CertScore.ai report
Loading report
The report is ready; we’re loading its retained findings and evidence.
CertScore.ai report
The report is ready; we’re loading its retained findings and evidence.
Jul 13, 2026, 12:25:57 AM UTC
Page score
3 priority issues
1 page scanned
Overall, this scan points to a focused review rather than a site-wide breakdown. The review centers on visitor choice and pre-consent storage. Cookies/storage also appeared before any recorded consent action. Transport security checks were observed. No checklist items were technically limited in this retained scan. This overview reflects retained automated evidence and is a practical review aid, not a legal conclusion.
Each resource is counted once. Services group requests, cookies/storage and frames.
Requests35
Cookies & storage4
Embedded frames0
Priority review
{
"assessmentStatus": "review_signal",
"checklistItemId": "reject_all_path_availability",
"coverageArea": "Decline consent control",
"evidenceState": "observed",
"explanation": "Whether a first-layer reject, necessary-only, decline, refuse, or equivalent refusal option was observed on a sufficiently retained consent surface.",
"note": "Whether a first-layer reject, necessary-only, decline, refuse, or equivalent refusal option was observed on a sufficiently retained consent surface.",
"status": "Review signal",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.reject_all_path_availability.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.reject_all_path_availability"
},
"statusBasis": "No observable refusal path was retained before non-essential activity.",
"retainedEvidence": {
"evidenceRefs": [
"scan_runtime_artifacts.consent_control_assessment",
"Consent governance disclosure note: retained public materials did not clearly explain how users can revisit, change, withdraw, retain, renew, expire, or understand consent choices.",
"Evidence: complete pre-interaction consent-surface inspection",
"Evidence: classified non-essential pre-consent activity"
],
"scoreAttribution": "reject_all_path_availability",
"missingEvidenceNeeded": [
"Confirmed first-layer GDPR/ePrivacy cookie banner and same-surface accept/reject control inventory."
],
"rejectControlObserved": false,
"consentSurfaceObserved": false,
"selectedEvidenceReason": "Selected retained same-surface reject-path or post-reject comparison evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"consentRefusalPathConcern": {
"originKey": "consent.refusal_path.unavailable_before_nonessential_activity",
"canonicalConcernKey": "runtime_artifact:consent.refusal_path.unavailable_before_nonessential_activity",
"regulatoryChecklistEligibility": "review_signal"
},
"selectedEvidenceArtifactId": "rejectPathDepthAndAvailability",
"consentOperationalSurfaceConcern": {
"originKey": "consent.operational_surface.not_observed",
"canonicalConcernKey": "runtime_artifact:consent.operational_surface.not_observed"
},
"firstLayerCookieConsentBannerObserved": false,
"preconsentCookieOrTrackingActivityObserved": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": [],
"groupedEvidence": [],
"evidenceDetails": {
"policyEvidenceDetails": {
"assessmentStatus": "review_signal",
"evidenceRefs": [
"scan_runtime_artifacts.consent_control_assessment",
"Consent governance disclosure note: retained public materials did not clearly explain how users can revisit, change, withdraw, retain, renew, expire, or understand consent choices.",
"Evidence: complete pre-interaction consent-surface inspection",
"Evidence: classified non-essential pre-consent activity"
],
"explanation": "Whether a first-layer reject, necessary-only, decline, refuse, or equivalent refusal option was observed on a sufficiently retained consent surface.",
"regulatoryAreaId": "gdpr_eprivacy",
"regulatoryAreaTitle": "GDPR / ePrivacy",
"regulatoryMapping": [],
"missingOrIncompleteSourceSignals": [],
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.reject_all_path_availability.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.reject_all_path_availability"
},
"projectedFindings": [],
"retainedEvidence": {
"evidenceRefs": [
"scan_runtime_artifacts.consent_control_assessment",
"Consent governance disclosure note: retained public materials did not clearly explain how users can revisit, change, withdraw, retain, renew, expire, or understand consent choices.",
"Evidence: complete pre-interaction consent-surface inspection",
"Evidence: classified non-essential pre-consent activity"
],
"scoreAttribution": "reject_all_path_availability",
"missingEvidenceNeeded": [
"Confirmed first-layer GDPR/ePrivacy cookie banner and same-surface accept/reject control inventory."
],
"rejectControlObserved": false,
"consentSurfaceObserved": false,
"selectedEvidenceReason": "Selected retained same-surface reject-path or post-reject comparison evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"consentRefusalPathConcern": {
"originKey": "consent.refusal_path.unavailable_before_nonessential_activity",
"canonicalConcernKey": "runtime_artifact:consent.refusal_path.unavailable_before_nonessential_activity",
"regulatoryChecklistEligibility": "review_signal"
},
"selectedEvidenceArtifactId": "rejectPathDepthAndAvailability",
"consentOperationalSurfaceConcern": {
"originKey": "consent.operational_surface.not_observed",
"canonicalConcernKey": "runtime_artifact:consent.operational_surface.not_observed"
},
"firstLayerCookieConsentBannerObserved": false,
"preconsentCookieOrTrackingActivityObserved": true
},
"rowId": "reject_all_path_availability",
"rowLabel": "Decline consent control",
"rowNote": "Partial support from scan evidence; No observable refusal path was retained before non-essential activity.",
"statusBasis": "Partial support from scan evidence; No observable refusal path was retained before non-essential activity.",
"regulatoryConcernKind": "partial_rating",
"status": "Review signal"
}
},
"evidenceRefs": [
"scan_runtime_artifacts.consent_control_assessment",
"Consent governance disclosure note: retained public materials did not clearly explain how users can revisit, change, withdraw, retain, renew, expire, or understand consent choices.",
"Evidence: complete pre-interaction consent-surface inspection",
"Evidence: classified non-essential pre-consent activity"
],
"findingId": "regulatory_gap__gdpr_eprivacy__reject_all_path_availability"
}{
"assessmentStatus": "review_signal",
"checklistItemId": "pre_consent_cookies_storage",
"coverageArea": "Pre-consent storage classification review",
"evidenceState": "observed",
"explanation": "Pre-consent storage was observed, but one or more records could not be classified as essential or non-essential or could not be reconciled to the aggregate count. Review the retained storage inventory before drawing a conclusion.",
"note": "Pre-consent storage was observed, but one or more records could not be classified as essential or non-essential or could not be reconciled to the aggregate count. Review the retained storage inventory before drawing a conclusion.",
"status": "Review signal",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.pre_consent_cookies_storage.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.pre_consent_cookies_storage"
},
"statusBasis": "Pre-consent storage was observed, but one or more records could not be classified as essential or non-essential or could not be reconciled to the aggregate count. Review the retained storage inventory before drawing a conclusion.",
"retainedEvidence": {
"evidenceRefs": [
"__Host-next-auth.csrf-token (www.kbdlab.io): unknown, first observed 0.787s after scan start",
"__Secure-next-auth.callback-url (www.kbdlab.io): unknown, first observed 0.788s after scan start",
"_ga_H1SWTMGGJ4 (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"_ga (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"Aggregate pre-consent storage count: 4",
"Assessment reconciliation: reconciled"
],
"cookiesSeenCount": 4,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained concrete cookie/storage evidence for storage timing; request-only tracking evidence is not used as storage proof.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"cookiesBeforeConsentCount": 2,
"selectedEvidenceArtifactId": "preConsentCookieOrStorageEvidence.missing",
"preConsentStorageAssessment": {
"status": "partially_classified",
"evidenceRows": [
{
"name": "__Host-next-auth.csrf-token",
"party": "first_party",
"domain": "www.kbdlab.io",
"category": "unknown",
"storageType": "cookie",
"essentiality": "unknown",
"timingEvidence": "before_consent_write",
"exclusionReason": "functional_or_consent_storage",
"firstObservedMs": 787,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "unknown"
},
{
"name": "__Secure-next-auth.callback-url",
"party": "first_party",
"domain": "www.kbdlab.io",
"category": "unknown",
"storageType": "cookie",
"essentiality": "unknown",
"timingEvidence": "before_consent_write",
"exclusionReason": null,
"firstObservedMs": 788,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "unknown"
},
{
"name": "_ga_H1SWTMGGJ4",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
},
{
"name": "_ga",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"provenWriteCount": 0,
"assessmentVersion": "pre-consent-storage-assessment-v1",
"unclassifiedCount": 2,
"reconciliationStatus": "reconciled",
"snapshotPresenceCount": 2,
"aggregateObservedCount": 4,
"classifiedEssentialCount": 0,
"classifiedNonEssentialCount": 2,
"attributedPreConsentRecordCount": 4,
"excludedFunctionalOrConsentCount": 1
},
"excludedEssentialOrFunctionalRows": [
{
"name": "__Host-next-auth.csrf-token",
"party": "first_party",
"domain": "www.kbdlab.io",
"category": "unknown",
"storageType": "cookie",
"essentiality": "unknown",
"timingEvidence": "before_consent_write",
"exclusionReason": "functional_or_consent_storage",
"firstObservedMs": 787,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "unknown"
}
],
"preConsentStorageAssessmentStatus": "partially_classified",
"eligiblePreconsentCookieStorageRows": [
{
"name": "_ga_H1SWTMGGJ4",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
},
{
