Scan your site free
Consent & Tracking Compliance · US Websites

Your website is tracking visitors before they say yes. We prove it — then fix it for good.

Enter your domain and we load your site like a first-time US visitor who never touched a cookie banner — then show you exactly which pixels and session-replay tools fire anyway. Free, no login, no call, about 60 seconds.

Free scan & reportNo call requiredResults in ~60s

Zero third-party requests on this page — scan us back Engineers, not lawyers Fixed price — no hourly billing
4,000+website "wiretapping" lawsuits filed since 2024
~$15,000typical settlement per demand letter
$1.35MCPPA fine against Tractor Supply (2025)
$5,000statutory damages per violation under CIPA
Figures from public court filings and California Privacy Protection Agency enforcement actions (Tractor Supply, Sept 2025; Honda, $632,500, March 2025).
Free scan

See what's firing on your site — right now.

Enter your domain. We run the same passive scan a plaintiff's firm would, and show you the result with a fixed-price quote — on this page, in about a minute.

We scan public pages only, passively, with an identified user agent. Your email is used to send the full report and follow-ups about your result — unsubscribe anytime.

Loading your site like a first-time US visitor…

How it works

From evidence to fixed — in one sprint.

1

Passive scan

We load your site exactly like a first-time US visitor who hasn't touched a consent banner — and log every tracking request that fires anyway, with timestamps and URLs.

2

Evidence report

You get the request log in plain English: which vendors fired, before what, and how the same evidence reads in a demand letter. Plus your email-security (DMARC) status.

3

Fix sprint

Fixed-price engagement: consent-gate every tag, install or rewire your consent platform, set up DMARC. Most sprints complete within days, verified by re-scan.

4

Monitoring

Tags creep back in with every marketing campaign. We re-scan on a schedule and alert you before a plaintiff's firm notices — with a monthly compliance record.

What the scan surfaces

Only client-side, observable facts.

Ad & analytics pixels firing pre-consent

Meta, TikTok, Google Ads, Pinterest, Snap, Bing, LinkedIn and ~30 more vendor signatures — each logged with timestamp and evidence URL.

Session-replay tools

Hotjar, Microsoft Clarity, FullStory, LogRocket and similar recorders — the highest-risk category in current litigation.

Consent banner reality check

Whether a consent platform is present — and whether your tags actually respect it, or silently leak around it.

Email security (DMARC/SPF)

Roughly 85% of domains have no DMARC record, leaving their brand open to spoofing. We check yours and set it up correctly.

Why a banner isn't enough

"We have a cookie banner" is the most expensive false comfort.

The lawsuits aren't about whether you have a banner. They're about what your tags do before anyone clicks it.

What most sites assume

  • A cookie banner means we're covered
  • The banner blocks tags until someone chooses
  • Our platform was set up once, so it still holds
  • Nobody's actually checking small stores

What the request log shows

  • Pixels fire in the first ~50 ms — long before the banner appears
  • Most banners record a choice they never enforce on the tags
  • Every campaign and theme update quietly re-adds trackers
  • Plaintiff firms scan sites at scale — the log is the evidence

We don't tell you whether you'll be sued — we're engineers, not lawyers. We show you exactly what your site does, and change what those facts are.

Pricing

Fixed-price sprints. No hourly billing.

Full Coverage

from $5,000
+ $199/mo monitoring
  • Everything in Consent Fix
  • Session-replay remediation and input masking
  • High tag counts (9+)
  • Accessibility (WCAG) quick wins
Get your quote from a free scan

Monitoring

$199/mo
no sprint required
  • Scheduled re-scans of your site
  • Alert when a new tag starts firing before consent
  • Quarterly report for your files
  • For sites that are already clean
Check my site first

The sprint price follows the actual work — tag count, platform and consent setup — and your free scan report contains the exact quote before you decide anything. Either number is a fraction of a single ~$15,000 settlement.

Who you're working with

Engineers, not lawyers.

Leon Sternel · VECTR Shield (OTA Precision Consulting LLC)

Connect on LinkedIn →

I run the scan that lands in your inbox, and I do the fix myself. Everything we report is client-side and verifiable — you can reproduce every finding in your own browser's network tab. We document what any visitor can observe, we don't practice law, and if you want legal advice on top of the engineering, we're happy to work alongside your counsel.

Scan us back. This page makes zero third-party requests — no pixels, no analytics, no fonts CDN, nothing. Open your network tab and check. That's the standard we hold your site to.
FAQ

Common questions.

How did you scan my site without my permission?

The scan is passive: it loads your public website once, the same way any visitor's browser does, and records which requests your own pages make. No login, no forms, no probing — just observation of publicly served assets, with an identified user agent.

We have a cookie banner. Aren't we covered?

A banner alone is the most common false comfort. In most scans where a consent platform is present, tags still fire before the visitor makes any choice — that gap between banner and behavior is exactly what current lawsuits target. The request log shows whether yours holds.

What does the fix actually involve, and how long?

We consent-gate every tag, set up or rewire your consent platform, and configure DMARC/SPF/DKIM — then prove it with a before/after re-scan you keep on file. Most sprints complete within days. It's a fixed price quoted from your scan, never hourly.

What happens after the fix sprint?

You get a verification re-scan showing the before/after request logs. Ongoing monitoring then re-scans your site on a schedule, because every new campaign tag or theme update can silently reintroduce pre-consent tracking.

Is this only about California?

California's CIPA drives the largest volume of claims, but similar suits are active in Pennsylvania, Florida, Illinois and Arizona, and roughly 20 states now have privacy statutes. The report also covers email security (DMARC), which is jurisdiction-independent.

Get the same evidence a plaintiff's firm would find — before they do.

Enter your domain and see what's firing on your site right now, with a fixed quote. Free report, no call, no commitment.

Scan your site free

Free scan & reportNo call requiredEngineers, not lawyers