A baseline for comparison
The Accept Path provides a score-neutral baseline for consent-dependent activity. The click itself does not establish that consent was registered; a verified state transition is a separate observation.
The CertScore.ai methodology
What loads before consent? What happens after Reject? See cookies, services, privacy signals, and supporting evidence together in one browser-based website report.
Each finding describes evidence observed during a visit to a public website. Read it with the report's scan time, region, and coverage; it is a point-in-time observation, not a legal determination or certification.
Loading scan form…
No credit card required. Public websites only. Existing scan allowances apply.
From website to evidence
Visit a public website in an instrumented browser under defined test conditions.
Capture technical evidence with timestamps, location, and observation context.
Explore supported findings and their evidence in a report your team can inspect.
Inside your report
01 / 07
Start with the signal snapshot, inventory, and priority review. Follow a finding back to the retained evidence that supports it.
A clear starting point for your next privacy review.
Coverage depends on the page, available controls, and retained evidence. Unavailable or inconclusive observations remain explicit.
What we measure
Each scan captures observable technical signals under defined conditions. Every result belongs to that visit and its coverage.
Identify observed consent-management platforms and the consent interface presented during the visit.
Inspect first-layer Accept, Reject, and Options visibility, with explicit limits when inspection is incomplete.
Review requests and storage after eligible actions, when available. Click completion and consent confirmation remain separate.
Inspect retained cookies and storage, their purposes, ownership, and when they first appeared.
Explore vendors, service relationships, request destinations, and observed activity before consent.
Review the GPC observation path, verified signal delivery, and supported comparisons with the passive baseline.
Check retained HTTPS, SSL/TLS certificate, redirect, mixed-content, and form-transport observations.
Review form types, field labels, required states, and checkboxes. View masked form captures when available.
Inspect retained links hidden by off-screen or zero-size styling, their destinations, and affected pages. Human review establishes context.
Review discovered privacy and cookie-policy surfaces, supported transparency observations, and retained excerpts where available.
Review embedded frames and services, plus supported session-replay and fingerprinting signals.
Follow the page event timeline and review scan location, coverage, and timing to interpret each observation.
Use report sharing and evidence exports to give your team a concrete starting point.
Explore a sample report →Explore full-site scanning and monitoring within your plan’s access and crawl limits.
Compare plans →API, MCP, and browser-extension options support additional workflows. Start your free website scan here.
Explore integrations →Separate sessions. Distinct observations.
Eligible controls are observed in separate, clean browser sessions. A completed click, a completed observation, and a confirmed consent decision remain separate facts.
The Accept Path provides a score-neutral baseline for consent-dependent activity. The click itself does not establish that consent was registered; a verified state transition is a separate observation.
The confirmed-refusal path requires an independently verified refusal-state transition and qualifying activity anchored after it. Requests already in flight at confirmation are excluded.
A completed authorized Reject click with directly observed, verified analytics, advertising, or session-replay requests may support a Reject-click tracking review signal even when registration is unverified. An unchanged stored cookie alone does not prove active tracking.
Unsupported, ambiguous, incomplete, stale, timed-out, or unverifiable interactions remain limited coverage. Missing evidence cannot become a clean result or a finding.
Evidence & scope
Findings are tied to retained observations. A score summarizes supported findings; it does not replace the evidence behind them.
Evidence may include cookies, network and runtime records, tracker or vendor observations, consent interfaces, policy surfaces, timestamps, and geographic context, so reported findings can be reviewed and audited.
Websites may return different content, consent interfaces, cookies, or third-party activity by location. CertScore can observe the same website from different locations while keeping its core measurement approach consistent.
The measurement approach is evaluated through defined manual-validation studies and repeated browser observations. Each study describes its own sample and conditions, rather than a universal accuracy claim.
CertScore measures observable technical states and runtime outcomes for privacy engineering and assurance. Legal compliance, processing purpose, and operator intent may require additional context.
Read an annotated retained report →The measurement glossary
Start with a free scan. Review the observations and their evidence.