What you get
One scan. Ten compliance checks. A full report in 60 seconds.
See exactly what fires before anyone clicks Accept.
Tag Leak loads your site in a stealth Chromium browser and captures every outbound network request, Set-Cookie header, cookie write, localStorage write, and sessionStorage write that occurs before the consent banner is interacted with. Each finding is classified by vendor, severity, and category against 50,000+ known tracker signals.
What it checks
Not just whether GCM v2 is present β whether it is correctly implemented.
GCM v2 is required for compliant GA4 and Google Ads conversion measurement in EU markets. A common mistake: implementing the gtag consent call but defaulting parameters to 'granted' instead of 'denied'. Tag Leak injects an interceptor before any page code runs, captures all consent calls in the correct order, and scores the implementation against all seven required parameters.
What it checks
The consent standard your CMP must implement β verified at the API level.
IAB TCF v2.2 is the technical consent framework all IAB-registered CMPs (Cookiebot, Didomi, OneTrust, Axeptio, and 200+ others) are required to implement. Tag Leak calls __tcfapi directly β the same interface DPA verification tools use β and checks version, event status, TC string validity, and consent status across all 11 IAB consent purposes.
What it checks
Six headers. One scan. No extra tool required.
Security response headers are a GDPR Article 32 requirement and appear in DPA technical audits. Tag Leak checks all six in the same scan as the consent audit β no separate security scanner needed. Missing headers are reported as info findings with the specific value recommended.
What it checks
Your checkout page and product pages need to be compliant too.
GDPR violations frequently occur on pages other than the homepage β particularly forms, checkout flows, and content pages that load additional tracking scripts. Tag Leak discovers pages from your sitemap.xml automatically (with link crawl fallback) and scans them in parallel, giving you a full-site compliance picture.
What it checks
GDPR, UK GDPR, CCPA, LGPD, POPIA, and PDPA β scored in one scan.
Every Tag Leak scan automatically evaluates compliance against all six major privacy regulations without pre-selection. Each regulation gets its own score (0β100), a status (compliant / issues / critical), and a per-check pass/fail breakdown that maps to the specific technical requirements of that framework.
What it checks
Test from the jurisdiction that matters β not just your office location.
Many sites serve different consent experiences based on visitor location β a compliant Cookiebot setup for EU visitors, a banner-less experience for US visitors, or a geo-redirect to a different domain entirely. Geo-scanning detects all of this by running the scan from a real IP in the target jurisdiction.
What it checks
Every finding has an owner. Every fix has a step.
Generated from your actual scan findings using GPT-4o-mini, the Remediation Document is a structured fix plan that assigns every violation to the team that owns it β Developer, GTM Manager, or Legal. It is not a generic template. Download as PDF for your evidence file or to hand to the dev team.
What it checks
Competitive comparison
CookieYes and Cookiebot are Consent Management Platforms β their scanner is a secondary feature inside a banner product. Tag Leak is a standalone audit tool, banner-agnostic and depth-first.
| Capability | Tag Leak | CookieYes | Cookiebot | OneTrust |
|---|---|---|---|---|
| Pre vs post-consent two-pass scan | β | β | β | β |
| GCM v2 implementation audit (0β100 score) | β | β | β | β |
| TCF v2.2 implementation audit (third-party) | β | β | β | β |
| 6-regulation compliance scoring | β | β | β | β |
| Geo-scanning (EU, UK, US, BR, APAC) | β | β | β | β |
| Security headers audit | β | β | β | β |
| AI remediation document | β | β | β | β |
| Cookie policy generated from scan data | β | β | β | β |
| Scan any URL free β no account, no install | β | β | β | β |
| Consent banner product | β | β | β | β |
"Implementation audit" = verifying whether an existing GCM v2 or TCF v2.2 setup is correctly configured, scored 0β100. CookieYes and Cookiebot implement these standards in their own banners β they do not audit third-party implementations. Comparison as of April 2026.
Pricing
$0
$19/mo
$49/mo
Free scan, no signup. Paid features unlock automatically when you create an account.