"name": "_ga",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"rowLevelEssentialityEvidenceRetained": true,
"firstPreconsentCookieOrStorageObservedMs": 4328,
"preConsentStorageClassificationLimitation": true,
"preconsentCookieOrStorageExactTimingRetained": false,
"eligibleNonEssentialCookieStorageFindingProjected": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": [],
"groupedEvidence": [],
"evidenceDetails": {
"policyEvidenceDetails": {
"assessmentStatus": "review_signal",
"evidenceRefs": [
"__Host-next-auth.csrf-token (www.kbdlab.io): unknown, first observed 0.787s after scan start",
"__Secure-next-auth.callback-url (www.kbdlab.io): unknown, first observed 0.788s after scan start",
"_ga_H1SWTMGGJ4 (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"_ga (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"Aggregate pre-consent storage count: 4",
"Assessment reconciliation: reconciled"
],
"explanation": "Pre-consent storage was observed, but one or more records could not be classified as essential or non-essential or could not be reconciled to the aggregate count. Review the retained storage inventory before drawing a conclusion.",
"regulatoryAreaId": "gdpr_eprivacy",
"regulatoryAreaTitle": "GDPR / ePrivacy",
"regulatoryMapping": [],
"missingOrIncompleteSourceSignals": [],
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.pre_consent_cookies_storage.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.pre_consent_cookies_storage"
},
"projectedFindings": [],
"retainedEvidence": {
"evidenceRefs": [
"__Host-next-auth.csrf-token (www.kbdlab.io): unknown, first observed 0.787s after scan start",
"__Secure-next-auth.callback-url (www.kbdlab.io): unknown, first observed 0.788s after scan start",
"_ga_H1SWTMGGJ4 (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"_ga (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"Aggregate pre-consent storage count: 4",
"Assessment reconciliation: reconciled"
],
"cookiesSeenCount": 4,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained concrete cookie/storage evidence for storage timing; request-only tracking evidence is not used as storage proof.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"cookiesBeforeConsentCount": 2,
"selectedEvidenceArtifactId": "preConsentCookieOrStorageEvidence.missing",
"preConsentStorageAssessment": {
"status": "partially_classified",
"evidenceRows": [
{
"name": "__Host-next-auth.csrf-token",
"party": "first_party",
"domain": "www.kbdlab.io",
"category": "unknown",
"storageType": "cookie",
"essentiality": "unknown",
"timingEvidence": "before_consent_write",
"exclusionReason": "functional_or_consent_storage",
"firstObservedMs": 787,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "unknown"
},
{
"name": "__Secure-next-auth.callback-url",
"party": "first_party",
"domain": "www.kbdlab.io",
"category": "unknown",
"storageType": "cookie",
"essentiality": "unknown",
"timingEvidence": "before_consent_write",
"exclusionReason": null,
"firstObservedMs": 788,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "unknown"
},
{
"name": "_ga_H1SWTMGGJ4",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
},
{
"name": "_ga",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"provenWriteCount": 0,
"assessmentVersion": "pre-consent-storage-assessment-v1",
"unclassifiedCount": 2,
"reconciliationStatus": "reconciled",
"snapshotPresenceCount": 2,
"aggregateObservedCount": 4,
"classifiedEssentialCount": 0,
"classifiedNonEssentialCount": 2,
"attributedPreConsentRecordCount": 4,
"excludedFunctionalOrConsentCount": 1
},
"excludedEssentialOrFunctionalRows": [
{
"name": "__Host-next-auth.csrf-token",
"party": "first_party",
"domain": "www.kbdlab.io",
"category": "unknown",
"storageType": "cookie",
"essentiality": "unknown",
"timingEvidence": "before_consent_write",
"exclusionReason": "functional_or_consent_storage",
"firstObservedMs": 787,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "unknown"
}
],
"preConsentStorageAssessmentStatus": "partially_classified",
"eligiblePreconsentCookieStorageRows": [
{
"name": "_ga_H1SWTMGGJ4",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
},
{
"name": "_ga",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"rowLevelEssentialityEvidenceRetained": true,
"firstPreconsentCookieOrStorageObservedMs": 4328,
"preConsentStorageClassificationLimitation": true,
"preconsentCookieOrStorageExactTimingRetained": false,
"eligibleNonEssentialCookieStorageFindingProjected": false
},
"rowId": "pre_consent_cookies_storage",
"rowLabel": "Pre-consent storage classification review",
"rowNote": "Cookies or browser storage were observed before consent, but the scan could not determine whether every item was essential or non-essential.",
"statusBasis": "Cookies or browser storage were observed before consent, but the scan could not determine whether every item was essential or non-essential.",
"regulatoryConcernKind": "partial_rating",
"status": "Review signal"
}
},
"evidenceRefs": [
"__Host-next-auth.csrf-token (www.kbdlab.io): unknown, first observed 0.787s after scan start",
"__Secure-next-auth.callback-url (www.kbdlab.io): unknown, first observed 0.788s after scan start",
"_ga_H1SWTMGGJ4 (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"_ga (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"Aggregate pre-consent storage count: 4",
"Assessment reconciliation: reconciled"
],
"findingId": "regulatory_gap__gdpr_eprivacy__pre_consent_cookies_storage"
}{
"assessmentStatus": "review_signal",
"checklistItemId": "session_replay_fingerprinting_review",
"coverageArea": "Session replay signal",
"evidenceState": "observed",
"explanation": "CertScore.ai observed session replay or behavioral analytics vendors not observed pre-consent in retained evidence, including Microsoft Clarity. Because these tools can capture user interaction behavior, review consent timing, disclosure, masking/exclusion settings, sensitive-page coverage, and withdrawal controls.",
"note": "CertScore.ai observed session replay or behavioral analytics vendors not observed pre-consent in retained evidence, including Microsoft Clarity. Because these tools can capture user interaction behavior, review consent timing, disclosure, masking/exclusion settings, sensitive-page coverage, and withdrawal controls.",
"status": "Review signal",
"tone": "warning",
"pipeline": {
"projectionStage": "unified_finding",
"concernPolicyKey": "gdpr_eprivacy_coverage.session_replay_fingerprinting_review.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.session_replay_fingerprinting_review"
},
"statusBasis": "Selected the strongest retained canonical coverage evidence available for this row.",
"retainedEvidence": {
"status": "Review signal",
"evidenceRefs": [
"Session replay observed",
"Signal: Session replay runtime detected",
"Signal: Session replay runtime vendors",
"Signal: Session replay tool detected",
"Evidence flag: contradiction_runtime_artifact_retained",
"Evidence flag: privacy.session_replay_runtime_detected"
],
"findingEntities": [
{
"id": "session_replay_observed",
"entities": {
"runtimeVendors": [
"Microsoft Clarity"
],
"runtimeRequestUrls": [
"https://www.clarity.ms",
"https://www.clarity.ms/tag/m97n86hou6",
"https://scripts.clarity.ms/0.8.67/clarity.js",
"https://r.clarity.ms/collect"
],
"observedTrackingVendors": [
"Microsoft Clarity"
],
"sessionReplayEvidenceSummary": [
"{\"artifactCount\":3,\"collectionEndpointObserved\":true,\"consentStates\":[\"pre_consent\"],\"coverageRetained\":true,\"firstSeenMs\":2132,\"libraryOnly\":false,\"preConsentObserved\":true,\"requestUrls\":[\"https://www.clarity.ms/tag/m97n86hou6\",\"https://scripts.clarity.ms/0.8.67/clarity.js\",\"https://r.clarity.ms/collect\"],\"vendors\":[\"Microsoft Clarity\"]}"
],
"session_replay_runtime_vendors": [
"Microsoft Clarity"
]
},
"sourceRefs": [
"Signal: Session replay runtime detected",
"Signal: Session replay runtime vendors",
"Signal: Session replay tool detected"
],
"evidenceFlags": [
"privacy.session_replay_runtime_detected",
"privacy.session_replay_runtime_vendors",
"commerce.session_replay_tool_detected"
]
}
],
"evidenceHighlights": [
"\"Microsoft Clarity\", \"category\": \"session_replay\", \"preConsent\": false"
],
"missingEvidenceNeeded": [],
"sessionReplayEvidence": {
"vendors": [
"Microsoft Clarity"
],
"firstSeenMs": 2132,
"requestUrls": [
"https://www.clarity.ms/tag/m97n86hou6",
"https://scripts.clarity.ms/0.8.67/clarity.js",
"https://r.clarity.ms/collect"
],
"consentStates": [
"pre_consent"
],
"vendorDisclosed": false,
"postAcceptObserved": false,
"preConsentObserved": true,
"libraryLoadObserved": true,
"vendorDisclosureGap": false,
"collectionEndpointObserved": true,
"vendorDisclosureMatchedCount": 0,
"vendorDisclosureUnmatchedCount": 0,
"postChoiceConsentControlsObserved": false,
"vendorDisclosureComparisonObserved": false
},
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "unified_finding"
},
"projectedFindings": [
{
"id": "session_replay_observed",
"label": "Session replay observed",
"severity": "high"
}
],
"missingOrIncompleteSourceSignals": [],
"groupedEvidence": [],
"evidenceDetails": {
"policyEvidenceDetails": {
"assessmentStatus": "review_signal",
"evidenceRefs": [
"Session replay observed",
"Signal: Session replay runtime detected",
"Signal: Session replay runtime vendors",
"Signal: Session replay tool detected",
"Evidence flag: contradiction_runtime_artifact_retained",
"Evidence flag: privacy.session_replay_runtime_detected"
],
"explanation": "CertScore.ai observed session replay or behavioral analytics vendors not observed pre-consent in retained evidence, including Microsoft Clarity. Because these tools can capture user interaction behavior, review consent timing, disclosure, masking/exclusion settings, sensitive-page coverage, and withdrawal controls.",
"regulatoryAreaId": "gdpr_eprivacy",
"regulatoryAreaTitle": "GDPR / ePrivacy",
"regulatoryMapping": [],
"missingOrIncompleteSourceSignals": [],
"pipeline": {
"projectionStage": "unified_finding",
"concernPolicyKey": "gdpr_eprivacy_coverage.session_replay_fingerprinting_review.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.session_replay_fingerprinting_review"
},
