Free Website Scan · Mobile App Scan In Development

The independent forensic privacy assessment your compliance stack cannot run objectively on itself.

Point CairnScan at any website and get a 15-section forensic report in under five minutes. A five-pass scan documents your site's actual consent behavior — pre-consent, after Accept All, after Reject All, under a Global Privacy Control signal, and across internal pages — scored against 37 privacy jurisdictions. Mobile app assessment is in development. Unlike tools and platforms that double as both CMP and auditor (a conflict of interest), and/or those that simply list the cookies you have, CairnScan objectively shows you what a regulator would find, what a plaintiff's attorney would argue, and exactly what to fix.

Jurisdictions Covered

37 regulatory frameworks, plus the EU ePrivacy Directive, US CIPA, US COPPA and US GPC signal testing. Automatic multi-jurisdiction detection.

See the full jurisdiction list →

Why Use CairnScan

Not a CMP vendor. Not a cookie scanner. An independent forensic auditor.

1

Independent Auditor

We audit OneTrust, Cookiebot, CookieYes, and every other consent platform. No CMP vendor will build this tool objectively — because it exposes failures in their own product. Normetics builds CairnScan as an unbiased independent auditor for consent platforms and privacy stacks.

2

Forensic Evidence

Designed by Normetics, a company focused on responsible AI and regulatory technology, CairnScan documents every finding with SHA-256 hashed screenshots, a timestamped action log, and reproducible browser evidence — the format regulators cite in enforcement actions.

3

Jurisdiction-Aware

The same website or mobile app gets different grades under GDPR vs CCPA vs multiple other regimes. We detect applicable jurisdictions automatically and score against each one — including GPC testing, where applicable.

In March 2026, 25 European data protection authorities launched a coordinated enforcement action on transparency obligations (GDPR Articles 12–14).
Feb 2026 — California's AG reached a $2.75M settlement with Disney, the largest CCPA fine to date, over opt-out failures across its toggle, webform, and Global Privacy Control signals.
March 2026 — the CPPA fined PlayOn Sports $1.10M in its first CCPA action on student privacy, for tracking-based targeted ads and an ineffective opt-out.
Feb 2026 — Jam City agreed to pay $1.4M after 21 mobile gaming apps lacked CCPA-compliant opt-outs and shared data of 13-to-16-year-olds without consent.
CIPA courts are split: CNN's website-tracking suit (D'Antonio) survived dismissal in the SDNY in April 2026, while NetScout's was dismissed with prejudice in May 2026 — with statutory damages up to $5,000 per violation.
Sept 2025 — France's CNIL issued €325M against Google and €150M against Shein over cookie-consent and ad-tech practices.
GDPR penalties since 2018 now exceed €7.1 billion, with about €1.2 billion issued in 2025 alone.
Dec 2025 — Disney agreed to pay $10M to settle FTC allegations that child-directed YouTube videos collected children's data without parental consent under COPPA.
The CPPA's dark-patterns advisory requires symmetric opt-out design and clear language — consent obtained through dark patterns is invalid.
NewMobile app scanning is in development. Switch to the Mobile App Scan tab below to help shape it and request early access.

Scan Your Website

Select the jurisdiction where your company is based. CairnScan automatically detects additional applicable jurisdictions from your privacy policy, domain, and legal documents.

Results in 1 – 5 minutes.

0%
Initializing assessment

What We Scan For

23 automated checks across cookie compliance and privacy infrastructure.

Cookie & Tracker Assessment

Pre-Consent Cookies

Cookies that fire before any user interaction — the #1 GDPR enforcement trigger.

The #1 reason EU regulators issue fines.

Reject-Path Testing

What happens when a user clicks Reject All? Fresh browser context, isolated from the accept path. SHA-256 evidence hashing at each step.

CNIL fined Google EUR 150M on 31 December 2021 (deliberation SAN-2021-023) for asymmetric cookie refusal mechanics under Article 82 of the French Data Protection Act.

Third-Party Trackers

Every pixel, script, and beacon sending your visitor data to external companies — before and after consent.

Each undisclosed transfer requires a Data Processing Agreement.

Data Flow Mapping

Which organizations receive your visitors' data — Google, Meta, HubSpot, and more — mapped to each transfer.

GDPR Article 13 requires you to disclose every recipient.

Visual Evidence

Timestamped screenshots at each consent phase — the documented proof regulators look for in enforcement proceedings.

