One platform. Every privacy surface.
PrivacyRadar watches the places privacy risk actually accumulates — the running website, the consent flow, the third-party surface, the policy, the API — and turns changes into evidence-backed findings.
Website monitoring
Playwright-instrumented crawls capture the cookies, scripts, network requests, storage writes, and fingerprinting signals (canvas, WebGL, WebRTC, font enumeration) observed on every scanned page.
- Scheduled daily/weekly scans
- Depth and page budgets per plan
- Real browser execution — JS included
Consent monitoring
Five scenarios per scan — ignore, accept, reject, accept-then-revoke, and a Global Privacy Control load — in isolated browser contexts, interacting with 13+ CMPs (OneTrust, Cookiebot, TrustArc, Didomi, Usercentrics…) plus generic banners.
- Trackers after rejection = consent bypass findings
- Broken reject buttons detected
- Per-scenario screenshots and state evidence
Vendor monitoring
Every domain your site contacts, mapped to a maintained catalog of ~70 vendors with category, country, and risk level — then diffed against the previous scan.
- vendor.added / vendor.removed change events
- Policy-disclosure status per vendor
- PII leakage to third parties flagged
Privacy policy drift
Deterministic discovery, fetch, and disclosure extraction of your privacy notice, compared claim-by-claim against observed behavior and hashed for drift detection.
- Undisclosed session replay and fingerprinting
- Removed-disclosure detection across scans
- Policy HTML/text preserved as evidence
Cookie monitoring
First vs. third party, vendor signatures, categories, before/after-consent status, and lifetime — for every cookie on every scanned page.
- Signature catalog across ad-tech and analytics
- Pre-consent cookies flagged per jurisdiction
- Cookie evidence in every scan
API monitoring
Deterministic analysis of OpenAPI specifications and GraphQL schemas: PII-named fields, unauthenticated endpoints exposing personal data, identifiers in query strings, and plaintext transports.
- OpenAPI 3.x and GraphQL SDL/introspection
- PII field inventory per endpoint
- Spec preserved as hashed evidence
AI Surface
Continuous inventory of customer-facing AI chat, search, and recommendation widgets — with disclosure and consent-topic findings for EU AI Act Art. 50 and US clear-disclosure expectations. Included on Business and Enterprise. Not an AI governance or model-eval suite.
- Signature + DOM inventory with screenshot evidence
- Art. 50 interaction-transparency topics (from 2 Aug 2026)
- AI vendor notice gaps and post-Reject traffic
Healthcare Surface
On assets marked as handling health data: HIPAA web PHI surface detectors (pixels, GA/GTM, chat, scheduling, forms, NPP, transport) plus a LEGAL BAA gap appendix on Business and Enterprise — evidence for counsel, not a HIPAA certification.
- Attribute-gated hipaa pack (healthData)
- Curated vendor BAA research + org attestations
- Optional allowlisted form probe (off by default)
Underneath: an observability pipeline
- Rules engine — 27 versioned packs across GDPR/ePrivacy, CCPA/CPRA, PIPEDA/Law 25, 18 US state privacy laws, COPPA, HIPAA web PHI signals, AI-adjacent web transparency, and AI Surface (Art. 50 / US disclosure topics) — toggleable per organization; attribute-gated where required.
- Diff engine — findings reconcile across scans (first seen / last seen); only changes produce events, emails, and webhooks.
- Evidence engine — SHA-256 at collection, content-addressed blobs, digest re-verified on every download, Ed25519-signed PDF exports.
- Public API — versioned REST with scoped keys, OpenAPI docs, and HMAC-signed webhooks with retries and delivery logs.
Know about privacy risks before lawyers do.
Add your first website in minutes. The first scan is the conversation-changer.