Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Platform / Radar · THE ENGINE
Powers every Captain scan

Most scanners list cookies.
Radar verifies the banner actually works.

Radar visits your site with a real, undetectable browser and walks a visitor’s full consent journey across multiple isolated browser phases, so it doesn’t just inventory trackers but proves whether clicking “Reject” truly blocks them. Every run ends in a regulation-aware score and a legally-framed report.

6 isolated phases100+ privacy lawsSonar detection model
radar://scan/Acme.com
RUNNING
01
Pre-consentload + observe
fail · 8 pre-consent fires
02
Accept allbaseline w/ consent
pass · 23 trackers
03
Reject alldoes it actually stop?
fail · 7 still firing
04
GPC signalglobal privacy control
fail · ignored
05
Settings panelgranular toggles
pass · honoured
06
IAB frameworkTCF v2 · GPP · CMv2
pass · valid string
Phases: 6/6 Violations: 3 Each phase in a fresh browser context
The test every other tool skips

Does “Reject” actually block the trackers?

A cookie list tells you what loads. It says nothing about whether your banner does its job. Radar clicks "Reject all," then re-instruments the page and watches what fires anyway. This is the gap between "we have a banner" and "we're compliant."

acme.com, after "Reject all"7 still firing
Meta Pixel connect.facebook.netFIRED
GA4 googletagmanager.comFIRED
TikTok Pixel analytics.tiktok.comFIRED
Criteo OneTag static.criteo.netFIRED
LiveRamp idsync.rlcdn.comFIRED
What a passing banner looks like0 firing
Meta Pixel blocked pre-loadBLOCKED
GA4 consent-mode v2, cookielessGATED
TikTok Pixel blocked pre-loadBLOCKED
Criteo OneTag blocked pre-loadBLOCKED
LiveRamp never requestedBLOCKED
One scan, six isolated browsers

Each phase runs in a fresh context, so cookies can’t contaminate the result.

Most scanners load a page once and stop at that. Radar runs the consent journey six times over. Every phase is a brand-new browser with no memory of the last, so what we measure in "Reject" is never polluted by what happened in "Accept." Cybersecurity is about stopping the attacker; privacy is about surviving the auditor and litigator. We showcase your risk so you can protect against exactly that.

PHASE 01

Pre-consent

Load the page and do nothing. Catch every script, pixel, and cookie that fires before the visitor ever chooses.

isolated context · cold cache
PHASE 02

Accept all

Click accept and record the full set of trackers the site intends to run with consent. The baseline.

isolated context · cold cache
PHASE 03

Reject all

The headline test. Click reject, then verify whether the trackers actually stop, or quietly keep firing.

isolated context · cold cache
PHASE 04

GPC signal

Send a Global Privacy Control header and confirm the site treats it as a legally-binding opt-out.

isolated context · cold cache
PHASE 05

Settings panel

Open the preference center, toggle each category off, and check the granular choices are honoured.

isolated context · cold cache
PHASE 06

IAB framework

Validate TCF v2, GPP, and Google Consent Mode signals against the strings the site actually broadcasts.

isolated context · cold cache
What you get back

A score you can defend. A screenshot you can hand a regulator.

Every scan resolves to three things plaintiff firms and DPAs both understand: a regulation-aware grade, an annotated screenshot of exactly where the banner fails, and a per-state legal verdict with statute citations.