"projectedFindings": [
{
"id": "session_replay_observed",
"label": "Session replay observed",
"severity": "high"
}
],
"retainedEvidence": {
"status": "Review signal",
"evidenceRefs": [
"Session replay observed",
"Signal: Session replay runtime detected",
"Signal: Session replay runtime vendors",
"Signal: Session replay tool detected",
"Evidence flag: contradiction_runtime_artifact_retained",
"Evidence flag: privacy.session_replay_runtime_detected"
],
"findingEntities": [
{
"id": "session_replay_observed",
"entities": {
"runtimeVendors": [
"Microsoft Clarity"
],
"runtimeRequestUrls": [
"https://www.clarity.ms",
"https://www.clarity.ms/tag/m97n86hou6",
"https://scripts.clarity.ms/0.8.67/clarity.js",
"https://r.clarity.ms/collect"
],
"observedTrackingVendors": [
"Microsoft Clarity"
],
"sessionReplayEvidenceSummary": [
"{\"artifactCount\":3,\"collectionEndpointObserved\":true,\"consentStates\":[\"pre_consent\"],\"coverageRetained\":true,\"firstSeenMs\":2132,\"libraryOnly\":false,\"preConsentObserved\":true,\"requestUrls\":[\"https://www.clarity.ms/tag/m97n86hou6\",\"https://scripts.clarity.ms/0.8.67/clarity.js\",\"https://r.clarity.ms/collect\"],\"vendors\":[\"Microsoft Clarity\"]}"
],
"session_replay_runtime_vendors": [
"Microsoft Clarity"
]
},
"sourceRefs": [
"Signal: Session replay runtime detected",
"Signal: Session replay runtime vendors",
"Signal: Session replay tool detected"
],
"evidenceFlags": [
"privacy.session_replay_runtime_detected",
"privacy.session_replay_runtime_vendors",
"commerce.session_replay_tool_detected"
]
}
],
"evidenceHighlights": [
"\"Microsoft Clarity\", \"category\": \"session_replay\", \"preConsent\": false"
],
"missingEvidenceNeeded": [],
"sessionReplayEvidence": {
"vendors": [
"Microsoft Clarity"
],
"firstSeenMs": 2132,
"requestUrls": [
"https://www.clarity.ms/tag/m97n86hou6",
"https://scripts.clarity.ms/0.8.67/clarity.js",
"https://r.clarity.ms/collect"
],
"consentStates": [
"pre_consent"
],
"vendorDisclosed": false,
"postAcceptObserved": false,
"preConsentObserved": true,
"libraryLoadObserved": true,
"vendorDisclosureGap": false,
"collectionEndpointObserved": true,
"vendorDisclosureMatchedCount": 0,
"vendorDisclosureUnmatchedCount": 0,
"postChoiceConsentControlsObserved": false,
"vendorDisclosureComparisonObserved": false
},
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "unified_finding"
},
"rowId": "session_replay_fingerprinting_review",
"rowLabel": "Session replay signal",
"rowNote": "Session replay or behavioral analytics signals were observed: Microsoft Clarity; first seen 2.13s after scan start; before any recorded consent action.",
"statusBasis": "Session replay or behavioral analytics signals were observed: Microsoft Clarity; first seen 2.13s after scan start; before any recorded consent action.",
"regulatoryConcernKind": "partial_rating",
"status": "Review signal"
}
},
"evidenceRefs": [
"Session replay observed",
"Signal: Session replay runtime detected",
"Signal: Session replay runtime vendors",
"Signal: Session replay tool detected",
"Evidence flag: contradiction_runtime_artifact_retained",
"Evidence flag: privacy.session_replay_runtime_detected"
],
"findingId": "regulatory_gap__gdpr_eprivacy__session_replay_fingerprinting_review"
}0s
Scan start
Public page observation began
0.79s
Cookie/storage
Cookie/storage first observed
0.99s
3P request
3P request first observed
2.13s
Session replay
Session replay first observed
2.62s
Analytics
Analytics first observed
5.19s
Observation end
Retained scan window closed
Supporting evidence
39 distinct resources = 35 requests + 4 cookies & storage. Services group these resources.
Type | Priority legendShows the highest priority among the service’s resources. Expand the service to inspect individual resources. | Domain | Site relationship | JSON evidence | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 3 | Google Analytics | Analytics | Policy disclosure · UnknownGoogle Analytics Review scope: retained site policy from the homepage scan; this is a disclosure lookup, not a finding about compliance. No verified retained policy text is available for this lookup. | Location detailsGoogle Analytics Server locations describe the endpoint associated with the captured browser response. They may be CDN edges and do not establish subsequent processing or storage locations. No server IP is available in this inventory entry. Historical evidence may not include a destination summary. For newly assessed requests, a service-worker, failed or incomplete response may not expose an address; check retained connection evidence for the reason. 1 of 1 request events assessed; 1 without a retained server IP. Provider headquarters: US Transfer mechanism: Mechanism not assessed US-controlled vendor; mechanism requires current vendor/legal verification. Registry reference date: 2026-07-23. This is registry context, not verification of this site's transfer arrangements. Corporate headquartersGoogle LLC Google identifies Mountain View, California as its headquarters. This does not identify a customer's regional Google contracting entity or Alphabet's headquarters. Sources checked 2026-09-07 Headquarters and network operator are distinct; neither establishes this site's contracting entity or subsequent data processing locations. | 2.62s | kbdlab.io Service domains
| Mixed | Captured on 1 page | |||
| 1 | Google Tag Manager | Tag management | Policy disclosure · UnknownGoogle Tag Manager Review scope: retained site policy from the homepage scan; this is a disclosure lookup, not a finding about compliance. No verified retained policy text is available for this lookup. | Location detailsGoogle Tag Manager Server locations describe the endpoint associated with the captured browser response. They may be CDN edges and do not establish subsequent processing or storage locations. No server IP is available in this inventory entry. Historical evidence may not include a destination summary. For newly assessed requests, a service-worker, failed or incomplete response may not expose an address; check retained connection evidence for the reason. 1 of 1 request events assessed; 1 without a retained server IP. Provider headquarters: US Transfer mechanism: Mechanism not assessed US-controlled vendor; mechanism requires current vendor/legal verification. Registry reference date: 2026-07-23. This is registry context, not verification of this site's transfer arrangements. Corporate headquartersGoogle LLC Google identifies Mountain View, California as its headquarters. This does not identify a customer's regional Google contracting entity or Alphabet's headquarters. Sources checked 2026-09-07 Headquarters and network operator are distinct; neither establishes this site's contracting entity or subsequent data processing locations. | 2.13s | www.googletagmanager.com | Third party | Captured on 1 page | |||
| 3 | Microsoft Clarity | Session replay | Policy disclosure · UnknownMicrosoft Clarity Review scope: retained site policy from the homepage scan; this is a disclosure lookup, not a finding about compliance. No verified retained policy text is available for this lookup. | Location detailsMicrosoft Clarity Server locations describe the endpoint associated with the captured browser response. They may be CDN edges and do not establish subsequent processing or storage locations. No server IP is available in this inventory entry. Historical evidence may not include a destination summary. For newly assessed requests, a service-worker, failed or incomplete response may not expose an address; check retained connection evidence for the reason. 4 of 4 request events assessed; 4 without a retained server IP. Provider headquarters: US Transfer mechanism: Mechanism not assessed Headquarters reference only; this vendor's transfer arrangements have not been assessed. Registry reference date: 2026-09-07. This is registry context, not verification of this site's transfer arrangements. Corporate headquartersMicrosoft Corporation Microsoft identifies Redmond, Washington as its global headquarters; this does not identify a regional contracting entity. Sources checked 2026-09-07 Headquarters and network operator are distinct; neither establishes this site's contracting entity or subsequent data processing locations. | 2.13s | r.clarity.ms Service domains
| Third party | Captured on 1 page | |||
| 1 | Vercel Speed Insights | Performance monitoring | Policy disclosure · UnknownVercel Speed Insights Review scope: retained site policy from the homepage scan; this is a disclosure lookup, not a finding about compliance. No verified retained policy text is available for this lookup. | Location detailsVercel Speed Insights Server locations describe the endpoint associated with the captured browser response. They may be CDN edges and do not establish subsequent processing or storage locations. No server IP is available in this inventory entry. Historical evidence may not include a destination summary. For newly assessed requests, a service-worker, failed or incomplete response may not expose an address; check retained connection evidence for the reason. 2 of 2 request events assessed; 2 without a retained server IP. Provider headquarters: Unknown Transfer mechanism: Mechanism not assessed Corporate headquartersVercel Inc. No verified headquarters reference available. Headquarters and network operator are distinct; neither establishes this site's contracting entity or subsequent data processing locations. | 1.55s | vitals.vercel-insights.com | Third party | Captured on 1 page |
These resources were observed during the scan, but the retained evidence does not fully establish which integration loaded them. A service may be identifiable even when its loading origin is not.
They are grouped here for review, not as a parent–child relationship. This uncertainty does not itself indicate a risk or change their priority.
4 distinct services, including child services
Evidence RatingsStarting page
29 rows
CertScore.ai can make mistakes. Verify all findings.
Signal SnapshotStarting page
No consent-platform identity was retained in the completed scan context.
