Pre-consent defense & monitoring

Armor your site against consumer data leaks.

We load your site as a real visitor, catch every tracker that hands personal data to advertisers before anyone consents, and show you how to shut it down — then keep scanning on a schedule so it stays shut.

By scanning, you confirm you own this site or are authorized to have it scanned. Auramite loads the page once as an ordinary visitor and records what it requests — a technical measurement, not legal advice.

No signup · results in about half a minute · findings we detect, not a compliance certification

00What you get back

See the gap, then seal it.

Every finding is a request we actually caught leaving, with the clock reading at the moment it left. The gap between the first request and the question is the whole case.

Exhibit A — a real visitExample
  1. 0.31sGETsnap.licdn.com/li.lms-analytics/insight.min.js
  2. 0.44sGETwww.google-analytics.com/g/collect?v=2&tid=G-XXXX
  3. 0.68sPOSTpx.ads.linkedin.com/collect
  4. 6.90s of tracking with no way to say no
  5. 7.21sconsent banner rendered — the question is finally asked
01How it works

Four layers of cover.

01Probe

We find the gaps first

Headless Chrome opens your site cold — no cookies, no history — and records every request that fires before anyone touches your consent banner.

02Prove

Evidence, not opinions

You get the exact request URLs and their timestamps, so you can reproduce every finding yourself in DevTools in about thirty seconds.

03Reinforce

Close each gap, vendor by vendor

Which tags to gate behind consent, which need consent-mode wired up, and what to change in your tag manager to do it.

04Monitor

Data leaks stay sealed

We re-scan on a schedule and email you when a scan finds a new tag has slipped back in — which is usually how sites regress after a marketing hire.

02Coverage

What we check

Ad pixels firing before consent

Meta, Google, LinkedIn & TikTok tags that share visitor IDs on page load — a CCPA/CPRA “sale/share.”

Ignored “Do Not Track” (GPC) signals

A growing set of state laws require covered businesses to honor the browser opt-out signal automatically. Most sites don’t.

Session recording (CIPA)

Hotjar/FullStory/Clarity capturing what visitors type — the #1 “wiretapping” lawsuit issue of 2025.

Video + Meta Pixel (VPPA)

Tells Facebook which videos a visitor watched — a fast-growing class-action wave.

A cookie banner that doesn’t block

Termly/CookieYes installed but not gating anything — the pattern behind the $1.35M Tractor Supply fine.

Missing “Your Privacy Choices” opt-out

Required of businesses covered by CCPA and similar state laws that sell or share data.

03Pricing

Simple pricing

Starter

$99/mo

Keep your homepage clean

  • Monthly scan of your homepage
  • Every finding in full, with the proof
  • Alerts with every scan when a new tracker appears

Growth

Recommended

$299/mo

Cover the pages that matter

  • Everything in Starter
  • Weekly scans of up to 5 pages
  • Per-page finding granularity
  • GPC and consent-mode verification

Enterprise

$999/mo

Daily cover, with a human

  • Everything in Growth and Starter
  • Daily scans of up to 100 pages on your domain, subdomains included
  • Live consultation to build remediation plans
  • Fix verification after each change
  • Priority email support

One-time done-with-you remediation audits also available. No access to your servers required.

04FAQ

Common questions

Is scanning my homepage enough?

It’s a strong start, not the whole picture. A homepage scan catches anything installed across your whole site: tags loaded through Google Tag Manager or your theme, a consent banner that doesn’t actually block anything, and ignored Global Privacy Control (GPC) signals. Those are the most common problems. But several of the highest-risk leaks tend to live on other pages:

  • Video pages. The video + Meta Pixel pattern behind video-privacy (VPPA) suits, at $2,500 per violation, needs a video on the page — and that’s rarely the homepage.
  • Checkout and cart. Conversion pixels and session recording are often set up only there, right where the most sensitive data is.
  • Paid-ad landing pages. Often built in separate tools with their own tags, outside your consent banner’s control.
  • Blog templates. Ad networks like Taboola and Outbrain usually load only on articles.
  • Contact and demo forms. Along with chat widgets that only load on support or pricing pages.
  • Subdomains. shop. and blog. sites often run their own tags and their own consent setup.
  • Your “Your Privacy Choices” link. It can sit in your homepage footer and be missing from landing pages that have no footer.

That’s why Growth covers up to 5 pages you choose, and Enterprise covers up to 100 pages on one domain and its subdomains.

Start

Armor your site.

Free scan. No account. Results in under a minute.

Scan my site →