pending

GDPR: Stop non-compliant data actions before they happen.

Xelinier Compliance Authority (XCA). Real-time decision infrastructure for GDPR- governed data actions. Violations prevented. Not discovered.

XCA Decision infrastructure · Live
Sync salary data → US analytics tool DENY
Sync salary data → UK storage · Legitimate Interest ALLOW
Sync salary data → US · Legitimate Interest CONDITIONAL
7
GDPR Art. 5 Principles Enforced
72hr
ICO Breach Notification Clock — Started Automatically
28
Pre-Built Compliance Rules
£19.6m+
ICO Fines Issued in 2025
How It Works

Use Case: HR SaaS governance enforced

XCA evaluates sensitive employee-data actions before execution. GDPR violations are prevented before employee data is transferred, processed, or exposed.

01 — TRIGGER
Eployee Data Action Initiated
A UK HR SaaS platform initiates a request to transfer employee performance data to a third-party AI analytics provider in the US.
02 — EVALUATE
XCA Assesses Policy
XCA evaluates the request against lawful basis, jurisdiction rules, processor approval status, transfer safeguards, retention policy, and ICO accountability requirements in real time.
03 — DECIDE
Deterministic Decision
XCA returns an ALLOW, DENY, or CONDITIONAL decision before execution occurs, including governance rationale, policy reference, and audit evidence.
ALLOW DENY CONDITIONAL
04 — RESOLVE
Remediation & Revalidation
Where policy conditions can be resolved, approved remediation workflows execute automatically. XCA then re-evaluates the request before execution proceeds.
DENY
Block

The action is stopped before execution. The data never moves. A complete audit log — timestamp, reason, risk score, GDPR article — is written immediately. The violation never occurred.

ALLOW
Proceed

All conditions are satisfied. The action proceeds. XCA records the decision and the basis for it. Your audit trail is complete — with no manual effort required.

CONDITIONAL
Pending

A lawful basis exists, but a transfer or processing condition must be met first — SCCs for a cross-border move, for example. XCA tells you exactly what is required and in many cases resolves it automatically.

Governance Overreach

Traditional governance tools sit downstream in the data path — reading traffic, inspecting payloads, and logging content to make decisions. Your data passes through their hand. Trust is assumed, not infrastructureered.

How Xelinier Works

XCA infrastructure evaluates intent, not content. Your payload never enters our boundary — by architectural design, not policy promise. We govern whether execution may proceed. We never see what is being executed.

The Broken Status Quo

Data action executes → logs written → audit happens later → violation found → ICO fine issued. By the time anyone knows something went wrong, it is already too late.

The XCA Model

Data action triggered → XCA evaluates → ALLOW or DENY returned → if blocked and fixable, agent resolves → action proceeds or is stopped. Violations prevented, not discovered.

XCA Enforcement Scale

How much control do you have before data moves?

Most systems react after data has already been processed, shared, stored, or transferred. Xelinier XCA moves compliance to the moment before execution.

No XCA Full XCA
100%
Full XCA Authority
7 Principle AI Agents assess every data action before execution. Approved, blocked, remediated, and audit-logged.
7 Principle AI Agents Active Policy Engine Enforced Decision Trail Generated
The XCA Platform

The full compliance register, live

XCA delivers complete GDPR enforcement — not just a score, but the entire register underneath it, visible to your DPO and auditable by the ICO on demand.

Pre-Execution Decision Infrastructure

POST /check-action returns ALLOW, DENY, or CONDITIONAL with confidence score, triggered rules, reason, and remediation steps. Real enforcement — not advisory.

Remediation Agent

When XCA blocks a fixable action, an AI agent executes approved remediation — DPA request emails, compliant infrastructure provisioning, sensitive field redaction. XCA re-validates before proceeding.

Compliance Register

Controller/Processor Register, Breach Response, Training Dashboard, App Inventory, Security Controls, ROPA and Lawful Basis — all live, all linked to the decision infrastructure.

Immutable Audit Log

Every decision ever made — timestamp, outcome, reason, risk score, data type, jurisdiction. Fully exportable. Regulator-ready on demand. No manual trail required.

ICO Report

A live compliance report generated from XCA decision data. Overall score, risk tier, GDPR article violations, top risk decisions, and immediate actions — in the format an auditor needs to see.

Metering & Billing

Every governed invocation metered. Live allowance gauge. Usage-linked pricing — pay for what you evaluate, not a flat fee. Audit-grade billing records automatically generated.

