Consent-differential audit
Each scan runs an 8-session consent matrix: Accept All, Reject / Disagree All, Essential-only, Analytics-only, Withdraw marketing (Accept then revoke), GPC/DNT signal, Returning user (Reject cookies), and a passive baseline. We compare which third-party domains and cookies are active in each isolated session. Trackers in both Accept and Reject may run before or regardless of consent; trackers on Essential-only or Analytics-only when they should not are flagged as granular-leaky or marketing-leaky. Multi-session consent-differential audit (Method I): set arithmetic across Accept, Reject, Essential-only, Analytics-only, Withdrawal, GPC, Returning-user, and passive recordings.
CMP effectiveness
After all consent sessions we classify each third-party domain and produce a measured effectiveness summary (effective, partial, ineffective, or no CMP). This is independent of your OneTrust/Cookiebot/Didomi dashboard — we observe network requests and cookies, not vendor configuration.
Consent Mode Enforcement
Where Google tags are present, we capture Consent Mode / dataLayer state and network gcs/gcd signals, including Basic vs Advanced Mode nuance and GTM Consent Initialization race risks. Verdicts (enforced, miswired, banner_only, absent, review) are technical indicators — not a Google certification or legal finding.
Audience classification
We combine readability, visual design signals, colour patterns, and COPPA-style statutory factors into an estimated child-appeal score. This is a regulatory audit signal for site operators — not a parental content-rating or “safe for children” score.
Regulatory mapping
Findings are matched to our Regulatory Knowledge Base (RKB). Citations indicate possible relevance for your compliance team — they are not violations, fines, or legal advice.