Initial control inspection
Not observed
Not observed
Not observed
Initial visit · first layer
Not observed
Not observed
Not observed
Initial visit · first layer
CMP identity and control context are retained in the canonical consent projection.
complete ConsentControlAssessment v2
{
"assessmentStatus": "checked",
"checklistItemId": "consent_surface_observed",
"coverageArea": "Consent mechanism",
"evidenceState": "not_observed",
"explanation": "Whether an actionable cookie/consent banner or CMP preference surface was observed in the tested context.",
"note": "Whether an actionable cookie/consent banner or CMP preference surface was observed in the tested context.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.consent_surface_observed.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.consent_surface_observed"
},
"statusBasis": "No operational consent surface was retained in the tested context.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: complete ConsentControlAssessment v2"
],
"consentSurfaceState": "not_observed",
"missingEvidenceNeeded": [],
"consentSurfaceObserved": false,
"selectedEvidenceReason": "Retained evidence did not confirm an uncontaminated first-layer GDPR/ePrivacy cookie/CMP consent surface.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "consentControlLifecycleEvidence.surfaceClassification"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}No remediation is established by this check alone. Retain its evidence and reassess after relevant changes.
runtime capture completed
{
"assessmentStatus": "checked",
"checklistItemId": "cmp_framework_signal_observed",
"coverageArea": "CMP framework",
"evidenceState": "not_observed",
"explanation": "Whether a consent-management framework, CMP vendor, or CMP runtime signal was observed in the pre-consent/public-web context.",
"note": "Whether a consent-management framework, CMP vendor, or CMP runtime signal was observed in the pre-consent/public-web context.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.cmp_framework_signal_observed.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.cmp_framework_signal_observed"
},
"statusBasis": "Runtime consent/CMP checks completed for the tested context and did not retain a CMP framework signal.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: runtime capture completed"
],
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"cmpFrameworkSignalObserved": false,
"selectedEvidenceArtifactId": "coverage_policy"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}CMP framework is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
scan_runtime_artifacts.consent_control_assessment
Consent governance disclosure note: retained public materials did not clearly explain how users can revisit, change, withdraw, retain, renew, expire, or understand consent choices.
complete pre-interaction consent-surface inspection
{
"assessmentStatus": "review_signal",
"checklistItemId": "reject_all_path_availability",
"coverageArea": "Decline consent control",
"evidenceState": "observed",
"explanation": "Whether a first-layer reject, necessary-only, decline, refuse, or equivalent refusal option was observed on a sufficiently retained consent surface.",
"note": "Whether a first-layer reject, necessary-only, decline, refuse, or equivalent refusal option was observed on a sufficiently retained consent surface.",
"status": "Review signal",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.reject_all_path_availability.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.reject_all_path_availability"
},
"statusBasis": "No observable refusal path was retained before non-essential activity.",
"retainedEvidence": {
"evidenceRefs": [
"scan_runtime_artifacts.consent_control_assessment",
"Consent governance disclosure note: retained public materials did not clearly explain how users can revisit, change, withdraw, retain, renew, expire, or understand consent choices.",
"Evidence: complete pre-interaction consent-surface inspection",
"Evidence: classified non-essential pre-consent activity"
],
"scoreAttribution": "reject_all_path_availability",
"missingEvidenceNeeded": [
"Confirmed first-layer GDPR/ePrivacy cookie banner and same-surface accept/reject control inventory."
],
"rejectControlObserved": false,
"consentSurfaceObserved": false,
"selectedEvidenceReason": "Selected retained same-surface reject-path or post-reject comparison evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"consentRefusalPathConcern": {
"originKey": "consent.refusal_path.unavailable_before_nonessential_activity",
"canonicalConcernKey": "runtime_artifact:consent.refusal_path.unavailable_before_nonessential_activity",
"regulatoryChecklistEligibility": "review_signal"
},
"selectedEvidenceArtifactId": "rejectPathDepthAndAvailability",
"consentOperationalSurfaceConcern": {
"originKey": "consent.operational_surface.not_observed",
"canonicalConcernKey": "runtime_artifact:consent.operational_surface.not_observed"
},
"firstLayerCookieConsentBannerObserved": false,
"preconsentCookieOrTrackingActivityObserved": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}complete pre-interaction consent-surface inspection
{
"assessmentStatus": "checked",
"checklistItemId": "accept_consent_control",
"coverageArea": "Accept consent control",
"evidenceState": "not_observed",
"explanation": "Whether a first-layer accept, accept-all, allow-all, or agree control was observed on the retained consent surface.",
"note": "Whether a first-layer accept, accept-all, allow-all, or agree control was observed on the retained consent surface.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.accept_consent_control.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.accept_consent_control"
},
"statusBasis": "No accept control was retained because no operational consent surface was retained.",
"retainedEvidence": {
"scoreEffect": "none",
"evidenceRefs": [
"Evidence: complete pre-interaction consent-surface inspection"
],
"acceptControlObserved": false,
"missingEvidenceNeeded": [],
"consentSurfaceObserved": false,
"selectedEvidenceReason": "Selected retained same-surface accept consent control evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"selectedEvidenceArtifactId": "firstLayerConsentChoices.acceptControl",
"consentOperationalSurfaceConcern": {
"originKey": "consent.operational_surface.not_observed",
"canonicalConcernKey": "runtime_artifact:consent.operational_surface.not_observed"
},
"firstLayerCookieConsentBannerObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}No remediation is established by this check alone. Retain its evidence and reassess after relevant changes.
complete pre-interaction consent-surface inspection
{
"assessmentStatus": "checked",
"checklistItemId": "options_settings_preferences_control",
"coverageArea": "Options / settings / preferences control",
"evidenceState": "not_observed",
"explanation": "Whether a first-layer options, settings, preferences, or manage-preferences control was observed on the retained consent surface.",
"note": "Whether a first-layer options, settings, preferences, or manage-preferences control was observed on the retained consent surface.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.options_settings_preferences_control.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.options_settings_preferences_control"
},
"statusBasis": "No options control was retained because no operational consent surface was retained.",
"retainedEvidence": {
"scoreEffect": "none",
"evidenceRefs": [
"Evidence: complete pre-interaction consent-surface inspection"
],
"missingEvidenceNeeded": [],
"consentSurfaceObserved": false,
"optionsControlObserved": false,
"selectedEvidenceReason": "Selected retained same-surface options/settings/preferences control evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"selectedEvidenceArtifactId": "firstLayerConsentChoices.optionsControl",
"consentOperationalSurfaceConcern": {
"originKey": "consent.operational_surface.not_observed",
"canonicalConcernKey": "runtime_artifact:consent.operational_surface.not_observed"
},
"firstLayerCookieConsentBannerObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}No remediation is established by this check alone. Retain its evidence and reassess after relevant changes.
cookie policy or cookie disclosure surface retained
Not confirmed: granular named-cookie inventory
Not confirmed: cookie preference interface
{
"assessmentStatus": "checked",
"checklistItemId": "cookie_notice_policy_availability",
"coverageArea": "Cookie notice / cookie policy availability",
"evidenceState": "observed",
"explanation": "Whether a cookie notice, cookie policy, cookie settings surface, or equivalent cookie disclosure surface was retained.",
"note": "Whether a cookie notice, cookie policy, cookie settings surface, or equivalent cookie disclosure surface was retained.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.cookie_notice_policy_availability.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.cookie_notice_policy_availability"
},
"statusBasis": "A durable cookie disclosure surface was retained in the tested context; a granular named-cookie inventory or preference interface was not confirmed.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: cookie policy or cookie disclosure surface retained",
"Not confirmed: granular named-cookie inventory",
"Not confirmed: cookie preference interface",
"Policy URL: https://kbdlab.io/privacy-policy"
],
"cookiePolicyUrls": [
"https://kbdlab.io/privacy-policy"
],
"cookiePolicyPresent": true,
"cookieNoticeObserved": true,
"observedPolicyTopics": [
"cookies",
"analytics",
"advertising",
"do_not_sell_or_share",
"california_privacy_rights",
"third_party_disclosures"
],
"missingEvidenceNeeded": [],
"observedPolicyControls": [
"consent_withdrawal"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"selectedEvidenceArtifactId": "coverage_policy",
"preferenceInterfaceConfirmed": false,
"granularCookieInventoryConfirmed": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Cookie notice / cookie policy availability is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Tracking & embedded content · Starting page
Third-party tracking observed before recorded consent
Review issue: Trackers fired before consent interaction
Review issue: Pre-consent tracking incidents detected
{
"assessmentStatus": "review_signal",
"checklistItemId": "pre_consent_third_party_tracking",
"coverageArea": "Pre-consent non-essential tracking",
"evidenceState": "not_observed",
"explanation": "High priority pre-consent tracker inventory was retained without a promotion-eligible normalized concern or unified finding: Microsoft Clarity - Session replay (2.13s). Tracking is not confirmed from grouped inventory alone. This row is limited to concrete 3rd party tracker/request evidence retained before a recorded consent choice.",
"note": "High priority pre-consent tracker inventory was retained without a promotion-eligible normalized concern or unified finding: Microsoft Clarity - Session replay (2.13s). Tracking is not confirmed from grouped inventory alone. This row is limited to concrete 3rd party tracker/request evidence retained before a recorded consent choice.",
"status": "Not confirmed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_fallback",
"concernPolicyKey": "gdpr_eprivacy.pre_consent_third_party_tracking.tracker_inventory.high",
"ws01EvidenceRole": "retained_pre_consent_tracker_inventory",
"wc01NormalizedConcernKey": "pre_consent_third_party_tracking"
},
"statusBasis": "High priority pre-consent tracker inventory was retained without a promotion-eligible normalized concern or unified finding: Microsoft Clarity - Session replay (2.13s). Tracking is not confirmed from grouped inventory alone.",
"retainedEvidence": {
"tagManagerOnly": false,
"trackerPriority": "high",
"trackerPriorityLabel": "High",
"missingEvidenceNeeded": [
"CertScore.unifiedFinding.preconsent_tracking: Grouped tracker inventory remains review evidence unless the canonical promotion-grade sequence contract passes."
],
"serviceConnectionOnly": false,
"selectedEvidenceReason": "Selected retained pre-consent request/vendor timing evidence; storage evidence is evaluated separately.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"selectedEvidenceArtifactId": "preConsentTrackingRequestEvidence.missing",
"trackingEvidenceAssessment": {
"result": "not_confirmed_from_grouped_inventory",
"scoreEffect": "review"
},
"contextualInfrastructureOnly": false,
"preconsentThirdPartyTrackerGroups": [
{
"party": "third_party",
"vendor": "Microsoft Clarity",
"purpose": "Session replay",
"priority": "high",
"firstSeenMs": 2132
},
{
"party": "third_party",
"vendor": "Google Analytics",
"purpose": "Analytics",
"priority": "medium",
"firstSeenMs": 2128
}
],
"preconsentThirdPartyTrackingVendors": [
"Microsoft Clarity"
],
"preconsentThirdPartyTrackerGroupCount": 2,
"firstPreconsentThirdPartyTrackingObservedMs": 2132,
"selectedPreconsentThirdPartyTrackingVendors": [
"Microsoft Clarity"
]
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": [
{
"field": "CertScore.unifiedFinding.preconsent_tracking",
"actual": "tracker inventory only",
"source": "CertScore.ai",
"expected": "promotion-eligible normalized concern and unified finding",
"whyNeeded": "Grouped tracker inventory remains review evidence unless the canonical promotion-grade sequence contract passes."
