CertScore.ai report
Loading report
The report is ready; we’re loading its retained findings and evidence.
CertScore.ai report
The report is ready; we’re loading its retained findings and evidence.
Sep 3, 2026, 6:26:00 PM UTC
Overall score
Targeted review
3 priority items across consent surface and tracking & external services.
Signal snapshot
Consent-platform identity retained in the canonical runtime and consent projection.
Priority review
Open for evidence, JSON, and correction steps.
{
"assessmentStatus": "gap_observed",
"checklistItemId": "post_reject_tracking_reduction",
"coverageArea": "Post-choice tracking reduction",
"evidenceState": "observed",
"explanation": "A reject action and post-reject comparison window were retained, and eligible non-essential tracking activity persisted after reject.",
"note": "A reject action and post-reject comparison window were retained, and eligible non-essential tracking activity persisted after reject.",
"status": "Gap observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.post_reject_tracking_reduction.gap_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.post_reject_tracking_reduction"
},
"statusBasis": "A reject action and post-reject comparison window were retained, and eligible non-essential tracking activity persisted after reject.",
"retainedEvidence": {
"scoreEffect": "canonical_post_refusal_policy",
"evidenceRefs": [
"Evidence: post-reject tracking reduction evidence"
],
"resolverMethod": "tcf_api_cmp_registry_recipe",
"observationWindowMs": 8000,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained same-surface reject-path or post-reject comparison evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "strong",
"postRejectWindowAvailable": true,
"reductionEvaluationStatus": "not_reduced",
"rejectInteractionConfirmed": true,
"selectedEvidenceArtifactId": "postRejectTrackingReductionEvidence",
"preConsentStorageNotCleared": false,
"postRejectNonEssentialRequests": [
{
"url": "https://www.google-analytics.com/g/collect",
"vendor": "Google",
"category": "analytics",
"hostname": "www.google-analytics.com",
"requestId": "post_refusal_request_3",
"activityType": "network_request",
"consentState": "post_reject",
"nonEssential": true,
"msAfterReject": 171,
"nonEssentialReason": "canonical_post_refusal_classification"
},
{
"url": "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/9032601",
"vendor": "Google",
"category": "advertising",
"hostname": "googleads.g.doubleclick.net",
"requestId": "post_refusal_request_4",
"activityType": "network_request",
"consentState": "post_reject",
"nonEssential": true,
"msAfterReject": 172,
"nonEssentialReason": "canonical_post_refusal_classification"
},
{
"vendor": "Google",
"category": "analytics",
"hostname": "ergoveritas.com",
"cookieName": "_ga",
"activityType": "storage_write",
"consentState": "post_reject",
"nonEssential": true,
"msAfterReject": 168,
"nonEssentialReason": "canonical_post_refusal_classification"
},
{
"vendor": "Google",
"category": "analytics",
"hostname": "ergoveritas.com",
"cookieName": "_gid",
"activityType": "storage_write",
"consentState": "post_reject",
"nonEssential": true,
"msAfterReject": 168,
"nonEssentialReason": "canonical_post_refusal_classification"
}
],
"refusalSignalContradictsAction": false,
"postRejectRequestRecordsObserved": true,
"preConsentStorageNotClearedCount": 0,
"postRejectNonEssentialRequestCount": 4,
"postRejectNonEssentialActivityRetained": true,
"storagePresenceDoesNotEstablishActiveUse": false,
"concretePostRejectNonEssentialDetailsRetained": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}0s
Scan start
Public page observation began
0.59s
Analytics
Analytics first observed
1.12s
3P request
3P request first observed
0.82s before consent surface1.52s
Cookie/storage
Cookie/storage first observed
1.94s
Consent banner
Accept observed · Reject observed · Options observed
6.41s
Observation end
Retained scan window closed
Resource inventory
Evidence mix
Purpose mix
Site relationship
Consent, tracking & external services, pre-consent runtime, GPC comparison, GDPR Transparency, transport security and collection details.
Rating mix
30 rows
After Accept
Activity observedConsent-dependent activity observed
A confirmed Accept was followed by 2 requests and 2 storage writes, establishing the post-Accept comparison baseline.
3s observation · TCF + CMP registry resolver
After Reject
Issue observedActivity observed after Reject
A reject action and post-reject comparison window were retained, and eligible non-essential tracking activity persisted after reject.
8s observation · TCF + CMP registry resolver
No observable baseline delta was retained under the otherwise equivalent passive GPC condition. This does not determine whether any law was satisfied.
Sec-GPC request evidence: 2 retained requests; main-document browser property: true.
Cookies
1 1
Trackers
2 2
Advertising / measurement
7 7
Consent / CMP
0 0
Overall, this scan points to a focused review rather than a site-wide breakdown. The review centers on visitor choice, pre-consent third-party activity, and pre-consent storage. The confirmed Accept path retained consent-dependent activity as the post-Accept comparison baseline. The confirmed Reject path did not stop qualifying non-essential activity during the retained 8-second post-Reject window.
Overall, this scan points to a focused review rather than a site-wide breakdown. The review centers on visitor choice, pre-consent third-party activity, and pre-consent storage. The confirmed Accept path retained consent-dependent activity as the post-Accept comparison baseline. The confirmed Reject path did not stop qualifying non-essential activity during the retained 8-second post-Reject window.
Industry benchmark
Legal/Compliance & Risk Advisory
Non-essential requests
Non-essential cookies/storage
{
"assessmentStatus": "review_signal",
"checklistItemId": "pre_consent_third_party_tracking",
"coverageArea": "Pre-consent non-essential tracking",
"evidenceState": "not_observed",
"explanation": "Medium priority pre-consent tracker inventory was retained without a promotion-eligible normalized concern or unified finding: Google Analytics - Analytics (1.11s). Tracking is not confirmed from grouped inventory alone. This row is limited to concrete 3rd party tracker/request evidence retained before a recorded consent choice.",
"note": "Medium priority pre-consent tracker inventory was retained without a promotion-eligible normalized concern or unified finding: Google Analytics - Analytics (1.11s). Tracking is not confirmed from grouped inventory alone. This row is limited to concrete 3rd party tracker/request evidence retained before a recorded consent choice.",
"status": "Not confirmed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_fallback",
"concernPolicyKey": "gdpr_eprivacy.pre_consent_third_party_tracking.tracker_inventory.medium",
"ws01EvidenceRole": "retained_pre_consent_tracker_inventory",
"wc01NormalizedConcernKey": "pre_consent_third_party_tracking"
},
"statusBasis": "Medium priority pre-consent tracker inventory was retained without a promotion-eligible normalized concern or unified finding: Google Analytics - Analytics (1.11s). Tracking is not confirmed from grouped inventory alone.",
"retainedEvidence": {
"tagManagerOnly": false,
"trackerPriority": "medium",
"trackerPriorityLabel": "Medium",
"missingEvidenceNeeded": [
"CertScore.unifiedFinding.preconsent_tracking: Grouped tracker inventory remains review evidence unless the canonical promotion-grade sequence contract passes."
