Skip to main content

Early accessSign-in is running on Clerk development keys. Live DPO accounts need production Clerk keys — this is not a silent configuration.

System status →
🏢
ConsentSignals for Agencies

Flagged PDF. Fix. Re-scan PDF. That’s the client deliverable.

Your clients trust you with their websites. The client deliverable is flagged PDF → fix → re-scan PDF — not a one-off audit. On a CMP migration: baseline → staging acceptance → cutover re-scan. The CMP keeps the banner; we prove Accept / Reject / Consent Mode on the wire. After the CMP is live: run our acceptance checklist (Reject, prominence, Consent Mode, GTM race, preference-centre navigation QA). Independent evidence for the DPO — we do not host the banner. ConsentSignals gives agencies measured evidence — our 8-session consent matrix (8 browser sessions) — plus client workspaces, read-only share links, and a before/after pair of tamper-evident PDFs for every property you represent.

Does Reject actually stop trackers? We run an 8-session consent matrix — independent of your CMP. The scan is the trial; flagged → fixed PDFs are the product.

For agencies and advisors: retain written client authorisation. Anonymous scans are limited to properties you operate; major third-party platforms require sign-in.

Scan only URLs you own or have written permission to test.

Regulations that may apply to agencies sites

Educational reference — not a prediction for your scan.

FrameworkWhat it coversStatutory ceiling (ref.)
GDPR Art.5Reject-persistent optional tags — still fire after Reject (review signal)Qualitative band (human review)
ePrivacy / PECRReject All must stop non-essential tags in practiceICO / CNIL enforcement indicators
CPRA / GPCGlobal Privacy Control must default-deny non-essential tagsState AG letters (indicator)
Consent Mode / DMAConsent Mode storage & ads signals on the wire (interpret with ad_user_data / ad_personalization)Measurement + compliance risk

Illustrative statutory maxima from public enforcement examples — not predictions about any scanned site. Automated indicators only; not legal advice.

What ConsentSignals checks for agencies sites

Flagged → fixed: re-scan after remediation and hand the client both signed PDFs
CMP migration acceptance — baseline → staging → cutover evidence packs (you keep the CMP; we prove behaviour)
Post-CMP acceptance checklist — copyable pass/fail/review for Reject, Consent Mode, GTM race, preference-centre navigation QA
Client workspaces — group scans by end customer
Client one-pager on every full report — Reject result, domains, GTM steps, re-scan link
Reject session replay — before/after viewport clips + hosts that still fired
Subdomain packs — www + shop (and optional app with login warning)
Optional done-for-you GTM / Consent Mode remediation (/services)
Read-only share links for client DPOs (no login required)
8-session consent-differential audit — Accept, Reject, granular, withdrawal, GPC, returning user
CMP vendor-list reconcile — expected behaviour vs observed (OneTrust/Cookiebot CSV)
Banner theatre check — Accept vs Reject prominence (L0 heuristic)
Authenticated journeys (dashboard) — test consent beyond the homepage with controlled test accounts
Consent Mode v2 scorecard — verify Google Consent Mode + TCF 2.3 on the wire
White-label PDF reports with agency branding (Agency plan)
Bulk scan API — scan entire client portfolios programmatically
Scheduled re-scans with drift alerts (portfolio monitoring)
CI gate — fail staging builds when Reject leaks (/ci)
Optional child-audience vertical via ConsentSignals Kids (/kids)

Common questions

Ready to check your agencies site?

Free scan · No sign-up · Preview in a few minutes · Signed PDF on Starter+

Scan now