}
]
}retained pre-consent iframe inventory
{
"assessmentStatus": "checked",
"checklistItemId": "third_party_iframe_pre_consent",
"coverageArea": "3rd party iframes before consent",
"evidenceState": "not_observed",
"explanation": "Whether retained scanner evidence showed known 3rd party iframe embeds before a recorded consent action.",
"note": "Whether retained scanner evidence showed known 3rd party iframe embeds before a recorded consent action.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.third_party_iframe_pre_consent.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.third_party_iframe_pre_consent"
},
"statusBasis": "Retained iframe inventory did not show known 3rd party iframe embeds before a recorded consent action.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained pre-consent iframe inventory"
],
"missingEvidenceNeeded": [],
"preConsentIframeCount": 0,
"iframeObservationCount": 0,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}3rd party iframes before consent is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
retained pre-consent embedded-content inventory
{
"assessmentStatus": "checked",
"checklistItemId": "social_media_embed_pre_consent",
"coverageArea": "Social/media embeds or plugins loaded before consent",
"evidenceState": "not_observed",
"explanation": "Whether retained network/runtime evidence showed a social, video, media embed, social pixel, or plugin provider loading before a recorded consent action.",
"note": "Whether retained network/runtime evidence showed a social, video, media embed, social pixel, or plugin provider loading before a recorded consent action.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.social_media_embed_pre_consent.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.social_media_embed_pre_consent"
},
"statusBasis": "Retained embedded-content checks did not show a social/media embed, plugin, widget, or pixel provider request before consent. Plain outbound links are not treated as evidence for this row.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained pre-consent embedded-content inventory"
],
"placeholderDetected": false,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"socialMediaEmbedObservationCount": 0
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Social/media embeds or plugins loaded before consent is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
EmbeddedContentObservationCount: 0
{
"assessmentStatus": "checked",
"checklistItemId": "embedded_content_pre_consent",
"coverageArea": "Embedded third-party services before consent",
"evidenceState": "not_observed",
"explanation": "Whether retained scanner evidence showed iframe, embed, widget, or visibly integrated third-party services before a recorded consent action. This row does not represent all background analytics or network requests.",
"note": "Whether retained scanner evidence showed iframe, embed, widget, or visibly integrated third-party services before a recorded consent action. This row does not represent all background analytics or network requests.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.embedded_content_pre_consent.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.embedded_content_pre_consent"
},
"statusBasis": "Iframe/runtime checks completed for the tested context and did not retain a concrete 3rd party embedded-content iframe before consent.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained pre-consent embedded-content inventory"
],
"missingEvidenceNeeded": [],
"preConsentIframeCount": 0,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"embeddedContentObservationCount": 0
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Embedded third-party services before consent is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Policy and transparency · Starting page
Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceprivacy notice link/surface retained
Limitation: substantive policy body not retained
Policy URL: https://kbdlab.io/privacy-policy
{
"assessmentStatus": "checked",
"checklistItemId": "privacy_notice_availability",
"coverageArea": "Privacy notice link/surface discovered",
"evidenceState": "observed",
"explanation": "Whether a reachable privacy notice or privacy policy link/surface was retained. This row does not by itself confirm that substantive notice content was available.",
"note": "Whether a reachable privacy notice or privacy policy link/surface was retained. This row does not by itself confirm that substantive notice content was available.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.privacy_notice_availability.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.privacy_notice_availability"
},
"statusBasis": "A privacy-notice link or page surface was reachable, but substantive notice content was not available in the retained rendered text. Row-specific transparency disclosures remain unconfirmed.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: privacy notice link/surface retained",
"Limitation: substantive policy body not retained",
"Policy URL: https://kbdlab.io/privacy-policy"
],
"signalObserved": "surface_only_substantive_content_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"policyEvidenceAssessment": {
"result": "disclosure_observed",
"scoreEffect": "canonical_policy",
"topicRelevance": "direct",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "moderate",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"policySurfaceSummary": {
"scanStartedAt": "2026-07-13T00:25:57.617Z",
"observedTopics": [
"cookies",
"analytics",
"advertising",
"do_not_sell_or_share",
"california_privacy_rights",
"third_party_disclosures",
"consent_withdrawal",
"controller_contact",
"processing_purposes",
"recipients_or_vendor_categories",
"data_subject_rights",
"contact_privacy"
],
"cookiePolicyUrls": [],
"cookieDisclosures": [],
"mentionedControls": [
"consent_withdrawal"
],
"privacyPolicySize": null,
"privacyPolicyUrls": [
"https://kbdlab.io/privacy-policy"
],
"cookie_disclosures": [],
"policySectionCount": 10,
"policySurfaceCount": 2,
"cookiePolicyPresent": false,
"scannedPageLanguage": "en",
"privacyPolicyPresent": true,
"policyPrimaryLanguage": "en",
"policyLastUpdatedTexts": [],
"policyTextCoverageMode": "section_targeted",
"retainedPolicySections": [
{
"charEnd": 3025,
"heading": "Privacy Policy for KBD Lab",
"quality": "strong",
"charStart": 2241,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "At KBD Lab, accessible from kbdlab.io, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by KBD Lab and how we use it. If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us at [email protected]. This Privacy Policy applies only to our online activities and is valid for visitors to our website with regards to the information that they shared and/or collect in KBD Lab. This policy is not applicable to any information collected offline or via channels other than this website."
},
{
"charEnd": 3844,
"heading": "Information we collect",
"quality": "strong",
"charStart": 3165,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information. If you contact us directly, we may receive additional information about you such as your name, email address, phone number, the contents of the message and/or attachments you may send us, and any other information you may choose to provide. When you register for an Account, we may ask for your contact information, including items such as name, company name, address, email address, and telephone number."
},
{
"charEnd": 4540,
"heading": "How we use your information",
"quality": "partial",
"charStart": 3844,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "We use the information we collect in various ways, including to: Provide, operate, and maintain our website Improve, personalize, and expand our website Understand and analyze how you use our website Develop new products, services, features, and functionality Communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the website, and for marketing and promotional purposes Send you emails Find and prevent fraud"
},
{
"charEnd": 5225,
"heading": "Log Files",
"quality": "partial",
"charStart": 4540,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "KBD Lab follows a standard procedure of using log files. These files log visitors when they visit websites. All hosting companies do this and a part of hosting services' analytics. The information collected by log files include internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, and possibly the number of clicks. These are not linked to any information that is personally identifiable. The purpose of the information is for analyzing trends, administering the site, tracking users' movement on the website, and gathering demographic information."
},
{
"charEnd": 5663,
"heading": "Cookies and Web Beacons",
"quality": "strong",
"charStart": 5225,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "Like any other website, KBD Lab uses 'cookies'. These cookies are used to store information including visitors' preferences, and the pages on the website that the visitor accessed or visited. The information is used to optimize the users' experience by customizing our web page content based on visitors' browser type and/or other information."
},
{
"charEnd": 6431,
"heading": "Advertising Partners Privacy Policies",
"quality": "strong",
"charStart": 5663,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "You may consult this list to find the Privacy Policy for each of the advertising partners of KBD Lab. Third-party ad servers or ad networks uses technologies like cookies, JavaScript, or Web Beacons that are used in their respective advertisements and links that appear on KBD Lab, which are sent directly to users' browser. They automatically receive your IP address when this occurs. These technologies are used to measure the effectiveness of their advertising campaigns and/or to personalize the advertising content that you see on websites that you visit. Note that KBD Lab has no access to or control over these cookies that are used by third-party advertisers."
},
{
"charEnd": 7040,
"heading": "Third Party Privacy Policies",
"quality": "strong",
"charStart": 6431,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "KBD Lab's Privacy Policy does not apply to other advertisers or websites. Thus, we are advising you to consult the respective Privacy Policies of these third-party ad servers for more detailed information. It may include their practices and instructions about how to opt-out of certain options. You can choose to disable cookies through your individual browser options. To know more detailed information about cookie management with specific web browsers, it can be found at the browsers' respective websites."
},
{
"charEnd": 7816,
"heading": "CCPA Privacy Rights (Do Not Sell My Personal Information)",
"quality": "strong",
"charStart": 7040,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "Under the CCPA, among other rights, California consumers have the right to: Request that a business that collects a consumer's personal data disclose the categories and specific pieces of personal data that a business has collected about consumers. Request that a business delete any personal data about the consumer that a business has collected. Request that a business that sells a consumer's personal data, not sell the consumer's personal data. If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us."
},
{
"charEnd": 9164,
"heading": "GDPR Data Protection Rights",
"quality": "strong",
"charStart": 7816,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following: The right to access – You have the right to request copies of your personal data. We may charge you a small fee for this service. The right to rectification – You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete. The right to erasure – You have the right to request that we erase your personal data, under certain conditions. The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions. The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions. The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions. If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us."
},
{
"charEnd": 9826,
"heading": "Children's Information",
"quality": "strong",
"charStart": 9164,
"sourceUrl": "https://kbdlab.io/privacy-policy",
"textExcerpt": "Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity. KBD Lab does not knowingly collect any Personal Identifiable Information from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records."
