Code you or your developer added
Screen recorders, a Meta Pixel pasted into custom code
Consentinel
Stopped before it runsAnyone else
Only if their code loads firstThe product
Consentinel combines Enforcement, Verification, Documentation, and Actionable Exposure Management. The consent tool blocks what it can control and identifies where website administrators must act when the remaining risk originates elsewhere – CIPA, CCPA, CPRA, GDPR, FSCA...
How it works
Three things, in order:
01. Hold the trackers we can see | 02. Watch what happens | 03. Keep a Record you can hand to someone.
The Scan
Most GDPR & EU privacy consent tools check your site against a list of tracking companies they already know about. While Consentinel does maintain a list, we actively crawl your site in a real browser two times — Once refusing cookies, Once accepting them.
Our system then compares the two visits and identifies trackers that were blocked on the first visit, then allowed on the second after consent was given. Consentinel's double-scan is why we can discover trackers no other consent tool has heard of, and Exposes them to you.
A real browser
Chromium, fresh profile, every request recorded.
IllustrationSame pages, same browser, twice. Red marks the visit with no consent cookie; green the visit with one.
Visit one — cookies refused
Discover Trackers that Fire Regardless of Consent
What a real visitor gets before they click anything. Any trackers that load here is your exposure.
www.google-analytics.com/g/collect?v=2&tid=G-…
Google Analytics 4·Analytics
connect.facebook.net/en_US/fbevents.js
Meta Pixel·Marketing
www.clarity.ms/tag/t8j5…
Microsoft Clarity·Analytics
www.googletagmanager.com/gtm.js?id=GTM-…
Google Tag Manager·Marketing
fonts.googleapis.com/css2?family=Inter
Google Fonts·Functional
IllustrationReal trackers, documented endpoints, sample site.
Visit two — cookies accepted
Identify Trackers that Fire Only After Consent is Given
Trackers that only appear after consent was given were genuinely being held the first time. The difference between the two visits is your exposure.
consentinel_v1
{analytics:1, marketing:1, …}
_ga = GA1.1.1853…
Google Analytics 4
_ga_J02DJ… = GS2.1.s175…
Google Analytics 4
_fbp = fb.1.1758…
Meta Pixel
_clck = 1k9x2q|2|…
Microsoft Clarity
_clsk = 1dq0lm|17…
Microsoft Clarity
IllustrationReal cookie names, shortened values, sample site.
One refuses, one accepts. The difference is your exposure, measured rather than guessed.
It sees what actually loads. Trackers we don't recognize go into a list marked “unknown companies we saw” rather than being quietly dropped.
100 pages per domain on Free, 600 on Pro and Agency, 4,000 on Scale — per crawl. Deep enough to find what a homepage check never will.
A full check runs after you've proved the domain is yours by adding a short line of text to your domain settings. That's permanent. It's why nobody can point us at your site, and why we can't be pointed at anyone else's.
Monthly on Free, weekly on every paid plan. When a new tracker turns up on a site you look after, you hear about it on a schedule instead of in a letter.
What a check found on a given day stays what it found. Nobody can edit it afterwards, including us.
If we check after you've told us to block something and it's still running, we tell you. We don't quietly mark it green.
The Privacy Defense Report — Pro, Agency and Scale Plans
If someone ever asks what your website was doing on a particular day, this is the document that answers. It's generated on demand, it covers one scan, and it's put together so nobody can change it afterwards.
The Privacy Defense Report is an integrity-protected technical snapshot of conditions observed during a scan, intended to support compliance review, remediation, and counsel's evaluation. It is not a legal opinion, proof of compliance, or a guarantee of admissibility or litigation outcome.
First visit, before any interaction

Pre-consent transmissions
Cookie attribution
Banner configuration history
56,926 rows · cannot be edited
Every observation is fingerprinted into a single code that can be re-checked at any time, over a history nothing rewrites. One report covered 56,926 observations. There is no official timestamp and no digital signature, and we don't pretend otherwise.
