Skip to main content

ConsentSignals

Your CMP records consent. ConsentSignals verifies enforcement.

Run real Accept, Reject, Withdraw and GPC journeys. See which tags, domains and storage items remain active. Produce independently verifiable evidence for every finding and fix.

Not a CMP. Not a policy generator. Consent regression testing — URL to signed PDF in typically 5–12 minutes

8-session consent matrix · Evidence timeline · HMAC PDF · CI gate

Start here

Scan a URL you control

Enter your domain (e.g. yourcompany.com) — or use a Try link below

For agencies and advisors: retain written client authorisation. Anonymous scans are limited to properties you operate; major third-party platforms require sign-in.

One region per scan. CMP banners and tracker sets often differ by jurisdiction. Re-scan other geos if your users are not only here. A/B tests and server-side CAPI are still outside this browser.

Try a live demo

1 free scan per day without sign-up — preview scores and counts only. Full tracker evidence, plain-language report, and signed PDF require Starter or above. Outputs are technical indicators for human review — not a compliance certification or legal advice.

Built for teams that must prove it

Agencies, DPOs, and operators — not drive-by scanners or parental-control apps.

CMPs collect consent. We prove it on the wire.

OneTrust, Cookiebot, Didomi, and Usercentrics run your banner and vendor lists. They rarely prove — at the network layer — whether Reject All stops trackers, whether analytics-only still fires ads, whether GTM fires before the CMP signal, or whether new tags slipped in after your last cookie scan.

Consent on paper ≠ consent in the browser

Vendor lists and CMP dashboards describe what should happen. Our 8-session consent matrix measures which third-party domains fire under each major consent choice — including Essential-only and Analytics-only.

Consent Mode can look fine in GTM and still fail on the wire

After Google’s Ads gate change, Reject must update Consent Mode in the browser. We score enforcement from observed defaults, updates, and network signals — not from the CMP admin UI alone.

Evidence for DPOs and boards is slow to assemble

Consultants and certification programmes take weeks. You need timestamped, tamper-evident audit artefacts you can hand to counsel — without asserting legal verdicts about third parties.

Your CMP manages consent. We verify it actually works.

Use your CMP for banners. Use ConsentSignals for independent Accept / Reject / Consent Mode evidence.

Vendor list ≠ measured behaviour

CMP dashboards show configured categories. We run a 8-session consent matrix (Accept All, Reject / Disagree All, Essential-only, Analytics-only, Withdraw marketing (Accept then revoke), GPC/DNT signal, Returning user (Reject cookies), and a passive baseline) and record which third-party domains actually fire — the test regulators use.

Consent Mode on the wire

After Google’s 15 June 2026 change, we verify whether Reject/GPC updates Consent Mode v2 (ad_storage and friends) and whether TCF 2.3 disclosedVendors is present — not just the banner UI.

Granular choices are tested, not assumed

Many sites leak trackers on Reject or when users save Essential-only or Analytics-only preferences. We flag reject-persistent, consent-dependent, granular-leaky, and marketing-leaky domains per session.

Drift after you ship

A new marketing tag or plugin update can undo months of CMP work. Scheduled scans and drift alerts catch regressions before a complaint does.

Honest limits

  • ×We are not a CMP — we do not install banners, store consent records, or host vendor lists
  • ×Server-side / CAPI tracking invisible to browser sessions (we may hint; we do not replace CAPI)
  • ×Geo-gated CMP banners and tag sets — each scan uses one region profile
  • ×A/B or multivariate experiments — headless Chromium typically sees one variant
  • ×Shadow pixels inside widgets the CMP authorised
  • ×Every possible per-category toggle a human might choose (we approximate Essential-only, Analytics-only, and post-Accept withdrawal)
  • ×CMP consent-log timestamps without a read-only API or export upload
  • ×DSAR / subject-access portals, EUDI wallet relying-party flows, or consumer parental-control apps
  • ×Legal verdicts — evidence for your DPO and counsel only

Evidence, not guesswork

01

Consent-differential audit

8 isolated browser sessions — Accept All, Reject / Disagree All, Essential-only, Analytics-only, Withdraw marketing (Accept then revoke), GPC/DNT signal, Returning user (Reject cookies), and a passive baseline — with measured domain labels and a CMP effectiveness verdict.

02

Consent Mode on the wire

Prove CMP choices update Consent Mode v2 and TCF 2.3. Labels Basic vs Advanced so cookieless Google pings are not mistaken for CMP failure.

03

Signed audit report

HMAC-SHA-256 tamper-evident PDF for board packs, DPO records, and independent verification.

04

Continuous assurance (Pro)

Agent + scheduled re-scans for properties you control. Drift alerts after deploy — not a legal SLA.

What we do

  • Runs a 8-session consent matrix to show pre-consent and granular consent behaviour
  • Checks Consent Mode Enforcement — Google Consent Mode v2 + TCF 2.3 on the wire
  • Produces tamper-evident PDF reports for DPO and board review
  • Continuous assurance on your own sites when you install our agent (Pro+)
  • Optional kids / accessibility modules when that vertical applies

What we do not

  • ×Issue legal verdicts, certifications, or compliance guarantees
  • ×Act as a Consent Management Platform (we do not install banners)
  • ×Run DSAR portals, CAPI pipelines, EUDI wallets, or consumer parental apps
  • ×Scan sites you do not own without written permission
  • ×Replace qualified legal counsel

Automated technical indicators for human review — not legal advice. Have counsel review findings before regulatory decisions.

Extra modules — clearly labelled

Core scans already cover consent verification and Consent Mode. These stay optional.

HEAA & age assurance (UK)

Beta

Beta signals for Highly Effective Age Assurance readiness — vendor references, self-declaration patterns, and bypass risks. Ahead of 2027 UK platform duties.

EU digital wallet & eID

Beta

Beta detection of Ireland gov.ie wallet, EUDI / eIDAS 2, and verifiable-credential language — readiness for digital-ID pilots, not certified age verification.

EAA accessibility audit

Beta

Beta WCAG 2.1 AA scan with EAA article mapping and signed remediation roadmap — for EU retail and services facing accessibility enforcement.

Open →

All beta modules · Which rules apply? · Need a human fix?

Independent evidence surfaces: verify a signed PDF · Consent Reality Index · methodology