CertScore.ai report
Loading report
The report is ready; we’re loading its retained findings and evidence.
CertScore.ai report
The report is ready; we’re loading its retained findings and evidence.
Sep 11, 2026, 11:26:01 PM UTC
Overall score
No priority issues
No projected top findings in the retained evidence.
Signal snapshot
No consent-platform identity was retained in the completed scan context.
Priority review
Open for evidence, JSON, and correction steps.
0s
Scan start
Public page observation began
12.28s
Observation end
Retained scan window closed
Resource inventory
Evidence mix
Purpose mix
Site relationship
Consent, tracking & external services, pre-consent runtime, GPC comparison, GDPR Transparency, transport security and collection details.
Rating mix
30 rows
After Accept
LimitedAccept path limited
Accept testing did not retain enough evidence to verify that consent was granted.
Bounded GPC observation completed. GPC was observed on the main-document request and browser property. The CMP's sale/sharing opt-out state was unavailable. No qualifying classified requests were observed in this bounded capture. Paired activity comparison: no observable response.
Sec-GPC request evidence: 3 retained requests; main-document browser property: true.
Signal delivery: verified. Comparison coverage: complete.
Cookies
0 0
Web storage
0 0
Trackers
0 0
Advertising / measurement
0 0
Consent / CMP
0 0
Overall, this scan did not surface a priority issue in the retained evidence. That is encouraging, but it is not a legal conclusion or proof that every site behavior was observed. Captured consent, runtime, policy, and transport signals should still be read alongside the underlying evidence before decisions are made. Limited evidence remains for Cookie notice / cookie policy availability and Post-choice tracking reduction.
Overall, this scan did not surface a priority issue in the retained evidence. That is encouraging, but it is not a legal conclusion or proof that every site behavior was observed. Captured consent, runtime, policy, and transport signals should still be read alongside the underlying evidence before decisions are made. Limited evidence remains for Cookie notice / cookie policy availability and Post-choice tracking reduction.
Industry benchmark
Legal/Compliance & Risk Advisory
Non-essential requests
Non-essential cookies/storage
| Domains | Relationship | Confidence | Review priority |
|---|
Not observed
Not observed
Not observed
CMP identity and control context are retained in the canonical consent projection.
After Accept
LimitedAccept path limited
Accept testing did not retain enough evidence to verify that consent was granted.
complete ConsentControlAssessment v2
{
"assessmentStatus": "checked",
"checklistItemId": "consent_surface_observed",
"coverageArea": "Consent mechanism",
"evidenceState": "not_observed",
"explanation": "Whether an actionable cookie/consent banner or CMP preference surface was observed in the tested context.",
"note": "Whether an actionable cookie/consent banner or CMP preference surface was observed in the tested context.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.consent_surface_observed.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.consent_surface_observed"
},
"statusBasis": "No operational consent surface was retained in the tested context.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: complete ConsentControlAssessment v2"
],
"consentSurfaceState": "not_observed",
"missingEvidenceNeeded": [],
"consentSurfaceObserved": false,
"selectedEvidenceReason": "Retained evidence did not confirm an uncontaminated first-layer GDPR/ePrivacy cookie/CMP consent surface.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "consentControlLifecycleEvidence.surfaceClassification"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Consent mechanism is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
runtime capture completed
{
"assessmentStatus": "checked",
"checklistItemId": "cmp_framework_signal_observed",
"coverageArea": "CMP framework",
"evidenceState": "not_observed",
"explanation": "Whether a consent-management framework, CMP vendor, or CMP runtime signal was observed in the pre-consent/public-web context.",
"note": "Whether a consent-management framework, CMP vendor, or CMP runtime signal was observed in the pre-consent/public-web context.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.cmp_framework_signal_observed.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.cmp_framework_signal_observed"
},
"statusBasis": "Runtime consent/CMP checks completed for the tested context and did not retain a CMP framework signal.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: runtime capture completed"
],
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"cmpFrameworkSignalObserved": false,
"selectedEvidenceArtifactId": "coverage_policy"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}CMP framework is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
complete pre-interaction consent-surface inspection
{
"assessmentStatus": "checked",
"checklistItemId": "reject_all_path_availability",
"coverageArea": "Decline consent control",
"evidenceState": "not_observed",
"explanation": "Whether a first-layer reject, necessary-only, decline, refuse, or equivalent refusal option was observed on a sufficiently retained consent surface.",
"note": "Whether a first-layer reject, necessary-only, decline, refuse, or equivalent refusal option was observed on a sufficiently retained consent surface.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.reject_all_path_availability.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.reject_all_path_availability"
},
"statusBasis": "No reject control was retained because no operational consent surface was retained.",
"retainedEvidence": {
"scoreEffect": "none",
"evidenceRefs": [
"Evidence: complete pre-interaction consent-surface inspection"
],
"missingEvidenceNeeded": [],
"rejectControlObserved": false,
"consentSurfaceObserved": false,
"selectedEvidenceReason": "Selected retained same-surface reject-path or post-reject comparison evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"selectedEvidenceArtifactId": "rejectPathDepthAndAvailability",
"consentOperationalSurfaceConcern": {
"originKey": "consent.operational_surface.not_observed",
"canonicalConcernKey": "runtime_artifact:consent.operational_surface.not_observed"
},
"firstLayerCookieConsentBannerObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Decline consent control is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
complete pre-interaction consent-surface inspection
{
"assessmentStatus": "checked",
