Comparison

Privacy scanner vs cookie scanner: what is the difference?

Cookie inventory answers what was stored. Runtime privacy testing also asks when requests or writes happened, what choice preceded them, and what the retained evidence supports. Products can overlap: compare actual tested capabilities, not the label “cookie scanner” or “privacy scanner.”

By CertScore.ai · Updated

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan
Questions to use when evaluating a scanner
Review taskEvidence to request
Cookie inventoryNames, domains, paths, expiry, and capture conditions; cookie values redacted.
Pre-consent activityRequest and write timing tied to a fresh session before any choice.
Accept and Reject testingSeparate sessions, completed click, confirmed decision, observation window, and failures.
GPC responseActual signal delivery plus a comparable baseline; indeterminate coverage kept separate.
Policy reviewOwned policy excerpts and corresponding browser evidence, with retrieval limitations.
Team handoffAn addressable report, retained references, export options, and reproducible test conditions.

What cookie scanners usually do

Cookie scanners commonly inventory cookies, cookie names, domains, categories, and sometimes cookie lifetimes or vendor labels.

That inventory is useful, but it may not explain whether tracking requests appeared before consent, whether reject behavior changed vendor activity, or whether related website signals need review.

What CertScore.ai adds

CertScore.ai reviews observed public website behavior around tracking requests, cookie timing, consent surfaces, accessibility signals, session recording indicators, fingerprinting-related signals, and disclosure consistency.

The output is designed to help teams review risk signals with retained evidence rather than rely only on a static cookie list.

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan