Privacy policy risk scanner

Privacy policy risk scanner

CertScore.ai helps teams compare what a public website appears to do in the browser with what its privacy and cookie disclosures appear to cover.

By CertScore.ai · Updated

CertScore.ai scans public website behavior for review signals. Findings are automated observations backed by retained evidence, not legal advice, certification, or compliance determinations.

What the scan reviews

Policy/runtime alignment
Tracking and vendor disclosure coverage
Cookie disclosure gaps
Session replay disclosure review
Privacy request and contact surface signals

Scan a public website

Loading scan form…

From a scan to a reviewable decision

  1. Check the context. Open the report and confirm the target, scan date, region, and coverage. A blocked or incomplete observation is a limitation, not evidence of an absent control.
  2. Inspect the observation. Follow a finding to its retained request, cookie, storage, or policy evidence. Keep pre-consent activity separate from activity after an Accept or Reject click.
  3. Verify the interpretation. A visible Reject button, a completed click, and confirmed refusal are different facts. A cookie remaining in storage does not by itself prove active tracking.
  4. Assign and retest. Give the responsible team the affected vendor, page, consent state, and evidence. After a configuration change, compare a new scan under the same conditions.

Use the sample report to explore the report format; it describes its own retained scan, not your website.

Turn a policy concern into a review task

Start with the retained policy excerpt and the corresponding browser observation. Identify the vendor or data category, confirm the policy belongs to the scanned site, and record any retrieval or coverage limitation. Missing evidence is an unknown, not proof that a disclosure is absent. Ask the policy owner and implementation team to review the same evidence.

Direct answer

A privacy policy risk scanner reviews whether public policy surfaces appear to cover important observable website behavior. CertScore.ai focuses on evidence-backed disclosure review signals, not legal advice.

What CertScore.ai checks

CertScore.ai can compare runtime behavior with visible privacy-policy and cookie-policy surfaces, including tracking categories, vendor behavior, cookies, session replay indicators, fingerprinting-related signals, and privacy request routes.

Why runtime context matters

A policy can look complete while the live site changes through tag managers, experiments, vendors, and embedded services. Runtime evidence helps teams spot drift.

Best review workflow

Use scan evidence to prioritize policy review, vendor inventory updates, CMP configuration checks, and engineering changes where the observed site behavior and disclosure surfaces appear misaligned.

Frequently asked questions

What is a privacy policy risk scanner?

It is a tool that reviews public policy content and observable website behavior to surface potential disclosure gaps or policy/runtime mismatches for human and agentic review.

Does CertScore.ai write privacy policies?

No. CertScore.ai surfaces review signals and retained evidence that can help privacy, legal, and engineering teams prioritize policy and implementation work.

What is a policy/runtime gap?

A policy/runtime gap is a review signal where observed browser behavior, such as tracking or cookies, may not appear clearly covered by public disclosure surfaces.

Key takeaways

CertScore.ai can help teams review privacy policy risk by comparing public policy surfaces with observable website behavior.

CertScore.ai is designed for evidence-backed review workflows and does not provide legal advice or compliance determinations.