"checklistItemId": "accept_consent_control",
"coverageArea": "Accept consent control",
"evidenceState": "not_observed",
"explanation": "Whether a first-layer accept, accept-all, allow-all, or agree control was observed on the retained consent surface.",
"note": "Whether a first-layer accept, accept-all, allow-all, or agree control was observed on the retained consent surface.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.accept_consent_control.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.accept_consent_control"
},
"statusBasis": "No accept control was retained because no operational consent surface was retained.",
"retainedEvidence": {
"scoreEffect": "none",
"evidenceRefs": [
"Evidence: complete pre-interaction consent-surface inspection"
],
"acceptControlObserved": false,
"missingEvidenceNeeded": [],
"consentSurfaceObserved": false,
"selectedEvidenceReason": "Selected retained same-surface accept consent control evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"selectedEvidenceArtifactId": "firstLayerConsentChoices.acceptControl",
"consentOperationalSurfaceConcern": {
"originKey": "consent.operational_surface.not_observed",
"canonicalConcernKey": "runtime_artifact:consent.operational_surface.not_observed"
},
"firstLayerCookieConsentBannerObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Accept consent control is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
complete pre-interaction consent-surface inspection
{
"assessmentStatus": "checked",
"checklistItemId": "options_settings_preferences_control",
"coverageArea": "Options / settings / preferences control",
"evidenceState": "not_observed",
"explanation": "Whether a first-layer options, settings, preferences, or manage-preferences control was observed on the retained consent surface.",
"note": "Whether a first-layer options, settings, preferences, or manage-preferences control was observed on the retained consent surface.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.options_settings_preferences_control.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.options_settings_preferences_control"
},
"statusBasis": "No options control was retained because no operational consent surface was retained.",
"retainedEvidence": {
"scoreEffect": "none",
"evidenceRefs": [
"Evidence: complete pre-interaction consent-surface inspection"
],
"missingEvidenceNeeded": [],
"consentSurfaceObserved": false,
"optionsControlObserved": false,
"selectedEvidenceReason": "Selected retained same-surface options/settings/preferences control evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"selectedEvidenceArtifactId": "firstLayerConsentChoices.optionsControl",
"consentOperationalSurfaceConcern": {
"originKey": "consent.operational_surface.not_observed",
"canonicalConcernKey": "runtime_artifact:consent.operational_surface.not_observed"
},
"firstLayerCookieConsentBannerObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Options / settings / preferences control is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Evidence limitation: incomplete canonical cookie-notice/policy coverage
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "cookie_notice_policy_availability",
"coverageArea": "Cookie notice / cookie policy availability",
"evidenceState": "not_testable",
"explanation": "Whether a cookie notice, cookie policy, cookie settings surface, or equivalent cookie disclosure surface was retained.",
"note": "Whether a cookie notice, cookie policy, cookie settings surface, or equivalent cookie disclosure surface was retained.",
"status": "Not testable",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.cookie_notice_policy_availability.not_testable",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.cookie_notice_policy_availability"
},
"statusBasis": "Cookie notice/policy absence cannot be determined because policy-surface link discovery did not retain complete typed coverage.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence limitation: incomplete canonical cookie-notice/policy coverage"
],
"cookiePolicyPresent": false,
"cookieNoticeObserved": false,
"missingEvidenceNeeded": [
"runtimeArtifacts.policySurfaceInspection.linkDiscoveryCoverageStatus: Complete typed policy-surface discovery is required before projecting cookie-policy absence."
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"policySurfaceInspection": {
"outcome": "privacy_policy_observed",
"coverageStatus": "limited",
"limitationKeys": [
"privacy_policy_link_observed_document_not_retained"
],
"inspectionCompleted": true,
"observedSurfaceTypes": [
"privacy_policy"
],
"privacyPolicyObserved": true,
"linkDiscoveryCoverageStatus": "complete",
"documentRetrievalCoverageStatus": "insufficient"
},
"selectedEvidenceStrength": "limited",
"preConsentRuntimeEvidence": false,
"selectedEvidenceArtifactId": "coverage_policy",
"policyLinkDiscoveryComplete": false,
"consentSurfaceCoverageComplete": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": [
{
"field": "runtimeArtifacts.policySurfaceInspection.linkDiscoveryCoverageStatus",
"actual": "complete",
"source": "scanner",
"expected": "complete",
"whyNeeded": "Complete typed policy-surface discovery is required before projecting cookie-policy absence."
}
]
}complete first-layer consent-control assessment
Reason: no_actionable_reject_control
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "post_reject_tracking_reduction",
"coverageArea": "Post-choice tracking reduction",
"evidenceState": "not_testable",
"explanation": "What tracking activity was observed after Reject, including the services contacted and when requests began. Consent-state confirmation is recorded separately.",
"note": "What tracking activity was observed after Reject, including the services contacted and when requests began. Consent-state confirmation is recorded separately.",
"status": "Not testable",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.post_reject_tracking_reduction.not_testable",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.post_reject_tracking_reduction"
},
"statusBasis": "The completed first-layer consent inventory retained no actionable Reject or necessary-only control, so a post-Reject activity window was not applicable. Missing refusal-control availability is assessed separately.",
"retainedEvidence": {
"scoreEffect": "canonical_post_refusal_policy",
"evidenceRefs": [
"Evidence: complete first-layer consent-control assessment",
"Reason: no_actionable_reject_control"
],
"productionPosture": "not_applicable_no_reject_control",
"missingEvidenceNeeded": [
"Confirmed reject action plus refusal-anchored request/write evidence, a contradictory consent signal, or exact unchanged storage identity-and-value evidence."
