Consent audits for agencies

The banner is the promise.
This is the receipt.

Real browsers in real countries take every path through your client's cookie banner and record what actually fires. You get a report you can replay — and a ready-to-ship fix for every violation.

nothing to install · no client access · works with any CMP

see it happen
1 2 3

A visitor in Frankfurt.

You replay the report.

Your engineer is handed the fix.

🌐 +36 regions
🇺🇸 california
🇺🇸 virginia
🇬🇧 london
https://alpinesupply.co 🇩🇪 Frankfurt
Diese Website verwendet Cookies.
0 cookies set
0 trackers active
0 leaking
Google Tag Manager waiting
! Meta Pixel 🔧 fix it waiting
! Google Ads 🔧 fix it waiting
TikTok Pixel waiting
f! Meta Pixel 🔧 fix it
! Leaking · fired after reject
f Meta Pixel
⊘ Blocked · refusal respected

run № 2 · leak closed ✓

your engineer · or their coding agent
▸ paste fix-brief · alpinesupply.co · reject-all ▸ agent gating Meta Pixel + Google Ads behind marketing consent… ✓ done  shipped — verify with run № 2
COOKIETRAIL · FIX BRIEF
alpinesupply.co · UK · reject-all · run № 1
STOP META PIXEL FIRING AFTER “REJECT ALL”
observed  _fbp, fr written post-reject record    all-rejected (0/4 on) task      gate pixel behind marketing category verify    fresh profile → reject → _fbp absent
Leak closed ✓
open the full sample →
scroll
The whole picture

Global coverage. A replayable artifact.
Actionable receipts.

Global coverage

Real browsers on residential connections — local language, local clock, local law. Not a VPN, not a simulation.

A replayable artifact

Every visit replays like a recording — every path, every tracker, every claim opens down to its evidence.

Actionable receipts

Every leak prints a paste-ready fix brief — for your dev or a coding agent. Re-run proves it closed.

Why not just ask the CMP

Nothing audits itself.

Your CMP reports what it was told to do. CookieTrail reports what the site actually did. Here are both, from the visit you just watched.

The CMP's own record
consentStateall-rejected categories0 / 4 on marketingdenied statisticsdenied

self-reported · nothing looks wrong

What the browser actually did
_fbpwritten · .alpinesupply.co frwritten · .facebook.com IDEwritten · .doubleclick.net gtm triggerungated · fires outside the CMP

observed from Frankfurt · after an explicit no

It only sees what it controls

Not the hardcoded pixel, the ungated tag-manager trigger, or the tag another team shipped last quarter. Outside its blocking layer, it's blind.

It logs intent, not outcome

It sends “denied” and trusts the vendor to comply. Its record reads the same whether the pixel obeyed or fired anyway.

It decides what a Berliner sees

It never checks what a Berliner got. Configuration isn't verification — and a tool grading its own homework isn't an audit.

Both sides of the line

Too loose, your client carries the risk.
Too locked, you eat the loss.

Everyone audits one direction — the legal one. But a consent setup fails both ways, and the second failure is the one that lands on the agency.

⚑ Legal exposure — fires too much

The site tracks people who said no.

  • Ad pixels fire before anyone touches the banner
  • “Reject all” closes the banner — and changes nothing
  • The CMP defaults every category to accepted and calls it consent

Under GDPR and UK-GDPR that's exposure — and when it surfaces, it surfaces in the client relationship you own.

◌ Measurement loss — fires too little

The site blinds the tools you report with.

  • Trackers stay blocked even after the visitor accepts
  • A consent wall holds analytics hostage where no wall is required
  • Tags are installed, configured — and silent

The campaign dashboard is quietly fiction — and you're the one presenting it.

The target is maximum lawful measurement. CookieTrail scores both directions — every leak, and every signal you're entitled to but not getting.
What we find

The same messes, portfolio after portfolio.

We precheck whole agency rosters. Nearly every one surfaces a few of these — usually on the sites everyone assumed were fine.

fake-install

A real CMP, installed and answering — while vendors beacon away with no consent recorded at all. The banner is scenery.

seen: national-press site · CMP live, 5 vendors beaconing, 166 third-party cookies
implied-consent

The record defaults every category to accepted before anyone touches anything. The CMP “works” — it just presumes yes.

seen: fintech site · 29/29 categories pre-accepted on load
wide-open

No CMP at all. Ad and analytics trackers fire on first paint for every visitor in every jurisdiction.

seen: DTC brand · 6 trackers firing, no banner anywhere
no-reject-offered

The first layer offers “Accept” and a settings maze — no reject. In the UK and EU that's not a choice, it's a toll booth.

seen: two of five sites in one demo portfolio
over-locked

A consent wall holds every tag hostage — including in markets that don't require one. Lawful measurement, thrown away.

seen: US visitors walled, analytics dark in the biggest market
silent-tags

Tags installed, configured, paid for — and never firing, on any path. Nobody noticed because nobody looked.

seen: telehealth site · pixel present, zero hits on all six visits

Verdicts from real prechecks and audits; sites anonymized. Findings about client sites stay private — outreach is one-to-one, never a wall of shame.

The engagement

Portfolio in, receipts out.

1

Point us at your agency free

Give us your site — we read the portfolio and pull the client list. Or paste domains. No client access, no script tags, nothing to install, ever.

2

Precheck the whole roster free

One passive visit per site ranks the portfolio by how interesting the consent mess is — fake installs and wide-open sites float to the top. Seconds per site, so thirty clients isn't thirty audits.

3

Full audit on the sites that matter

Real browsers on residential connections walk every consent path in every market you sell into — recording cookies, decoding consent records, reading toggles back, screenshotting each step.

cookie ledgerconsent-record read-backpreference-panel read-back banner cartographyscreenshotsagent escalation
4

One branded link per client

Send it ahead of the call or walk them through it live. The findings are theirs; the deliverable — and the fix work it creates — is yours to sell.

Honest to a fault, by design. If we didn't observe something, the report says so — no invented timelines, no “no banner found” over a screenshot of a banner, and never a CMP's self-report taken as truth. We read the toggles back after every action, because consent tools lie about themselves more often than you'd think.

Keep whatever banner they have. CookieTrail is CMP-agnostic and outside-in — it doesn't replace OneTrust, Cookiebot or the rest. It's the independent check that says whether they're doing their job.

Start here

Three client sites. Fifteen minutes.

Drop your agency's site below. We'll precheck your whole portfolio free and walk you through the findings actually worth your time.

Precheck the whole portfolio · free Per-client audit · any market · every path · branded link Launch plan · audit every launch + re-verify fixes

Nothing to install, no client access needed. Keep whatever banner they have — CookieTrail is the independent check.