ConsentProof
cookie compliance scanner

Cookie Compliance Scanner — Pre-Consent Evidence, Not a Score

ConsentProof is a cookie consent checker that scans any website with a real browser and records which cookies and third-party trackers fire before the visitor consents.

No account needed · results usually under a minute · Free public scans, rate-limited per site and per IP

A limited number of free scans run each day; if today's are used, we queue yours for tomorrow and email you.

Evidence beats a compliance score

Plenty of scanners return a number out of 100. A score is easy to display and impossible to defend: the first question any client asks is how it was calculated, and the second is why it changed.

A finding is defensible. 'connect.facebook.net loaded a script 210ms after page load, before any consent interaction, at 09:41:12 UTC on 6 September 2026' is a sentence you can put in front of a developer, a client or a regulator without a footnote.

What is in the evidence bundle

Each scan records the pre-consent cookie list, the pre-consent third-party request list, screenshots before and after the consent click, the consent strategy that was used to find the banner, the Consent Mode v2 signals, the absolute UTC capture time, and a SHA-256 over the captured bytes.

The same hash appears on the result page and in the exported PDF, so a report and its source can be tied together after the fact.

Frequently asked

Why does this scanner not give a compliance score?
Because a score implies a legal conclusion we are not in a position to make, and because a number nobody can reproduce is a liability in an audit. You get findings, timestamps and a hash instead.
Can I use the output in an audit?
You can use it as evidence of what a browser observed at a specific UTC time, which is what the timestamp and hash are for. Whether that satisfies a particular audit is a decision for your legal advisers.
How often should a site be scanned?
Whenever the site changes, which in practice means on a schedule. Most pre-consent regressions arrive with a marketing tag, not with a deployment, so the person who caused it is often not watching the site.

Related

Try ConsentProof

Free public scan, no account needed.

Start free Pricing