],
"selectedEvidenceReason": "Reject-path evidence is not selected as testable unless a first-layer GDPR/ePrivacy cookie banner and valid reject state are confirmed.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"postRejectWindowAvailable": false,
"reductionEvaluationStatus": "not_testable",
"rejectInteractionConfirmed": false,
"selectedEvidenceArtifactId": "postRejectTrackingReductionEvidence",
"preConsentStorageNotCleared": false,
"rejectInteractionFailureClass": "reject_path_incomplete_at_passive_barrier",
"refusalSignalContradictsAction": false,
"rejectInteractionFailureReason": "The independent Reject Path did not complete by the passive-lane barrier; control absence is not established in that session.",
"postRejectRequestRecordsObserved": false,
"preConsentStorageNotClearedCount": 0,
"postRejectNonEssentialRequestCount": 0,
"postRejectNonEssentialActivityRetained": false,
"storagePresenceDoesNotEstablishActiveUse": false,
"concretePostRejectNonEssentialDetailsRetained": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Tracking & external services
runtime capture completed
{
"assessmentStatus": "checked",
"checklistItemId": "pre_consent_third_party_tracking",
"coverageArea": "Pre-consent non-essential tracking",
"evidenceState": "not_observed",
"explanation": "Whether classified non-essential analytics, advertising, measurement, replay, or similar requests were observed before recorded consent. Site relationship and entity ownership are reported separately.",
"note": "Whether classified non-essential analytics, advertising, measurement, replay, or similar requests were observed before recorded consent. Site relationship and entity ownership are reported separately.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.pre_consent_third_party_tracking.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.pre_consent_third_party_tracking"
},
"statusBasis": "Runtime tracking checks completed for the tested context, and no eligible pre-consent non-essential tracking finding was projected.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: runtime capture completed"
],
"trackerVendorCount": 0,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained pre-consent request/vendor timing evidence; storage evidence is evaluated separately.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"preconsentTimingEvidence": {
"cookieOrStorage": {
"preconsentCookieOrStorageExactTimingRetained": false,
"preconsentCookieOrStorageTimedObservationCount": 0,
"preconsentCookieOrStorageUntimedObservationCount": 0,
"preconsentCookieOrStorageInitialInventoryObserved": false
},
"thirdPartyTracking": {
"preconsentThirdPartyTrackingTimedObservationCount": 0
}
},
"selectedEvidenceStrength": "moderate",
"preconsentTrackingDetected": false,
"selectedEvidenceArtifactId": "preConsentTrackingRequestEvidence.missing",
"preconsentCookieOrStorageExactTimingRetained": false,
"preconsentCookieOrStorageTimedObservationCount": 0,
"preconsentCookieOrStorageUntimedObservationCount": 0,
"preconsentCookieOrStorageInitialInventoryObserved": false,
"preconsentThirdPartyTrackingTimedObservationCount": 0
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Pre-consent non-essential tracking is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
retained pre-consent iframe inventory
{
"assessmentStatus": "checked",
"checklistItemId": "third_party_iframe_pre_consent",
"coverageArea": "3rd party iframes before consent",
"evidenceState": "not_observed",
"explanation": "Whether retained scanner evidence showed known 3rd party iframe embeds before a recorded consent action.",
"note": "Whether retained scanner evidence showed known 3rd party iframe embeds before a recorded consent action.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.third_party_iframe_pre_consent.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.third_party_iframe_pre_consent"
},
"statusBasis": "Retained iframe inventory did not show known 3rd party iframe embeds before a recorded consent action.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained pre-consent iframe inventory"
],
"missingEvidenceNeeded": [],
"preConsentIframeCount": 0,
"iframeObservationCount": 0,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}3rd party iframes before consent is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
retained pre-consent embedded-content inventory
{
"assessmentStatus": "checked",
"checklistItemId": "social_media_embed_pre_consent",
"coverageArea": "Social/media embeds or plugins loaded before consent",
"evidenceState": "not_observed",
"explanation": "Whether retained network/runtime evidence showed a social, video, media embed, social pixel, or plugin provider loading before a recorded consent action.",
"note": "Whether retained network/runtime evidence showed a social, video, media embed, social pixel, or plugin provider loading before a recorded consent action.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.social_media_embed_pre_consent.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.social_media_embed_pre_consent"
},
"statusBasis": "Retained embedded-content checks did not show a social/media embed, plugin, widget, or pixel provider request before consent. Plain outbound links are not treated as evidence for this row.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained pre-consent embedded-content inventory"
],
"placeholderDetected": false,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"socialMediaEmbedObservationCount": 0
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Social/media embeds or plugins loaded before consent is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
EmbeddedContentObservationCount: 0
{
"assessmentStatus": "checked",
"checklistItemId": "embedded_content_pre_consent",
"coverageArea": "Embedded third-party services before consent",
"evidenceState": "not_observed",
"explanation": "Whether retained scanner evidence showed iframe, embed, widget, or visibly integrated third-party services before a recorded consent action. This row does not represent all background analytics or network requests.",
"note": "Whether retained scanner evidence showed iframe, embed, widget, or visibly integrated third-party services before a recorded consent action. This row does not represent all background analytics or network requests.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.embedded_content_pre_consent.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.embedded_content_pre_consent"
},
"statusBasis": "Iframe/runtime checks completed for the tested context and did not retain a concrete 3rd party embedded-content iframe before consent.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained pre-consent embedded-content inventory"
],
"missingEvidenceNeeded": [],
"preConsentIframeCount": 0,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"embeddedContentObservationCount": 0
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Embedded third-party services before consent is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Policy and transparency
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
privacy notice link/surface retained
