Fidelity

fidelity.com

Compare

https://fidelity.com

Scanned Apr 15, 2026 · 37.4s

Your website score is

0/100
Critical

Grade

F0

Banner

Yes

Regulatory Compliance

Multi-regulation overview — click any regulation for details

Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.

Tag Leak detected 75 user data leaks before consent on fidelity.com, including Adobe (Tracker Tracker), Advertising Tracker, ContentSquare (Analytics Tracker) and 30 more.

Security Headers

4/6 present

Strict-Transport-Security

max-age=31536000; includeSubDomains

Content-Security-Policy

Add a Content-Security-Policy header to prevent XSS and code injection attacks

X-Frame-Options

SAMEORIGIN

X-Content-Type-Options

nosniff

Referrer-Policy

no-referrer-when-downgrade

Permissions-Policy

Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation

Google Consent Mode

Not Detected

Google Consent Mode v2 was not found on this page. GCM v2 allows Google's tags to adjust their behavior based on user consent, and is required for compliant advertising measurement in the EU. Without it, your Google Ads and GA4 conversions may be impacted after consent is declined.

Post-Rejection Audit

Reject Button

Found

Post-Rejection Fires

0 vendors

Consent Mode

Not Detected

GTM Load

Not detected

Consent Mode V2: Not Detected

Google Consent Mode was not detected on this site.

No tracking vendors detected firing after rejection

Consent Record Audit

Issues detected

Consent record stored after interaction

GDPR Art. 7(1)

Found: OptanonConsent (OneTrust)

Record contains timestamp

Art. 7(1)

Timestamp field detected

Record contains consent state

Art. 7(1)

Consent state (accepted/rejected) not found in record

Record contains consent categories

Art. 7(1)

Consent categories (analytics, marketing, etc.) not found in record

Consent withdrawal mechanism accessible

GDPR Art. 7(3)

No way for users to withdraw consent found on page

No cookie settings link, footer link, or floating consent button was detected. GDPR requires users to withdraw consent as easily as they gave it.

Why this matters

Under GDPR Article 7, controllers must be able to demonstrate that consent was given (Art. 7(1)) and ensure users can withdraw consent at any time, as easily as giving it (Art. 7(3)). Sites with no consent record or no withdrawal mechanism cannot legally rely on consent as a lawful basis.

Tracker categories detected

Advertising11 vendors
Analytics8 vendors
Marketing11 vendors
Security2
Functional2 vendors
Critical61
Segment
Segment6 findingsID tracked

cdn.segment.com, api.segment.io, ajs_anonymous_id, ajs_user_id, ajs_user_traits

Segment
criticalNetworkAnalyticsSegment

Segment (Twilio) loaded before consent: Segment customer data platform — routes data to multiple destinations

ID: YhIHGbwsOzNaANEek8UTzMdnEz7lKUIlHost: cdn.segment.comFired: 2132ms after load
Segment
criticalNetworkAnalyticsSegment

Segment (Twilio) loaded before consent: Segment data collection endpoint

Host: api.segment.ioFired: 7482ms after load
Segment
criticalCookieAnalyticsSegment

Segment cookie "ajs_anonymous_id" set before consent

Cookie: ajs_anonymous_idDomain: .fidelity.com
Segment
criticalStorageAnalyticsSegment

Segment (Twilio) wrote "ajs_user_id" to localStorage before consent

Key: ajs_user_idType: localStorageFired: 7445ms after load
Segment
criticalStorageAnalyticsSegment

Segment (Twilio) wrote "ajs_user_traits" to localStorage before consent

Key: ajs_user_traitsType: localStorageFired: 7446ms after load
Segment
criticalStorageAnalyticsSegment

Segment (Twilio) wrote "ajs_anonymous_id" to localStorage before consent

Key: ajs_anonymous_idType: localStorageFired: 7450ms after load
Google Analytics
Google Analytics4 findingsID tracked

region1.analytics.google.com, www.googletagmanager.com, _ga, _ga_GL9JN8SMCE

GA4
criticalNetworkAnalyticsGA4

GA4 (Google) loaded before consent: Sends pageview and event data to Google Analytics