],
"serviceConnectionOnly": false,
"selectedEvidenceReason": "Selected retained pre-consent request/vendor timing evidence; storage evidence is evaluated separately.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"selectedEvidenceArtifactId": "preConsentTrackingRequestEvidence.missing",
"trackingEvidenceAssessment": {
"result": "not_confirmed_from_grouped_inventory",
"scoreEffect": "review"
},
"contextualInfrastructureOnly": false,
"preconsentThirdPartyTrackerGroups": [
{
"party": "mixed",
"vendor": "Google Analytics",
"purpose": "Analytics",
"priority": "medium",
"firstSeenMs": 1115
}
],
"preconsentThirdPartyTrackingVendors": [
"Google Analytics"
],
"preconsentThirdPartyTrackerGroupCount": 1,
"firstPreconsentThirdPartyTrackingObservedMs": 1115,
"selectedPreconsentThirdPartyTrackingVendors": [
"Google Analytics"
]
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": [
{
"field": "CertScore.unifiedFinding.preconsent_tracking",
"actual": "tracker inventory only",
"source": "CertScore.ai",
"expected": "promotion-eligible normalized concern and unified finding",
"whyNeeded": "Grouped tracker inventory remains review evidence unless the canonical promotion-grade sequence contract passes."
}
]
}{
"assessmentStatus": "review_signal",
"checklistItemId": "pre_consent_cookies_storage",
"coverageArea": "Non-essential storage timing review",
"evidenceState": "observed",
"explanation": "Classified non-essential storage identities were present in a pre-consent snapshot, but retained evidence did not confirm that they were written during the scan.",
"note": "Classified non-essential storage identities were present in a pre-consent snapshot, but retained evidence did not confirm that they were written during the scan.",
"status": "Review signal",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.pre_consent_cookies_storage.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.pre_consent_cookies_storage"
},
"statusBasis": "Classified non-essential storage identities were present in a pre-consent snapshot, but retained evidence did not confirm that they were written during the scan.",
"retainedEvidence": {
"evidenceRefs": [
"_ga (ergoveritas.com): non_essential, present in periodic pre-consent snapshot",
"Aggregate pre-consent storage count: 1",
"Assessment reconciliation: reconciled"
],
"cookiesSeenCount": 1,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained concrete cookie/storage evidence for storage timing; request-only tracking evidence is not used as storage proof.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"cookiesBeforeConsentCount": 1,
"selectedEvidenceArtifactId": "preConsentCookieOrStorageEvidence.missing",
"preConsentStorageAssessment": {
"status": "snapshot_presence_only",
"evidenceRows": [
{
"name": "_ga",
"party": "first_party",
"domain": "ergoveritas.com",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 1517,
"initiatorDomain": "ergoveritas.com",
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"provenWriteCount": 0,
"assessmentVersion": "pre-consent-storage-assessment-v1",
"unclassifiedCount": 0,
"reconciliationStatus": "reconciled",
"snapshotPresenceCount": 1,
"aggregateObservedCount": 1,
"classifiedEssentialCount": 0,
"classifiedNonEssentialCount": 1,
"attributedPreConsentRecordCount": 1,
"excludedFunctionalOrConsentCount": 0
},
"preConsentStorageAssessmentStatus": "snapshot_presence_only",
"eligiblePreconsentCookieStorageRows": [
{
"name": "_ga",
"party": "first_party",
"domain": "ergoveritas.com",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 1517,
"initiatorDomain": "ergoveritas.com",
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"snapshotOnlyNonEssentialCookieNames": [
"_ga"
],
"rowLevelEssentialityEvidenceRetained": true,
"firstPreconsentCookieOrStorageObservedMs": 1517,
"preConsentStorageClassificationLimitation": true,
"preconsentCookieOrStorageExactTimingRetained": false,
"eligibleNonEssentialCookieStorageFindingProjected": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}| Domains | Relationship | Confidence | Review priority |
|---|
Accept path
Activity observedA confirmed Accept was followed by 2 requests and 2 storage writes, establishing the post-Accept comparison baseline.
Consent-state confirmation: recorded.
Retained evidence
Reject path
Issue observedA reject action and post-reject comparison window were retained, and eligible non-essential tracking activity persisted after reject.
Consent-state confirmation: recorded.
Retained evidence
Observed
Observed
Observed
CMP identity and control context are retained in the canonical consent projection.
After Accept
Activity observedConsent-dependent activity observed
A confirmed Accept was followed by 2 requests and 2 storage writes, establishing the post-Accept comparison baseline.
3s observation · TCF + CMP registry resolver
After Reject
Issue observedActivity observed after Reject
A reject action and post-reject comparison window were retained, and eligible non-essential tracking activity persisted after reject.
8s observation · TCF + CMP registry resolver
A verified first-layer consent surface with actionable controls was retained in the tested context.
{
"assessmentStatus": "checked",
"checklistItemId": "consent_surface_observed",
"coverageArea": "Consent mechanism",
"evidenceState": "observed",
"explanation": "An actionable cookie/consent banner or preference surface was observed in the tested context. This confirms CMP availability; consent-enforcement timing is assessed separately.",
"note": "An actionable cookie/consent banner or preference surface was observed in the tested context. This confirms CMP availability; consent-enforcement timing is assessed separately.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.consent_surface_observed.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.consent_surface_observed"
},
"statusBasis": "A verified first-layer consent surface with actionable controls was retained in the tested context.",
"retainedEvidence": {
"consentSurfaceState": "observed_actionable",
"missingEvidenceNeeded": [],
"consentSurfaceObserved": true,
"selectedEvidenceReason": "Retained evidence did not confirm an uncontaminated first-layer GDPR/ePrivacy cookie/CMP consent surface.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "consentControlLifecycleEvidence.surfaceClassification"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Consent mechanism is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
CMP: OneTrust CMP
CMP signal: #onetrust-banner-sdk
CMP signal: OneTrust
{
"assessmentStatus": "checked",
"checklistItemId": "cmp_framework_signal_observed",
"coverageArea": "CMP framework",
"evidenceState": "observed",
"explanation": "Whether a consent-management framework, CMP vendor, or CMP runtime signal was observed in the pre-consent/public-web context.",
"note": "Whether a consent-management framework, CMP vendor, or CMP runtime signal was observed in the pre-consent/public-web context.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.cmp_framework_signal_observed.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.cmp_framework_signal_observed"
},
"statusBasis": "A consent-management framework signal was retained: OneTrust CMP.",
"retainedEvidence": {
"evidenceRefs": [
"CMP: OneTrust CMP",
"CMP signal: #onetrust-banner-sdk",
"CMP signal: OneTrust",
"Evidence: pre-consent CMP runtime observation"
],
"cmpVendorName": "OneTrust CMP",
"missingEvidenceNeeded": [],
"cmpRuntimeSignalLabels": [
"#onetrust-banner-sdk",
"OneTrust"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"cmpFrameworkSignalObserved": true,
"selectedEvidenceArtifactId": "coverage_policy"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}CMP framework is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
candidate_0
/tmp/certscore-v2-dag-lambda/f4362840-376e-4d8c-897a-34a220136ad4/lanes/consent_proof/screenshot-pre-consent-geometry-proof.png
Consent Ui Pre Consent:Accept all
{
"assessmentStatus": "checked",
"checklistItemId": "reject_all_path_availability",
"coverageArea": "Decline consent control",
"evidenceState": "observed",
"explanation": "A reject-all or equivalent refusal path was observed from the consent surface in the tested context. This positive control is assessed separately from pre-consent tracking enforcement.",
"note": "A reject-all or equivalent refusal path was observed from the consent surface in the tested context. This positive control is assessed separately from pre-consent tracking enforcement.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.reject_all_path_availability.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.reject_all_path_availability"
},
"statusBasis": "A reject or equivalent refusal path was retained in the tested consent surface.",
"retainedEvidence": {
"evidenceRefs": [
"candidate_0",
"/tmp/certscore-v2-dag-lambda/f4362840-376e-4d8c-897a-34a220136ad4/lanes/consent_proof/screenshot-pre-consent-geometry-proof.png",
"consent_ui_pre_consent:Accept all",
"candidate_1",
"consent_ui_pre_consent:Reject all",
"candidate_2"
],
"layerInspected": "first_layer",
"visibleRejectLabels": [
"Reject all"
],
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained same-surface reject-path or post-reject comparison evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "strong",