Limitation: substantive policy body not retained
{
"assessmentStatus": "checked",
"checklistItemId": "privacy_notice_availability",
"coverageArea": "Privacy notice link/surface discovered",
"evidenceState": "observed",
"explanation": "Whether a reachable privacy notice or privacy policy link/surface was retained. This row does not by itself confirm that substantive notice content was available.",
"note": "Whether a reachable privacy notice or privacy policy link/surface was retained. This row does not by itself confirm that substantive notice content was available.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.privacy_notice_availability.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.privacy_notice_availability"
},
"statusBasis": "A privacy-notice link or page surface was reachable, but substantive notice content was not available in the retained rendered text. Row-specific transparency disclosures remain unconfirmed.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: privacy notice link/surface retained",
"Limitation: substantive policy body not retained"
],
"signalObserved": "surface_only_substantive_content_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"policyEvidenceAssessment": {
"result": "disclosure_observed",
"scoreEffect": "canonical_policy",
"topicRelevance": "direct",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "moderate",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"policySurfaceSummary": {
"scanStartedAt": "2026-09-11T23:26:07.314Z",
"observedTopics": [],
"cookiePolicyUrls": [],
"cookieDisclosures": [],
"mentionedControls": [],
"privacyPolicySize": null,
"privacyPolicyUrls": [],
"cookie_disclosures": [],
"policySectionCount": 0,
"policySurfaceCount": 1,
"cookiePolicyPresent": false,
"scannedPageLanguage": "en",
"privacyPolicyPresent": false,
"policyPrimaryLanguage": null,
"policyLastUpdatedTexts": [],
"policyTextCoverageMode": "none",
"retainedPolicySections": [],
"policyCookieDisclosures": [],
"privacyPolicyDiscovered": true,
"processingErrorObserved": false,
"observedPolicyTopicHints": [],
"policyDocumentProvenance": [],
"policy_cookie_disclosures": [],
"article13DisclosureSignals": [],
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"privacyPolicyEvidencePaths": [],
"discoveredPrivacyPolicyUrls": [
"https://example.invalid/privacy"
],
"article13CoverageAssessments": [
{
"topic": "automated_decision_making_or_profiling",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "controller_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_retention",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_subject_rights",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "dpo_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "international_transfers",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "legal_basis",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "processing_purposes",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "recipients_or_vendor_categories",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "supervisory_authority",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
}
],
"policyTextEvidenceProjection": {
"scanId": "d957bb0c-7577-4a90-8360-82b444dc1abb",
"documents": [
{
"documentRole": "unknown",
"requestedUrl": "https://example.invalid/privacy",
"observationId": "policy_surface_41a1e33d",
"redirectChain": [
"https://example.invalid/privacy",
"https://www.example.invalid/privacy"
],
"documentFormat": "unknown",
"limitationKeys": [
"policy_text_artifact_reference_missing",
"policy_text_artifact_text_unavailable",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text"
],
"extractionStatus": "unavailable",
"retainedTextChars": 0,
"documentFetchState": "failed",
"targetRelationship": "unknown",
"documentTextCoverage": {
"status": "unavailable",
"limitationKeys": [
"policy_document_text_coverage_derived_for_legacy_observation"
],
"sourceTextChars": 0,
"retainedTextChars": 0
},
"documentEvaluationState": "not_attempted",
"documentRoleReasonCodes": [],
"governingPolicySelection": {
"score": 0,
"state": "ineligible",
"reasonCodes": [
"policy_document_status_failed",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_role_unknown",
"policy_document_target_ownership_unverified"
],
"contractVersion": "governing_policy_selection.v1"
},
"artifactVerificationStatus": "missing_reference",
"gdprTransparencyTopicCoverageDiagnostics": []
}
],
"generatedAt": "2026-09-11T23:26:19.597Z",
"sourceBundle": {
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/d957bb0c-7577-4a90-8360-82b444dc1abb/CanonicalEvidenceBundle.json",
"sha256": "8ea8b90b589984a1b093932250300e4bcb78a6c31f1942f9de8a78827bc5f540",
"sizeBytes": 76856,
"schemaVersion": "certscore.v2.alpha.1",
"verificationStatus": "verified"
},
"limitationKeys": [
"policy_text_artifact_reference_missing",
"policy_text_artifact_text_unavailable",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text",
"verified_owned_complete_policy_document_unavailable"
],
"contractVersion": "certscore.policy-text-evidence-projection.v1",
"projectionStatus": "verified_partial"
},
"privacyPolicyEvaluationState": "discovered_fetch_failed",
"legalFrameworkValidityMatches": [],
"missingExpectedPolicySections": [
"Your privacy controls",
"Exporting and deleting your information",
"Retaining your information",
"Compliance and cooperation with regulators",
"European requirements",
"Data transfers"
],
"policy_text_extraction_health": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"retainedPolicySectionHeadings": [],
"selectedPrivacyPolicyDocument": null,
"article13_coverage_assessments": [
{
"topic": "automated_decision_making_or_profiling",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "controller_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_retention",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_subject_rights",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "dpo_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "international_transfers",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "legal_basis",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "processing_purposes",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "recipients_or_vendor_categories",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "supervisory_authority",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
}
],
"discoveredPrivacyPolicyDetails": [
{
"url": "https://example.invalid/privacy",
"status": "failed",
"documentFetchState": "failed",
"fetchFailureReason": "network_error",
"linkObservationState": "observed",
"documentEvaluationState": "not_attempted"
}
],
"article13DisclosureTypesPartial": [],
"discoveredPrivacyPolicyStatuses": [
"failed"
],
"gdprTransparencyEvidenceProfile": "gdpr_transparency_multilingual_article13_v1",
"policy_text_evidence_projection": {
"scanId": "d957bb0c-7577-4a90-8360-82b444dc1abb",
"documents": [
{
"documentRole": "unknown",
"requestedUrl": "https://example.invalid/privacy",
"observationId": "policy_surface_41a1e33d",
"redirectChain": [
"https://example.invalid/privacy",
"https://www.example.invalid/privacy"
],
"documentFormat": "unknown",
"limitationKeys": [
"policy_text_artifact_reference_missing",
