SecureSpells
    Website runtime compliance verification

    Your banner says no.
    Your site says yes.

    Consent banners define the rules. Runtime verification proves they're followed. Run a 40-second runtime scan to catch tracking scripts and cookies firing behind your banner.

    By running this scan, you confirm you are authorized to audit this domain and agree to our Terms of Service and Privacy Policy.

    Free. No signup required. Full browser audit ready in few minutes.

    Real capture. Domain withheld.engine v2.8
    European travel commerce site
    Cookies present on arrival
    9
    Consent banner detected
    yes, OneTrust
    Cookies removed by reject
    0
    VERDICTThe reject control removed nothing. Nine cookies before, nine after.
    8 of 39 checks failedrisk 5.0 of 5 · Critical
    The problem

    Most websites pass CMP setup and fail in the browser.

    CMPs define consent rules, but they do not monitor runtime network requests. SecureSpells watches what actually executes.

    of audited sites load marketing tags before consent
    average findings per site
    audits analysed in the last 30 days

    Measured by the SecureSpells engine on a rolling window.

    Why it breaks after launch

    • Marketing adds new pixels

      A GTM container update ships trackers the launch audit never saw.

    • Plugins pull in new hosts

      Third-party domains appear after a CMS or plugin update - often unlisted in the policy.

    • Reject removes nothing

      The control looks compliant; cookies and scripts keep running after refuse.

    • The 'Trojan Horse' audit trigger

      A single visitor reporting a pre-consent tracking leak obligates authorities to investigate. Regulators do not stop at the website: a public script leak opens your entire company to months of intrusive GDPR auditing, vendor reviews, and forced system redesigns.

    Real enforcement - small business precedents
    • 5,000 lei (about €985)Coral Travel & Tourism Services - A regional travel agency stored non-essential cookies and tracking modules before visitors had consented.ANSPDCP 2025
    • 15,000 lei (about €2,950)Lenjeria Magica - An online lingerie shop set cookies that were not technically necessary, with no clear information and no explicit consent.ANSPDCP 2025
    • €30,000, reduced to €18,000Vueling Airlines - The cookie banner offered no way to refuse. Users were told to change their browser settings, and consent was inferred from continued browsing.AEPD 2019
    How it works

    Scan. Analyse. Prove.

    A real browser, cold profile, and an evidence report you can hand to someone who did not run the scan.

    01 · Scan

    Scan

    Automated behavioural audit in a real EU browser, cold profile, no prior consent.

    02 · Analyse

    Analyse

    100+ evidence-backed ePrivacy and GDPR checks against what actually executed.

    03 · Prove

    Prove

    An evidence report with article mapping and concrete remediation steps.

    Evidence is the product

    Evidence is the product.

    Whether you are answering to a client, a regulator, or a board, opinion is not enough. SecureSpells delivers timestamped execution logs, network captures, and GDPR article mapping - 100+ evidence-backed checks on what actually ran.

    European travel commerce site8 of 39 checks failed
    critical

    Third party domains not on any known vendor list

    An unrecognised third party host was contacted at runtime alongside adtech and CMP infrastructure. Domains outside the known vendor list cannot be assessed for purpose or transfer basis.

    check: unlisted_third_party_domains · criticality 5 of 5

    GDPR Art. 13(1)(c)
    GDPR Art. 14(1)(c)
    high

    Reject mechanism is ineffective

    Nine cookies were present before any consent choice. After the reject control was clicked, nine remained and none were removed. Five were unclassified rather than confirmed as essential.

    check: cookies_after_reject · criticality 4 of 5

    GDPR Art. 6(1)(a)
    GDPR Art. 7
    high

    Cross border tracking detected

    Tracking requests were observed to hosts outside the EEA, which engages transfer obligations separately from the consent question.

    check: cross_border_tracking_detected · criticality 4 of 5

    GDPR Art. 6(1)(a)
    GDPR Art. 7
    medium

    Known tracking services loaded

    pagead2.googlesyndication.com was observed during the crawl. The engine notes this check alone does not prove pre-consent execution and must be read against the timeline checks.

    check: known_trackers_loaded · criticality 3 of 5

    GDPR Art. 6(1)(a)
    GDPR Art. 7
    5.0/5Critical. Every deduction is itemised in the full report.
    Why runtime

    HTML scanners read the page. We watch it behave.

    Banner detectors and static analysis can confirm a CMP is present. They cannot prove what fired in the milliseconds before consent.

    CapabilityHTML / banner scannersSecureSpells
    Static / HTML analysisYesNo
    Detects that a cookie banner existsYesYes
    Sees runtime behaviour before consentNoYes
    Timestamped network and cookie timelineNoYes
    GDPR / ePrivacy article mappingNoYes
    Choose your task

    Choose what you need to accomplish today

    Pick the job in front of you - not a persona label.

    I need to check a specific website right now

    One-off audit for an immediate launch, update, or concern.