"rejectInteractionSucceeded": false,
"selectedEvidenceArtifactId": "rejectPathDepthAndAvailability",
"completeRejectPathAvailable": true,
"consentControlInventoryConcern": {
"originKey": "consent.control_inventory.complete_first_layer",
"canonicalConcernKey": "runtime_artifact:consent.control_inventory.complete_first_layer"
}
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Decline consent control is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
candidate_0
/tmp/certscore-v2-dag-lambda/f4362840-376e-4d8c-897a-34a220136ad4/lanes/consent_proof/screenshot-pre-consent-geometry-proof.png
Consent Ui Pre Consent:Accept all
{
"assessmentStatus": "checked",
"checklistItemId": "accept_consent_control",
"coverageArea": "Accept consent control",
"evidenceState": "observed",
"explanation": "An accept, accept-all, or allow-all control was observed from structured first-layer consent-surface evidence. This confirms availability, not the result of clicking it.",
"note": "An accept, accept-all, or allow-all control was observed from structured first-layer consent-surface evidence. This confirms availability, not the result of clicking it.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.accept_consent_control.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.accept_consent_control"
},
"statusBasis": "A structured accept, accept-all, or allow-all consent control was observed in the policy-gated normalized first-layer inventory.",
"retainedEvidence": {
"evidenceRefs": [
"candidate_0",
"/tmp/certscore-v2-dag-lambda/f4362840-376e-4d8c-897a-34a220136ad4/lanes/consent_proof/screenshot-pre-consent-geometry-proof.png",
"consent_ui_pre_consent:Accept all",
"candidate_1",
"consent_ui_pre_consent:Reject all",
"candidate_2"
],
"acceptControlObserved": true,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained same-surface accept consent control evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "strong",
"selectedEvidenceArtifactId": "firstLayerConsentChoices.acceptControl",
"consentControlInventoryConcern": {
"originKey": "consent.control_inventory.complete_first_layer",
"canonicalConcernKey": "runtime_artifact:consent.control_inventory.complete_first_layer"
}
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Accept consent control is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
/tmp/certscore-v2-dag-lambda/f4362840-376e-4d8c-897a-34a220136ad4/lanes/consent_proof/screenshot-pre-consent-geometry-proof.png
scan_runtime_artifacts.consent_control_assessment
Consent governance disclosure note: retained public materials did not clearly explain how users can revisit, change, withdraw, retain, renew, expire, or understand consent choices.
{
"assessmentStatus": "checked",
"checklistItemId": "options_settings_preferences_control",
"coverageArea": "Options / settings / preferences control",
"evidenceState": "observed",
"explanation": "Whether a first-layer options, settings, preferences, or manage-preferences control was observed on the retained consent surface.",
"note": "Whether a first-layer options, settings, preferences, or manage-preferences control was observed on the retained consent surface.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.options_settings_preferences_control.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.options_settings_preferences_control"
},
"statusBasis": "A dedicated options, settings, or preferences control was observed on the retained first-layer consent surface.",
"retainedEvidence": {
"evidenceRefs": [
"/tmp/certscore-v2-dag-lambda/f4362840-376e-4d8c-897a-34a220136ad4/lanes/consent_proof/screenshot-pre-consent-geometry-proof.png",
"scan_runtime_artifacts.consent_control_assessment",
"Consent governance disclosure note: retained public materials did not clearly explain how users can revisit, change, withdraw, retain, renew, expire, or understand consent choices.",
"Observed control: Manage options"
],
"missingEvidenceNeeded": [],
"optionsControlObserved": true,
"selectedEvidenceReason": "Selected retained same-surface options/settings/preferences control evidence.",
"weakerArtifactsIgnored": [],
"optionsControlProminence": "dedicated_button",
"selectedEvidenceStrength": "strong",
"selectedEvidenceArtifactId": "firstLayerConsentChoices.optionsControl",
"retainedConsentOptionsControls": [
{
"label": "Manage options",
"layer": "first_layer",
"evidenceId": "candidate_2",
"artifactRefs": [
"/tmp/certscore-v2-dag-lambda/f4362840-376e-4d8c-897a-34a220136ad4/lanes/consent_proof/screenshot-pre-consent-geometry-proof.png"
],
"placementType": "unknown",
"presentationType": "dedicated_button"
},
{
"label": "Manage options",
"layer": "first_layer",
"evidenceId": "consent_ui_pre_consent:Manage options",
"artifactRefs": [],
"placementType": "unknown",
"presentationType": "unknown"
}
],
"consentOptionsControlProminenceConcern": {
"state": "dedicated_button",
"originKey": "consent.options_control_prominence.dedicated_button",
"canonicalConcernKey": "runtime_artifact:consent.options_control_prominence.dedicated_button",
"regulatoryChecklistEligibility": "observed"
}
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Options / settings / preferences control is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
typed first-layer cookie consent surface retained
typed cookie settings/preferences control retained
Not confirmed: separate durable cookie policy or named-cookie inventory
{
"assessmentStatus": "checked",
"checklistItemId": "cookie_notice_policy_availability",
"coverageArea": "Cookie notice / cookie policy availability",
"evidenceState": "observed",
"explanation": "Whether a cookie notice, cookie policy, cookie settings surface, or equivalent cookie disclosure surface was retained.",
"note": "Whether a cookie notice, cookie policy, cookie settings surface, or equivalent cookie disclosure surface was retained.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.cookie_notice_policy_availability.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.cookie_notice_policy_availability"
},
"statusBasis": "A first-layer cookie notice and a cookie settings/preferences control were retained in the tested context. A separate durable cookie policy or named-cookie inventory was not confirmed.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: typed first-layer cookie consent surface retained",
"Evidence: typed cookie settings/preferences control retained",
"Not confirmed: separate durable cookie policy or named-cookie inventory"
],
"cookiePolicyPresent": false,
"cookieNoticeObserved": true,
"missingEvidenceNeeded": [],
"bannerOnlyCookieNotice": true,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"preConsentRuntimeEvidence": true,
"selectedEvidenceArtifactId": "coverage_policy",
"preferenceInterfaceConfirmed": true,
"granularCookieInventoryConfirmed": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Cookie notice / cookie policy availability is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
post-reject tracking reduction evidence
{
"assessmentStatus": "gap_observed",
"checklistItemId": "post_reject_tracking_reduction",
"coverageArea": "Post-choice tracking reduction",
"evidenceState": "observed",
"explanation": "A reject action and post-reject comparison window were retained, and eligible non-essential tracking activity persisted after reject.",
"note": "A reject action and post-reject comparison window were retained, and eligible non-essential tracking activity persisted after reject.",
"status": "Gap observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.post_reject_tracking_reduction.gap_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.post_reject_tracking_reduction"
},
"statusBasis": "A reject action and post-reject comparison window were retained, and eligible non-essential tracking activity persisted after reject.",
"retainedEvidence": {
"scoreEffect": "canonical_post_refusal_policy",
"evidenceRefs": [
"Evidence: post-reject tracking reduction evidence"
],
"resolverMethod": "tcf_api_cmp_registry_recipe",
"observationWindowMs": 8000,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained same-surface reject-path or post-reject comparison evidence.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "strong",
"postRejectWindowAvailable": true,
"reductionEvaluationStatus": "not_reduced",
"rejectInteractionConfirmed": true,
"selectedEvidenceArtifactId": "postRejectTrackingReductionEvidence",
"preConsentStorageNotCleared": false,
"postRejectNonEssentialRequests": [
{
"url": "https://www.google-analytics.com/g/collect",
"vendor": "Google",
"category": "analytics",
"hostname": "www.google-analytics.com",
"requestId": "post_refusal_request_3",
"activityType": "network_request",
"consentState": "post_reject",
"nonEssential": true,
"msAfterReject": 171,
"nonEssentialReason": "canonical_post_refusal_classification"
},
{
"url": "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/9032601",
"vendor": "Google",
"category": "advertising",
"hostname": "googleads.g.doubleclick.net",
"requestId": "post_refusal_request_4",
"activityType": "network_request",
"consentState": "post_reject",
"nonEssential": true,
"msAfterReject": 172,