"policy_text_artifact_text_unavailable",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text"
],
"extractionStatus": "unavailable",
"retainedTextChars": 0,
"documentFetchState": "failed",
"targetRelationship": "unknown",
"documentTextCoverage": {
"status": "unavailable",
"limitationKeys": [
"policy_document_text_coverage_derived_for_legacy_observation"
],
"sourceTextChars": 0,
"retainedTextChars": 0
},
"documentEvaluationState": "not_attempted",
"documentRoleReasonCodes": [],
"governingPolicySelection": {
"score": 0,
"state": "ineligible",
"reasonCodes": [
"policy_document_status_failed",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_role_unknown",
"policy_document_target_ownership_unverified"
],
"contractVersion": "governing_policy_selection.v1"
},
"artifactVerificationStatus": "missing_reference",
"gdprTransparencyTopicCoverageDiagnostics": []
}
],
"generatedAt": "2026-09-11T23:26:19.597Z",
"sourceBundle": {
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/d957bb0c-7577-4a90-8360-82b444dc1abb/CanonicalEvidenceBundle.json",
"sha256": "8ea8b90b589984a1b093932250300e4bcb78a6c31f1942f9de8a78827bc5f540",
"sizeBytes": 76856,
"schemaVersion": "certscore.v2.alpha.1",
"verificationStatus": "verified"
},
"limitationKeys": [
"policy_text_artifact_reference_missing",
"policy_text_artifact_text_unavailable",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text",
"verified_owned_complete_policy_document_unavailable"
],
"contractVersion": "certscore.policy-text-evidence-projection.v1",
"projectionStatus": "verified_partial"
},
"privacyPolicyTextCharacterCount": 0,
"retainedCookiePolicyTextExcerpt": "",
"validatedDisclosureTypesPartial": [],
"article13DisclosureTypesObserved": [],
"retainedArticle13SectionEvidence": [],
"retainedPrivacyPolicyTextExcerpt": "",
"validatedDisclosureTypesObserved": [],
"privacyNoticeAvailabilityObserved": true,
"evaluatedPrivacyPolicySurfaceCount": 0,
"discardedArticle13DisclosureSignals": [],
"staleLegalFrameworkReferenceObserved": false,
"policyEvidenceProvenanceContractVersion": "certscore.policy-evidence-provenance.v1",
"gdprTransparencyProductionEvidenceEnabled": true,
"gdprTransparencyProductionEvidenceDiagnostics": {
"sourceCandidateCount": 0,
"candidateDispositions": [],
"acceptedCandidateCount": 0,
"rejectedCandidateCount": 0,
"discardedCandidateCount": 0,
"diagnosticCandidateCount": 0,
"productionCreditSignalCount": 0
}
}
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Privacy notice link/surface discovered is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "legal_basis_disclosure_observed",
"coverageArea": "Legal basis disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence included a canonical legal-basis disclosure signal.",
"note": "Whether retained privacy-policy evidence included a canonical legal-basis disclosure signal.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.legal_basis_disclosure_observed.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.legal_basis_disclosure_observed"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "legal_basis",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "retention_disclosure_observed",
"coverageArea": "Retention disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence included a data-retention disclosure signal.",
"note": "Whether retained privacy-policy evidence included a data-retention disclosure signal.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.retention_disclosure_observed.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.retention_disclosure_observed"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "data_retention",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "controller_contact_disclosure",
"coverageArea": "Controller/contact disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence included a controller, privacy contact, or equivalent contact point.",
"note": "Whether retained privacy-policy evidence included a controller, privacy contact, or equivalent contact point.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.controller_contact_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.controller_contact_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "controller_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "processing_purposes_disclosure",
"coverageArea": "Processing purposes disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described the purposes for processing personal data.",
"note": "Whether retained privacy-policy evidence described the purposes for processing personal data.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.processing_purposes_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.processing_purposes_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "processing_purposes",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "recipients_vendor_categories_disclosure",
"coverageArea": "Recipients/vendor categories disclosed",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described recipient, vendor, or 3rd party categories.",
"note": "Whether retained privacy-policy evidence described recipient, vendor, or 3rd party categories.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.recipients_vendor_categories_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.recipients_vendor_categories_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "recipients_or_vendor_categories",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "data_subject_rights_disclosure",
"coverageArea": "Data subject rights disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described data subject rights or a rights request path.",
"note": "Whether retained privacy-policy evidence described data subject rights or a rights request path.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.data_subject_rights_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.data_subject_rights_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "data_subject_rights",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "international_transfers_disclosure",
"coverageArea": "International transfer disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described international transfers or transfer-relevant endpoint/vendor context.",
"note": "Whether retained privacy-policy evidence described international transfers or transfer-relevant endpoint/vendor context.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.international_transfers_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.international_transfers_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "international_transfers",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "dpo_contact_point_disclosure",
"coverageArea": "DPO contact point (where applicable)",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence identified a designated data protection officer or equivalent statutory DPO contact. A generic privacy mailbox is credited under controller/contact disclosure and does not by itself establish a DPO designation.",
