Your CMP records consent. ConsentSignals verifies enforcement.
Run real Accept, Reject, Withdraw and GPC journeys. See which tags, domains and storage items remain active. Produce independently verifiable evidence for every finding and fix.
Not a CMP. Not a policy generator. Consent regression testing — URL to signed PDF in typically 5–12 minutes
8-session consent matrix · Evidence timeline · HMAC PDF · CI gate
consentsignals.com/scan — yourcompany.com
Loading page in isolated browser…
Initialising matrix…
Start here
Scan a URL you control
1 free scan per day without sign-up — preview scores and counts only. Full tracker evidence, plain-language report, and signed PDF require Starter or above. Outputs are technical indicators for human review — not a compliance certification or legal advice.
01Who it is for
Built for teams that must prove it
Agencies, DPOs, and operators — not drive-by scanners or parental-control apps.
OneTrust, Cookiebot, Didomi, and Usercentrics run your banner and vendor lists. They rarely prove — at the network layer — whether Reject All stops trackers, whether analytics-only still fires ads, whether GTM fires before the CMP signal, or whether new tags slipped in after your last cookie scan.
Consent on paper ≠ consent in the browser
Vendor lists and CMP dashboards describe what should happen. Our 8-session consent matrix measures which third-party domains fire under each major consent choice — including Essential-only and Analytics-only.
Consent Mode can look fine in GTM and still fail on the wire
After Google’s Ads gate change, Reject must update Consent Mode in the browser. We score enforcement from observed defaults, updates, and network signals — not from the CMP admin UI alone.
Evidence for DPOs and boards is slow to assemble
Consultants and certification programmes take weeks. You need timestamped, tamper-evident audit artefacts you can hand to counsel — without asserting legal verdicts about third parties.
03Verification
Your CMP manages consent. We verify it actually works.
Use your CMP for banners. Use ConsentSignals for independent Accept / Reject / Consent Mode evidence.
Vendor list ≠ measured behaviour
CMP dashboards show configured categories. We run a 8-session consent matrix (Accept All, Reject / Disagree All, Essential-only, Analytics-only, Withdraw marketing (Accept then revoke), GPC/DNT signal, Returning user (Reject cookies), and a passive baseline) and record which third-party domains actually fire — the test regulators use.
Consent Mode on the wire
After Google’s 15 June 2026 change, we verify whether Reject/GPC updates Consent Mode v2 (ad_storage and friends) and whether TCF 2.3 disclosedVendors is present — not just the banner UI.
Granular choices are tested, not assumed
Many sites leak trackers on Reject or when users save Essential-only or Analytics-only preferences. We flag reject-persistent, consent-dependent, granular-leaky, and marketing-leaky domains per session.
Drift after you ship
A new marketing tag or plugin update can undo months of CMP work. Scheduled scans and drift alerts catch regressions before a complaint does.
Honest limits
×We are not a CMP — we do not install banners, store consent records, or host vendor lists
×Server-side / CAPI tracking invisible to browser sessions (we may hint; we do not replace CAPI)
×Geo-gated CMP banners and tag sets — each scan uses one region profile
×A/B or multivariate experiments — headless Chromium typically sees one variant
×Shadow pixels inside widgets the CMP authorised
×Every possible per-category toggle a human might choose (we approximate Essential-only, Analytics-only, and post-Accept withdrawal)
×CMP consent-log timestamps without a read-only API or export upload
×Legal verdicts — evidence for your DPO and counsel only
04What you get
Evidence, not guesswork
01
Consent-differential audit
8 isolated browser sessions — Accept All, Reject / Disagree All, Essential-only, Analytics-only, Withdraw marketing (Accept then revoke), GPC/DNT signal, Returning user (Reject cookies), and a passive baseline — with measured domain labels and a CMP effectiveness verdict.
02
Consent Mode on the wire
Prove CMP choices update Consent Mode v2 and TCF 2.3. Labels Basic vs Advanced so cookieless Google pings are not mistaken for CMP failure.
03
Signed audit report
HMAC-SHA-256 tamper-evident PDF for board packs, DPO records, and independent verification.
04
Continuous assurance (Pro)
Agent + scheduled re-scans for properties you control. Drift alerts after deploy — not a legal SLA.
05Scope
What we do
—Runs a 8-session consent matrix to show pre-consent and granular consent behaviour
—Checks Consent Mode Enforcement — Google Consent Mode v2 + TCF 2.3 on the wire
—Produces tamper-evident PDF reports for DPO and board review
—Continuous assurance on your own sites when you install our agent (Pro+)
—Optional kids / accessibility modules when that vertical applies
What we do not
×Issue legal verdicts, certifications, or compliance guarantees
×Act as a Consent Management Platform (we do not install banners)
×Scan sites you do not own without written permission
×Replace qualified legal counsel
Automated technical indicators for human review — not legal advice. Have counsel review findings before regulatory decisions.
06Also available
Extra modules — clearly labelled
Core scans already cover consent verification and Consent Mode. These stay optional.
HEAA & age assurance (UK)
Beta
Beta signals for Highly Effective Age Assurance readiness — vendor references, self-declaration patterns, and bypass risks. Ahead of 2027 UK platform duties.
EU digital wallet & eID
Beta
Beta detection of Ireland gov.ie wallet, EUDI / eIDAS 2, and verifiable-credential language — readiness for digital-ID pilots, not certified age verification.