Skip to main content
ComplicerAUDIT GRADE
MethodologyUse casesEU AI ActPricingBlogDocsSign inSTART FREE AUDIT
USE CASES

Who runs Complicer — and what they find.

Four teams, one flagship test: click Reject and Accept on the live banner, watch whether the site actually obeyed, score 70 rules, and seal the evidence. The verticals below are illustrative — the finding patterns are exactly what the audits are built to catch.

AUTO-CYCLING · CLICK A TAB TO PIN
DPO · E-COMMERCE RETAILER · ~800 EMPLOYEES

Reject is clicked. The pixels keep firing.

The CMP was installed two years ago and everyone moved on. Complicer clicks Reject on the live banner and watches the network: analytics and session recording continue after the click, and marketing pixels fire on first paint — before anyone has answered at all. The request log and screenshots are sealed the moment they are captured.

WHAT CATCHES IT
✓Reject clicked, then verified — We press Reject on the live banner and require at least one observable signal before claiming anything about the outcome.
✓Pre-consent request timeline — Every request fired before the first banner interaction is recorded, timestamped and classified.
✓Sealed evidence — SHA-256 hashed, Ed25519 signed, RFC 3161-ready — retained 7 years, so remediation can be proven later.
HOW THE TEST WORKS →PLANS & LIMITS →
SAMPLE AUDIT — EXAMPLE-SHOP.EUEU-W1 · 70 RULES
CRITICAL
Trackers continue after Reject
reject_all clicked + confirmed · analytics.js and session-rec still firing
HIGH
Marketing pixels fire before consent
ad pixel request on first paint · no banner interaction recorded yet
MEDIUM
Consent cookie outlives its policy
consent cookie set for 24 months · cookie policy states 12
FINDINGS MIX
32%Verified25%In review25%High risk18%Critical
WEIGHTED GRADE
D48 / 100
SAMPLE — NOT SEALED
real audits: sha256 → ed25519 → rfc3161-ready
Illustrative sample data — not a real audit.
WHAT’S AT STAKE — STATUTORY EXPOSURE

Trackers that ignore a Reject click go to the heart of consent — the exposure is statutory, not theoretical:

ART. 83(5) GDPR

Administrative fines up to €20M or 4% of total worldwide annual turnover — whichever is higher — for infringements of the basic principles for processing, including the conditions for consent (Art. 5, 6 and 7 GDPR).

NATIONAL ePRIVACY

Cookies and trackers set before consent are also enforced under national ePrivacy rules — in France, for example, the CNIL enforces cookie violations under national law, outside the GDPR one-stop-shop.

Statutory maximums under GDPR Art. 83 and national ePrivacy law. Complicer reports what your site does — it does not predict enforcement or fines.
05 — ONE ENGINE, FIVE DIMENSIONS

“Is it just cookies?” — no. Five dimensions, one grade.

Consent is the flagship test, but every audit scores security headers, risk, cookie classification and WCAG 2.2 AA accessibility in the same run — because accessibility complaints land on the same desk as privacy complaints. Click a dimension:

CONSENT · 32% OF THE WEIGHTED GRADE
The flagship test — Reject and Accept, clicked and proven

We press Reject and Accept on your live banner and demand confirmation from at least one of four observable signals: the banner disappeared, consent storage changed, the CMP’s own __tcfapi consent string changed, or a known success message appeared. “Verified” only when both clicks are confirmed — otherwise the audit says “cannot verify” and names the reason.

Weights as implemented in the scoring engine — every audit runs the same 70rules, one A+–F grade.
HOW WE COMPARE TO TOOLS & AGENCIES →
RUN IT ON YOUR OWN SITE

Your vertical is different. The test isn’t.

Every plan runs the same flagship test: Reject and Accept clicked on your live banner, confirmed by signals anyone can check, sealed as evidence. No credit card. Free plan: 1 website · 5 audits/month.

START FREE AUDIT →OR SCAN ANY SITE FREE — NO SIGNUP →
ComplicerAUDIT GRADE

We test whether Reject actually works on your site — and seal the evidence you can hand to a regulator.

GDPR-ALIGNED · SHA-256 · Ed25519 · EU-W1
PRODUCT
Free scanUse casesMethodologyEU AI ActPricingDocsBlog
COMPANY
ContactSecurityTrust
LEGAL
PrivacyTermsSubprocessorsComplaint
EVIDENCE CHAIN INTACT · SHA-256 · Ed25519 · RFC 3161-READY© 2026 COMPLICER