"note": "Whether retained privacy-policy evidence identified a designated data protection officer or equivalent statutory DPO contact. A generic privacy mailbox is credited under controller/contact disclosure and does not by itself establish a DPO designation.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.dpo_contact_point_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.dpo_contact_point_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "dpo_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "supervisory_authority_complaint_disclosure",
"coverageArea": "Supervisory authority complaint",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence referenced a right to complain to a supervisory authority.",
"note": "Whether retained privacy-policy evidence referenced a right to complain to a supervisory authority.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.supervisory_authority_complaint_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.supervisory_authority_complaint_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "supervisory_authority",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-11T23:26:07.314Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "automated_decision_making_profiling_disclosure",
"coverageArea": "Automated decision-making / profiling disclosure",
"evidenceState": "not_testable",
"explanation": "Whether adapter-approved Article 13 evidence retained automated decision-making or profiling disclosure context for review.",
"note": "Whether adapter-approved Article 13 evidence retained automated decision-making or profiling disclosure context for review.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.automated_decision_making_profiling_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.automated_decision_making_profiling_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-11T23:26:07.314Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://example.invalid/privacy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "automated_decision_making_or_profiling",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Pre-consent runtime
Aggregate pre-consent storage count: 0
Assessment reconciliation: reconciled
{
"assessmentStatus": "checked",
"checklistItemId": "pre_consent_cookies_storage",
"coverageArea": "Non-essential pre-consent cookies/storage",
"evidenceState": "not_observed",
"explanation": "Whether non-essential cookies or browser storage were observed before a recorded consent action.",
"note": "Whether non-essential cookies or browser storage were observed before a recorded consent action.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.pre_consent_cookies_storage.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.pre_consent_cookies_storage"
},
"statusBasis": "The retained pre-consent storage inventory was classified and did not contain eligible non-essential storage. Essential, consent-management, security, and functional storage remains contextual evidence only.",
"retainedEvidence": {
"evidenceRefs": [
"Aggregate pre-consent storage count: 0",
"Assessment reconciliation: reconciled"
],
"cookiesSeenCount": 0,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained concrete cookie/storage evidence for storage timing; request-only tracking evidence is not used as storage proof.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"cookiesBeforeConsentCount": 0,
"selectedEvidenceArtifactId": "preConsentCookieOrStorageEvidence.missing",
"preConsentStorageAssessment": {
"status": "classified_zero",
"evidenceRows": [],
"provenWriteCount": 0,
"assessmentVersion": "pre-consent-storage-assessment-v1",
"unclassifiedCount": 0,
"reconciliationStatus": "reconciled",
"snapshotPresenceCount": 0,
"aggregateObservedCount": 0,
"classifiedEssentialCount": 0,
"classifiedNonEssentialCount": 0,
"attributedPreConsentRecordCount": 0,
"excludedFunctionalOrConsentCount": 0
},
"preConsentStorageAssessmentStatus": "classified_zero",
"rowLevelEssentialityEvidenceRetained": false,
"preConsentStorageClassificationLimitation": false,
"preconsentCookieOrStorageExactTimingRetained": false,
"eligibleNonEssentialCookieStorageFindingProjected": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Non-essential pre-consent cookies/storage is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
retained session replay / fingerprinting coverage summary
{
"assessmentStatus": "checked",
"checklistItemId": "session_replay_fingerprinting_review",
"coverageArea": "Session replay signal",
"evidenceState": "not_observed",
"explanation": "No eligible session replay, behavioral recording, or fingerprinting-like signal was observed in the tested context.",
"note": "No eligible session replay, behavioral recording, or fingerprinting-like signal was observed in the tested context.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.session_replay_fingerprinting_review.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.session_replay_fingerprinting_review"
},
"statusBasis": "Runtime vendor/fingerprinting checks completed for the tested context, and no eligible replay or fingerprinting finding was projected.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained session replay / fingerprinting coverage summary"
],
"sessionReplayCount": 0,
"missingEvidenceNeeded": [],
"sessionReplayObserved": false,
"fingerprintingObserved": false,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"sessionReplayRuntimeCoverageRetained": true,
"fingerprintingRuntimeCoverageRetained": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Session replay signal is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
retained fingerprinting/browser API coverage summary
{
"assessmentStatus": "checked",
"checklistItemId": "device_identification_fingerprinting_signal_observed",
"coverageArea": "Device identification / fingerprinting signal",
"evidenceState": "not_observed",
"explanation": "Whether browser/device entropy, fingerprinting, or identifier-like device collection signals were observed in retained runtime evidence.",
"note": "Whether browser/device entropy, fingerprinting, or identifier-like device collection signals were observed in retained runtime evidence.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.device_identification_fingerprinting_signal_observed.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.device_identification_fingerprinting_signal_observed"
},
"statusBasis": "Runtime fingerprinting/device-identification checks completed for the tested context and did not retain an eligible signal.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained fingerprinting/browser API coverage summary"
],
"missingEvidenceNeeded": [],
"fingerprintingObserved": false,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"runtimeEvidenceRetained": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"fingerprintingRuntimeCoverageRetained": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Device identification / fingerprinting signal is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
GPC observation and comparison
Bounded GPC observation completed. GPC was observed on the main-document request and browser property. The CMP's sale/sharing opt-out state was unavailable. No qualifying classified requests were observed in this bounded capture. Paired activity comparison: no observable response.
