Most websites leak data
before anyone clicks accept.
Tracking cookies fire the moment a page loads, long before a visitor consents. In most cases, that’s a GDPR and ePrivacy breach, and it’s visible to anyone who runs a check: a prospect running due diligence, an enterprise buyer working through a security questionnaire, a competitor, an auditor, a regulator.
Find out what your site is doing, before they do. The check is free.
How we grade
Grades B–F reflect both the count of non-essential cookies and how many distinct third-party vendors received visitor data before consent. More vendors, lower grade — even at the same cookie count.
Built by Cycubix, a Dublin cybersecurity and GRC consultancy. We run ISO 27001, GDPR and security programmes for regulated companies, and we kept finding this same gap on sites that were otherwise well run. So we made the check free.
Most sites we scan fail. It is rarely negligence, usually a consent platform that was installed but never configured to actually block the tags.