Platform deep-dive

Platform capabilities

Every feature built to survive an audit. 19 capabilities across 6 stages of compliance intelligence.

22

features

6

stages

< 15 KB

gzipped

01

Stage 1

Baseline

The foundation - consent collection, scanning, analytics, and accessibility from day one.

Prior-consent script blocking

Third-party scripts are blocked before they can execute, not after. The level of enforcement required by CNIL, ICO, and German data protection authorities.

Regulator-grade

Automated cookie scanning

Scans up to 50 pages per domain, discovers every cookie, tracker, pixel, and beacon. Configurable depth and schedule so your declaration is always current.

Multi-page

Consent analytics

Opt-in rates by geography, regulation, and time period. Real-time dashboards that show exactly how your banners are performing, with full export capability.

Real data

WCAG 2.1 AA banner

Fully accessible consent banner with keyboard navigation, screen reader support, and high contrast. Six layout options including modal and full-screen.

Accessible

Cookie declaration widget

Embed a live cookie table on your privacy page that updates automatically after every scan. Grouped by category, with light and dark themes.

Auto-updating
02

Stage 2

Enforcement

Standards-compliant enforcement across every consent signal, server and client.

IAB TCF 2.2

Full IAB Transparency & Consent Framework support. Compatible with the global vendor ecosystem and ready for official CMP registration.

IAB compliant

Google Consent Mode v2

Consent signals pushed to Google Tag Manager and GA4 the moment a visitor makes a decision. Your ad and analytics tools stay compliant automatically.

GCM v2

Server-side enforcement

Consent validation at the server level for server-side tag management. Unauthorized events are blocked before they leave your infrastructure.

sGTM ready

Purpose-based policy engine

Supports all six GDPR lawful bases including legitimate interest with advertising carve-outs. Automatically applies the correct consent model per regulation.

GDPR Art. 6

Preference center

A persistent privacy button lets visitors update their consent preferences at any time, not just on first visit. Required for GDPR compliance.

Always accessible
03

Stage 3

Discovery

See everything that touches your visitors - every cookie, script, pixel, and beacon mapped and monitored.

Tracking graph

Interactive visual map of every tracker, script, pixel, and data flow on your site. See exactly who collects what, and how trackers relate to each other.

Visual intelligence

Multi-page crawling

Deep scans across up to 50 pages per domain with configurable depth. Discovers trackers on inner pages that homepage-only scanners miss entirely.

Deep scanning

Drift detection

Automatically detects when new trackers appear, existing ones disappear, or categories change between scans. Email alerts keep you informed before auditors do.

Real-time alerts

Pre/post consent audit

Runs your site twice: once before consent, once after. Identifies any tracker that fires before the visitor has given permission - the exact issue regulators look for.

Compliance audit
04

Stage 4

Compliance

Cryptographic proof, governance workflows, and version-controlled audit trails.

Tamper-proof consent ledger

Every consent record is cryptographically signed. Provides regulator-ready audit evidence that proves consent was collected, when, and what the visitor agreed to.

Cryptographic proof

Governance workflows

Structured review pipeline for every discovered cookie. SLA tracking flags unreviewed items after 7 days. Bulk actions for efficient governance at scale.

Audit workflow

Banner version history

Every banner configuration change is versioned with who changed it, when, and what was modified. Full audit timeline for compliance reviews.

Version control

ROPA/DPIA linkage

Link cookie purposes directly to your Records of Processing Activities and Data Protection Impact Assessments. Keeps governance documentation connected.

Governance links
05

Stage 5

Intelligence

AI-powered classification, continuous posture scoring, and dark pattern detection.

AI cookie classification

Unknown cookies are automatically classified by AI and presented as suggestions in your review queue. Human approval is always required - never auto-applied.

AI-powered

Consent posture score

A single compliance score (0-100) for each domain, measuring classification maturity, governance coverage, banner fairness, and enforcement quality.

Continuous scoring

Dark pattern detection

Real-time fairness analysis of your banner configuration. Flags practices that regulators consider deceptive, like missing close buttons or pre-checked categories.

Fairness guard
06

Stage 6

Enterprise

SDKs, policy-as-code, experimentation, multi-brand governance, and enterprise auth.

React SDK

Drop-in React components for consent-aware rendering. Gate content by category, read consent state from hooks, and listen for changes in real time.

Developer SDK

Next.js SDK

Server-side consent reading for Next.js App Router. Render different content based on consent state without client-side flicker.

Developer SDK

Policy-as-code

Export your entire consent policy as a portable file. Import it to restore, clone across domains, or version-control in your Git workflow.

GitOps ready

A/B testing

Test different banner designs with real traffic splits. Built-in fairness guardrails flag configurations that could be considered deceptive.

Compliant testing

Multi-brand governance

Manage consent across multiple brands and domains from a single account. Set central policy templates with per-brand overrides.

Enterprise scale

Consent sandbox

Simulate how enforcement behaves for any region and consent combination. Preview exactly what gets blocked or released before going live.

Safe testing

Consent debugger

Inspect any consent session in detail: what was consented to, which signals were sent, and whether the record passes integrity verification.

Deep inspection

Single Sign-On

SAML 2.0 SSO with automatic email domain routing. Team members are redirected to your identity provider without manual configuration.

Enterprise auth

Multi-factor authentication

Authenticator app-based MFA with org-level enforcement. Require all team members to verify their identity on every login.

Zero-trust

Under the hood

Technical specs

Built for performance-obsessed engineering teams.

specs.json
Script size< 15 KB gzipped
TCF version2.2
Banner renderingIsolated, zero layout shift
Load impactAsync, non-blocking
Google Consent Modev2
Consent ledgerCryptographically signed
APIREST with scoped API keys
SDKsReact, Next.js
Declaration widgetAuto-updating embed
Enterprise authSSO + MFA

Ready to deploy?

Start free. No credit card required. Live on your domain in under five minutes.