Bounded observation: complete. 3 retained request attempts; 0 blocked before transmission. Scope: main document and retained HTTP requests.
CMP GPC signal: unknown. Visible acknowledgment: not observed in the supported search.
| Signal | Baseline | GPC | Delta | Baseline only | Shared | GPC only |
|---|---|---|---|---|---|---|
| Cookies | 0 | 0 | 0 | 0 | 0 |
Transport security
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_https_delivery",
"coverageArea": "HTTPS delivery for scanned pages",
"evidenceState": "observed",
"explanation": "Whether the retained scanned page was served over HTTPS.",
"note": "Whether the retained scanned page was served over HTTPS.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_https_delivery.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_https_delivery"
},
"statusBasis": "The scanned page was served over HTTPS in the retained transport observation.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}HTTPS delivery for scanned pages is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Company / Legal
Privacy rights requests can be submitted at certscore.ai/privacy-request or by emailing [email protected].
© 2026 CertScore.ai, LLC. All rights reserved.
| 0 |
| Web storage | 0 | 0 | 0 | 0 | 0 | 0 |
| Trackers | 0 | 0 | 0 | 0 | 0 | 0 |
| Advertising / measurement | 0 | 0 | 0 | 0 | 0 | 0 |
| Consent / CMP | 0 | 0 | 0 | 0 | 0 | 0 |
Cookie/storage and CMP identity differences are descriptive snapshots. The response uses classified activity within the matched window, not an inferred consent decision.
{
"assessment": {
"contractVersion": "certscore.gpc-response-assessment.v3",
"generatedAt": "2026-09-11T23:26:19.551Z",
"status": "no_observable_response",
"findingTitle": "No observable GPC response",
"scoreEffect": "none",
"legalInterpretation": "not_assessed",
"comparison": {
"comparable": true,
"protocol": "passive_baseline_with_sec_gpc",
"baselineArtifact": {
"lane": "runtime_evidence",
"sha256": "e9282fc455de2964020252de8281223e40e7dc042a40e83762abd30c3eef1072",
"sizeBytes": 38342,
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/d957bb0c-7577-4a90-8360-82b444dc1abb/lanes/runtime_evidence/CanonicalEvidenceBundle.json"
},
"gpcArtifact": {
"lane": "gpc_observation",
"sha256": "fa7fb3724fe7b94ea59322193ca492661f2b5a5ad9a4051f91ff79ce9f13efb5",
"sizeBytes": 41612,
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/d957bb0c-7577-4a90-8360-82b444dc1abb/lanes/gpc_observation/CanonicalEvidenceBundle.json"
},
"enabledProof": {
"secGpcHeaderValue": "1",
"requestsWithSecGpc": 3,
"requestEventIds": [
"net_2",
"net_5",
"net_7"
],
"navigatorGlobalPrivacyControl": true
},
"delivery": {
"status": "verified",
"baseline": {
"contractVersion": "certscore.gpc-signal-observation.v1",
"expectedEnabled": false,
"documentUrlSha256": "55fec65354d1c37696aea284717d237375899b5bfded731191af99489c2e97b5",
"contextConfigSha256": "2c01f9f29c0e012648bf492ecade8fa330858be6cd066f749be47e8cad0c572e",
"capturedAtMs": 2902,
"documentStartedAtMs": 1525,
"frameCount": 1,
"frames": [
{
"documentUrlSha256": "55fec65354d1c37696aea284717d237375899b5bfded731191af99489c2e97b5",
"mainFrame": true,
"navigatorValue": false
}
],
"workerCount": 0,
"limitationKeys": []
},
"gpc": {
"contractVersion": "certscore.gpc-signal-observation.v1",
"expectedEnabled": true,
"documentUrlSha256": "55fec65354d1c37696aea284717d237375899b5bfded731191af99489c2e97b5",
"contextConfigSha256": "2c01f9f29c0e012648bf492ecade8fa330858be6cd066f749be47e8cad0c572e",
"prototypeCaptureBinding": {
"captureId": "2824326a-e3a3-42cd-ab19-c6eae92a018f",
"documentIdentitySource": "cdp_loader_id",
"documentToken": "68866B0D669D05BCE5D0E429C2216961"
},
"prototypeSessionSha256": "1c8c7d83b8b14aeeb80b4216b6921b4d2edf009d363c7dc73243cef5f85de91a",
"capturedAtMs": 2917,
"documentStartedAtMs": 1483,
"frameCount": 1,
"frames": [
{
"documentUrlSha256": "55fec65354d1c37696aea284717d237375899b5bfded731191af99489c2e97b5",
"mainFrame": true,
"navigatorValue": true
}
],
"workerCount": 0,
"limitationKeys": []
}
},
"coverage": {
"status": "complete",
"comparedThroughMs": 1377
},
"responseBasis": "no_qualified_reduction",
"deltas": {
"cookies": {
"baselineCount": 0,
"gpcCount": 0,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": [],
"baselineOnlyCount": 0,
"gpcOnlyCount": 0,
"sharedCount": 0,
"samplesTruncated": false
},
"webStorage": {
"baselineCount": 0,
"gpcCount": 0,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": [],
"baselineOnlyCount": 0,
"gpcOnlyCount": 0,
"sharedCount": 0,
"samplesTruncated": false
},
"trackers": {
"baselineCount": 0,
"gpcCount": 0,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": [],
"baselineOnlyCount": 0,
"gpcOnlyCount": 0,
"sharedCount": 0,
"samplesTruncated": false
},
"advertisingOrMeasurementActivity": {
"baselineCount": 0,
"gpcCount": 0,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": [],
"baselineOnlyCount": 0,
"gpcOnlyCount": 0,
"sharedCount": 0,
"samplesTruncated": false
},
"advertisingOrMarketingActivity": {
"baselineCount": 0,
