Privacy scanner vs cookie scanner: what is the difference?
Cookie inventory answers what was stored. Runtime privacy testing also asks when requests or writes happened, what choice preceded them, and what the retained evidence supports. Products can overlap: compare actual tested capabilities, not the label “cookie scanner” or “privacy scanner.”
By CertScore.ai · Updated
Run a free website behavior scan
Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.
| Review task | Evidence to request |
|---|---|
| Cookie inventory | Names, domains, paths, expiry, and capture conditions; cookie values redacted. |
| Pre-consent activity | Request and write timing tied to a fresh session before any choice. |
| Accept and Reject testing | Separate sessions, completed click, confirmed decision, observation window, and failures. |
| GPC response | Actual signal delivery plus a comparable baseline; indeterminate coverage kept separate. |
| Policy review | Owned policy excerpts and corresponding browser evidence, with retrieval limitations. |
| Team handoff | An addressable report, retained references, export options, and reproducible test conditions. |
What cookie scanners usually do
Cookie scanners commonly inventory cookies, cookie names, domains, categories, and sometimes cookie lifetimes or vendor labels.
That inventory is useful, but it may not explain whether tracking requests appeared before consent, whether reject behavior changed vendor activity, or whether related website signals need review.
What CertScore.ai adds
CertScore.ai reviews observed public website behavior around tracking requests, cookie timing, consent surfaces, accessibility signals, session recording indicators, fingerprinting-related signals, and disclosure consistency.
The output is designed to help teams review risk signals with retained evidence rather than rely only on a static cookie list.
Related CertScore.ai pages
Run a free website behavior scan
Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.