F
41/100
Regulation-aware. Radar understands opt-in GDPR vs opt-out US, so an opt-out banner firing pre-consent can’t fake a 100.
GDPRCCPA / CPRACIPAVPPA
Annotated capture · acme.com banner
violationdark pattern
State
Law
Citation
Verdict
California
CCPA / CPRA
§1798.135(a)
FAIL
Colorado
CPA
6-1-1306(1)(a)
FAIL
Texas
TDPSA
§541.055(b)
AT RISK
Virginia
VCDPA
59.1-577(A)(5)
FAIL
Connecticut
CTDPA
§6(e)(1)
PASS
Oregon
OCPA
§9(1)(a)
FAIL
Montana
MCDPA
§30-14-2812
AT RISK
Delaware
DPDPA
§12D-104(a)
FAIL
New Jersey
NJDPA
§56:8-166.9
FAIL
New Hampshire
NHPA
§507-H:6(I)
FAIL
Maryland
MODPA
§14-4607(a)
FAIL
Minnesota
MCDPA
§325O.05
AT RISK
Nebraska
NDPA
§87-1106
AT RISK
Kentucky
KCDPA
§367.3611
FAIL
Rhode Island
RIDTPPA
§6-48.1-4
FAIL
Indiana
INCDPA
§24-15-4-1
AT RISK
Iowa
ICDPA
§715D.4
PASS
Tennessee
TIPA
§47-18-3304
PASS
Utah
UCPA
§13-61-302
PASS
Florida
FDBR
§501.702(2)
AT RISK
Rules library covering 100+ privacy frameworks & 23+ US state verdicts can be evaluated · scroll for the full list10 FAIL · 6 AT RISK · 7 PASS
Measured, not guessed

Radar reads the real pixels of your banner.

Dark patterns hide in the geometry: a giant green Accept next to a gray four-pixel Reject link. Radar measures the rendered button colors and sizes, finds buried reject paths, and flags pre-checked boxes the same way a regulator's expert witness would.

A

Asymmetric accept vs reject

Compares the rendered size, color, and contrast of each path. A banner where Accept is 4× the visual weight of Reject gets flagged.

measured: accept 108×38px · reject 54×24px · 3.1:1 area ratio
H

Hidden reject button

Detects reject options pushed behind a "settings" click, rendered off-screen, or styled as plain text to look like a footnote.

found: reject 2 clicks deep · text-link styling · no button affordance
✓

Pre-checked consent boxes

Opens the preference center and reads the default state of every toggle. Marketing on by default is a GDPR violation, full stop.

found: 4 of 6 categories pre-enabled on load
⟳

Consent re-prompting / nagging

Flags banners that re-appear every page-load after a reject, wearing the visitor down until they accept just to make it stop.

observed: banner re-shown on every navigation post-reject
Everything else Radar catches

Built for the claims that actually get filed.

G

GPC compliance

Verifies the site honors Global Privacy Control browser signals, now legally enforceable in California and multiple states.

I

IAB framework validation

Checks TCF v2, GPP, and Google Consent Mode are present, well-formed, and consistent with on-page behavior.

$

Data-broker & "sale" detection

Flags pre-consent calls to LiveRamp, Acxiom, Meta and others as CCPA "sale" evidence, the finding that turns a scan into a class action case.

◷

Pre-consent tracker catch

Itemizes every script, pixel, and cookie firing before the visitor ever interacts with the banner.

⌖

Geo-disparity detection

Scans from multiple regions to catch sites that show a banner in California but not Tennessee. Compliance theater as the regulators call it.

S

Sonar detection model

Our own privately-trained ML model fingerprints unknown banners and classifies never-before-seen trackers, so nothing lands in an "unidentified" bucket.

Why the evidence holds up

A real browser. Undetectable. Continuous.

Real browser

Sees what a visitor sees

Stealth fingerprinting means Radar isn't served the bot-blocked, sanitized version of your site. It gets the real one.

Continuous

Not a one-off snapshot

Continuous scanning capabilities. Drift gets caught before a regulator finds it.

Our own ML

Sonar, trained in-house

A private model we built and own fingerprints unknown banners and novel trackers, never dropping them into an "unidentified" bucket.

Litigation-grade

Statute-cited, court-ready

Findings map to specific articles and case law: factual, evidentiary, the kind counsel can put in a binder.

For legal teams

Same engine, built into a brief. Meet Patrol.

Radar produces the evidence. Patrol turns it into a dual-voice report: an Operator summary for your team and a Legal summary that cites statutes and reads like an exhibit. Purpose-built for compliance and plaintiff-side counsel.

Patrol · Now Available

Do a Radar Scan. See if the banner holds?

Create a free account and run the full six-phase scan. A defensible grade in minutes.