Paste your URL
One field. No signup, no card, no sales call. The crawler hits your live pages the moment you submit. Work email only, because the report goes to your inbox and it has to be one a regulator would believe.
Two-pass Playwright scan under default and consent-denied conditions. 155+ ad and analytics vendors detected, consent violations flagged, PII leakage caught, multi-browser performance gaps measured, CSP and cross-domain attribution issues surfaced. Editorial PDF in your inbox in under two minutes. First scan free, work email only (Gmail, Yahoo, Outlook, iCloud aren’t eligible).
Because a single tag firing before consent is the one finding that ends up in a regulator letter. After that, GTM plumbing, GA4 config, attribution, ecommerce, server-side, app. Every tag, every signal, tested in a real browser, not against a copy of your source code.
No calendar invites, no scoping calls, no NDA. Paste, wait, download.
One field. No signup, no card, no sales call. The crawler hits your live pages the moment you submit. Work email only, because the report goes to your inbox and it has to be one a regulator would believe.
Real Chromium browsers load your pages, accept and reject consent, trigger ecommerce flows, and capture the actual network behaviour. Two passes, default consent and consent-denied, so we see what changes when a visitor opts out. Not a static scan of your source code.
Every finding ranked P1, P2, or P3 with the evidence, the regulation cited, a cost estimate on the data or exposure, and the exact fix your dev team can ship. 10 pages of editorial writing, not a CSV dump. Designed to forward to legal without an explainer email.
A DIY checklist grades your intent. Neither reads what your tags actually do in a visitor’s browser. That’s the only grade that matters when a regulator opens a file.
| Legal / agency review | AuditDrishti | |
|---|---|---|
| Price | $2,000 to $5,000 | Free for the first 5 |
| Turnaround | 2 to 4 weeks | Under 5 minutes |
| What gets tested | Policy text, cookie table | Live runtime, real browsers |
| Checks | 20 to 30, manual | 57, automated |
| Evidence | Screenshots in a slide deck | Network logs and HAR captures |
| Re-run after fixes | Pay the full fee again | Re-run on demand |
Seven issues found. Both P1s regulator-grade. This is the kind of thing nobody on the team knew was broken.
# scanned 12 apr 2026 · 57 checks complete
_fbp set before the CMP returns. GDPR Art. 6 lawful basis, CCPA sale disclosure. Fix: gate the tag behind the CMP callback, see page 4.ad_user_data & ad_personalizationGoogle tags default to granted without the v2 signals. EEA ad personalization and DMA both triggered. Fix: update default consent state in GTM, see page 5.Navigator.globalPrivacyControl=true detected, tags fire anyway. CCPA and CPRA treat GPC as a valid opt-out.page_locationOrder-confirmation URLs include ?email=user@.... GA4 ToS violation, DPDP 2023 personal data. Fix: add a page_location rewrite rule, see page 7.Two-pass browser scan under default and consent-denied conditions. 155+ ad/analytics vendors, consent violations, PII leakage, multi-browser performance gaps, CSP and cross-domain attribution all checked. Editorial PDF in your inbox in under two minutes.