The evidence format the ICO and CNIL cite in enforcement actions.

Cookie Classification

Every cookie identified by vendor, category, purpose, and data recipient — with unknowns flagged for review.

Unclassified cookies are regulatory unknowns — fix them first.

GPC Signal Testing

Does your site honor the Global Privacy Control opt-out signal? We send GPC headers and measure what changes.

CPPA fined Todd Snyder $350K for ignoring GPC signals.

Dark Pattern Detection

Measured CSS evidence of visual prominence asymmetry, click count asymmetry, pre-checked toggles, and hidden reject options.

EDPB Guidelines 03/2022 made dark patterns an enforcement priority.

Consent Banner / CMP Identification

Detects whether a consent banner is present and which platform is behind it — OneTrust, Cookiebot, CookieYes, Osano, IAB TCF, or a custom build.

No banner where one is required is a first-order consent failure.

CIPA Interception Timing

Measures whether trackers fire before any consent is given and after consent is rejected; and quantifies per-vendor CIPA exposure for California.

CIPA §638.51 / §631 — statutory damages of $5,000 per violation.

Privacy Setup Checks

Legal Page Detection

Privacy policy, terms of service, cookie policy, and accessibility statement — verified across common URL paths.

Missing pages are the first thing a regulator checks.

Footer & Navigation Links

Whether required legal pages are linked from the footer of every page, not buried or missing.

A page that exists but isn't linked is legally invisible.

CCPA Opt-Out Link

"Do Not Sell or Share" link detection — required if you share visitor data with advertising platforms.

California AG actively enforces missing opt-out links.

Consent Withdrawal

A persistent cookie preferences link so users can change their consent after the initial banner disappears.

GDPR Art. 7(3): withdrawal must be as easy as giving consent.

Form Consent Mechanisms

Forms collecting email addresses checked for consent checkboxes, pre-checked dark patterns, and privacy links.

Pre-checked boxes are invalid consent under CJEU Planet49.

Policy Adequacy Scan

Analyzes your privacy policy against 13 required GDPR disclosure elements with sub-element analysis.

Missing any of the 13 elements violates GDPR Art. 13.

Multi-Jurisdiction Detection

Automatic identification of all applicable jurisdictions from your domain, privacy policy, hreflang tags, and legal documents.

A UK company with EU visitors faces 3+ jurisdictions.

Company Domicile Inference

Determines your primary legal obligation from governing law clauses, corporate entity suffixes, and physical address patterns.

Your domicile determines which regulator has primary authority.

COPPA Child-Directed Risk

Flags child-directed signals — content and keyword cues, advertising trackers, a privacy policy silent on children, and a registration flow — that raise COPPA obligations.

FTC COPPA — children's data requires verifiable parental consent.

Cross-Border Transfer Check

Checks recipient vendors for EU-US Data Privacy Framework certification and detects the transfer mechanism your policy relies on, such as Standard Contractual Clauses.

GDPR Chapter V governs transfers out of the EEA.

DSAR Readiness

Verifies a working data-subject-rights mechanism and a contact method so visitors can actually exercise their access, deletion, and correction rights.

GDPR Arts. 15–22 / CCPA consumer rights.

Consent Record-Keeping

Inspects the CMP consent receipt via its browser-side API for a timestamp and granular, category-level consent choices.

GDPR Art. 7(1): you must be able to demonstrate consent.

DPIA Trigger Indicators

Detects processing activities — pre-consent tracking, behavioral profiling, undisclosed recipients, and unsafeguarded cross-border transfers — that trigger a mandatory Data Protection Impact Assessment.

GDPR Article 35 — a DPIA is mandatory for high-risk processing before it begins.

Mobile app assessment (in development)

A declared-vs-observed runtime assessment of app-store binaries is in development as the mobile counterpart to the website scan. Not yet live; join the early-access list from the scan section.

Assessment Tiers & Pricing

The free scan gives you your compliance grade and headline findings. Paid tiers go deeper.

