The product

CIPA Wire Tapping-focused Compliance, with Actionable Exposure Management.

Consentinel combines Enforcement, Verification, Documentation, and Actionable Exposure Management. The consent tool blocks what it can control and identifies where website administrators must act when the remaining risk originates elsewhere – CIPA, CCPA, CPRA, GDPR, FSCA...

How it works

Hold. Watch. Record.

Three things, in order:
01. Hold the trackers we can see | 02. Watch what happens | 03. Keep a Record you can hand to someone.

  1. 01Page requestedThe browser asks your server for the page.
  2. 02Consentinel loadsOur script runs before the trackers it controls.
  3. 03Trackers heldHeld scripts cannot set cookies or send data.
  4. 04Visitor choosesAccept all, reject all, or pick categories.
  5. 05Approved trackers releasedOnly what the visitor agreed to runs.

The Scan

Not a Checklist. A Real Browser Crawler, that Visits Twice.

Most GDPR & EU privacy consent tools check your site against a list of tracking companies they already know about. While Consentinel does maintain a list, we actively crawl your site in a real browser two times — Once refusing cookies, Once accepting them.

Our system then compares the two visits and identifies trackers that were blocked on the first visit, then allowed on the second after consent was given. Consentinel's double-scan is why we can discover trackers no other consent tool has heard of, and Exposes them to you.

https://

The instant check reads your homepage as your server sends it. One page, no account, no browser needed. The deeper check — a real browser visiting up to 100 of your pages twice, once saying no to cookies and once saying yes — runs with a free account, once you've confirmed the domain is yours.

Visit one · cookies refusedVisit two · cookies accepted
Crawler

A real browser

Chromium, fresh profile, every request recorded.

yoursite.com
  • /
  • /services/
  • /about/
  • /contact/
  • /blog/
  • /checkout/

IllustrationSame pages, same browser, twice. Red marks the visit with no consent cookie; green the visit with one.

Visit one — cookies refused

Discover Trackers that Fire Regardless of Consent

What a real visitor gets before they click anything. Any trackers that load here is your exposure.

Network · consent cookie: absent
RequestBefore consent

www.google-analytics.com/g/collect?v=2&tid=G-…

Google Analytics 4·Analytics

Fired

connect.facebook.net/en_US/fbevents.js

Meta Pixel·Marketing

Fired

www.clarity.ms/tag/t8j5…

Microsoft Clarity·Analytics

Fired

www.googletagmanager.com/gtm.js?id=GTM-…

Google Tag Manager·Marketing

Fired

fonts.googleapis.com/css2?family=Inter

Google Fonts·Functional

Fired
5 requests to 3 companies before any click. This is the exposure.

IllustrationReal trackers, documented endpoints, sample site.

Visit two — cookies accepted

Identify Trackers that Fire Only After Consent is Given

Trackers that only appear after consent was given were genuinely being held the first time. The difference between the two visits is your exposure.

Application · Cookies · consent cookie: present
CookieVisit oneVisit two

consentinel_v1

{analytics:1, marketing:1, …}

—set

_ga = GA1.1.1853…

Google Analytics 4

—set

_ga_J02DJ… = GS2.1.s175…

Google Analytics 4

—set

_fbp = fb.1.1758…

Meta Pixel

—set

_clck = 1k9x2q|2|…

Microsoft Clarity

—set

_clsk = 1dq0lm|17…

Microsoft Clarity

—set
5 cookies appear only after consent. They were held the first time.

IllustrationReal cookie names, shortened values, sample site.

Two visits, every time

One refuses, one accepts. The difference is your exposure, measured rather than guessed.

We watch, we don't check a list

It sees what actually loads. Trackers we don't recognize go into a list marked “unknown companies we saw” rather than being quietly dropped.

How deep we look depends on your plan

100 pages per domain on Free, 600 on Pro and Agency, 4,000 on Scale — per crawl. Deep enough to find what a homepage check never will.

Only sites you own

A full check runs after you've proved the domain is yours by adding a short line of text to your domain settings. That's permanent. It's why nobody can point us at your site, and why we can't be pointed at anyone else's.

Checked on a schedule

Monthly on Free, weekly on every paid plan. When a new tracker turns up on a site you look after, you hear about it on a schedule instead of in a letter.

The record can't be rewritten

What a check found on a given day stays what it found. Nobody can edit it afterwards, including us.

If a block fails, we say so

If we check after you've told us to block something and it's still running, we tell you. We don't quietly mark it green.

The Privacy Defense Report — Pro, Agency and Scale Plans

A Dated Record of What Your Site Actually Did.

If someone ever asks what your website was doing on a particular day, this is the document that answers. It's generated on demand, it covers one scan, and it's put together so nobody can change it afterwards.

The Privacy Defense Report is an integrity-protected technical snapshot of conditions observed during a scan, intended to support compliance review, remediation, and counsel's evaluation. It is not a legal opinion, proof of compliance, or a guarantee of admissibility or litigation outcome.