"nonEssentialReason": "canonical_post_refusal_classification"
},
{
"vendor": "Google",
"category": "analytics",
"hostname": "ergoveritas.com",
"cookieName": "_ga",
"activityType": "storage_write",
"consentState": "post_reject",
"nonEssential": true,
"msAfterReject": 168,
"nonEssentialReason": "canonical_post_refusal_classification"
},
{
"vendor": "Google",
"category": "analytics",
"hostname": "ergoveritas.com",
"cookieName": "_gid",
"activityType": "storage_write",
"consentState": "post_reject",
"nonEssential": true,
"msAfterReject": 168,
"nonEssentialReason": "canonical_post_refusal_classification"
}
],
"refusalSignalContradictsAction": false,
"postRejectRequestRecordsObserved": true,
"preConsentStorageNotClearedCount": 0,
"postRejectNonEssentialRequestCount": 4,
"postRejectNonEssentialActivityRetained": true,
"storagePresenceDoesNotEstablishActiveUse": false,
"concretePostRejectNonEssentialDetailsRetained": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Tracking & external services
Third-party tracking observed before recorded consent
Review issue: Trackers fired before consent interaction
Signal: Pre-consent tracking detected
{
"assessmentStatus": "review_signal",
"checklistItemId": "pre_consent_third_party_tracking",
"coverageArea": "Pre-consent non-essential tracking",
"evidenceState": "not_observed",
"explanation": "Medium priority pre-consent tracker inventory was retained without a promotion-eligible normalized concern or unified finding: Google Analytics - Analytics (1.11s). Tracking is not confirmed from grouped inventory alone. This row is limited to concrete 3rd party tracker/request evidence retained before a recorded consent choice.",
"note": "Medium priority pre-consent tracker inventory was retained without a promotion-eligible normalized concern or unified finding: Google Analytics - Analytics (1.11s). Tracking is not confirmed from grouped inventory alone. This row is limited to concrete 3rd party tracker/request evidence retained before a recorded consent choice.",
"status": "Not confirmed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_fallback",
"concernPolicyKey": "gdpr_eprivacy.pre_consent_third_party_tracking.tracker_inventory.medium",
"ws01EvidenceRole": "retained_pre_consent_tracker_inventory",
"wc01NormalizedConcernKey": "pre_consent_third_party_tracking"
},
"statusBasis": "Medium priority pre-consent tracker inventory was retained without a promotion-eligible normalized concern or unified finding: Google Analytics - Analytics (1.11s). Tracking is not confirmed from grouped inventory alone.",
"retainedEvidence": {
"tagManagerOnly": false,
"trackerPriority": "medium",
"trackerPriorityLabel": "Medium",
"missingEvidenceNeeded": [
"CertScore.unifiedFinding.preconsent_tracking: Grouped tracker inventory remains review evidence unless the canonical promotion-grade sequence contract passes."
],
"serviceConnectionOnly": false,
"selectedEvidenceReason": "Selected retained pre-consent request/vendor timing evidence; storage evidence is evaluated separately.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"selectedEvidenceArtifactId": "preConsentTrackingRequestEvidence.missing",
"trackingEvidenceAssessment": {
"result": "not_confirmed_from_grouped_inventory",
"scoreEffect": "review"
},
"contextualInfrastructureOnly": false,
"preconsentThirdPartyTrackerGroups": [
{
"party": "mixed",
"vendor": "Google Analytics",
"purpose": "Analytics",
"priority": "medium",
"firstSeenMs": 1115
}
],
"preconsentThirdPartyTrackingVendors": [
"Google Analytics"
],
"preconsentThirdPartyTrackerGroupCount": 1,
"firstPreconsentThirdPartyTrackingObservedMs": 1115,
"selectedPreconsentThirdPartyTrackingVendors": [
"Google Analytics"
]
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": [
{
"field": "CertScore.unifiedFinding.preconsent_tracking",
"actual": "tracker inventory only",
"source": "CertScore.ai",
"expected": "promotion-eligible normalized concern and unified finding",
"whyNeeded": "Grouped tracker inventory remains review evidence unless the canonical promotion-grade sequence contract passes."
}
]
}retained pre-consent iframe inventory
{
"assessmentStatus": "checked",
"checklistItemId": "third_party_iframe_pre_consent",
"coverageArea": "3rd party iframes before consent",
"evidenceState": "not_observed",
"explanation": "Whether retained scanner evidence showed known 3rd party iframe embeds before a recorded consent action.",
"note": "Whether retained scanner evidence showed known 3rd party iframe embeds before a recorded consent action.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.third_party_iframe_pre_consent.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.third_party_iframe_pre_consent"
},
"statusBasis": "Retained iframe inventory did not show known 3rd party iframe embeds before a recorded consent action.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained pre-consent iframe inventory"
],
"missingEvidenceNeeded": [],
"preConsentIframeCount": 0,
"iframeObservationCount": 0,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}3rd party iframes before consent is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
retained pre-consent embedded-content inventory
{
"assessmentStatus": "checked",
"checklistItemId": "social_media_embed_pre_consent",
"coverageArea": "Social/media embeds or plugins loaded before consent",
"evidenceState": "not_observed",
"explanation": "Whether retained network/runtime evidence showed a social, video, media embed, social pixel, or plugin provider loading before a recorded consent action.",
"note": "Whether retained network/runtime evidence showed a social, video, media embed, social pixel, or plugin provider loading before a recorded consent action.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.social_media_embed_pre_consent.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.social_media_embed_pre_consent"
},
"statusBasis": "Retained embedded-content checks did not show a social/media embed, plugin, widget, or pixel provider request before consent. Plain outbound links are not treated as evidence for this row.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained pre-consent embedded-content inventory"
],
"placeholderDetected": false,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"socialMediaEmbedObservationCount": 0
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Social/media embeds or plugins loaded before consent is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
EmbeddedContentObservationCount: 0
{
"assessmentStatus": "checked",
"checklistItemId": "embedded_content_pre_consent",
"coverageArea": "Embedded third-party services before consent",
"evidenceState": "not_observed",
"explanation": "Whether retained scanner evidence showed iframe, embed, widget, or visibly integrated third-party services before a recorded consent action. This row does not represent all background analytics or network requests.",
"note": "Whether retained scanner evidence showed iframe, embed, widget, or visibly integrated third-party services before a recorded consent action. This row does not represent all background analytics or network requests.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.embedded_content_pre_consent.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.embedded_content_pre_consent"
},
"statusBasis": "Iframe/runtime checks completed for the tested context and did not retain a concrete 3rd party embedded-content iframe before consent.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained pre-consent embedded-content inventory"
],
"missingEvidenceNeeded": [],
"preConsentIframeCount": 0,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"embeddedContentObservationCount": 0
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Embedded third-party services before consent is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Policy and transparency
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
privacy notice link/surface retained
Limitation: substantive policy body not retained
{
"assessmentStatus": "checked",
"checklistItemId": "privacy_notice_availability",
"coverageArea": "Privacy notice link/surface discovered",
"evidenceState": "observed",
"explanation": "Whether a reachable privacy notice or privacy policy link/surface was retained. This row does not by itself confirm that substantive notice content was available.",
"note": "Whether a reachable privacy notice or privacy policy link/surface was retained. This row does not by itself confirm that substantive notice content was available.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.privacy_notice_availability.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.privacy_notice_availability"
},
"statusBasis": "A privacy-notice link or page surface was reachable, but substantive notice content was not available in the retained rendered text. Row-specific transparency disclosures remain unconfirmed.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: privacy notice link/surface retained",
"Limitation: substantive policy body not retained"
],
"signalObserved": "surface_only_substantive_content_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"policyEvidenceAssessment": {
