The Product
Four products. One mechanism. Built for CIPA, not translated from GDPR.
The scan finds exposure. The banner and blocker stop it. The report proves it. Each piece is honest about its limits — and the last section says exactly where those limits are.
§4 — The Mechanism
Block. Observe. Prove.
§01 — The Crawler, as a Product
Not a scanner. A crawler that visits twice.
The CIPA Exposure Scan isn't a match against a vendor list. It's a real browser that loads your site two times — once refusing consent, once granting it — and measures the difference. Observation, not a catalog.
Pass A — consent refused
Everything that fires anyway
What a real visitor loads before clicking anything. Whatever transmits here is your exposure.
Pass B — consent granted
Everything that was being held
Trackers that appear only in this pass were provably gated in the first one. The difference between the two is the evidence.
Two-pass crawl
One visit refuses consent, one grants it. The diff is your exposure — measured, not guessed.
Observation, not signatures
It watches what actually loads. Finds vendors no catalog knows about.
Page-by-page
Not just the homepage. Free scans cover 5 pages; paid plans crawl your full site.
Scheduled re-crawls
Daily or weekly. When a new tracker sneaks in, you're told before a plaintiff is.
Tamper-evident digest
Every crawl is hashed and timestamped. One report digest held 56,926 rows.
Shareable, ungated
A public read-only URL anyone can open — no login, no email gate.
§02 — Defense-Ready Documentation · Agency+
A report a lawyer can hand to a judge.
Every scan produces a defense-ready report — chronological, tamper-evident, and mapped to CIPA categories. It proves what was there, what you blocked, and when. The record speaks before you have to.
56,926 rows · append-only · signed
Tamper-evident
Each digest is hashed and timestamped. Append-only — nothing is ever rewritten.
CIPA category mapping
Every tracker labeled to its alleged CIPA category — session recording, pixel, chat widget.
Before / after proof
Shows what was blocked and what slipped, per page, per tracker, per crawl.
Shareable read-only URL
Ungated — opposing counsel, a client, or a judge can open it with no login.
White-label (Agency+)
Your logo, your domain. Your clients never see our name if you don't want them to.
PDF for the record
Export a timestamped PDF snapshot. For the file, not just the dashboard.
§5 — The Honesty Section
Here's exactly what we can and can't block.
Blocking isn't purely a property of a consent tool. It's a property of where the website platform lets that tool's script run — and, on WordPress, of how each plugin chooses to emit its tag. Any vendor who tells you they block everything, everywhere, is describing a product that doesn't exist.
| Where the tracker lives | Example | Consentinel | Anyone else |
|---|---|---|---|
| Custom code / JS-injected | Session recorders, Meta Pixel via custom code | Blocked | Only if they load first |
| Platform-native marketing tags | Wix Marketing Integrations, GA4 | Consent signals + cookie suppression | Nobody. Not Wix, not CookieYes. |
| Tags another plugin enqueues | wp_enqueue_script, id="handle-js" | Blocked server-side on WordPress, before the page is sent | Client-side tools can't reach these |
| Tags a plugin prints directly | Beehive's gtag loader, echoed into wp_head | Blocked server-side — with output-buffer gating switched on | Client-side tools can't reach these |
| Injected at the CDN edge | Cloudflare /cdn-cgi/, Rocket Loader | Not blockable — we detect and report it | Nobody. It lands after the server finishes. |
"We'd rather tell you the ceiling than sell you past it. When something is outside what any client-side tool can stop, we detect it, we tell you, and we document it."
Read the full breakdown →