Most scanners treat “this cookie exists” as “the website put it there.” Those aren't the same thing, and a demand letter that dumps a raw cookie list is counting on the confusion. We show who caused each one.
Screen recording, ad pixel, chat widget.
What was held, what got through, on which page, on which check.
Your logo and your company on the report. Your clients don't have to see ours.
The report prints cleanly from your browser as a PDF. There's no separately generated, officially timestamped file, and we don't claim one.
Written inside the report itself. It shows the file hasn't changed since we made it. It is not a signature and not a seal, and we don't call it one.
Trackers we Can Block and Trackers we Expose
Whether a tracker can be blocked is not really about the consent tool. It is about where your website platform lets that tool's code run — and, on WordPress, how each plugin chooses to add its tag. Any vendor telling you they block everything, everywhere, is describing a product that does not exist.
Caveats to Keep in Mind –– Consentinel blocks what it can control and makes external exposure actionable when blocking is not technically possible.
Examples:
• Google Fonts loaded by a style file rather than by the page itself runs before consent on every platform.
• Server-to-server tracking, such as Facebook Conversions API or server-side tag managers, does not touch the browser, so no browser-based tool can directly detect or block it.
→ Consentinel identifies where these exposures appear, explains the risk, and shows administrators where to act.
Scan · deep crawl
yoursite.com
174
Pages analyzed
7
Pre-consent trackers
7
Pre-consent cookies
8
Unrecognized hosts
Pre-consent tracker traffic
Google Fonts (CDN) Google
Contacted before consent
Observed arriving as a stylesheet. The browser's CSS pipeline fetches it, and no client-side consent tool can intercept that — so as of the last crawl this tracker was not blocked before consent on this site. Blocking it requires a server-side change on this site; there is no browser-side way to stop it.
3 of 87 pages
yoursite.com/
yoursite.com/services/
yoursite.com/contact/
Cloudflare Web Analytics Cloudflare
Injected by your CDN's edge — Consentinel cannot intercept it
Bunny Fonts BunnyWay
Contacted before consent
Observed arriving as a stylesheet. The browser's CSS pipeline fetches it, and no client-side consent tool can intercept that — so as of the last crawl this tracker was not blocked before consent on this site. Blocking it requires a server-side change on this site; there is no browser-side way to stop it.
YouTube Embeds Google
Contacted before consent
IllustrationReal trackers, sample counts. The amber note is the product's own wording.
Screen recorders, a Meta Pixel pasted into custom code
Consentinel
Stopped before it runsAnyone else
Only if their code loads firstWix Marketing Integrations, Google Analytics
Consentinel
We send the consent signal and clear the cookiesAnyone else
Nobody. Not Wix, not CookieYes.Anything a plugin registers with WordPress itself
Consentinel
Removed on the server, before the page is sentAnyone else
Browser-based tools can't reach theseWordPress Custom code plugins like Google tag, printed into the page head
Consentinel
Removed on the Server — With one extra setting switched on, which is off when you installAnyone else
Browser-based tools can't reach theseCloudflare's own Analytics, Rocket Loader
Consentinel
Cannot be Stopped — We identify where it appears, explain the exposure, and show your administrator where to actAnyone else
Nobody. It goes in after your server has finished.A font pulled in by a plugin's own stylesheet
Consentinel
Can't be stopped by anyone — including when you've set it to Always block. We identify where it appears, explain the exposure, and show your administrator where to act.Anyone else
Nobody. Browsers fetch these by a route no code can reach.Facebook's Conversions API, server-side tag managers
Consentinel
Invisible to us, and to every browser-based tool. We say so rather than leave it out.Anyone else
Nobody can see it from the browser.What Consentinel cannot automatically block from inside your page, you can often remove at its source — Host the font yourself, Switch the script off at your CDN, Scope down the server-side tracking you set up. You just have to know it is there. Our platform scan tell you which scropts are running, on which pages, and when we saw them. What you do about each one is your call — but at least it is a call you get to make.
We would rather tell you where we cannot reach than sell you past it. Ask any other consent tool for documentation like this one.
Read the full breakdown →