Noru

Website privacy audit

Scan your site for privacy risks.

A technical scan as a first-time visitor.Enter a domain and the scanner grades your website's stance against its privacy obligations and highlights the key addressable findings.

Start a scan

Domain only — we add https:// and follow redirects. Paste a full URL and we trim it to the site.

Regimes to check
1 selected
EU/EEA — GDPR + ePrivacy

Controls automated jurisdiction checks only; it does not decide which laws apply. GPC is tested as evidence where relevant.

From domain to graded report

How it works

01

Enter a domain

The scanner loads one public page as a first-time visitor — no login, no crawl.

02

The scanner runs

It records what happens before and after a consent choice, then grades it.

03

Read the report

Findings ordered by severity, each with a fix. The link is shareable.

What the scan checks

4 signal groups

Trackers & pixels

Requests to known analytics, advertising, social and pixel hosts — and whether they fired before consent. Host relationship is reported separately and does not establish ownership or purpose.

Cookies before consent

Cookies set before the visitor has made a choice, and which of them usually require consent.

Consent banner

Whether a banner appears, and whether refusing takes the same effort as accepting.

Policies & disclosures

Whether privacy and cookie notices can be found, and which required information they leave out.

FAQ

Frequently asked questions

Talk to us

Is this really free?

Yes. Enter a domain, add your email address, and the assessment opens straight away — no account, no payment, and no sales call.

Why do you ask for my email address?

So we know who ran the scan and can help if you want support acting on it. The report opens as soon as you enter it, and the link stays shareable afterwards. We store the address, and we only send you marketing if you tick the opt-in box — every email we do send carries an unsubscribe link.

What does the technical privacy risk grade mean?

It summarises the cookies, known trackers, consent controls, policy links, and transport signals observed on the submitted page. It helps prioritise investigation; it is not a legal compliance determination.

Does a good grade make me GDPR compliant?

No. This is a limited external scan of one submitted page, not legal advice or a full audit. Compliance also depends on the law's applicability, processing purposes, contracts, internal practices, and parts of the site the scan did not observe.

How do I fix the issues it finds?

Every issue the scan observes is listed with its severity, so you can see what to tackle first. Noru can map observed signals to your selected privacy regimes and recheck the site over time as it changes.

How do I check whether my website is GDPR compliant?

You cannot establish compliance from the outside, but you can find the common failures quickly. Under the GDPR and ePrivacy regime, non-essential cookies and trackers must not fire before consent, refusing must be as easy as accepting, and privacy information has to be genuinely findable. This scan checks all three on the page you submit. The rest — lawful basis, purposes, contracts, retention — lives inside your organisation and needs a proper assessment.

Why do cookies set before consent matter?

Because consent has to come before the processing it authorises, not after. A cookie the scanner classifies as commonly requiring consent that appears before the visitor has chosen is the most common finding in this category, and it is what supervisory authorities act on most readily, since anyone can observe it from outside.

Does having a consent banner mean we are covered?

No. A banner records that you asked; it does not prove you honoured the answer. Scripts that fire before a choice is made, ignore a rejection, or ignore a browser-level opt-out signal are common, and they are what enforcement turns on. That is why this scan exercises the choice rather than only checking that a banner exists.

What should I enter — a domain or a full URL?

Either. A domain on its own is enough: the scanner adds https:// and follows any redirect, so there is no need to type http://, https:// or www. If you paste a full URL, everything after the domain is trimmed and the scan loads that domain's front page rather than the path you pasted. A subdomain is scanned as its own site, so shop.example.com and example.com are two different scans.

Does the scan check pages behind a login?

No. It observes the single public page you submit, without credentials. Anything behind authentication, and any other page on the site, is outside what it can see — which is worth remembering when reading the grade.

Can I share or re-run the result?

Yes. Each scan produces a shareable link to that report, and you can re-run a scan at any time. Because a site's privacy behaviour changes with every deploy, vendor update and new tag, a single scan is a snapshot rather than a standing state.

Privacy Automation

Automated data discovery and compliance controls for GDPR Article 30.

Take control of your privacy compliance — across every system that holds personal data, not just the website.