}
],
"policyCookieDisclosures": [],
"privacyPolicyDiscovered": true,
"processingErrorObserved": false,
"observedPolicyTopicHints": [
"cookies",
"analytics",
"advertising",
"do_not_sell_or_share",
"california_privacy_rights",
"third_party_disclosures",
"consent_withdrawal",
"controller_contact",
"processing_purposes",
"recipients_or_vendor_categories",
"data_subject_rights",
"contact_privacy"
],
"policyDocumentProvenance": [
{
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"effectiveDate": null,
"observationId": "policy_surface_a3f43701",
"discoveryMethod": "page_text_link",
"lastUpdatedText": null,
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"documentOwnerEntity": null,
"ownershipConfidence": null,
"translationTargetLanguage": null,
"directlyLinkedFromScannedPage": true
}
],
"policy_cookie_disclosures": [],
"article13DisclosureSignals": [],
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"privacyPolicyEvidencePaths": [],
"discoveredPrivacyPolicyUrls": [
"https://kbdlab.io/privacy-policy"
],
"article13CoverageAssessments": [
{
"topic": "automated_decision_making_or_profiling",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "controller_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_retention",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_subject_rights",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "dpo_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "international_transfers",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "legal_basis",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "processing_purposes",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "recipients_or_vendor_categories",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "supervisory_authority",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
}
],
"policyTextEvidenceProjection": {
"scanId": "scan_1783902357617_kbdlab.io",
"documents": [
{
"artifactId": "policy_surface_text_a3f43701",
"documentRole": "unknown",
"requestedUrl": "/privacy-policy",
"failureReason": "policy_text_artifact_missing_from_verified_manifest",
"observationId": "policy_surface_a3f43701",
"redirectChain": [],
"documentFormat": "unknown",
"limitationKeys": [
"policy_text_artifact_missing_from_verified_manifest",
"policy_text_artifact_text_unavailable",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text"
],
"artifactFileName": "policy_surface_text_a3f43701.txt",
"extractionStatus": "unavailable",
"retainedTextChars": 0,
"documentFetchState": "fetched",
"targetRelationship": "unknown",
"documentTextCoverage": {
"status": "unavailable",
"limitationKeys": [
"policy_document_text_coverage_derived_for_legacy_observation"
],
"sourceTextChars": 0,
"retainedTextChars": 0
},
"documentEvaluationState": "usable",
"documentRoleReasonCodes": [],
"artifactVerificationStatus": "missing_manifest_entry",
"gdprTransparencyTopicCoverageDiagnostics": []
}
],
"generatedAt": "2026-07-13T00:26:02.806Z",
"sourceBundle": {
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f20f885d-10d4-4a07-899f-f7ea5a1825d8/CanonicalEvidenceBundle.json",
"sha256": "e138ca73017b3cf719c7ac28ade03f99445382ffea89579115eb6b088bcb75e0",
"sizeBytes": 330557,
"schemaVersion": "certscore.v2.alpha.1",
"verificationStatus": "verified"
},
"limitationKeys": [
"policy_text_artifact_missing_from_verified_manifest",
"policy_text_artifact_text_unavailable",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text",
"verified_owned_complete_policy_document_unavailable"
],
"contractVersion": "certscore.policy-text-evidence-projection.v1",
"projectionStatus": "verified_partial"
},
"privacyPolicyEvaluationState": "fetched_insufficient",
"legalFrameworkValidityMatches": [],
"missingExpectedPolicySections": [
"Your privacy controls",
"Exporting and deleting your information",
"Retaining your information",
"Compliance and cooperation with regulators",
"European requirements",
"Data transfers"
],
"policy_text_extraction_health": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"retainedPolicySectionHeadings": [
"Privacy Policy for KBD Lab",
"Information we collect",
"How we use your information",
"Log Files",
"Cookies and Web Beacons",
"Advertising Partners Privacy Policies",
"Third Party Privacy Policies",
"CCPA Privacy Rights (Do Not Sell My Personal Information)",
"GDPR Data Protection Rights",
"Children's Information"
],
"selectedPrivacyPolicyDocument": null,
"article13_coverage_assessments": [
{
"topic": "automated_decision_making_or_profiling",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "controller_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_retention",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_subject_rights",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "dpo_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "international_transfers",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "legal_basis",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "processing_purposes",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "recipients_or_vendor_categories",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "supervisory_authority",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
}
],
"discoveredPrivacyPolicyDetails": [
{
"url": "https://kbdlab.io/privacy-policy",
"status": "fetched",
"documentFetchState": "fetched",
"fetchFailureReason": null,
"linkObservationState": "candidate",
"documentEvaluationState": "not_attempted"
}
],
"article13DisclosureTypesPartial": [],
"discoveredPrivacyPolicyStatuses": [
"fetched"
],
"gdprTransparencyEvidenceProfile": "gdpr_transparency_multilingual_article13_v1",
"policy_text_evidence_projection": {
"scanId": "scan_1783902357617_kbdlab.io",
"documents": [
{
"artifactId": "policy_surface_text_a3f43701",
"documentRole": "unknown",
"requestedUrl": "/privacy-policy",
"failureReason": "policy_text_artifact_missing_from_verified_manifest",
"observationId": "policy_surface_a3f43701",
"redirectChain": [],
"documentFormat": "unknown",
"limitationKeys": [
"policy_text_artifact_missing_from_verified_manifest",
"policy_text_artifact_text_unavailable",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text"
],
"artifactFileName": "policy_surface_text_a3f43701.txt",
"extractionStatus": "unavailable",
"retainedTextChars": 0,
"documentFetchState": "fetched",
"targetRelationship": "unknown",
"documentTextCoverage": {
"status": "unavailable",
"limitationKeys": [
"policy_document_text_coverage_derived_for_legacy_observation"
],
"sourceTextChars": 0,
"retainedTextChars": 0
},
"documentEvaluationState": "usable",
"documentRoleReasonCodes": [],
"artifactVerificationStatus": "missing_manifest_entry",
"gdprTransparencyTopicCoverageDiagnostics": []
}
],
"generatedAt": "2026-07-13T00:26:02.806Z",
"sourceBundle": {
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f20f885d-10d4-4a07-899f-f7ea5a1825d8/CanonicalEvidenceBundle.json",
"sha256": "e138ca73017b3cf719c7ac28ade03f99445382ffea89579115eb6b088bcb75e0",
"sizeBytes": 330557,
"schemaVersion": "certscore.v2.alpha.1",
"verificationStatus": "verified"
},
"limitationKeys": [
"policy_text_artifact_missing_from_verified_manifest",
"policy_text_artifact_text_unavailable",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text",
"verified_owned_complete_policy_document_unavailable"
],
"contractVersion": "certscore.policy-text-evidence-projection.v1",
"projectionStatus": "verified_partial"
},
"privacyPolicyTextCharacterCount": 0,
"retainedCookiePolicyTextExcerpt": "",
"validatedDisclosureTypesPartial": [],
"article13DisclosureTypesObserved": [],
"retainedArticle13SectionEvidence": [
{
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"coverageArea": "data_retention",
"evidenceSource": "deterministic",
"signalObserved": "not_confirmed",
"extractionLimitation": "section_retained_without_row_specific_disclosure",
"selectedEvidenceStrength": "limited",
"selectedPolicySectionUrl": "https://kbdlab.io/privacy-policy",
"selectedPolicySectionExcerpt": "CCPA Privacy Rights (Do Not Sell My Personal Information). siness that collects a consumer's personal data disclose the categories and specific pieces of personal data that a business has collected about consumers. Request that a business delete any personal data about the consumer that a business has collected. Request that a business that sells a consumer's personal data, not sell the consumer's personal data. If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.",
"selectedPolicySectionHeading": "CCPA Privacy Rights (Do Not Sell My Personal Information)"
},
{
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"coverageArea": "data_subject_rights",
"evidenceSource": "deterministic",
"signalObserved": "partial",
"selectedEvidenceStrength": "partial",
"selectedPolicySectionUrl": "https://kbdlab.io/privacy-policy",
"selectedPolicySectionExcerpt": "CCPA Privacy Rights (Do Not Sell My Personal Information). Under the CCPA, among other rights, California consumers have the right to: Request that a business that collects a consumer's personal data disclose the categories and specific pieces of personal data that a business has collected about consumers. Request that a business delete any personal data about the consumer that a business has collected. Request that a business that sells a consumer's personal data, not sell the consumer's personal data. If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.",
"selectedPolicySectionHeading": "CCPA Privacy Rights (Do Not Sell My Personal Information)"
},
{
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"coverageArea": "dpo_contact",
"evidenceSource": "deterministic",
"signalObserved": "not_confirmed",
"extractionLimitation": "section_retained_without_row_specific_disclosure",
"selectedEvidenceStrength": "limited",
"selectedPolicySectionUrl": "https://kbdlab.io/privacy-policy",
"selectedPolicySectionExcerpt": "GDPR Data Protection Rights. r organization, or directly to you, under certain conditions. If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.",
"selectedPolicySectionHeading": "GDPR Data Protection Rights"
},
{
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"coverageArea": "controller_contact",
"evidenceSource": "deterministic",
"signalObserved": "not_confirmed",
"extractionLimitation": "section_retained_without_row_specific_disclosure",
"selectedEvidenceStrength": "limited",
"selectedPolicySectionUrl": "https://kbdlab.io/privacy-policy",
"selectedPolicySectionExcerpt": "Privacy Policy for KBD Lab. information that is collected and recorded by KBD Lab and how we use it. If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us at [email protected]. This Privacy Policy applies only to our online activities and is valid for visitors to our website with regards to the information that they shared and/or collect in KBD Lab. This policy is not applicable to any information collected offline or via channels other than this website.",
"selectedPolicySectionHeading": "Privacy Policy for KBD Lab"
},
{
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"coverageArea": "legal_basis",
"evidenceSource": "deterministic",
"signalObserved": "partial",
"selectedEvidenceStrength": "partial",