"result": "disclosure_observed",
"scoreEffect": "canonical_policy",
"topicRelevance": "direct",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "moderate",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"policySurfaceSummary": {
"scanStartedAt": "2026-09-03T18:26:02.813Z",
"observedTopics": [],
"cookiePolicyUrls": [],
"cookieDisclosures": [],
"mentionedControls": [],
"privacyPolicySize": null,
"privacyPolicyUrls": [],
"cookie_disclosures": [],
"policySectionCount": 0,
"policySurfaceCount": 1,
"cookiePolicyPresent": false,
"scannedPageLanguage": "en",
"privacyPolicyPresent": false,
"policyPrimaryLanguage": null,
"policyLastUpdatedTexts": [],
"policyTextCoverageMode": "none",
"retainedPolicySections": [],
"policyCookieDisclosures": [],
"privacyPolicyDiscovered": true,
"processingErrorObserved": false,
"observedPolicyTopicHints": [],
"policyDocumentProvenance": [],
"policy_cookie_disclosures": [],
"article13DisclosureSignals": [],
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"privacyPolicyEvidencePaths": [],
"discoveredPrivacyPolicyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"article13CoverageAssessments": [
{
"topic": "automated_decision_making_or_profiling",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "controller_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_retention",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_subject_rights",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "dpo_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "international_transfers",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "legal_basis",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "processing_purposes",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "recipients_or_vendor_categories",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "supervisory_authority",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
}
],
"policyTextEvidenceProjection": {
"scanId": "f4362840-376e-4d8c-897a-34a220136ad4",
"documents": [
{
"documentRole": "unknown",
"requestedUrl": "/.well-known/certscore-canary/broad-baseline-policy.html",
"observationId": "policy_surface_69a06545",
"redirectChain": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"documentFormat": "unknown",
"limitationKeys": [
"policy_text_artifact_reference_missing",
"policy_text_artifact_text_unavailable",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text"
],
"extractionStatus": "unavailable",
"retainedTextChars": 0,
"documentFetchState": "failed",
"targetRelationship": "unknown",
"documentTextCoverage": {
"status": "unavailable",
"limitationKeys": [
"policy_document_text_coverage_derived_for_legacy_observation"
],
"sourceTextChars": 0,
"retainedTextChars": 0
},
"documentEvaluationState": "not_attempted",
"documentRoleReasonCodes": [],
"governingPolicySelection": {
"score": 0,
"state": "ineligible",
"reasonCodes": [
"policy_document_status_failed",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_role_unknown",
"policy_document_target_ownership_unverified"
],
"contractVersion": "governing_policy_selection.v1"
},
"artifactVerificationStatus": "missing_reference",
"gdprTransparencyTopicCoverageDiagnostics": []
}
],
"generatedAt": "2026-09-03T18:26:09.224Z",
"sourceBundle": {
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f4362840-376e-4d8c-897a-34a220136ad4/CanonicalEvidenceBundle.json",
"sha256": "b39f7c4b1393aa4553312a6ac4ed806055935baeb62327c6e1862ac256d4661b",
"sizeBytes": 92984,
"schemaVersion": "certscore.v2.alpha.1",
"verificationStatus": "verified"
},
"limitationKeys": [
"policy_text_artifact_reference_missing",
"policy_text_artifact_text_unavailable",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text",
"verified_owned_complete_policy_document_unavailable"
],
"contractVersion": "certscore.policy-text-evidence-projection.v1",
"projectionStatus": "verified_partial"
},
"privacyPolicyEvaluationState": "discovered_fetch_failed",
"legalFrameworkValidityMatches": [],
"missingExpectedPolicySections": [
"Your privacy controls",
"Exporting and deleting your information",
"Retaining your information",
"Compliance and cooperation with regulators",
"European requirements",
"Data transfers"
],
"policy_text_extraction_health": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"retainedPolicySectionHeadings": [],
"selectedPrivacyPolicyDocument": null,
"article13_coverage_assessments": [
{
"topic": "automated_decision_making_or_profiling",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "controller_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_retention",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "data_subject_rights",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "dpo_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "international_transfers",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "legal_basis",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "processing_purposes",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "recipients_or_vendor_categories",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
{
"topic": "supervisory_authority",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
}
],
"discoveredPrivacyPolicyDetails": [
{
"url": "https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html",
"status": "failed",
"documentFetchState": "failed",
"fetchFailureReason": "http_error",
"linkObservationState": "observed",
"documentEvaluationState": "not_attempted"
}
],
"article13DisclosureTypesPartial": [],
"discoveredPrivacyPolicyStatuses": [
"failed"
],
"gdprTransparencyEvidenceProfile": "gdpr_transparency_multilingual_article13_v1",
"policy_text_evidence_projection": {
"scanId": "f4362840-376e-4d8c-897a-34a220136ad4",
"documents": [
{
"documentRole": "unknown",
"requestedUrl": "/.well-known/certscore-canary/broad-baseline-policy.html",
"observationId": "policy_surface_69a06545",
"redirectChain": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"documentFormat": "unknown",
"limitationKeys": [
"policy_text_artifact_reference_missing",
"policy_text_artifact_text_unavailable",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text"
],
"extractionStatus": "unavailable",
"retainedTextChars": 0,
"documentFetchState": "failed",
"targetRelationship": "unknown",
"documentTextCoverage": {
"status": "unavailable",
"limitationKeys": [
"policy_document_text_coverage_derived_for_legacy_observation"
],
"sourceTextChars": 0,
"retainedTextChars": 0
},
"documentEvaluationState": "not_attempted",
"documentRoleReasonCodes": [],
"governingPolicySelection": {
"score": 0,
"state": "ineligible",
"reasonCodes": [
"policy_document_status_failed",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_role_unknown",
"policy_document_target_ownership_unverified"
],
"contractVersion": "governing_policy_selection.v1"
},
"artifactVerificationStatus": "missing_reference",
"gdprTransparencyTopicCoverageDiagnostics": []
}
],
"generatedAt": "2026-09-03T18:26:09.224Z",
"sourceBundle": {
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f4362840-376e-4d8c-897a-34a220136ad4/CanonicalEvidenceBundle.json",
"sha256": "b39f7c4b1393aa4553312a6ac4ed806055935baeb62327c6e1862ac256d4661b",
"sizeBytes": 92984,
"schemaVersion": "certscore.v2.alpha.1",
"verificationStatus": "verified"
},
"limitationKeys": [
"policy_text_artifact_reference_missing",
"policy_text_artifact_text_unavailable",
"policy_document_fetch_failed",
"policy_document_evaluation_not_attempted",
"policy_document_target_ownership_unverified",
"policy_content_coverage_missing",
"policy_document_text_coverage_derived_for_legacy_observation",
"empty_policy_text",
"verified_owned_complete_policy_document_unavailable"
],
"contractVersion": "certscore.policy-text-evidence-projection.v1",
"projectionStatus": "verified_partial"
},
"privacyPolicyTextCharacterCount": 0,
"retainedCookiePolicyTextExcerpt": "",
"validatedDisclosureTypesPartial": [],
"article13DisclosureTypesObserved": [],
"retainedArticle13SectionEvidence": [],
"retainedPrivacyPolicyTextExcerpt": "",
"validatedDisclosureTypesObserved": [],
"privacyNoticeAvailabilityObserved": true,
"evaluatedPrivacyPolicySurfaceCount": 0,
"discardedArticle13DisclosureSignals": [],
"staleLegalFrameworkReferenceObserved": false,
"policyEvidenceProvenanceContractVersion": "certscore.policy-evidence-provenance.v1",
"gdprTransparencyProductionEvidenceEnabled": true,
"gdprTransparencyProductionEvidenceDiagnostics": {
"sourceCandidateCount": 0,
"candidateDispositions": [],
"acceptedCandidateCount": 0,
"rejectedCandidateCount": 0,
"discardedCandidateCount": 0,
"diagnosticCandidateCount": 0,
"productionCreditSignalCount": 0
}
}
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Privacy notice link/surface discovered is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "legal_basis_disclosure_observed",
"coverageArea": "Legal basis disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence included a canonical legal-basis disclosure signal.",
"note": "Whether retained privacy-policy evidence included a canonical legal-basis disclosure signal.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.legal_basis_disclosure_observed.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.legal_basis_disclosure_observed"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "legal_basis",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "retention_disclosure_observed",
