A visitor in Frankfurt.
You replay the report.
Your engineer is handed the fix.
! Leaking · fired after reject f⊘ Meta Pixel
⊘ Blocked · refusal respected
run № 2 · leak closed ✓
Real browsers in real countries take every path through your client's cookie banner and record what actually fires. You get a report you can replay — and a ready-to-ship fix for every violation.
nothing to install · no client access · works with any CMP
see it happen↓run № 2 · leak closed ✓
Real browsers on residential connections — local language, local clock, local law. Not a VPN, not a simulation.
Every visit replays like a recording — every path, every tracker, every claim opens down to its evidence.
Every leak prints a paste-ready fix brief — for your dev or a coding agent. Re-run proves it closed.
Your CMP reports what it was told to do. CookieTrail reports what the site actually did. Here are both, from the visit you just watched.
self-reported · nothing looks wrong
observed from Frankfurt · after an explicit no
Not the hardcoded pixel, the ungated tag-manager trigger, or the tag another team shipped last quarter. Outside its blocking layer, it's blind.
It sends “denied” and trusts the vendor to comply. Its record reads the same whether the pixel obeyed or fired anyway.
It never checks what a Berliner got. Configuration isn't verification — and a tool grading its own homework isn't an audit.
Everyone audits one direction — the legal one. But a consent setup fails both ways, and the second failure is the one that lands on the agency.
Under GDPR and UK-GDPR that's exposure — and when it surfaces, it surfaces in the client relationship you own.
The campaign dashboard is quietly fiction — and you're the one presenting it.
We precheck whole agency rosters. Nearly every one surfaces a few of these — usually on the sites everyone assumed were fine.
A real CMP, installed and answering — while vendors beacon away with no consent recorded at all. The banner is scenery.
seen: national-press site · CMP live, 5 vendors beaconing, 166 third-party cookiesThe record defaults every category to accepted before anyone touches anything. The CMP “works” — it just presumes yes.
seen: fintech site · 29/29 categories pre-accepted on loadNo CMP at all. Ad and analytics trackers fire on first paint for every visitor in every jurisdiction.
seen: DTC brand · 6 trackers firing, no banner anywhereThe first layer offers “Accept” and a settings maze — no reject. In the UK and EU that's not a choice, it's a toll booth.
seen: two of five sites in one demo portfolioA consent wall holds every tag hostage — including in markets that don't require one. Lawful measurement, thrown away.
seen: US visitors walled, analytics dark in the biggest marketTags installed, configured, paid for — and never firing, on any path. Nobody noticed because nobody looked.
seen: telehealth site · pixel present, zero hits on all six visitsVerdicts from real prechecks and audits; sites anonymized. Findings about client sites stay private — outreach is one-to-one, never a wall of shame.
Give us your site — we read the portfolio and pull the client list. Or paste domains. No client access, no script tags, nothing to install, ever.
One passive visit per site ranks the portfolio by how interesting the consent mess is — fake installs and wide-open sites float to the top. Seconds per site, so thirty clients isn't thirty audits.
Real browsers on residential connections walk every consent path in every market you sell into — recording cookies, decoding consent records, reading toggles back, screenshotting each step.
Send it ahead of the call or walk them through it live. The findings are theirs; the deliverable — and the fix work it creates — is yours to sell.
Honest to a fault, by design. If we didn't observe something, the report says so — no invented timelines, no “no banner found” over a screenshot of a banner, and never a CMP's self-report taken as truth. We read the toggles back after every action, because consent tools lie about themselves more often than you'd think.
Keep whatever banner they have. CookieTrail is CMP-agnostic and outside-in — it doesn't replace OneTrust, Cookiebot or the rest. It's the independent check that says whether they're doing their job.
Drop your agency's site below. We'll precheck your whole portfolio free and walk you through the findings actually worth your time.
Nothing to install, no client access needed. Keep whatever banner they have — CookieTrail is the independent check.