    Deliverable: Free runtime scan plus a path to a full evidence report with 100+ evidence-backed checks and developer remediation guidance.

    Run Free Audit →

    I audit websites professionally for clients

    Attach legal-grade, timestamped proof to formal opinions or DPIA reviews.

    Deliverable: Annex-ready evidence packs, GDPR article mapping, and runtime network context counsel can cite.

    Explore Legal & Audit Workflows →

    I build or manage multiple client websites

    Hand off launch proof to protect liability and monitor sites for tag regressions.

    Deliverable: White-label PDF exports, reusable delivery capacity, and automated change alerts.

    Explore Multi-Site Workflows →
    Why SecureSpells

    Evidence you can act on — and annex.

    Confidence backed by evidence

    Raw logs, network captures, and timestamps - not a vague score.

    Annexable reports

    Built to forward to a lawyer, DPO, or enterprise client.

    Continuous monitoring

    Catch regressions when marketing adds new tags after launch.

    Actionable remediation

    Concrete configuration and code-level fix guidance.

    European privacy focus

    EU-hosted Estonian company operating under GDPR.

    Built for professionals

    Workspaces, white-label proof, and evidence trails when you need them.

    What it costs

    There is no traffic threshold
    below which this stops mattering.

    Regulators do not only pursue large companies. These are real decisions against small businesses, for exactly the defect a site ships with by default when nobody checks what runs before the banner.

    Small business enforcement
    • 5,000 lei (about €985)

      Coral Travel & Tourism Services

      A regional travel agency stored non-essential cookies and tracking modules before visitors had consented.

      ANSPDCP Romania 2025
    • 15,000 lei (about €2,950)

      Lenjeria Magica

      An online lingerie shop set cookies that were not technically necessary, with no clear information and no explicit consent.

      ANSPDCP Romania 2025
    • €30,000, reduced to €18,000

      Vueling Airlines

      The cookie banner offered no way to refuse. Users were told to change their browser settings, and consent was inferred from continued browsing.

      AEPD Spain 2019
    • €30,000

      Iberia

      Visitors searching for a flight were given no option to reject cookies and were told they had to accept to continue. Upheld on appeal.

      AEPD Spain 2024
    • €90,000

      Techpump Solutions

      Third-party cookies stayed active after the visitor clicked reject all. Offering a reject button is not enough if the site keeps collecting.

      AEPD Spain 2023

    France's regulator issued 83 sanctions in 2025, of which 21 were specifically about cookies and trackers. Its simplified procedure, capped at €20,000 and aimed at organisations of every size, was used 67 times that year. CNIL

    Every figure on this page links to the issuing authority or a named legal source. We do not publish average fines, because no regulator produces one and any number claiming to be an average of these is invented.

    Trust

    A person you can reach - and a score you can interrogate.

    Compliance tooling asks you to trust its judgement. It is reasonable to want to know whose judgement it is, and how the number is built.

    Founder
    Ott Ristikivi

    Ott Ristikivi | Founder & CEO of SecureSpells

    Built in Estonia 🇪🇺 · Runtime privacy compliance specialist

    I launched SecureSpells because static HTML scrapers keep missing the scripts that actually trigger regulatory fines.

    We treat privacy compliance like a network-level unit test, monitoring real browser execution so you get actual legal evidence, not a vague score.

    LinkedIn profileott@securespells.com
    Evidence you can argue with

    Risk scoring uses published weights for severity, likelihood, regulatory focus, and user impact — not a black box. We build the runtime scanner, the check engine, the risk scoring model and the GDPR article mapping in house. Not a reseller of somebody else's scanner, and not a team you will never speak to.

    We audit ourselves too

    securespells.com scores 2.85 of 5, Medium, across 35 checks. It passes the pre-consent cookie check. It is not a perfect score, and we publish it rather than claim one.

    Pricing

    Pricing for agency delivery and counsel evidence

    Web trackers evolve. Regulatory enforcement shifts. Our audit engine updates continuously to keep your evidence aligned with current GDPR standards.

    White-label retainers for agencies; annex-ready runtime packs for lawyers and DPOs. Capacity runs on reusable audit slots from the live plan catalog.

    Reusable Audit Slots - Monitor active client projects. When a project is complete, reuse the slot for your next client after the rotation period.

    Loading pricing card
    Loading pricing card
    Loading pricing card

    First-audit guarantee

    If your first paid audit finds nothing beyond what the free scan on this page already showed you, we refund it.

    Run the free scan first, then compare it against the paid report. If the paid one surfaces no finding the free one missed, tell us within 14 days and the payment comes back. Applies to the one-off report and to the first month of a new subscription. No forms and no argument.

    Objections

    The questions agencies actually ask

    Including the ones where the honest answer is not the flattering one.

    Next step

    Ready to know where your website stands?

    Free. No registration. No credit card required.

    By running this scan, you confirm you are authorized to audit this domain and agree to our Terms of Service and Privacy Policy.

    Prefer to look first?