"coverageArea": "Retention disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence included a data-retention disclosure signal.",
"note": "Whether retained privacy-policy evidence included a data-retention disclosure signal.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.retention_disclosure_observed.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.retention_disclosure_observed"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "data_retention",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "controller_contact_disclosure",
"coverageArea": "Controller/contact disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence included a controller, privacy contact, or equivalent contact point.",
"note": "Whether retained privacy-policy evidence included a controller, privacy contact, or equivalent contact point.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.controller_contact_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.controller_contact_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "controller_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "processing_purposes_disclosure",
"coverageArea": "Processing purposes disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described the purposes for processing personal data.",
"note": "Whether retained privacy-policy evidence described the purposes for processing personal data.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.processing_purposes_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.processing_purposes_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "processing_purposes",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "recipients_vendor_categories_disclosure",
"coverageArea": "Recipients/vendor categories disclosed",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described recipient, vendor, or 3rd party categories.",
"note": "Whether retained privacy-policy evidence described recipient, vendor, or 3rd party categories.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.recipients_vendor_categories_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.recipients_vendor_categories_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "recipients_or_vendor_categories",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "data_subject_rights_disclosure",
"coverageArea": "Data subject rights disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described data subject rights or a rights request path.",
"note": "Whether retained privacy-policy evidence described data subject rights or a rights request path.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.data_subject_rights_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.data_subject_rights_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "data_subject_rights",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "international_transfers_disclosure",
"coverageArea": "International transfer disclosure",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence described international transfers or transfer-relevant endpoint/vendor context.",
"note": "Whether retained privacy-policy evidence described international transfers or transfer-relevant endpoint/vendor context.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.international_transfers_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.international_transfers_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "international_transfers",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "dpo_contact_point_disclosure",
"coverageArea": "DPO contact point (where applicable)",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence identified a designated data protection officer or equivalent statutory DPO contact. A generic privacy mailbox is credited under controller/contact disclosure and does not by itself establish a DPO designation.",
"note": "Whether retained privacy-policy evidence identified a designated data protection officer or equivalent statutory DPO contact. A generic privacy mailbox is credited under controller/contact disclosure and does not by itself establish a DPO designation.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.dpo_contact_point_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.dpo_contact_point_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "dpo_contact",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "supervisory_authority_complaint_disclosure",
"coverageArea": "Supervisory authority complaint",
"evidenceState": "not_testable",
"explanation": "Whether retained privacy-policy evidence referenced a right to complain to a supervisory authority.",
"note": "Whether retained privacy-policy evidence referenced a right to complain to a supervisory authority.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.supervisory_authority_complaint_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.supervisory_authority_complaint_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "supervisory_authority",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Policy source
Policy source — URL not retained
Source policy language: Unknown; banner/page language: en; translation applied: No.
Policy reached through: Unknown; directly linked from scanned page: Unknown; retrieved during scan: 2026-09-03T18:26:02.813Z.
Section: Not retained.
No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.
{
"assessmentStatus": "coverage_limitation",
"checklistItemId": "automated_decision_making_profiling_disclosure",
"coverageArea": "Automated decision-making / profiling disclosure",
"evidenceState": "not_testable",
"explanation": "Whether adapter-approved Article 13 evidence retained automated decision-making or profiling disclosure context for review.",
"note": "Whether adapter-approved Article 13 evidence retained automated decision-making or profiling disclosure context for review.",
"status": "Not confirmed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.automated_decision_making_profiling_disclosure.not_confirmed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.automated_decision_making_profiling_disclosure"
},
"statusBasis": "No production-approved topic match was established. This neutral result does not establish that the disclosure is absent.",
"retainedEvidence": {
"signalObserved": "not_confirmed_canonical_projection_unavailable",
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"canonicalProjectionState": "normalized_concern_unavailable",
"policyEvidenceAssessment": {
"result": "extraction_incomplete",
"scoreEffect": "none",
"topicRelevance": "unknown",
"contractVersion": "certscore.policy-topic-evidence-assessment.v1"
},
"policyEvidenceProvenance": {
"bannerLanguage": "en",
"contractVersion": "certscore.policy-evidence-provenance.v1",
"retrievalTimestamp": "2026-09-03T18:26:02.813Z",
"translationApplied": false
},
"selectedEvidenceStrength": "missing",
"policyTextExtractionHealth": {
"policyUrls": [
"https://ergoveritas.com/.well-known/certscore-canary/broad-baseline-policy.html"
],
"nanoInvoked": false,
"nanoSkipReason": "policy_text_input_limited",
"contractVersion": "certscore.policy-text-extraction-health.v2",
"policyTextQuality": {
"reason": "empty_policy_text",
"usable": false,
"codeSignalCount": 0,
"codeSymbolRatio": 0,
"policyTermCount": 0,
"alphabeticWordRatio": 0,
"naturalLanguageSentenceCount": 0
},
"policyUrlRetained": true,
"extractedTextLength": 0,
"policySurfaceObserved": true,
"detectedPolicyLanguage": "en",
"extractionFailureReason": "privacy_policy_verified_text_artifact_unavailable",
"minimumTextLengthRequired": 500,
"policyTextExtractionStatus": "artifact_unavailable",
"verifiedPolicyDocumentCount": 0,
"detectedPolicyLanguageSource": "site_fallback",
"supportedGdprTransparencyLocales": [
"en",
"de",
"fr",
"es",
"it",
"nl",
"pl",
"pt",
"ru",
"ja",
"zh",
"ar",
"sv",
"ro",
"cs",
"el",
"hu",
"da",
"fi",
"sk",
"bg",
"hr",
"nb",
"sl",
"lt",
"lv",
"et",
"uk",
"tr",
"fa",
"vi",
"id",
"ko",
"th",
"he",
"sr",
"ca",
"hi",
"az",
"gl"
],
"gdprTransparencyLanguageSupported": true,
"policyTextEvidenceProjectionStatus": "verified_partial",
"policyTextEvidenceProjectionContractVersion": "certscore.policy-text-evidence-projection.v1"
},
"selectedEvidenceArtifactId": "coverage_policy",
"article13CoverageAssessment": {
"topic": "automated_decision_making_or_profiling",
"status": "insufficient_retained_evidence",
"sourceUrls": [],
"reasonCodes": [
"policy_absence_coverage_preconditions_not_met",
"typed_topic_coverage_diagnostic_missing_or_limited"
],
"coverageStatus": "insufficient",
"policyDocumentIds": [],
"policyDocumentRoles": [],
"policyDocumentSha256": [],
"assessmentContractVersion": "gdpr_transparency_article13_coverage_assessment.v1",
"unresolvedMaterialPolicyChildUrls": []
},
"gdprTransparencyReportStatusContract": "observed_not_confirmed_no_match_found.v1"
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}The scan could not retrieve enough policy text to evaluate this item. This does not indicate a policy problem by itself. Review the source policy manually or improve how the policy page is made available to the scan.