"selectedPolicySectionUrl": "https://kbdlab.io/privacy-policy",
"selectedPolicySectionExcerpt": "Consent. By using our website, you hereby consent to our Privacy Policy and agree to its terms.",
"selectedPolicySectionHeading": "Consent"
}
],
"retainedPrivacyPolicyTextExcerpt": "",
"validatedDisclosureTypesObserved": [],
"privacyNoticeAvailabilityObserved": true,
"evaluatedPrivacyPolicySurfaceCount": 1,
"discardedArticle13DisclosureSignals": [
{
"source": "deterministic",
"confidence": 0.66,
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"evidenceText": "Affiliate Disclosure | KBD Lab KBD Lab Builds Parts Blog Tools Sign in Open main menu Privacy Policy for KBD Lab At KBD Lab, accessible from kbdlab.io, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by KBD Lab and how",
"rejectReason": "insufficient_row_specific_terms",
"disclosureType": "controller_contact"
},
{
"source": "deterministic",
"confidence": 0.88,
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"evidenceText": "Service Provider (ISP), date and time stamp, referring/exit pages, and possibly the number of clicks. These are not linked to any information that is personally identifiable. The purpose of the information is for analyzing trends, administering the site, tracking users' movement on the website, and gathering demograph",
"rejectReason": "code_or_non_policy_excerpt",
"disclosureType": "processing_purposes"
},
{
"source": "deterministic",
"confidence": 0.7,
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"evidenceText": "regards to the information that they shared and/or collect in KBD Lab. This policy is not applicable to any information collected offline or via channels other than this website. Consent By using our website, you hereby consent to our Privacy Policy and agree to its terms. Information we collect The personal informati",
"rejectReason": "code_or_non_policy_excerpt",
"disclosureType": "legal_basis"
},
{
"source": "deterministic",
"confidence": 0.76,
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"evidenceText": "our website Understand and analyze how you use our website Develop new products, services, features, and functionality Communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the website, and for marketing and p",
"rejectReason": "code_or_non_policy_excerpt",
"disclosureType": "recipients_or_vendor_categories"
},
{
"source": "deterministic",
"confidence": 0.9,
"surfaceUrl": "https://kbdlab.io/privacy-policy",
"evidenceText": ", please contact us. GDPR Data Protection Rights We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following: The right to access – You have the right to request copies of your personal data. We may charge you a small fee for this service. The right to r",
"rejectReason": "code_or_non_policy_excerpt",
"disclosureType": "data_subject_rights"
}
],
"staleLegalFrameworkReferenceObserved": false,
"policyEvidenceProvenanceContractVersion": "certscore.policy-evidence-provenance.v1",
"gdprTransparencyProductionEvidenceEnabled": true,
"gdprTransparencyProductionEvidenceDiagnostics": {
"sourceCandidateCount": 1,
"candidateDispositions": [
{
"topic": "controller_contact",
"confidence": 0.82,
"disposition": "diagnostic_only",
"matchStrength": "equivalent",
"matchedLocale": "en",
"rejectionReason": "non_privacy_policy_surface",
"sourceObservationId": "policy_surface_a3f43701"
}
],
"acceptedCandidateCount": 0,
"rejectedCandidateCount": 1,
"discardedCandidateCount": 0,
"diagnosticCandidateCount": 1,
"productionCreditSignalCount": 0
}
}
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}No remediation is established by this check alone. Retain its evidence and reassess after relevant changes.
Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "legal_basis_disclosure_observed",
"coverageArea": "Legal basis disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence included a canonical legal-basis disclosure signal.",
"note": "Whether retained privacy-policy evidence included a canonical legal-basis disclosure signal.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.legal_basis_disclosure_observed.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.legal_basis_disclosure_observed"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "legal_basis",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "retention_disclosure_observed",
"coverageArea": "Retention disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence included a data-retention disclosure signal.",
"note": "Whether retained privacy-policy evidence included a data-retention disclosure signal.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.retention_disclosure_observed.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.retention_disclosure_observed"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "data_retention",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "controller_contact_disclosure",
"coverageArea": "Controller/contact disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence included a controller, privacy contact, or equivalent contact point.",
"note": "Whether retained privacy-policy evidence included a controller, privacy contact, or equivalent contact point.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.controller_contact_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.controller_contact_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "controller_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "processing_purposes_disclosure",
"coverageArea": "Processing purposes disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described the purposes for processing personal data.",
"note": "Whether retained privacy-policy evidence described the purposes for processing personal data.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.processing_purposes_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.processing_purposes_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "processing_purposes",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "recipients_vendor_categories_disclosure",
"coverageArea": "Recipients/vendor categories disclosed",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described recipient, vendor, or 3rd party categories.",
"note": "Whether retained privacy-policy evidence described recipient, vendor, or 3rd party categories.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.recipients_vendor_categories_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.recipients_vendor_categories_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "recipients_or_vendor_categories",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "data_subject_rights_disclosure",
"coverageArea": "Data subject rights disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described data subject rights or a rights request path.",
"note": "Whether retained privacy-policy evidence described data subject rights or a rights request path.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.data_subject_rights_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.data_subject_rights_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "data_subject_rights",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "international_transfers_disclosure",
"coverageArea": "International transfer disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described international transfers or transfer-relevant endpoint/vendor context.",
"note": "Whether retained privacy-policy evidence described international transfers or transfer-relevant endpoint/vendor context.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.international_transfers_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.international_transfers_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "international_transfers",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "dpo_contact_point_disclosure",
"coverageArea": "Privacy contact point",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence identified a privacy officer, privacy office, privacy contact, DPO, or data-protection contact point.",
"note": "Whether retained privacy-policy evidence identified a privacy officer, privacy office, privacy contact, DPO, or data-protection contact point.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.dpo_contact_point_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.dpo_contact_point_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "dpo_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "supervisory_authority_complaint_disclosure",
"coverageArea": "Supervisory authority complaint",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence referenced a right to complain to a supervisory authority.",
"note": "Whether retained privacy-policy evidence referenced a right to complain to a supervisory authority.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.supervisory_authority_complaint_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.supervisory_authority_complaint_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "supervisory_authority",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Policy source
Captured page title: Affiliate Disclosure | KBD Lab — https://kbdlab.io/privacy-policy
Source policy language: en; banner/page language: en; translation applied: No.
Policy reached through: Page Text Link; directly linked from scanned page: Yes; retrieved during scan: 2026-07-13T00:25:57.617Z.
Section: Not retained.
Open policy sourceNo production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "automated_decision_making_profiling_disclosure",
"coverageArea": "Automated decision-making / profiling disclosure",
"evidenceState": "not_testable",
"explanation": "Whether adapter-approved Article 13 evidence retained automated decision-making or profiling disclosure context for review.",
"note": "Whether adapter-approved Article 13 evidence retained automated decision-making or profiling disclosure context for review.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.automated_decision_making_profiling_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.automated_decision_making_profiling_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"sourceUrl": "https://kbdlab.io/privacy-policy",
"policyTitle": "Affiliate Disclosure | KBD Lab",
"artifactRefs": [
"policy_excerpt_a3f43701",
"policy_surface_text_a3f43701"
],
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"discoveryMethod": "page_text_link",
"detectedLanguage": "en",
"retrievalTimestamp": "2026-07-13T00:25:57.617Z",
"targetRelationship": "unknown",
"translationApplied": false,
"directlyLinkedFromScannedPage": true
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://kbdlab.io/privacy-policy"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "policy_surface",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "automated_decision_making_or_profiling",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Storage & tracking techniques · Starting page
_ga_H1SWTMGGJ4 (kbdlab.io) non-essential, present in a check performed before consent, first seen at 4.33s.
_ga (kbdlab.io) non-essential, present in a check performed before consent, first seen at 4.33s.
