Verification only — TrackGuard Pro checks and confirms. It never installs, removes, or repairs anything. Get Free Scan
TrackGuard Pro
The Pre-Consent Check  ·  5-Layer Scanner  ·  Evidence-Grade Reports
What’s Happening How Did We Get Here? Full Story Get Free Scan About Method
The Method

The Pre-Consent Check

The Pre-Consent Check loads a public page the way an ordinary first-time visitor does — no cookies carried in, no banner clicked, no consent given — and records every tracking technology that fires anyway during that window.

Checking only the HTML source finds less than half of what is actually running. Most trackers arrive after the page loads: injected by a tag manager, fired by a script, or set as a cookie before anything is clicked. Five layers are used because a tracker invisible to one layer is usually plainly visible to another.

The five layers
Layer 1 — HTML Source
Inspects: the delivered HTML document — script tags, pixel iframes, and embed markup written directly into the page.
Can prove: that a tracking technology is hard-coded into the page itself, and is therefore present on every load regardless of visitor behavior.
Layer 2 — Network Requests
Inspects: the live outbound calls the page makes, captured via the browser Performance API during the pre-consent window.
Can prove: that data actually left the visitor’s browser for a third-party destination before consent — not merely that a script was present, but that it transmitted.
Layer 3 — Window Globals
Inspects: the JavaScript objects a tracker installs in the page environment, such as window.fbq or window.gtag.
Can prove: that a tracking library initialized and is live in the page, even when it was injected dynamically and appears nowhere in the HTML source.
Layer 4 — Cookies
Inspects: the cookies and local storage entries written before any user interaction takes place.
Can prove: that identifiers were placed on the visitor’s device ahead of consent, and which technology set each one.
Layer 5 — Server-Side Signals
Inspects: first-party proxy signatures and timing patterns that indicate server-to-server tracking — tag manager relay configurations and conversions-API style transmission that fire with no browser-visible script.
Can prove: that tracking is routed through the site’s own domain, a pattern that is invisible to every browser-side layer above and to ad blockers.
Technologies detected

The scanner carries a signature set covering the tracking technologies most commonly found firing before consent. Among them:

Meta Pixel Google Analytics Google Tag Manager YouTube embeds HubSpot LinkedIn Insight Tag TikTok Pixel X / Twitter Pixel Microsoft Advertising UET Google Ads remarketing DoubleClick / Floodlight Session recording and heatmap scripts Live chat and support widgets Marketing automation trackers Third-party font and CDN calls Server-side tag relays

Signatures are added as new technologies appear. A technology absent from this list is not evidence of its absence from your site — it may simply mean no signature exists for it yet, which the report states plainly rather than reporting a clean result.

What a finding is and is not
What a finding is
  • A factual observation of network and script behavior recorded at a specific moment.
  • A record that a named technology fired, or a named identifier was written, before consent was given.
  • Reproducible — another party running the same check on the same page state should see the same behavior.
  • Verifiable after the fact, through the SHA-256 hash attached to the captured page state.
What a finding is not
  • A legal determination. We do not conclude that any law was broken.
  • Legal advice. TrackGuard Pro is not a law firm and none of its output is counsel.
  • A judgment about intent — most pre-consent firing is configuration, not decision.
  • A certification or an audit. No certification body exists for this, and we claim no accreditation.
  • A repair. We report what was observed; what to change is yours and your advisors’ call.

A detection describes behavior. Whether that behavior carries legal consequence depends on the jurisdiction, the data involved, the disclosures in place, and facts a scanner cannot see. Take these findings to your own counsel — the report is written to be handed to a lawyer, read by someone who was not present at the scan, and re-verified independently.

Scanner last updated:

This date reflects the last revision to the signature set and layer logic described above. It is set by hand when the scanner actually changes, not generated on page load — a date that renews itself every time someone visits would be a claim, not a signal.

For how reports are signed and how to re-compute the hash yourself, see About TrackGuard Pro.

Contact
Questions about the method, or a hash that will not match?
[email protected]

TrackGuard Pro checks and verifies only. It does not install, remove, configure, or repair anything on any site.

TrackGuard Pro provides technical scanning only. Results do not constitute legal advice. © 2026 TrackGuard Pro  ·  [email protected]  ·  TrackGuard Pro will never request payment by phone, wire transfer, or unsolicited email. All payments processed exclusively through trackguardpro.com.

Home  ·  About  ·  Method  ·  Terms of Service  ·  Privacy Policy