PrivacyRadar

One platform. Every privacy surface.

PrivacyRadar watches the places privacy risk actually accumulates — the running website, the consent flow, the third-party surface, the policy, the API — and turns changes into evidence-backed findings.

Website monitoring

Playwright-instrumented crawls capture the cookies, scripts, network requests, storage writes, and fingerprinting signals (canvas, WebGL, WebRTC, font enumeration) observed on every scanned page.

  • Scheduled daily/weekly scans
  • Depth and page budgets per plan
  • Real browser execution — JS included

Consent monitoring

Five scenarios per scan — ignore, accept, reject, accept-then-revoke, and a Global Privacy Control load — in isolated browser contexts, interacting with 13+ CMPs (OneTrust, Cookiebot, TrustArc, Didomi, Usercentrics…) plus generic banners.

  • Trackers after rejection = consent bypass findings
  • Broken reject buttons detected
  • Per-scenario screenshots and state evidence

Vendor monitoring

Every domain your site contacts, mapped to a maintained catalog of ~70 vendors with category, country, and risk level — then diffed against the previous scan.

  • vendor.added / vendor.removed change events
  • Policy-disclosure status per vendor
  • PII leakage to third parties flagged

Privacy policy drift

Deterministic discovery, fetch, and disclosure extraction of your privacy notice, compared claim-by-claim against observed behavior and hashed for drift detection.

  • Undisclosed session replay and fingerprinting
  • Removed-disclosure detection across scans
  • Policy HTML/text preserved as evidence

Cookie monitoring

First vs. third party, vendor signatures, categories, before/after-consent status, and lifetime — for every cookie on every scanned page.

  • Signature catalog across ad-tech and analytics
  • Pre-consent cookies flagged per jurisdiction
  • Cookie evidence in every scan

API monitoring

Deterministic analysis of OpenAPI specifications and GraphQL schemas: PII-named fields, unauthenticated endpoints exposing personal data, identifiers in query strings, and plaintext transports.

  • OpenAPI 3.x and GraphQL SDL/introspection
  • PII field inventory per endpoint
  • Spec preserved as hashed evidence

AI Surface

Continuous inventory of customer-facing AI chat, search, and recommendation widgets — with disclosure and consent-topic findings for EU AI Act Art. 50 and US clear-disclosure expectations. Included on Business and Enterprise. Not an AI governance or model-eval suite.

  • Signature + DOM inventory with screenshot evidence
  • Art. 50 interaction-transparency topics (from 2 Aug 2026)
  • AI vendor notice gaps and post-Reject traffic

Healthcare Surface

On assets marked as handling health data: HIPAA web PHI surface detectors (pixels, GA/GTM, chat, scheduling, forms, NPP, transport) plus a LEGAL BAA gap appendix on Business and Enterprise — evidence for counsel, not a HIPAA certification.

  • Attribute-gated hipaa pack (healthData)
  • Curated vendor BAA research + org attestations
  • Optional allowlisted form probe (off by default)

Underneath: an observability pipeline

  • Rules engine — 27 versioned packs across GDPR/ePrivacy, CCPA/CPRA, PIPEDA/Law 25, 18 US state privacy laws, COPPA, HIPAA web PHI signals, AI-adjacent web transparency, and AI Surface (Art. 50 / US disclosure topics) — toggleable per organization; attribute-gated where required.
  • Diff engine — findings reconcile across scans (first seen / last seen); only changes produce events, emails, and webhooks.
  • Evidence engine — SHA-256 at collection, content-addressed blobs, digest re-verified on every download, Ed25519-signed PDF exports.
  • Public API — versioned REST with scoped keys, OpenAPI docs, and HMAC-signed webhooks with retries and delivery logs.

Know about privacy risks before lawyers do.

Add your first website in minutes. The first scan is the conversation-changer.