Breach Response

72-hour ICO countdown triggered automatically on confirmed breach. Five-step workflow. Notification tracker for ICO, data subjects, sub-processors, customers and leadership.

Data Subject Rights

Pre-execution enforcement for Arts. 15–22 — SAR, Erasure, Rectification, Portability, Objection, Restriction. Each request has an Art. 12 one-month countdown with colour thresholds.

Compliance Rule Library

28 pre-built rules across all seven Art. 5 principles. Coverage grid, confidence scores, violation counts, and rule toggles. A visual demonstration of ruleset depth and breadth.

Trust & Security

There is no data here to protect

XCA governs by architecture, not policy. It returns a verdict on every data action without ever receiving the underlying data — so the strongest security posture is the one designed in, not bolted on.

Payload-Blind by Design

XCA evaluates on metadata and cryptographic eligibility evidence only. The intent validator physically rejects any field named payload, content, body, data or blob. We cannot see your records because we never receive them — this is architectural, not a promise.

Cross-Border Enforced

XCA does not merely document data residency — it enforces Chapter V at the point of action. Transfers to non-adequate countries return DENY regardless of the Article 6 lawful basis, because a lawful basis is not a transfer mechanism.

Fail-Closed Enforcement

If a rule cannot be evaluated with confidence, XCA does not guess and does not let the action through. The Policy Decision Point defaults to DENY when uncertain — the safe direction for a control plane sitting in the execution path.

Immutable Audit Trail

Every verdict is recorded — timestamp, outcome, reason, triggered rules, jurisdiction — under a system-enforced audit principle that cannot be disabled per tenant. Fully exportable and regulator-ready, with no manual trail to maintain.

Encryption & Isolation

All traffic is protected with TLS in transit. Tenant boundaries are enforced at every request — one customer's configuration and audit records are never reachable by another. Secrets are held outside source control.

AI Handling

The principle agents evaluate metadata and cryptographic eligibility evidence only — they never receive, inspect, or transmit the underlying data payload, enforced by the intent validator rather than by policy. Where a model assists evaluation, it sees the same metadata, never the payload, and no customer data trains any model. In-tenant deployment is available for data-residency-sensitive customers.

Breach Notification

If we become aware of a confirmed personal data breach affecting your organisation, we notify your named contact within 72 hours, with the nature of the incident, records affected, measures taken, and a direct contact for follow-up.

Certifications — In Progress

We are an early-stage company and explicit about it. Today we rely on managed infrastructure providers with their own established security programmes. We are evaluating our own assurance — including ISO/IEC 27001 — as the business scales, and will not present a provider's certification as our own.

Company & Contact

Xelinier is a trading name of Tek480 Ltd, registered in England and Wales, acting as Data Controller for this site. For our DPA, sub-processor list, or a security questionnaire, email contact@xelinier.com — we respond within one business day.

7 PRINCIPLE AI AGENTS ASSESS EVERY DATA ACTION

Scored in real time — not a single number

7 Xelinier propietary AI agents, one per GDPR Article 5 principle — each assessing every data action in real time before it executes.

P1 · Actively Enforced
Lawfulness, Fairness & Transparency
Art. 5(1)(a) · Art. 6 · Art. 7
Lawful Basis Agent
Confirms a valid Article 6 lawful basis (and Article 9 condition for special-category data) before any action executes.
P2 · Configurable
Purpose Limitation
Art. 5(1)(b)
Purpose Agent
Checks the action's declared purpose against the purpose the data was collected for.
P3 · Configurable
Data Minimisation
Art. 5(1)(c) · Art. 25
Minimisation Agent
Verifies only the data categories necessary for the declared purpose are in scope.
P4 · Configurable
Accuracy
Art. 5(1)(d)
Accuracy Agent
Assesses data freshness and validity signals against the accuracy threshold for the action.
P5 · Configurable
Storage Limitation
Art. 5(1)(e)
Retention Agent
Confirms the action sits within the configured retention window for its data category.
P6 · Actively Enforced
Integrity & Confidentiality
Art. 5(1)(f) · Art. 32 · Art. 4(12)
Security Agent
Evaluates destination, transfer route and integrity controls — including cross-border eligibility — before execution.
P7 · Actively Enforced
Accountability
Art. 5(2) · Art. 24 · Art. 30
Accountability Agent
Writes every verdict to the immutable audit trail with the rule references applied.
Live · Every Decision
Seven agents assess each action — every principle has a live score, decision count and risk rating.
Not a single compliance number — the full picture, every principle, every agent, in real time.
Why XCA?

