We do not ask your site. We watch it.

A consent banner records a choice. It does not prove anything was honoured. Consentinel loads your site twice, under two different answers, and reports every difference between what you promised and what actually happened.

The two-pass scan

  1. Pass one: refuse

    A real browser loads your page. We detect your consent platform, find the reject control, and click it. Then we record every network request that leaves the page and every cookie written to it.

    Anything that fires here fired against an explicit refusal. That is the finding regulators act on.

  2. Pass two: accept

    The same page, the same browser, the opposite answer. We record the same two things again.

    This pass is what stops us crying wolf. A tag that appears only here is behaving correctly, and we say so by name.

  3. The difference is the report

    Everything present in both passes ignored the choice. Everything present only in the second pass is correctly gated. The gap between them is your exposure, and it is measured rather than assumed.

Every finding carries its proof.

We do not report that something "may be" firing. Each line comes with the exact request or cookie that caused it, so the person who has to fix it can verify the claim in their own devtools in under a minute.

That matters when the report leaves your desk. Evidence survives being forwarded to a developer, an agency, a lawyer, or an auditor. An opinion does not.

What we grade, and how

Every non-essential tag that fires before consent is a violation. They are not equally urgent. If everything is critical, nothing is, and the report stops helping you decide what to fix first.

Critical

Advertising and session recording. Data leaves for profiling, cross-site targeting, and resale. Personal data sent to a tracker in plaintext. A tag that saw a denied consent signal and fired anyway.

Warning

Analytics, tag managers, and social embeds. Still unlawful before consent, lower exposure, and usually a one-line Consent Mode fix rather than a rebuild.

Never flagged

Payment processors, bot protection, and strictly necessary cookies. These are lawful before consent. Flagging them would be crying wolf, so we recognise them and stay quiet.

What we do not do

Every tool in this category publishes what it catches. Here is what ours misses, because you should know before you rely on it.

  • We cannot always find your reject button. If your consent platform is custom or unusual, we may not be able to click refuse. When that happens the scan runs in the banner's default state instead, and the report says so, because "before any choice was made" is weaker evidence than "after refusing" and should not be presented as the same thing.
  • Some sites refuse us. Enterprise bot management can reject an automated browser outright. We would rather fail loudly than return a clean report we did not earn.
  • We cannot attribute every cookie. Real sites set cookies we do not recognise. We list them separately as evidence rather than counting them as findings, because we cannot prove they are non-essential and guessing would waste your time.
  • A scan is a moment, not a guarantee. A clean scan today says nothing about the tag someone adds on Thursday. That is what monitoring is for.

Point it at a page you own.

The free scan takes about a minute and needs no account. If the report is useful, the paid audit runs the same method across your whole site.

Scan a site