Pick A Visitor Journey. Watch What Actually Loads.
Sample the same four-path consent audit that Feroot runs against your websites and mobile apps.
Before Consent (No Choice Yet)
5 violationsSimulated data for illustration. A real audit runs against your own properties and jurisdictions.
A Twenty-Millisecond Gap Is All It Takes
The most common consent failure is not a missing banner. It is a script that executes before the banner does, or quietly overwrites the visitor’s choice after, and every dashboard you own will still show green.
- 0 ms Page requested
- 180 ms Tag manager fires, 4 trackers load
- 200 ms Consent banner renders
- 3.4 s Visitor clicks Reject
The trackers were already loaded, the cookies were already set, and the identifiers were already sent, 3.2 seconds before the visitor was ever asked. The CMP records a valid rejection. The audit trail says you were compliant. The data left anyway.
Every Control, Every Visitor Journey, Every Jurisdiction
Feroot runs alongside whatever consent platform you already have, across your websites and mobile apps, and tells you what it actually does once it’s live.
CMP Override
A tag silently overwrites your consent platform’s stored preference and loads what the visitor explicitly declined anyway. Your dashboard still shows a valid rejection. This is the gap a regulator or plaintiff looks for first, and the one most sites never catch.
Pre-Consent Leakage
Scripts and cookies that execute before the visitor has made any choice, the failure that produces most enforcement exposure.
Signal Honoring
Whether Global Privacy Control and opt-out signals are actually respected downstream, not just received.
Control Presence
Banner, privacy notice, cookie policy, and a reject path as easy as the accept path, verified per jurisdiction.
Categorization Accuracy
Whether cookies marked “strictly necessary” actually are, the quiet exposure sitting in most consent configurations.
Drift Over Time
Websites change every week. The audit re-runs on your schedule and tells you when a control that passed last time stopped passing.
Three Steps To A Defensible Consent Posture
We Run Every Path
Before consent, accept, reject and GPC, across your websites and mobile apps and every jurisdiction you operate in, including properties built by agencies and partners.
You See What Actually Happened
Every tracker, every cookie, the vendor behind it and where the data went, mapped to the exact journey that triggered it, with a session recording of the run.
You Keep The Evidence
Dated, retained and exportable. When someone asks what your banner did last March, that question has an answer.
“Did You Do Anything About It?”
That is the question that decides an audit or a claim, not whether a problem ever existed. Every website has had a problem. Almost none can produce a contemporaneous record showing they were checking, what they found, and what they changed, the record that keeps a violation from turning into a fine.
A consent audit is not a scan. It is a standing evidentiary record of what your websites and mobile apps actually did, on every path a visitor could take.
Complements Your CMP
Feroot doesn’t replace your CMP, it verifies it. Your CMP reports its configuration; Feroot reports what visitors actually experienced, the evidence a regulator or plaintiff will examine.
Covers What You Don’t Control
Partner storefronts, agency microsites and acquired brands audited from the outside, without needing their cooperation.
Reviewable And Controllable, Not Just Reported
A session recording and reasoning log accompany every run, so a finding can be independently verified rather than taken on trust.
FREE DOWNLOAD:
Get the Consent Management Gap Report to identify hidden risks in your privacy practices.
Learn how to verify that your consent management platform actually enforces visitor choices.
Stop Consent Violations Before They Become Legal Issues.
See exactly what your websites and mobile apps do with visitor consent, and fix it before it becomes a compliance fine.