Enforcement — not intention

Most compliance tools are dashboards and checklists. They tell you what went wrong. They don't prevent violations. A car with no seatbelts.

Without Xelinier

  • Compliance relies on human checks and written policies
  • Violations discovered after the fact — in audits or ICO complaints
  • Fines up to 4% of global annual turnover under UK GDPR
  • Enterprise deals stalled by "how do you enforce compliance?" questions
  • DPO time consumed by manual reviews and retrospective audits
  • Every blocked action requires manual follow-up to resolve
  • Certifications show intent. Not enforcement.

With Xelinier XCA

  • Non-compliant actions blocked before execution — automatically
  • Remediable violations resolved by the agent — without human intervention
  • Real-time decision log ready for any regulatory inspection
  • Demonstrable enforcement — not just policies and intentions
  • Answers enterprise procurement's hardest compliance question with a live demo
  • Usage-linked billing — pay for what you evaluate, scale with your customers
  • Structural impossibility of non-compliance — not hope.
Built for GDPR

The right answer for every stakeholder

XCA is designed to answer the hardest questions from your CTO, DPO, and Finance teams — in a single, 20-minute live demo.

Commercial / CTO

Win enterprise deals competitors can't close

Demonstrate real enforcement — not policy documentation
API integration — same effort as connecting a payment gateway
Decision infrastructure and remediation agent live on your actual use cases
Usage-linked pricing — revenue scales with customer activity, not infrastructure
DPO / CISO / Legal

Give your DPO a structural superpower

All seven Art. 5 principles scored in real time — not a single aggregate
Full Controller/Processor Register with live DPA status per system
72-hour ICO breach countdown triggered automatically on confirmed incident
ROPA with all six Art. 6 lawful bases, DPIA status, and LIA tracking
Finance / Procurement

A model that aligns to your growth

Usage-linked — pay per governed invocation, not a flat licence fee
Live allowance gauge with GBP overage shown automatically
Every policy check, agent step, and audit write metered transparently
One avoided ICO fine pays for years of Xelinier
What this means for reseller partners

Add compliance enforcement and autonomous remediation to your existing client offering

Retain clients longer — enforcement plus automated resolution is stickier than features

Win enterprise deals that competitors cannot close without this capability

Simple API integration — no infrastructure to manage

Partner With Us
Pricing

Usage-linked. Transparent. Auditable.

Every governed invocation — every time XCA evaluates a data action — is metered. You pay for what you use, within your tier allowance. The billing record is audit-grade.

Tier 1
250 million
governed invocations / year

Full XCA decision infrastructure
28 pre-built compliance rules
Regulator-ready audit log with CSV export
ICO Report generation
Full Compliance Register (all six pages)
Overage: per additional 50M block
Request Pricing →
Tier 3 · Enterprise
3.5 billion
governed invocations / year

Everything in Tier 2
Dedicated implementation support
Custom rule development
Multi-tenant white-label deployment
SLA-backed uptime commitment
Overage: per additional 50M block
Request Pricing →

30-day sandboxed pilot available — XCA running on your actual use cases, no customer data required.  Contact us to discuss →

ICO Enforcement · 2025–2026

The cost of non-compliance is rising

ICO fines jumped 7× in 2025. In 2026, a single children's data failure cost one platform £14.47 million. These aren't breach cases — they are governance decision failures.

