Most scanners list cookies.
Radar verifies the banner actually works.
Radar visits your site with a real, undetectable browser and walks a visitor’s full consent journey across multiple isolated browser phases, so it doesn’t just inventory trackers but proves whether clicking “Reject” truly blocks them. Every run ends in a regulation-aware score and a legally-framed report.
Does “Reject” actually block the trackers?
A cookie list tells you what loads. It says nothing about whether your banner does its job. Radar clicks "Reject all," then re-instruments the page and watches what fires anyway. This is the gap between "we have a banner" and "we're compliant."
Each phase runs in a fresh context, so cookies can’t contaminate the result.
Most scanners load a page once and stop at that. Radar runs the consent journey six times over. Every phase is a brand-new browser with no memory of the last, so what we measure in "Reject" is never polluted by what happened in "Accept." Cybersecurity is about stopping the attacker; privacy is about surviving the auditor and litigator. We showcase your risk so you can protect against exactly that.
Pre-consent
Load the page and do nothing. Catch every script, pixel, and cookie that fires before the visitor ever chooses.
Accept all
Click accept and record the full set of trackers the site intends to run with consent. The baseline.
Reject all
The headline test. Click reject, then verify whether the trackers actually stop, or quietly keep firing.
GPC signal
Send a Global Privacy Control header and confirm the site treats it as a legally-binding opt-out.
Settings panel
Open the preference center, toggle each category off, and check the granular choices are honoured.
IAB framework
Validate TCF v2, GPP, and Google Consent Mode signals against the strings the site actually broadcasts.
A score you can defend. A screenshot you can hand a regulator.
Every scan resolves to three things plaintiff firms and DPAs both understand: a regulation-aware grade, an annotated screenshot of exactly where the banner fails, and a per-state legal verdict with statute citations.
Radar reads the real pixels of your banner.
Dark patterns hide in the geometry: a giant green Accept next to a gray four-pixel Reject link. Radar measures the rendered button colors and sizes, finds buried reject paths, and flags pre-checked boxes the same way a regulator's expert witness would.
Asymmetric accept vs reject
Compares the rendered size, color, and contrast of each path. A banner where Accept is 4× the visual weight of Reject gets flagged.
Hidden reject button
Detects reject options pushed behind a "settings" click, rendered off-screen, or styled as plain text to look like a footnote.
Pre-checked consent boxes
Opens the preference center and reads the default state of every toggle. Marketing on by default is a GDPR violation, full stop.
Consent re-prompting / nagging
Flags banners that re-appear every page-load after a reject, wearing the visitor down until they accept just to make it stop.
Built for the claims that actually get filed.
GPC compliance
Verifies the site honors Global Privacy Control browser signals, now legally enforceable in California and multiple states.
IAB framework validation
Checks TCF v2, GPP, and Google Consent Mode are present, well-formed, and consistent with on-page behavior.
Data-broker & "sale" detection
Flags pre-consent calls to LiveRamp, Acxiom, Meta and others as CCPA "sale" evidence, the finding that turns a scan into a class action case.
Pre-consent tracker catch
Itemizes every script, pixel, and cookie firing before the visitor ever interacts with the banner.
Geo-disparity detection
Scans from multiple regions to catch sites that show a banner in California but not Tennessee. Compliance theater as the regulators call it.
Sonar detection model
Our own privately-trained ML model fingerprints unknown banners and classifies never-before-seen trackers, so nothing lands in an "unidentified" bucket.
A real browser. Undetectable. Continuous.
Sees what a visitor sees
Stealth fingerprinting means Radar isn't served the bot-blocked, sanitized version of your site. It gets the real one.
Not a one-off snapshot
Continuous scanning capabilities. Drift gets caught before a regulator finds it.
Sonar, trained in-house
A private model we built and own fingerprints unknown banners and novel trackers, never dropping them into an "unidentified" bucket.
Statute-cited, court-ready
Findings map to specific articles and case law: factual, evidentiary, the kind counsel can put in a binder.
Same engine, built into a brief. Meet Patrol.
Radar produces the evidence. Patrol turns it into a dual-voice report: an Operator summary for your team and a Legal summary that cites statutes and reads like an exhibit. Purpose-built for compliance and plaintiff-side counsel.
Do a Radar Scan. See if the banner holds?
Create a free account and run the full six-phase scan. A defensible grade in minutes.