{
"assessmentStatus": "review_signal",
"checklistItemId": "pre_consent_cookies_storage",
"coverageArea": "Pre-consent storage classification review",
"evidenceState": "observed",
"explanation": "Pre-consent storage was observed, but one or more records could not be classified as essential or non-essential or could not be reconciled to the aggregate count. Review the retained storage inventory before drawing a conclusion.",
"note": "Pre-consent storage was observed, but one or more records could not be classified as essential or non-essential or could not be reconciled to the aggregate count. Review the retained storage inventory before drawing a conclusion.",
"status": "Review signal",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.pre_consent_cookies_storage.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.pre_consent_cookies_storage"
},
"statusBasis": "Pre-consent storage was observed, but one or more records could not be classified as essential or non-essential or could not be reconciled to the aggregate count. Review the retained storage inventory before drawing a conclusion.",
"retainedEvidence": {
"evidenceRefs": [
"__Host-next-auth.csrf-token (www.kbdlab.io): unknown, first observed 0.787s after scan start",
"__Secure-next-auth.callback-url (www.kbdlab.io): unknown, first observed 0.788s after scan start",
"_ga_H1SWTMGGJ4 (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"_ga (kbdlab.io): non_essential, present in periodic pre-consent snapshot",
"Aggregate pre-consent storage count: 4",
"Assessment reconciliation: reconciled"
],
"cookiesSeenCount": 4,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained concrete cookie/storage evidence for storage timing; request-only tracking evidence is not used as storage proof.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"cookiesBeforeConsentCount": 2,
"selectedEvidenceArtifactId": "preConsentCookieOrStorageEvidence.missing",
"preConsentStorageAssessment": {
"status": "partially_classified",
"evidenceRows": [
{
"name": "__Host-next-auth.csrf-token",
"party": "first_party",
"domain": "www.kbdlab.io",
"category": "unknown",
"storageType": "cookie",
"essentiality": "unknown",
"timingEvidence": "before_consent_write",
"exclusionReason": "functional_or_consent_storage",
"firstObservedMs": 787,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "unknown"
},
{
"name": "__Secure-next-auth.callback-url",
"party": "first_party",
"domain": "www.kbdlab.io",
"category": "unknown",
"storageType": "cookie",
"essentiality": "unknown",
"timingEvidence": "before_consent_write",
"exclusionReason": null,
"firstObservedMs": 788,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "unknown"
},
{
"name": "_ga_H1SWTMGGJ4",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
},
{
"name": "_ga",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"provenWriteCount": 0,
"assessmentVersion": "pre-consent-storage-assessment-v1",
"unclassifiedCount": 2,
"reconciliationStatus": "reconciled",
"snapshotPresenceCount": 2,
"aggregateObservedCount": 4,
"classifiedEssentialCount": 0,
"classifiedNonEssentialCount": 2,
"attributedPreConsentRecordCount": 4,
"excludedFunctionalOrConsentCount": 1
},
"excludedEssentialOrFunctionalRows": [
{
"name": "__Host-next-auth.csrf-token",
"party": "first_party",
"domain": "www.kbdlab.io",
"category": "unknown",
"storageType": "cookie",
"essentiality": "unknown",
"timingEvidence": "before_consent_write",
"exclusionReason": "functional_or_consent_storage",
"firstObservedMs": 787,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "unknown"
}
],
"preConsentStorageAssessmentStatus": "partially_classified",
"eligiblePreconsentCookieStorageRows": [
{
"name": "_ga_H1SWTMGGJ4",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
},
{
"name": "_ga",
"party": "first_party",
"domain": "kbdlab.io",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 4328,
"initiatorDomain": null,
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"rowLevelEssentialityEvidenceRetained": true,
"firstPreconsentCookieOrStorageObservedMs": 4328,
"preConsentStorageClassificationLimitation": true,
"preconsentCookieOrStorageExactTimingRetained": false,
"eligibleNonEssentialCookieStorageFindingProjected": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Microsoft Clarity, category: session_replay, preConsent: false
{
"assessmentStatus": "review_signal",
"checklistItemId": "session_replay_fingerprinting_review",
"coverageArea": "Session replay signal",
"evidenceState": "observed",
"explanation": "CertScore.ai observed session replay or behavioral analytics vendors not observed pre-consent in retained evidence, including Microsoft Clarity. Because these tools can capture user interaction behavior, review consent timing, disclosure, masking/exclusion settings, sensitive-page coverage, and withdrawal controls.",
"note": "CertScore.ai observed session replay or behavioral analytics vendors not observed pre-consent in retained evidence, including Microsoft Clarity. Because these tools can capture user interaction behavior, review consent timing, disclosure, masking/exclusion settings, sensitive-page coverage, and withdrawal controls.",
"status": "Review signal",
"tone": "warning",
"pipeline": {
"projectionStage": "unified_finding",
"concernPolicyKey": "gdpr_eprivacy_coverage.session_replay_fingerprinting_review.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.session_replay_fingerprinting_review"
},
"statusBasis": "Selected the strongest retained canonical coverage evidence available for this row.",
"retainedEvidence": {
"status": "Review signal",
"evidenceRefs": [
"Session replay observed",
"Signal: Session replay runtime detected",
"Signal: Session replay runtime vendors",
"Signal: Session replay tool detected",
"Evidence flag: contradiction_runtime_artifact_retained",
"Evidence flag: privacy.session_replay_runtime_detected"
],
"findingEntities": [
{
"id": "session_replay_observed",
"entities": {
"runtimeVendors": [
"Microsoft Clarity"
],
"runtimeRequestUrls": [
"https://www.clarity.ms",
"https://www.clarity.ms/tag/m97n86hou6",
"https://scripts.clarity.ms/0.8.67/clarity.js",
"https://r.clarity.ms/collect"
],
"observedTrackingVendors": [
"Microsoft Clarity"
],
"sessionReplayEvidenceSummary": [
"{\"artifactCount\":3,\"collectionEndpointObserved\":true,\"consentStates\":[\"pre_consent\"],\"coverageRetained\":true,\"firstSeenMs\":2132,\"libraryOnly\":false,\"preConsentObserved\":true,\"requestUrls\":[\"https://www.clarity.ms/tag/m97n86hou6\",\"https://scripts.clarity.ms/0.8.67/clarity.js\",\"https://r.clarity.ms/collect\"],\"vendors\":[\"Microsoft Clarity\"]}"
],
"session_replay_runtime_vendors": [
"Microsoft Clarity"
]
},
"sourceRefs": [
"Signal: Session replay runtime detected",
"Signal: Session replay runtime vendors",
"Signal: Session replay tool detected"
],
"evidenceFlags": [
"privacy.session_replay_runtime_detected",
"privacy.session_replay_runtime_vendors",
"commerce.session_replay_tool_detected"
]
}
],
"evidenceHighlights": [
"\"Microsoft Clarity\", \"category\": \"session_replay\", \"preConsent\": false"
],
"missingEvidenceNeeded": [],
"sessionReplayEvidence": {
"vendors": [
"Microsoft Clarity"
],
"firstSeenMs": 2132,
"requestUrls": [
"https://www.clarity.ms/tag/m97n86hou6",
"https://scripts.clarity.ms/0.8.67/clarity.js",
"https://r.clarity.ms/collect"
],
"consentStates": [
"pre_consent"
],
"vendorDisclosed": false,
"postAcceptObserved": false,
"preConsentObserved": true,
"libraryLoadObserved": true,
"vendorDisclosureGap": false,
"collectionEndpointObserved": true,
"vendorDisclosureMatchedCount": 0,
"vendorDisclosureUnmatchedCount": 0,
"postChoiceConsentControlsObserved": false,
"vendorDisclosureComparisonObserved": false
},
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "unified_finding"
},
"projectedFindings": [
{
"id": "session_replay_observed",
"label": "Session replay observed",
"severity": "high"
}
],
"missingOrIncompleteSourceSignals": []
}retained fingerprinting/browser API coverage summary
{
"assessmentStatus": "checked",
"checklistItemId": "device_identification_fingerprinting_signal_observed",
"coverageArea": "Device identification / fingerprinting signal",
"evidenceState": "not_observed",
"explanation": "Whether browser/device entropy, fingerprinting, or identifier-like device collection signals were observed in retained runtime evidence.",
"note": "Whether browser/device entropy, fingerprinting, or identifier-like device collection signals were observed in retained runtime evidence.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.device_identification_fingerprinting_signal_observed.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.device_identification_fingerprinting_signal_observed"
},
"statusBasis": "Runtime fingerprinting/device-identification checks completed for the tested context and did not retain an eligible signal.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained fingerprinting/browser API coverage summary"
],
"missingEvidenceNeeded": [],
"fingerprintingObserved": false,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"runtimeEvidenceRetained": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"fingerprintingRuntimeCoverageRetained": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Device identification / fingerprinting signal is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Transport security · Starting page
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_https_delivery",
"coverageArea": "HTTPS delivery for scanned pages",
"evidenceState": "observed",
"explanation": "Whether the retained scanned page was served over HTTPS.",
"note": "Whether the retained scanned page was served over HTTPS.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_https_delivery.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_https_delivery"
},
"statusBasis": "The scanned page was served over HTTPS in the retained transport observation.",
"retainedEvidence": {
"finalUrl": "https://www.kbdlab.io/",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"sampledPageUrls": [
"https://kbdlab.io/",
"https://www.kbdlab.io/"
],
"httpProbeFinalUrl": "https://kbdlab.io/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}HTTPS delivery for scanned pages is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Company / Legal
Privacy rights requests can be submitted at certscore.ai/privacy-request or by emailing [email protected].
© 2026 CertScore.ai, LLC. All rights reserved.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_tls_certificate",
"coverageArea": "Valid SSL/TLS certificate",
"evidenceState": "observed",
"explanation": "Whether a strict TLS probe verified the HTTPS origin certificate separately from the normal scanner runtime.",
"note": "Whether a strict TLS probe verified the HTTPS origin certificate separately from the normal scanner runtime.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_tls_certificate.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_tls_certificate"
},
"statusBasis": "The strict TLS probe verified the HTTPS origin certificate.",
"retainedEvidence": {
"finalUrl": "https://www.kbdlab.io/",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"sampledPageUrls": [
"https://kbdlab.io/",
"https://www.kbdlab.io/"
],
"httpProbeFinalUrl": "https://kbdlab.io/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Valid SSL/TLS certificate is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_http_redirect",
"coverageArea": "HTTP redirects to HTTPS",
"evidenceState": "observed",
"explanation": "Whether an explicit HTTP-origin probe redirected to HTTPS.",
"note": "Whether an explicit HTTP-origin probe redirected to HTTPS.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_http_redirect.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_http_redirect"
},
"statusBasis": "The explicit HTTP-origin probe redirected to HTTPS.",
"retainedEvidence": {
"finalUrl": "https://www.kbdlab.io/",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"sampledPageUrls": [
"https://kbdlab.io/",
"https://www.kbdlab.io/"
],
"httpProbeFinalUrl": "https://kbdlab.io/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}HTTP redirects to HTTPS is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_mixed_content",
"coverageArea": "Mixed content",
"evidenceState": "observed",
"explanation": "Whether HTTP subresources were observed or blocked on a retained HTTPS page.",
"note": "Whether HTTP subresources were observed or blocked on a retained HTTPS page.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_mixed_content.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_mixed_content"
},
"statusBasis": "No mixed-content HTTP subresources were retained for the scanned HTTPS page.",
"retainedEvidence": {
"finalUrl": "https://www.kbdlab.io/",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"sampledPageUrls": [
"https://kbdlab.io/",
"https://www.kbdlab.io/"
],
"httpProbeFinalUrl": "https://kbdlab.io/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Mixed content is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_form_transport",
"coverageArea": "Observed form transport",
"evidenceState": "observed",
"explanation": "Whether observed forms resolved to HTTPS transport without submitting form data.",
"note": "Whether observed forms resolved to HTTPS transport without submitting form data.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_form_transport.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_form_transport"
},
"statusBasis": "No insecure observed form transport was retained for the scanned page.",
"retainedEvidence": {
"finalUrl": "https://www.kbdlab.io/",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"sampledPageUrls": [
"https://kbdlab.io/",
"https://www.kbdlab.io/"
],
"httpProbeFinalUrl": "https://kbdlab.io/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Observed form transport is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.