ID: G-GL9JN8SMCEHost: region1.analytics.google.comFired: 3384ms after load
GA4
criticalNetworkAnalyticsGA4

GA4 (Google) loaded before consent: Google Analytics gtag.js library

Host: www.googletagmanager.comFired: 2879ms after load
Google Analytics
criticalCookieAnalyticsGoogle Analytics

Google Analytics cookie "_ga" set before consent

Cookie: _gaDomain: .fidelity.com
Google Analytics
criticalCookieAnalyticsGoogle Analytics

Google Analytics cookie "_ga_GL9JN8SMCE" set before consent

Cookie: _ga_GL9JN8SMCEDomain: .fidelity.com
Google (Tracker Tracker)
Google (Tracker Tracker)2 findingsID tracked

stats.g.doubleclick.net, cm.g.doubleclick.net

Google (Tracker Tracker)
criticalNetworkGoogle (Tracker Tracker)

Google (tracker) loaded before consent

ID: G-GL9JN8SMCEHost: stats.g.doubleclick.netFired: 3384ms after load
Google (Tracker Tracker)
criticalNetworkGoogle (Tracker Tracker)

Google (tracker) loaded before consent

Host: cm.g.doubleclick.netFired: 3544ms after load
Adobe (Tracker Tracker)
Adobe (Tracker Tracker)5 findings

dpm.demdex.net, fidelity.demdex.net, cm.everesttech.net, sync-tm.everesttech.net, rtd-tm.everesttech.net

Adobe (Tracker Tracker)
criticalNetworkAdobe (Tracker Tracker)

Adobe (tracker) loaded before consent

Host: dpm.demdex.netFired: 1900ms after load
Adobe (Tracker Tracker)
criticalNetworkAdobe (Tracker Tracker)

Adobe (tracker) loaded before consent

Host: fidelity.demdex.netFired: 2306ms after load
Adobe (Tracker Tracker)
criticalNetworkAdobe (Tracker Tracker)

Adobe (tracker) loaded before consent

Host: cm.everesttech.netFired: 2325ms after load
Adobe (Tracker Tracker)
criticalNetworkAdobe (Tracker Tracker)

Adobe (tracker) loaded before consent

Host: sync-tm.everesttech.netFired: 4172ms after load
Adobe (Tracker Tracker)
criticalNetworkAdobe (Tracker Tracker)

Adobe (tracker) loaded before consent

Host: rtd-tm.everesttech.netFired: 4289ms after load
Advertising Tracker
Advertising Tracker2 findings

doh.cq0.co, bat.bing.net

Advertising Tracker
criticalNetworkAdvertisingAdvertising Tracker

advertising tracker at doh.cq0.co loaded before consent

Host: doh.cq0.coFired: 1900ms after load
Advertising Tracker
criticalNetworkAdvertisingAdvertising Tracker

advertising tracker at bat.bing.net loaded before consent

Host: bat.bing.netFired: 3445ms after load
ContentSquare (Analytics Tracker)
criticalNetworkAnalyticsContentSquare (Analytics Tracker)

ContentSquare (analytics) loaded before consent

Host: cdnssl.clicktale.netFired: 1905ms after load
Adobe Analytics
Adobe Analytics2 findings

fmrcorp.tt.omtrdc.net, AMCV_EDCF01AC512D2B770A490D4C%40AdobeOrg

Adobe Analytics
criticalNetworkAnalyticsAdobe Analytics

Adobe Analytics (Adobe) loaded before consent: Adobe Analytics tracking endpoint

Host: fmrcorp.tt.omtrdc.netFired: 2506ms after load
Adobe Analytics
criticalCookieAnalyticsAdobe Analytics

Adobe Analytics cookie "AMCV_EDCF01AC512D2B770A490D4C%40AdobeOrg" set before consent

Cookie: AMCV_EDCF01AC512D2B770A490D4C%40AdobeOrgDomain: .fidelity.com
Microsoft Ads
criticalNetworkAdvertisingMicrosoft Ads

