01
Enter a domain
The scanner loads one public page as a first-time visitor — no login, no crawl.
Website privacy audit
A technical scan as a first-time visitor.Enter a domain and the scanner grades your website's stance against its privacy obligations and highlights the key addressable findings.
Start a scan
How it works
01
The scanner loads one public page as a first-time visitor — no login, no crawl.
02
It records what happens before and after a consent choice, then grades it.
03
Findings ordered by severity, each with a fix. The link is shareable.
What the scan checks
4 signal groups
Requests to known analytics, advertising, social and pixel hosts — and whether they fired before consent. Host relationship is reported separately and does not establish ownership or purpose.
Cookies set before the visitor has made a choice, and which of them usually require consent.
Whether a banner appears, and whether refusing takes the same effort as accepting.
Whether privacy and cookie notices can be found, and which required information they leave out.
Yes. Enter a domain, add your email address, and the assessment opens straight away — no account, no payment, and no sales call.
So we know who ran the scan and can help if you want support acting on it. The report opens as soon as you enter it, and the link stays shareable afterwards. We store the address, and we only send you marketing if you tick the opt-in box — every email we do send carries an unsubscribe link.
It summarises the cookies, known trackers, consent controls, policy links, and transport signals observed on the submitted page. It helps prioritise investigation; it is not a legal compliance determination.
No. This is a limited external scan of one submitted page, not legal advice or a full audit. Compliance also depends on the law's applicability, processing purposes, contracts, internal practices, and parts of the site the scan did not observe.
Every issue the scan observes is listed with its severity, so you can see what to tackle first. Noru can map observed signals to your selected privacy regimes and recheck the site over time as it changes.
You cannot establish compliance from the outside, but you can find the common failures quickly. Under the GDPR and ePrivacy regime, non-essential cookies and trackers must not fire before consent, refusing must be as easy as accepting, and privacy information has to be genuinely findable. This scan checks all three on the page you submit. The rest — lawful basis, purposes, contracts, retention — lives inside your organisation and needs a proper assessment.
Because consent has to come before the processing it authorises, not after. A cookie the scanner classifies as commonly requiring consent that appears before the visitor has chosen is the most common finding in this category, and it is what supervisory authorities act on most readily, since anyone can observe it from outside.
No. A banner records that you asked; it does not prove you honoured the answer. Scripts that fire before a choice is made, ignore a rejection, or ignore a browser-level opt-out signal are common, and they are what enforcement turns on. That is why this scan exercises the choice rather than only checking that a banner exists.
Either. A domain on its own is enough: the scanner adds https:// and follows any redirect, so there is no need to type http://, https:// or www. If you paste a full URL, everything after the domain is trimmed and the scan loads that domain's front page rather than the path you pasted. A subdomain is scanned as its own site, so shop.example.com and example.com are two different scans.
No. It observes the single public page you submit, without credentials. Anything behind authentication, and any other page on the site, is outside what it can see — which is worth remembering when reading the grade.
Yes. Each scan produces a shareable link to that report, and you can re-run a scan at any time. Because a site's privacy behaviour changes with every deploy, vendor update and new tag, a single scan is a snapshot rather than a standing state.
Privacy Automation
Take control of your privacy compliance — across every system that holds personal data, not just the website.