Annotated owned-fixture report

How to read a consent report: a retained example

This example uses an existing scan of an ErgoVeritas test page, not a customer case study or a new scan. The retained record is useful precisely because it shows both observed behavior and the limits of interpreting older report fields.

By CertScore.ai · Updated

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan

The retained scan context

Target: https://ergoveritas.com/sample_09_03_26_01.html. Scan ID: f4362840-376e-4d8c-897a-34a220136ad4. The scan started on September 3, 2026 at 18:26:00.362 UTC and completed at 18:26:09.986 UTC. The region recorded in the API is eu_ie.

The public record was checked on September 20, 2026. It reports partial coverage and an automated public-web scan limitation. The fixture is owned and intentionally constructed for testing; it is not a representative sample of production websites.

Primary sources:Retained public scan recordOpen the report

Read the historical Reject observation carefully

The legacy postRefusalObservation reports confirmed_observation, refusalExercised: true, four observations, and a verdict describing eligible non-essential activity after confirmed refusal. Its observation completed at 18:26:09.224 UTC. Its strategy stopped on the first eligible activity.

The same API response exposes a newer execution projection marked limited, with clickCompleted, observationCompleted, and consentConfirmed all false. These fields do not support a modern successful-path claim. Preserve the distinction: the historical observation verdict is not interchangeable with a current execution assessment.

This example is an interpretation aid, not proof that the older scan completed today’s full observation protocol. Do not infer an exact request timeline or identify four independent trackers from an observation count.

Read the GPC version before applying newer rules

The retained GPC result uses certscore.gpc-response-assessment.v1 and says No observable GPC response. It records a comparable passive baseline with Sec-GPC and no observed baseline delta.

That is a historical v1 conclusion. It does not establish compliance, and it must not be silently upgraded to newer delivery or comparison requirements. Current tests should use the GPC testing guide and retain the current contract and proof.

Turn the report into a review task

Open the finding and its retained evidence. Separate request timing, storage identity, completed action, confirmed registration, and coverage. Assign a concrete configuration question to the CMP or tag owner rather than copying a score as a diagnosis.

After an authorized change, a new comparable scan can test the intended behavior. This walkthrough does not initiate that scan or claim any remediation outcome.

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan
CertScore.ai automated findings may contain errors. Always review the underlying evidence. CertScore.ai does not provide legal advice, certification, or compliance determinations.