Microsoft Ads (Microsoft) loaded before consent: Microsoft Ads (Bing) UET conversion tracking

Host: bat.bing.comFired: 2880ms after load
TransUnion (Advertising Tracker)
criticalNetworkAdvertisingTransUnion (Advertising Tracker)

TransUnion (advertising) loaded before consent

Host: d.agkn.comFired: 2880ms after load
LiveRamp (Advertising Tracker)
criticalNetworkAdvertisingLiveRamp (Advertising Tracker)

LiveRamp (advertising) loaded before consent

Host: idsync.rlcdn.comFired: 2894ms after load
Microsoft (Advertising Tracker)
criticalNetworkAdvertisingMicrosoft (Advertising Tracker)

Microsoft (advertising) loaded before consent

Host: ib.adnxs.comFired: 3251ms after load
Dentsu (Advertising Tracker)
Dentsu (Advertising Tracker)2 findings

track.securedvisit.com, track.sv.rkdms.com

Dentsu (Advertising Tracker)
criticalNetworkAdvertisingDentsu (Advertising Tracker)

Dentsu (advertising) loaded before consent

Host: track.securedvisit.comFired: 3272ms after load
Dentsu (Advertising Tracker)
criticalNetworkAdvertisingDentsu (Advertising Tracker)

Dentsu (advertising) loaded before consent

Host: track.sv.rkdms.comFired: 3277ms after load
Google Ads
Google Ads3 findings

www.google.com, _gcl_au, _gcl_ls

Google Ads
criticalNetworkAdvertisingGoogle Ads

Google Ads (Google) loaded before consent: Google Consent Mode data collection for ad measurement

Host: www.google.comFired: 3534ms after load
Google Ads
criticalCookieAdvertisingGoogle Ads

Google Ads cookie "_gcl_au" set before consent

Cookie: _gcl_auDomain: .fidelity.com
Google Ads
criticalStorageAdvertisingGoogle Ads

Google Ads (Google) wrote "_gcl_ls" to localStorage before consent

Key: _gcl_lsType: localStorageFired: 3522ms after load
Adobe (Advertising Tracker)
criticalNetworkAdvertisingAdobe (Advertising Tracker)

Adobe (advertising) loaded before consent

Host: rtd.tubemogul.comFired: 4275ms after load
Magnite (Advertising Tracker)
Magnite (Advertising Tracker)2 findings

pixel.rubiconproject.com, sync.search.spotxchange.com

Magnite (Advertising Tracker)
criticalNetworkAdvertisingMagnite (Advertising Tracker)

Magnite (advertising) loaded before consent

Host: pixel.rubiconproject.comFired: 4482ms after load
Magnite (Advertising Tracker)
criticalNetworkAdvertisingMagnite (Advertising Tracker)

Magnite (advertising) loaded before consent

Host: sync.search.spotxchange.comFired: 4989ms after load
IndexExchange (Advertising Tracker)
criticalNetworkAdvertisingIndexExchange (Advertising Tracker)

IndexExchange (advertising) loaded before consent

Host: dsum-sec.casalemedia.comFired: 4583ms after load
OpenX (Tracker Tracker)
criticalNetworkOpenX (Tracker Tracker)

OpenX (tracker) loaded before consent

Host: us-u.openx.netFired: 4785ms after load
PubMatic (Advertising Tracker)
criticalNetworkAdvertisingPubMatic (Advertising Tracker)

PubMatic (advertising) loaded before consent

Host: image2.pubmatic.comFired: 4889ms after load
Quantcast
criticalCookieMarketingQuantcast

Quantcast cookie "MC" set before consent — Tracking of users and measure and improve performance and supports personalisation

Cookie: MCDomain: .fidelity.comRetention: 13 months
Marfeel
criticalCookieAnalyticsMarfeel

Marfeel cookie "_svsid" set before consent — This cookie is used to store for temporary session

Cookie: _svsidDomain: .fidelity.comRetention: Session
Adobe Audience Manager
Adobe Audience Manager5 findings

demdex, AMCVS_EDCF01AC512D2B770A490D4C%40AdobeOrg, mbox, dpm, dextp

Adobe Audience Manager
criticalCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "demdex" set before consent — Unique value with which Audience Manager can identify a user. Used, among others, for identification, segmentation, modeling and reporting purposes.