What's in the Report:

  • The cookie banner exactly as your visitors saw it.
  • Everything that was sent before anyone agreed.
  • The trackers that were held.
  • A list of identified trackers Consentinel did not recognize.
  • Which tracker caused which cookie — not just that the cookie existed.
  • Your consent statistics.
  • And the full history of your settings. In date order, and locked once written.
Included in the Pro, Agency and Scale Plans
report.digestsha256:a9f1…7c04
Sample rowsillustration, not a measurement

First visit, before any interaction

The report's opening page: a screenshot of the site as a first-time visitor saw it, with the consent banner in place

Pre-consent transmissions

2026-07-21 03:00 UTCCheck #1,184Held until consent
2026-07-21 03:00 UTCScreen recorderHeld ✓
2026-07-20 03:00 UTCCheck #1,183Held until consent

Cookie attribution

_gaset by script · .yoursite.comga4
_fbpset by script · .yoursite.commeta-pixel
__cf_bmset by Set-Cookie header · .yoursite.comcloudflare-bot

Banner configuration history

v29published 2026-08-09locked
v28published 2026-07-27locked
v22published 2026-07-21locked

56,926 rows · cannot be edited

Nobody can change it later

Every observation is fingerprinted into a single code that can be re-checked at any time, over a history nothing rewrites. One report covered 56,926 observations. There is no official timestamp and no digital signature, and we don't pretend otherwise.

Which tracker caused which cookie

Most scanners treat “this cookie exists” as “the website put it there.” Those aren't the same thing, and a demand letter that dumps a raw cookie list is counting on the confusion. We show who caused each one.

Each tracker sorted by the kind of claim it attracts

Screen recording, ad pixel, chat widget.

Before and after, page by page

What was held, what got through, on which page, on which check.

Your name on it (Agency)

Your logo and your company on the report. Your clients don't have to see ours.

Print it for the file

The report prints cleanly from your browser as a PDF. There's no separately generated, officially timestamped file, and we don't claim one.

What the fingerprint does and doesn't prove

Written inside the report itself. It shows the file hasn't changed since we made it. It is not a signature and not a seal, and we don't call it one.

Trackers we Can Block and Trackers we Expose

Every Consent Tool has a Point Where it Stops Working.
We are the Only One that Publishes Ours.

Whether a tracker can be blocked is not really about the consent tool. It is about where your website platform lets that tool's code run — and, on WordPress, how each plugin chooses to add its tag. Any vendor telling you they block everything, everywhere, is describing a product that does not exist.

Caveats to Keep in Mind –– Consentinel blocks what it can control and makes external exposure actionable when blocking is not technically possible.
Examples:
• Google Fonts loaded by a style file rather than by the page itself runs before consent on every platform.
• Server-to-server tracking, such as Facebook Conversions API or server-side tag managers, does not touch the browser, so no browser-based tool can directly detect or block it.

→ Consentinel identifies where these exposures appear, explains the risk, and shows administrators where to act.

Scan · deep crawl

yoursite.com

Exposed

174

Pages analyzed

7

Pre-consent trackers

7

Pre-consent cookies

8

Unrecognized hosts

Pre-consent tracker traffic

Google Fonts (CDN) Google

Contacted before consent

Functional11787
▶Where it fired

Observed arriving as a stylesheet. The browser's CSS pipeline fetches it, and no client-side consent tool can intercept that — so as of the last crawl this tracker was not blocked before consent on this site. Blocking it requires a server-side change on this site; there is no browser-side way to stop it.

3 of 87 pages

yoursite.com/

yoursite.com/services/

yoursite.com/contact/

Cloudflare Web Analytics Cloudflare

Injected by your CDN's edge — Consentinel cannot intercept it

Analytics8888

Bunny Fonts BunnyWay

Contacted before consent

Functional51
▶Where it fired

Observed arriving as a stylesheet. The browser's CSS pipeline fetches it, and no client-side consent tool can intercept that — so as of the last crawl this tracker was not blocked before consent on this site. Blocking it requires a server-side change on this site; there is no browser-side way to stop it.

YouTube Embeds Google

Contacted before consent

Marketing31

IllustrationReal trackers, sample counts. The amber note is the product's own wording.

Code you or your developer added

Screen recorders, a Meta Pixel pasted into custom code

We stop it

Consentinel

Stopped before it runs

Anyone else

Only if their code loads first

Tags your website builder adds itself

Wix Marketing Integrations, Google Analytics

Signals only

Consentinel

We send the consent signal and clear the cookies

Anyone else

Nobody. Not Wix, not CookieYes.

Tags another plugin adds the normal way

Anything a plugin registers with WordPress itself

We stop it

Consentinel

Removed on the server, before the page is sent

Anyone else

Browser-based tools can't reach these

Tags a plugin writes straight into the page

WordPress Custom code plugins like Google tag, printed into the page head

We stop it

Consentinel

Removed on the Server — With one extra setting switched on, which is off when you install

Anyone else

Browser-based tools can't reach these

Added by your hosting company

Cloudflare's own Analytics, Rocket Loader

Nobody can

Consentinel

Cannot be Stopped — We identify where it appears, explain the exposure, and show your administrator where to act

Anyone else

Nobody. It goes in after your server has finished.

A font loaded by a style file

A font pulled in by a plugin's own stylesheet

Nobody can

Consentinel

Can't be stopped by anyone — including when you've set it to Always block. We identify where it appears, explain the exposure, and show your administrator where to act.

Anyone else

Nobody. Browsers fetch these by a route no code can reach.

Tracking that happens server-to-server

Facebook's Conversions API, server-side tag managers

Nobody can

Consentinel

Invisible to us, and to every browser-based tool. We say so rather than leave it out.

Anyone else

Nobody can see it from the browser.

A Limit is Something You Can Act On

What Consentinel cannot automatically block from inside your page, you can often remove at its source — Host the font yourself, Switch the script off at your CDN, Scope down the server-side tracking you set up. You just have to know it is there. Our platform scan tell you which scropts are running, on which pages, and when we saw them. What you do about each one is your call — but at least it is a call you get to make.

We would rather tell you where we cannot reach than sell you past it. Ask any other consent tool for documentation like this one.

Read the full breakdown →