Most websites leak data
before anyone clicks accept.

Tracking cookies fire the moment a page loads, long before a visitor consents. In most cases, that’s a GDPR and ePrivacy breach, and it’s visible to anyone who runs a check: a prospect running due diligence, an enterprise buyer working through a security questionnaire, a competitor, an auditor, a regulator.

Find out what your site is doing, before they do. The check is free.

You’ll see the result here straight away, and we’ll email you the full cookie-by-cookie breakdown so you can forward it to whoever maintains the site. One follow-up at most. No list, no spam.

See what they seeWe load your site exactly as a first-time visitor does, and catch every cookie that fires before consent
Know how bad it isA clear pass or fail, plus an A to F grade so you can tell a stray tag from a systemic problem
Fix it fastNamed cookies, named vendors. Forward the report to your developers and it is usually a config change, not a rebuild

How we grade

A100No non-essential cookies fired before consent. The compliant pattern.
B781–2 non-essential cookies fired before consent. Minor exposure, likely a single misconfigured tag.
C623–4 non-essential cookies, or fewer with a consent platform present but not blocking correctly.
D485–6 non-essential cookies. Significant exposure across multiple trackers.
E347–9 non-essential cookies. The consent layer is not functioning.
F1810 or more non-essential cookies. Consent is absent or entirely non-functional.
N/ANo cookies detected and no consent platform found. The site may block automated browsers, or sets no cookies on the landing page. A manual check is needed.

Grades B–F reflect both the count of non-essential cookies and how many distinct third-party vendors received visitor data before consent. More vendors, lower grade — even at the same cookie count.

Built by Cycubix, a Dublin cybersecurity and GRC consultancy. We run ISO 27001, GDPR and security programmes for regulated companies, and we kept finding this same gap on sites that were otherwise well run. So we made the check free.

Most sites we scan fail. It is rarely negligence, usually a consent platform that was installed but never configured to actually block the tags.