Browser-based website measurement
CertScore.ai observes how public websites behave in a real browser, preserves supporting evidence, and reports structured privacy-related measurements for review. It does not rely only on policy text or static page inspection.
Separate Accept and Reject observations
Eligible Accept and Reject controls are observed in separate clean browser sessions. The Accept Path provides a score-neutral baseline for consent-dependent activity. The Reject Path can support a finding only after a refusal-state transition is independently confirmed and qualifying activity is temporally anchored after that confirmation.
Requests already in flight at confirmation are excluded. Unsupported, ambiguous, incomplete, stale, timed-out, or unverifiable interactions remain limited coverage and cannot become a clean result or a finding.
What CertScore measures
- Cookies and browser storage
- Third-party trackers and technology categories
- Consent-management platforms
- Privacy and cookie-policy surfaces
- Transport-security indicators
- Geographic differences in website execution
How observation works
- 1Execute a public website in an instrumented browser.
- 2Observe the website’s runtime state under defined test conditions.
- 3Capture supporting technical evidence and context.
- 4Normalize observations into consistent measurement categories.
- 5Retain evidence so reported findings can be reviewed and audited.
Geographic measurement
Websites may return different content, consent interfaces, cookies, or third-party activity according to a visitor’s location. CertScore can observe the same website from different geographic locations while keeping the core measurement approach consistent.
Evidence-backed findings
Findings are tied to retained observations rather than generated solely from a score. Evidence may include cookie observations, network and runtime records, tracker or vendor observations, CMP observations, policy surfaces, timestamps, and geographic context.
Key measurement terms
- Pre-consent cookie
- A cookie observed before the scanner records a visitor consent choice.
- Tracker detection
- A grouped technology observation supported by browser, network, cookie, storage, script, or related runtime evidence.
- Advertising & Measurement
- A functional category for technologies associated with advertising, advertising measurement, or audience measurement.
- CMP observation
- Evidence that a consent-management platform or consent interface was present during the tested visit.
- Policy surface
- A public page or document that presents privacy, cookie, consent, or related disclosure information.
- Confirmed interaction
- Evidence that a consent action produced a verified state transition, established independently of the click itself. Required before activity qualifies on the Reject Path.
- Confirmed clean
- No qualifying activity was retained during a completed observation window. A bounded statement about one observation, not a general claim about the site.
- Limited coverage
- An observation that was unavailable, unsupported, unsuccessful, stale, timed out, or unverifiable. It is explicit, score-neutral, and never equivalent to a clean result.
- Score-neutral comparison
- Evidence retained for interpretation rather than scoring, including the Accept Path baseline, unchanged stored values on their own, and every limited-coverage state.
Validation and repeatability
CertScore’s measurement approach is evaluated through defined manual-validation studies and repeated browser observations. Results from a particular validation study describe that study’s sample and conditions; they are not presented as universal accuracy claims.
Scope
CertScore measures observable technical states and runtime outcomes. These observations provide evidence for privacy engineering and assurance, while questions of legal compliance, processing purpose, or operator intent may require additional context.