For scale
Custom
Custom Pricing
For portfolios, programs, and partners.
  • Everything in Full Report, across multiple sites (and mobile apps as that launches)
  • Volume & multi-property pricing
  • Recurring scheduled scans
  • Consultant white-label / reseller arrangements
  • Bespoke jurisdictions or scope
  • Optional strategic consultation + board-ready summary
Coming soon
Continuous Monitoring
Monthly Subscription
Always-on compliance, not a point-in-time snapshot.
  • Monthly automated re-scans
  • Grade-trend tracking
  • New cookie / tracker / SDK detection
  • Delta reporting — improved / regressed / new
  • Drift and regression alerts

All plans are provided by Normetics LLC. Reports include timestamped forensic evidence with SHA-256 integrity hashes.

Frequently Asked Questions

How is CairnScan different from OneTrust, Cookiebot and CookieYes?

OneTrust, Cookiebot and CookieYes are Consent Management Platforms — they implement the consent banner. CairnScan is an independent auditor — we test whether their implementation actually works. We open a fresh browser, click Reject All, and document every cookie that persists. No CMP vendor will build this tool because it exposes failures in their own product. Beyond consent testing, CairnScan analyzes dark patterns with measured CSS evidence, checks your privacy policy against 13 GDPR-required disclosure elements, tests GPC signal compliance, and provides jurisdiction-specific scoring across 37 regulatory frameworks.

What jurisdictions do you cover?

GDPR (EU), UK GDPR + PECR, nFADP (Switzerland), CCPA/CPRA (US), PIPA (South Korea), APPI (Japan), PDPA (Singapore), LGPD (Brazil), DPDP Act (India), Privacy Act (Australia), PIPEDA (Canada), Quebec Law 25, Privacy Act 2020 (New Zealand), PIPL (China), 152-FZ (Russia), PDPA (Thailand), KVKK (Turkey), Privacy Protection Law (Israel), POPIA (South Africa), Law 25,326 (Argentina), Law 1581 (Colombia), Ley 29733 (Peru), Ley 18.331 (Uruguay), NDPA (Nigeria), PDPA (Taiwan), PDPL (Saudi Arabia), Federal PDPL (UAE), DPL No. 151 (Egypt), DPA 2019 (Kenya), DPA 2012 (Ghana), DPPA 2019 (Uganda), LFPDPPP (Mexico), Data Protection Law (Chile), Data Privacy Act 2012 (Philippines), PDPA 2010 (Malaysia), PDPL (Vietnam), and PDP Law 2022 (Indonesia). CairnScan automatically detects which jurisdictions apply based on your privacy policy content, domain signals, hreflang tags, and company location. GPC signal compliance is tested against the legal requirements of US states. We also assess US-specific exposure under CIPA (California wiretapping/pen-register) and COPPA (children's privacy).

Is this safe to run on my website?

Yes. The scan uses a standard headless browser — the same technology Google uses to index your site. It sends normal HTTP requests, clicks your consent banner, and observes the response. It does not modify your site, inject code, or access any authenticated areas.

Who sees my scan results?

Only you. Your report is delivered to the email address you provide and retained in accordance with our Privacy Policy; you may request deletion at any time. We do not publish, share, or sell scan results. Full details in our Privacy Policy.

What happens after I scan?

You get an instant summary report with your compliance grade, cookie breakdown, reject-path test result, and privacy setup findings. For the full 15-section report — complete cookie inventory, visual evidence, dark-pattern analysis, policy adequacy review, CIPA exposure, and a phased remediation roadmap — order the Full Report directly from the pricing section.

Do you assess mobile apps?

Mobile app assessment is in development. The website scan is live today; the mobile counterpart — a declared-vs-observed runtime assessment of app-store binaries — is in early access. Join the list from the scan section.

Can I use this report in a regulatory proceeding?

The report includes SHA-256 hashed screenshots, a timestamped forensic action log, and per-cookie penalty transparency — the evidence format regulators reference in enforcement actions. It is designed to be shared with legal counsel or attached to a regulatory filing. However, it is a technical assessment, not legal advice.

What's the difference between the free scan and paid tiers?

The free scan gives you both compliance grades and headline findings. The Full Report delivers diagnostic and remediation together as one document — complete technical evidence, prioritized remediation plan with timelines, and CMP configuration guidance. Custom pricing covers multi-property portfolios, recurring programs, consultants, and bespoke scope. Continuous Monitoring (coming soon) replaces point-in-time scans with always-on tracking — monthly re-scans, drift alerts, and delta reporting.

Who operates CairnScan?

CairnScan is developed and operated by Normetics LLC, a US-based company focused on building digital products and providing advisory services in the intertwined areas of responsible AI and regulatory technology.

Scan Now →