The Product

Four products. One mechanism. Built for CIPA, not translated from GDPR.

The scan finds exposure. The banner and blocker stop it. The report proves it. Each piece is honest about its limits — and the last section says exactly where those limits are.

§4 — The Mechanism

Block. Observe. Prove.

§01 — The Crawler, as a Product

Not a scanner. A crawler that visits twice.

The CIPA Exposure Scan isn't a match against a vendor list. It's a real browser that loads your site two times — once refusing consent, once granting it — and measures the difference. Observation, not a catalog.

Pass A — consent refused

Everything that fires anyway

What a real visitor loads before clicking anything. Whatever transmits here is your exposure.

Pass B — consent granted

Everything that was being held

Trackers that appear only in this pass were provably gated in the first one. The difference between the two is the evidence.

Two-pass crawl

One visit refuses consent, one grants it. The diff is your exposure — measured, not guessed.

Observation, not signatures

It watches what actually loads. Finds vendors no catalog knows about.

Page-by-page

Not just the homepage. Free scans cover 5 pages; paid plans crawl your full site.

Scheduled re-crawls

Daily or weekly. When a new tracker sneaks in, you're told before a plaintiff is.

Tamper-evident digest

Every crawl is hashed and timestamped. One report digest held 56,926 rows.

Shareable, ungated

A public read-only URL anyone can open — no login, no email gate.

§02 — Defense-Ready Documentation · Agency+

A report a lawyer can hand to a judge.

Every scan produces a defense-ready report — chronological, tamper-evident, and mapped to CIPA categories. It proves what was there, what you blocked, and when. The record speaks before you have to.

Included on Agency & Scale plans
report.digestsha256:a9f1…7c04
2026-07-21 03:00 UTCCrawl #1,1849 trackers → 0
2026-07-21 03:00 UTCBlock verifiedHotjar held ✓
2026-07-21 03:01 UTCCategory map§6387 session rec.
2026-07-20 03:00 UTCCrawl #1,1839 trackers → 0

56,926 rows · append-only · signed

Tamper-evident

Each digest is hashed and timestamped. Append-only — nothing is ever rewritten.

CIPA category mapping

Every tracker labeled to its alleged CIPA category — session recording, pixel, chat widget.

Before / after proof

Shows what was blocked and what slipped, per page, per tracker, per crawl.

Shareable read-only URL

Ungated — opposing counsel, a client, or a judge can open it with no login.

White-label (Agency+)

Your logo, your domain. Your clients never see our name if you don't want them to.

PDF for the record

Export a timestamped PDF snapshot. For the file, not just the dashboard.

§5 — The Honesty Section

Here's exactly what we can and can't block.

Blocking isn't purely a property of a consent tool. It's a property of where the website platform lets that tool's script run — and, on WordPress, of how each plugin chooses to emit its tag. Any vendor who tells you they block everything, everywhere, is describing a product that doesn't exist.

Where the tracker livesExampleConsentinelAnyone else
Custom code / JS-injectedSession recorders, Meta Pixel via custom codeBlockedOnly if they load first
Platform-native marketing tagsWix Marketing Integrations, GA4Consent signals + cookie suppressionNobody. Not Wix, not CookieYes.
Tags another plugin enqueueswp_enqueue_script, id="handle-js"Blocked server-side on WordPress, before the page is sentClient-side tools can't reach these
Tags a plugin prints directlyBeehive's gtag loader, echoed into wp_headBlocked server-side — with output-buffer gating switched onClient-side tools can't reach these
Injected at the CDN edgeCloudflare /cdn-cgi/, Rocket LoaderNot blockable — we detect and report itNobody. It lands after the server finishes.

"We'd rather tell you the ceiling than sell you past it. When something is outside what any client-side tool can stop, we detect it, we tell you, and we document it."

Read the full breakdown →