"gpcCount": 0,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": [],
"baselineOnlyCount": 0,
"gpcOnlyCount": 0,
"sharedCount": 0,
"samplesTruncated": false
},
"consentOrCmpBehavior": {
"baselineCount": 0,
"gpcCount": 0,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": [],
"baselineOnlyCount": 0,
"gpcOnlyCount": 0,
"sharedCount": 0,
"samplesTruncated": false
}
},
"evidenceRefs": [
"net_2",
"net_5",
"net_7",
"s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/d957bb0c-7577-4a90-8360-82b444dc1abb/lanes/gpc_observation/CanonicalEvidenceBundle.json",
"s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/d957bb0c-7577-4a90-8360-82b444dc1abb/lanes/runtime_evidence/CanonicalEvidenceBundle.json"
],
"limitationKeys": []
},
"observation": {
"contractVersion": "certscore.gpc-bounded-observation.v1",
"scope": "main_document_and_retained_http_requests",
"status": "complete",
"sourceSha256": "fa7fb3724fe7b94ea59322193ca492661f2b5a5ad9a4051f91ff79ce9f13efb5",
"sessionSha256": "1c8c7d83b8b14aeeb80b4216b6921b4d2edf009d363c7dc73243cef5f85de91a",
"documentUrlSha256": "55fec65354d1c37696aea284717d237375899b5bfded731191af99489c2e97b5",
"delivery": {
"httpHeaderRetained": true,
"mainNavigatorReadbackRetained": true,
"fullContextVerified": true
},
"semanticProbe": "unavailable",
"registration": {
"basis": "current_recorded_state",
"sale": "unknown",
"sharing": "unknown",
"cmpGpcSignal": "unknown",
"causedByGpc": "not_established"
},
"acknowledgment": {
"observed": false,
"captureComplete": true
},
"requests": {
"count": 3,
"blockedBeforeTransmissionCount": 0,
"complete": true,
"fromMs": 1406,
"documentCommittedAtMs": 2066,
"throughMs": 2926,
"classifiedCount": 0,
"collectionCount": 0,
"evidenceIds": [],
"samplesTruncated": false
},
"limitationKeys": [],
"scoreEffect": "none",
"legalInterpretation": "not_assessed"
}
},
"californiaPolicy": {
"deductionPoints": 0,
"framework": "california"
},
"evidenceRefs": [
"s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/d957bb0c-7577-4a90-8360-82b444dc1abb/lanes/runtime_evidence/CanonicalEvidenceBundle.json",
"s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/d957bb0c-7577-4a90-8360-82b444dc1abb/lanes/gpc_observation/CanonicalEvidenceBundle.json",
"net_2",
"net_5",
"net_7"
]
}ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_tls_certificate",
"coverageArea": "Valid SSL/TLS certificate",
"evidenceState": "observed",
"explanation": "Whether a strict TLS probe verified the HTTPS origin certificate separately from the normal scanner runtime.",
"note": "Whether a strict TLS probe verified the HTTPS origin certificate separately from the normal scanner runtime.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_tls_certificate.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_tls_certificate"
},
"statusBasis": "Retained certificate validation verified the HTTPS origin certificate. Retained certificate evidence: https://ergoveritas.com/ presented CN=ergoveritas.com certificate valid Aug 6, 2026–Feb 19, 2027.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Valid SSL/TLS certificate is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_http_redirect",
"coverageArea": "HTTP redirects to HTTPS",
"evidenceState": "observed",
"explanation": "Whether an explicit HTTP-origin probe redirected to HTTPS.",
"note": "Whether an explicit HTTP-origin probe redirected to HTTPS.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_http_redirect.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_http_redirect"
},
"statusBasis": "The explicit HTTP-origin probe redirected to HTTPS.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}HTTP redirects to HTTPS is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_mixed_content",
"coverageArea": "Mixed content",
"evidenceState": "observed",
"explanation": "Whether HTTP subresources were observed or blocked on a retained HTTPS page.",
"note": "Whether HTTP subresources were observed or blocked on a retained HTTPS page.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_mixed_content.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_mixed_content"
},
"statusBasis": "No mixed-content HTTP subresources were retained for the scanned HTTPS page.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Mixed content is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_form_transport",
"coverageArea": "Observed form transport",
"evidenceState": "observed",
"explanation": "Whether observed forms resolved to HTTPS transport without submitting form data.",
"note": "Whether observed forms resolved to HTTPS transport without submitting form data.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_form_transport.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_form_transport"
},
"statusBasis": "No insecure observed form transport was retained for the scanned page.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/sentinels/privacy-evidence.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Observed form transport is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.