Pre-consent runtime
_ga (ergoveritas.com) non-essential, present in a check performed before consent, first seen at 1.52s.
{
"assessmentStatus": "review_signal",
"checklistItemId": "pre_consent_cookies_storage",
"coverageArea": "Non-essential storage timing review",
"evidenceState": "observed",
"explanation": "Classified non-essential storage identities were present in a pre-consent snapshot, but retained evidence did not confirm that they were written during the scan.",
"note": "Classified non-essential storage identities were present in a pre-consent snapshot, but retained evidence did not confirm that they were written during the scan.",
"status": "Review signal",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.pre_consent_cookies_storage.review_signal",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.pre_consent_cookies_storage"
},
"statusBasis": "Classified non-essential storage identities were present in a pre-consent snapshot, but retained evidence did not confirm that they were written during the scan.",
"retainedEvidence": {
"evidenceRefs": [
"_ga (ergoveritas.com): non_essential, present in periodic pre-consent snapshot",
"Aggregate pre-consent storage count: 1",
"Assessment reconciliation: reconciled"
],
"cookiesSeenCount": 1,
"missingEvidenceNeeded": [],
"selectedEvidenceReason": "Selected retained concrete cookie/storage evidence for storage timing; request-only tracking evidence is not used as storage proof.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "limited",
"cookiesBeforeConsentCount": 1,
"selectedEvidenceArtifactId": "preConsentCookieOrStorageEvidence.missing",
"preConsentStorageAssessment": {
"status": "snapshot_presence_only",
"evidenceRows": [
{
"name": "_ga",
"party": "first_party",
"domain": "ergoveritas.com",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 1517,
"initiatorDomain": "ergoveritas.com",
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"provenWriteCount": 0,
"assessmentVersion": "pre-consent-storage-assessment-v1",
"unclassifiedCount": 0,
"reconciliationStatus": "reconciled",
"snapshotPresenceCount": 1,
"aggregateObservedCount": 1,
"classifiedEssentialCount": 0,
"classifiedNonEssentialCount": 1,
"attributedPreConsentRecordCount": 1,
"excludedFunctionalOrConsentCount": 0
},
"preConsentStorageAssessmentStatus": "snapshot_presence_only",
"eligiblePreconsentCookieStorageRows": [
{
"name": "_ga",
"party": "first_party",
"domain": "ergoveritas.com",
"category": "analytics",
"storageType": "cookie",
"essentiality": "non_essential",
"timingEvidence": "periodic_preconsent_snapshot",
"exclusionReason": null,
"firstObservedMs": 1517,
"initiatorDomain": "ergoveritas.com",
"initiatorVendor": null,
"essentialitySource": "canonical_registry"
}
],
"snapshotOnlyNonEssentialCookieNames": [
"_ga"
],
"rowLevelEssentialityEvidenceRetained": true,
"firstPreconsentCookieOrStorageObservedMs": 1517,
"preConsentStorageClassificationLimitation": true,
"preconsentCookieOrStorageExactTimingRetained": false,
"eligibleNonEssentialCookieStorageFindingProjected": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}retained session replay / fingerprinting coverage summary
{
"assessmentStatus": "checked",
"checklistItemId": "session_replay_fingerprinting_review",
"coverageArea": "Session replay signal",
"evidenceState": "not_observed",
"explanation": "No eligible session replay, behavioral recording, or fingerprinting-like signal was observed in the tested context.",
"note": "No eligible session replay, behavioral recording, or fingerprinting-like signal was observed in the tested context.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.session_replay_fingerprinting_review.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.session_replay_fingerprinting_review"
},
"statusBasis": "Runtime vendor/fingerprinting checks completed for the tested context, and no eligible replay or fingerprinting finding was projected.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained session replay / fingerprinting coverage summary"
],
"sessionReplayCount": 0,
"missingEvidenceNeeded": [],
"sessionReplayObserved": false,
"fingerprintingObserved": false,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"sessionReplayRuntimeCoverageRetained": true,
"fingerprintingRuntimeCoverageRetained": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Session replay signal is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
retained fingerprinting/browser API coverage summary
{
"assessmentStatus": "checked",
"checklistItemId": "device_identification_fingerprinting_signal_observed",
"coverageArea": "Device identification / fingerprinting signal",
"evidenceState": "not_observed",
"explanation": "Whether browser/device entropy, fingerprinting, or identifier-like device collection signals were observed in retained runtime evidence.",
"note": "Whether browser/device entropy, fingerprinting, or identifier-like device collection signals were observed in retained runtime evidence.",
"status": "Not observed",
"tone": "neutral",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.device_identification_fingerprinting_signal_observed.not_observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.device_identification_fingerprinting_signal_observed"
},
"statusBasis": "Runtime fingerprinting/device-identification checks completed for the tested context and did not retain an eligible signal.",
"retainedEvidence": {
"evidenceRefs": [
"Evidence: retained fingerprinting/browser API coverage summary"
],
"missingEvidenceNeeded": [],
"fingerprintingObserved": false,
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"runtimeCaptureCompleted": true,
"runtimeEvidenceRetained": true,
"selectedEvidenceStrength": "missing",
"selectedEvidenceArtifactId": "coverage_policy",
"fingerprintingRuntimeCoverageRetained": true
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Device identification / fingerprinting signal is currently rated Not observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
GPC observation and comparison
No observable baseline delta was retained under the otherwise equivalent passive GPC condition. This does not determine whether any law was satisfied.
| Signal | Baseline | GPC | Delta | Baseline only | Shared | GPC only |
|---|---|---|---|---|---|---|
| Cookies | 1 | 1 | 0 | 0 | 1 | 0 |
| Trackers | 2 | 2 | 0 | 0 | 2 | 0 |
Transport security
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_https_delivery",
"coverageArea": "HTTPS delivery for scanned pages",
"evidenceState": "observed",
"explanation": "Whether the retained scanned page was served over HTTPS.",
"note": "Whether the retained scanned page was served over HTTPS.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_https_delivery.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_https_delivery"
},
"statusBasis": "The scanned page was served over HTTPS in the retained transport observation.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/sample_09_03_26_01.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/sample_09_03_26_01.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}HTTPS delivery for scanned pages is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
Company / Legal
Privacy rights requests can be submitted at certscore.ai/privacy-request or by emailing [email protected].
© 2026 CertScore.ai, LLC. All rights reserved.