£19.6m
Total ICO fines
collected in 2025
from just 7 enforcement cases
More revenue than
all of 2024
avg. fine rose from £150k → £2.8m
40,000
Data protection
complaints in 2024/25
+ 36,000 breach reports filed
£14.47m
Largest 2026 fine
(Reddit · Feb 2026)
governance failure, not a breach
2025 Enforcement Actions ~£19.6m total · 7 cases
Capita
Security failings leading to a major data breach affecting millions of records. Inadequate MFA and vulnerability management.
Technology · Outsourcing
£14.0m
Advanced Computer Software Group
Inadequate security controls and MFA failures exposing sensitive NHS patient data following a ransomware attack in 2022.
Healthcare Technology · SaaS
£3.07m
23andMe
Security failures exposing UK customer genomic data. Weak access controls enabled a credential-stuffing attack on sensitive health information.
Consumer Genetics · US Company
£2.31m
LastPass UK
Security and access control failures resulting in the exposure of customer password vault data and personal information.
SaaS · Cybersecurity
£1.23m
DPP Law
Data protection failings involving the inadequate handling of sensitive client legal records and personal data.
Legal Services
£60k
2026 Enforcement Actions LIVE Year in progress
Reddit
Failed to implement robust age assurance, lacked lawful basis for processing children's data under 13, and did not conduct a DPIA until January 2025 — years after it was required. Fined 24 February 2026.
Social Platform · Children's Code · DPIA Failure
£14.47m
MediaLab.AI (Imgur)
Processed children's personal data without lawful basis from September 2021 to 2025. Failed age assurance requirements under the Children's Code. Fined 5 February 2026. Imgur subsequently withdrew from the UK market.
Image Hosting · Children's Code · Age Assurance
£247,590
Police Scotland
Serious failures in the handling and disclosure of sensitive personal information, including special category data, in breach of UK GDPR obligations.
Public Sector · Special Category Data
£66,000
South Staffordshire Water
Monetary penalty notice issued in 2026 for cybersecurity and data protection failings following a cyber incident. Final amount subject to confirmation.
Critical Infrastructure · Cybersecurity
Pending
Key Insight · Reddit Case
The £14.47m Reddit fine was not a breach case — it was a governance decision failure. Reddit had no DPIA, no lawful basis, and no age assurance. These are precisely the pre-execution compliance decisions XCA is built to enforce.
Emerging Themes

What is the ICO targeting?

Cybersecurity & MFA
Weak access controls, missing multi-factor authentication, and poor vulnerability management account for the majority of large fines in 2025. The Capita and Advanced Software cases both turned on preventable technical failures.
Children's Privacy & Age Assurance
Reddit and MediaLab were fined in February 2026 within 19 days of each other. Self-declaration of age is no longer considered adequate. Platforms must demonstrate robust, documented age verification mechanisms.
DPIA Failures
Failure to conduct Data Protection Impact Assessments before high-risk processing is a recurring enforcement trigger. Reddit did not complete a DPIA until January 2025 — years late. A completed DPIA can materially reduce fines.
Lawful Basis Validation
Both major 2026 fines centred on the absence of a lawful basis for data processing — not a technical breach. Organisations are being penalised for decisions made long before any data incident occurs.
Data Transfers & Cross-Border
The ICO continues to scrutinise organisations transferring personal data outside the UK without an adequate transfer mechanism. US-based companies holding UK data — including 23andMe — remain a focus area.
HR & Employee Monitoring
ICO guidance reinforces that employee monitoring must be fair, proportionate, and backed by a DPIA and documented lawful basis. AI recruitment tools and workplace surveillance are under increasing scrutiny heading into 2026.
XCA Relevance
Every one of these fines started with a decision someone made before the data moved.

The ICO received approximately 40,000 data protection complaints and 36,000 personal data breach reports during 2024/25 — yet issued only 11 monetary penalties. The real exposure is not in the fines. It is in the thousands of compliance decisions made every day inside HR, IT, and operations teams that no one is evaluating in real time.

XCA assesses those decisions at the moment they are made — before data moves, before a lawful basis is assumed, before a DPIA is skipped. It evaluates, blocks, and in many cases resolves the issue automatically. The Reddit fine was a DPIA governance failure. XCA would have required that assessment before the processing was permitted.

HR Action XCA Decision Point
Enable employee monitoring DPIA required? Lawful basis validated?
Deploy AI recruitment tool ADM rules satisfied? Transparency met?
Share employee data with vendor DPA in place? Article 28 compliant?
Transfer HR data overseas Transfer mechanism confirmed?
Process health / special category data Article 9 condition satisfied?
Retain recruitment records Retention period exceeded?
Sources: ICO.org.uk official enforcement notices · ICO Annual Report 2024/25 · URM Consulting ICO Analysis Jan–Jun 2025 · MeasuredCollective.com ICO 2025 Analysis · Chambers & Partners, Kennedy's Law, Brabners (Reddit/Imgur case analysis, 2026)
Founding Pilot Programme

Validate XCA Against Your Highest-Risk Data Actions

We're inviting up to 5 organisations to participate in the Xelinier Compliance Authority (XCA) Founding Pilot Programme.
Over a 30-day sandbox engagement, we'll work with your team to evaluate real-world compliance scenarios and demonstrate how XCA can identify, block, or condition non-compliant data actions before execution.
No customer data required. Metadata only.

