Keep your CMP
OneTrust, Cookiebot, Didomi, or Usercentrics continues to run your banner, store consent records, and manage vendor categories.
DPO workspace
We are not a CMP — we do not deploy your cookie banner or edit vendor categories inside OneTrust. We are the independent verification and evidence layer DPOs, agencies, and privacy teams use alongside their CMP.
Why not run the banner ourselves? CMPs are consent management systems — legal records, UI, and vendor taxonomy. ConsentSignals is consent verification — network measurement, drift detection, and audit artefacts. Combining both avoids vendor lock-in and matches how regulators test sites.
First-to-market readiness signals — visible in every child-privacy scan (HEAA, wallet) or as a dedicated audit (EAA). Indicators only; not certification.
OneTrust, Cookiebot, Didomi, or Usercentrics continues to run your banner, store consent records, and manage vendor categories.
We run a 8-session consent matrix (Accept All, Reject / Disagree All, Essential-only, Analytics-only, Withdraw marketing (Accept then revoke), GPC/DNT signal, Returning user (Reject cookies), and a passive baseline), flag GTM order issues, build an observed vendor inventory, and map findings to statute provisions.
Compare observed domains to your CMP vendor list. Export tracker CSV for import workflows. Fix tag order, re-scan, schedule daily CMP health checks.
Download HMAC-signed PDFs for board packs, client deliverables, and regulatory inquiry prep — indicators only, not legal verdicts.