Google | _ga | Analytics | 1.52s | ergoveritas.com | Same-site · entity unknown | review needed | |||
Google | Google Analytics | Analytics | 1.12s | google-analytics.com, ergoveritas.com | Mixed · entity unknown | medium | |||
| Advertising / measurement |
| 7 |
| 7 |
| 0 |
| 0 |
| 3 |
| 0 |
| Consent / CMP | 0 | 0 | 0 | 0 | 0 | 0 |
{
"assessment": {
"contractVersion": "certscore.gpc-response-assessment.v1",
"generatedAt": "2026-09-03T18:26:07.463Z",
"status": "no_observable_response",
"findingTitle": "No observable GPC response",
"scoreEffect": "none",
"legalInterpretation": "not_assessed",
"comparison": {
"comparable": true,
"protocol": "passive_baseline_with_sec_gpc",
"baselineArtifact": {
"lane": "runtime_evidence",
"sha256": "3b1614ae44013ceef2e6b76c1c4062c79c6c495572e46787131a4b203cda5920",
"sizeBytes": 40055,
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f4362840-376e-4d8c-897a-34a220136ad4/lanes/runtime_evidence/CanonicalEvidenceBundle.json"
},
"gpcArtifact": {
"lane": "gpc_observation",
"sha256": "bd44692bdb518814b64a4ef47c833c57dbd755a4af606120249a83b2d5a7968b",
"sizeBytes": 40078,
"uri": "s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f4362840-376e-4d8c-897a-34a220136ad4/lanes/gpc_observation/CanonicalEvidenceBundle.json"
},
"enabledProof": {
"secGpcHeaderValue": "1",
"requestsWithSecGpc": 2,
"requestEventIds": [
"net_1241",
"net_1244"
],
"navigatorGlobalPrivacyControl": true
},
"deltas": {
"cookies": {
"baselineCount": 1,
"gpcCount": 1,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": [
"[email protected]@/"
]
},
"trackers": {
"baselineCount": 2,
"gpcCount": 2,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": [
"Google|Google Analytics|analytics",
"Google|Google Analytics|tracker:vendor_d2f1fb1e"
]
},
"advertisingOrMeasurementActivity": {
"baselineCount": 7,
"gpcCount": 7,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": [
"Google|Google Analytics|analytics",
"Google|Google|analytics",
"request:www.google-analytics.com/g/collect"
]
},
"consentOrCmpBehavior": {
"baselineCount": 0,
"gpcCount": 0,
"countDelta": 0,
"baselineOnly": [],
"gpcOnly": [],
"shared": []
}
},
"evidenceRefs": [
"net_1241",
"net_1244",
"s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f4362840-376e-4d8c-897a-34a220136ad4/lanes/gpc_observation/CanonicalEvidenceBundle.json",
"s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f4362840-376e-4d8c-897a-34a220136ad4/lanes/runtime_evidence/CanonicalEvidenceBundle.json"
],
"limitationKeys": []
}
},
"californiaPolicy": {
"deductionPoints": 0,
"framework": "california"
},
"evidenceRefs": [
"s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f4362840-376e-4d8c-897a-34a220136ad4/lanes/runtime_evidence/CanonicalEvidenceBundle.json",
"s3://certscore-v2-dag-local-artifacts-eu-west-1-199536052647/v2-dag-lambda/local/f4362840-376e-4d8c-897a-34a220136ad4/lanes/gpc_observation/CanonicalEvidenceBundle.json",
"net_1241",
"net_1244"
]
}ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_tls_certificate",
"coverageArea": "Valid SSL/TLS certificate",
"evidenceState": "observed",
"explanation": "Whether a strict TLS probe verified the HTTPS origin certificate separately from the normal scanner runtime.",
"note": "Whether a strict TLS probe verified the HTTPS origin certificate separately from the normal scanner runtime.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_tls_certificate.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_tls_certificate"
},
"statusBasis": "Retained certificate validation verified the HTTPS origin certificate. Retained certificate evidence: https://ergoveritas.com/ presented CN=ergoveritas.com certificate valid Aug 6, 2026–Feb 19, 2027.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/sample_09_03_26_01.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/sample_09_03_26_01.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Valid SSL/TLS certificate is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_http_redirect",
"coverageArea": "HTTP redirects to HTTPS",
"evidenceState": "observed",
"explanation": "Whether an explicit HTTP-origin probe redirected to HTTPS.",
"note": "Whether an explicit HTTP-origin probe redirected to HTTPS.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_http_redirect.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_http_redirect"
},
"statusBasis": "The explicit HTTP-origin probe redirected to HTTPS.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/sample_09_03_26_01.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/sample_09_03_26_01.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}HTTP redirects to HTTPS is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_mixed_content",
"coverageArea": "Mixed content",
"evidenceState": "observed",
"explanation": "Whether HTTP subresources were observed or blocked on a retained HTTPS page.",
"note": "Whether HTTP subresources were observed or blocked on a retained HTTPS page.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_mixed_content.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_mixed_content"
},
"statusBasis": "No mixed-content HTTP subresources were retained for the scanned HTTPS page.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/sample_09_03_26_01.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/sample_09_03_26_01.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Mixed content is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.
ref_transport_security
{
"assessmentStatus": "checked",
"checklistItemId": "transport_security_form_transport",
"coverageArea": "Observed form transport",
"evidenceState": "observed",
"explanation": "Whether observed forms resolved to HTTPS transport without submitting form data.",
"note": "Whether observed forms resolved to HTTPS transport without submitting form data.",
"status": "Observed",
"tone": "warning",
"pipeline": {
"projectionStage": "coverage_policy",
"concernPolicyKey": "gdpr_eprivacy_coverage.transport_security_form_transport.observed",
"ws01EvidenceRole": "observed runtime signal identification, evidence capture, and logging",
"wc01NormalizedConcernKey": "gdpr_eprivacy.coverage.transport_security_form_transport"
},
"statusBasis": "No insecure observed form transport was retained for the scanned page.",
"retainedEvidence": {
"finalUrl": "https://ergoveritas.com/sample_09_03_26_01.html",
"finalScheme": "https",
"evidenceRefs": [
"ref_transport_security"
],
"httpProbeStatus": 200,
"sampledPageUrls": [
"https://ergoveritas.com/sample_09_03_26_01.html"
],
"httpProbeOutcome": "redirected_to_https",
"httpProbeFinalUrl": "https://ergoveritas.com/",
"pageHttpsObserved": true,
"tlsProbeAttempted": true,
"formTransportCount": 0,
"httpProbeAttempted": true,
"validTlsCertificate": true,
"httpProbeFinalScheme": "https",
"httpRedirectsToHttps": true,
"mixedContentObserved": false,
"missingEvidenceNeeded": [],
"httpProbeRedirectChain": [
"http://ergoveritas.com/",
"https://ergoveritas.com/"
],
"selectedEvidenceReason": "Selected the strongest retained canonical coverage evidence available for this row.",
"weakerArtifactsIgnored": [],
"selectedEvidenceStrength": "moderate",
"mixedContentObservedCount": 0,
"selectedEvidenceArtifactId": "coverage_policy",
"tlsCertificateObservations": [
{
"issuer": "CN=Amazon RSA 2048 M04, O=Amazon",
"subject": "CN=ergoveritas.com",
"validTo": "Feb 19 23:59:59 2027 GMT",
"inputUrl": "https://ergoveritas.com/",
"validFrom": "Aug 6 00:00:00 2026 GMT",
"validCertificate": true,
"chainCertificateCount": 4
}
],
"insecureFormTransportObserved": false
},
"projectedFindings": [],
"missingOrIncompleteSourceSignals": []
}Observed form transport is currently rated Observed. No site remediation is indicated from this row alone; rerun after material site, policy, or tag changes.