Code you or your developer added
Screen recorders, a Meta Pixel pasted into custom code
Consentinel
Stopped before it runsAnyone else
Only if their code loads firstThe product
The scan finds what's running on your site. The banner and blocker hold it until your visitor chooses. The report writes down what happened. Each part is honest about what it can't do — and the last section on this page is nothing but that.
How it works
Three things, in order: Hold the trackers we can hold, Watch what happens, and Keep a Record you can hand to someone.
The scan
Most tools check your site against a list of tracking companies they already know about. We don't. We load your site in a real browser two times — once refusing cookies, once accepting them — and compare the two. That's why we find trackers nobody's list has heard of, including our own.
Visit one — cookies refused
Everything that runs anyway
What a real visitor gets before they've clicked anything. Whatever is sent here is your exposure.
Visit two — cookies accepted
Everything that was being held
Trackers that only appear now were genuinely being held the first time. The gap between the two visits is the measurement.
One refuses, one accepts. The difference is your exposure, measured rather than guessed.
It sees what actually loads. Trackers we don't recognize go into a list marked “unknown companies we saw” rather than being quietly dropped.
100 pages per domain on Free, 600 on Pro and Agency, 4,000 on Scale — per crawl. Deep enough to find what a homepage check never will.
A full check runs after you've proved the domain is yours by adding a short line of text to your domain settings. That's permanent. It's why nobody can point us at your site, and why we can't be pointed at anyone else's.
Monthly on Free, weekly on every paid plan. When a new tracker turns up on a site you look after, you hear about it on a schedule instead of in a letter.
What a check found on a given day stays what it found. Nobody can edit it afterwards, including us.
If we check after you've told us to block something and it's still running, we tell you. We don't quietly mark it green.
The Privacy Defense Report — Agency and Scale
If someone ever asks what your website was doing on a particular day, this is the document that answers. It's generated on demand, it covers one scan, and it's put together so nobody can quietly change it afterwards.
The Privacy Defense Report is an integrity-protected technical snapshot of conditions observed during a scan, intended to support compliance review, remediation, and counsel's evaluation. It is not a legal opinion, proof of compliance, or a guarantee of admissibility or litigation outcome.
What's in it: the cookie banner exactly as your visitors saw it. Everything that was sent before anyone agreed. The trackers that were held. A list of companies we didn't recognize. Which tracker caused which cookie — not just that the cookie existed. Your consent statistics. And the full history of your settings. In date order, and locked once written.
56,926 rows · can't be edited
Every observation is fingerprinted into a single code that can be re-checked at any time, over a history nothing rewrites. One report covered 56,926 observations. There is no official timestamp and no digital signature, and we don't pretend otherwise.
Most scanners treat “this cookie exists” as “the website put it there.” Those aren't the same thing, and a demand letter that dumps a raw cookie list is counting on the confusion. We show who caused each one.
Screen recording, ad pixel, chat widget.
What was held, what got through, on which page, on which check.
Your logo and your company on the report. Your clients don't have to see ours.
The report prints cleanly from your browser as a PDF. There's no separately generated, officially timestamped file, and we don't claim one.
Written inside the report itself. It shows the file hasn't changed since we made it. It is not a signature and not a seal, and we don't call it one.
What we can and can't block
Whether a tracker can be blocked isn't really about the consent tool. It's about where your website platform lets that tool's code run — and, on WordPress, how each plugin chooses to add its tag. Any vendor telling you they block everything, everywhere, is describing a product that doesn't exist.
Two things are worth saying plainly here, because they're the ones a competitor would use against us if we didn't. A font loaded by a style file rather than by the page itself runs before consent on every platform, and setting it to “Always block” does not change that — measured on our own site, August 12, 2026. And tracking that happens server-to-server — Facebook's Conversions API, server-side tag managers — never touches a browser, so no browser-based tool can see it, ours included. We report what we can see and we name what we can't.
Screen recorders, a Meta Pixel pasted into custom code
Consentinel
Stopped before it runsAnyone else
Only if their code loads firstWix Marketing Integrations, Google Analytics
Consentinel
We send the consent signal and clear the cookiesAnyone else
Nobody. Not Wix, not CookieYes.Anything a plugin registers with WordPress itself
Consentinel
Removed on the server, before the page is sentAnyone else
Browser-based tools can't reach theseBeehive's Google tag, printed into the page head
Consentinel
Removed on the server — with one extra setting switched on, which is off when you installAnyone else
Browser-based tools can't reach theseCloudflare's own analytics, Rocket Loader
Consentinel
Can't be stopped — we find it and tell youAnyone else
Nobody. It goes in after your server has finished.A font pulled in by a plugin's own stylesheet
Consentinel
Can't be stopped by anyone — including when you've set it to Always block. We find it and tell you.Anyone else
Nobody. Browsers fetch these by a route no code can reach.Facebook's Conversions API, server-side tag managers
Consentinel
Invisible to us, and to every browser-based tool. We say so rather than leave it out.Anyone else
Nobody can see it from the browser.What we can't block from inside your page, you can often remove at its source — host the font yourself, switch the script off at your CDN, scope down the server-side tracking you set up. You just have to know it's there. We tell you which ones are running, on which pages, and when we saw them. What you do about each one is your call — but at least it's a call you get to make.
We'd rather tell you where we stop than sell you past it. Ask any other consent tool for this page.
Read the full breakdown →