30-day sandboxed pilot

XCA running on your actual scenarios in days, not months. No customer data required — only metadata crosses the boundary. Reproduce the reference verdicts and see ALLOW / DENY / CONDITIONAL enforced live.

Direct line to the founding team

Work alongside the Xelinier XCA team. Integration support measured in hours, not tickets — and a roadmap that responds to what your compliance and engineering leads actually need.

Founding partner terms

Preferential commercial terms locked in for the life of the engagement, priority access to new capabilities, and a reference position as one of the first to enforce GDPR before execution.

Pilot participants receive

Complimentary pilot access
Guided onboarding and configuration
Use-case assessment workshop
Governance and compliance evaluation
Pilot outcome report
Direct access to the Xelinier team

Pilot objectives

During the pilot we work with your team to evaluate:

Compliance enforcement before execution
Policy consistency across systems
Audit evidence generation
Governance visibility and traceability
Reduction of manual compliance processes

Ideal pilot candidates

HR & Workforce Platforms
Cross-border employee data transfers, processor management, and GDPR governance.
SaaS Platforms
Multi-tenant environments, enterprise integrations, and policy enforcement.
AI & Automation Workflows
Governance controls for automated decision-making and data processing.
Regulated Enterprises
Financial services, healthcare, public sector, telecoms, and other compliance-sensitive environments.
Limited availability — 5 organisations

To ensure a high-quality engagement, pilot participation is currently limited to five organisations. Applications are reviewed on use-case suitability and potential impact.

Apply Now →
Frequently Asked Questions

The questions we always answer

We already have a DPO and compliance processes. Why do we need XCA?+

XCA is not a replacement for your DPO — it gives your DPO a superpower. Right now, your DPO is manually reviewing policies after the fact. XCA enforces those policies automatically at the moment data moves. And when something is blockable but fixable, the remediation agent handles it. Your DPO gets to focus on strategy instead of firefighting.

We're GDPR compliant — we have certifications. Isn't that enough?+

Certifications show intent. Xelinier enforces intent demonstrably. There is a real difference between having a policy that says data shouldn't be transferred without lawful basis, and having a system that actually blocks it — and in many cases resolves it automatically. Regulators are increasingly interested in the second. Most companies fined by the ICO already have policies in place.

This sounds complex to integrate. How long does it take?+

It's an API call. Your system sends an action request to XCA — roughly the same integration effort as connecting a payment gateway. We have a sandbox environment you can test in hours, not months. Our 30-day pilot gets XCA running on your actual scenarios with no customer data involved.

Can XCA actually fix the issues it finds, not just flag them?+

Yes — that's the remediation agent. When XCA blocks something fixable — a missing DPA, data in the wrong region, a file with unmasked sensitive fields — the agent executes the approved fix automatically. It generates the vendor email, provisions the right storage, redacts the sensitive fields, then re-submits to XCA for a second evaluation. The agent cannot decide what's compliant — only XCA can do that. Once XCA says what needs fixing, the agent handles execution without human intervention.

What happens if we have a data breach?+

The moment a breach is confirmed, XCA starts a 72-hour countdown to ICO notification automatically — your Article 33 obligation. The Breach Response page runs a five-step workflow: contain, assess, notify the ICO, notify affected data subjects, remediate. Every party requiring notification is tracked in one place. Most organisations handle this in a spreadsheet under pressure. That's how they miss the 72-hour window.

We already have a ROPA. What does XCA add?+

A ROPA is a document. XCA maintains a live register. It shows DPA status per processor in real time — Signed, Expired, or Missing. It flags cross-border transfer mechanisms that are out of date. It surfaces Article 28 violations before the ICO does. The question isn't whether you have a ROPA — it's whether your ROPA tells you right now, today, which of your processors you are exposed on.

How is XCA priced and what counts as an invocation?+

Pricing is usage-linked — you pay per governed invocation, meaning every time XCA evaluates a data action. This includes policy checks, agent remediation steps, re-validations, DPIA evaluations, and audit writes. Overage is charged per additional 50 million block. One avoided ICO fine pays for years of Xelinier.

"Right now, your platform processes data and hopes it's compliant. With Xelinier, it knows — and when it finds a problem, it fixes it."

Two ways to move forward: a 30-day sandboxed pilot on your actual use cases, or a technical walkthrough with your CTO or compliance lead. Which makes more sense for where you are right now?