Cookie: demdexDomain: .demdex.netRetention: 180 days after last activity or 10 years when opting out
Adobe Audience Manager
criticalCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "AMCVS_EDCF01AC512D2B770A490D4C%40AdobeOrg" set before consent — The AMCVS cookie serves as a flag indicating that the session has been initialized. Its value is always 1 and discontinues when the session has ended.

Cookie: AMCVS_EDCF01AC512D2B770A490D4C%40AdobeOrgDomain: .fidelity.comRetention: Session
Adobe Audience Manager
criticalCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "mbox" set before consent — Adobe Target uses cookies to give website operators the ability to test which online content and offers are more relevant to visitors.

Cookie: mboxDomain: .fidelity.comRetention: 2 years
Adobe Audience Manager
criticalCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "dpm" set before consent — DPM is an abbreviation for Data Provider Match. It tells internal, Adobe systems that a call from Audience Manager or the Adobe Experience Cloud ID Service is passing in customer data for synchronization or requesting an ID.

Cookie: dpmDomain: .dpm.demdex.netRetention: 180 days
Adobe Audience Manager
criticalCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "dextp" set before consent — Registers the date plus time (timestamp) on which a data synchronization was last performed by the Audience Manager.

Cookie: dextpDomain: .demdex.netRetention: 180 days after last activity
Adobe Advertising
criticalCookieMarketingAdobe Advertising

Adobe Advertising cookie "everest_g_v2" set before consent — This cookie stores the browser and surfer ID.Created after a user initially clicks a client's ad, and used to map the current and subsequent clicks with other events on the client's website

Cookie: everest_g_v2Domain: .everesttech.netRetention: 2 years
ContentSquare
ContentSquare2 findings

_cs_ex, _cs_c

ContentSquare
criticalCookieAnalyticsContentSquare

ContentSquare cookie "_cs_ex" set before consent — This cookie stores if the user is excluded from tracking. Contains the timestamp of the last time this visitor was drawn.

Cookie: _cs_exDomain: .fidelity.comRetention: 30 days
ContentSquare
criticalCookieAnalyticsContentSquare

ContentSquare cookie "_cs_c" set before consent — Consent state: digit between 0 and 3. Used for capturing analytics on web pages

Cookie: _cs_cDomain: .fidelity.comRetention: 13 months
Rapleaf2 findings

rlas3, pxrc

criticalCookieMarketingRapleaf

Rapleaf cookie "rlas3" set before consent — Collects anonymous data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.

Cookie: rlas3Domain: .rlcdn.comRetention: 1 year
criticalCookieMarketingRapleaf

Rapleaf cookie "pxrc" set before consent — This cookie registers non-personal data on the visitor. The information is used to optimize advertisement relevance.

Cookie: pxrcDomain: .rlcdn.comRetention: 2 months
Neustar
criticalCookieMarketingNeustar

Neustar cookie "ab" set before consent — This cookie is used by the website’s operator in context with multi-variate testing. This is a tool used to combine or change content on the website. This allows the website to find the best variation/edition of the site.

Cookie: abDomain: .agkn.comRetention: 1 year
criticalCookieMarketingTotvs

Totvs cookie "u" set before consent — This cookie is Used for audience segmentation for advertising

Cookie: uDomain: .agkn.comRetention: 1 year
criticalCookieAnalyticsQualtrics

Qualtrics cookie "QSI_HistorySession" set before consent — Used in lieu of the “Site History” cookie, for the same purpose (keeping track of the number page views as well as how long the visitor has been on the site).

Cookie: QSI_HistorySessionDomain: .fidelity.comRetention: Session
DoubleClick/Google Marketing
criticalCookieMarketingDoubleClick/Google Marketing

DoubleClick/Google Marketing cookie "IDE" set before consent — This cookie is used for targeting, analyzing and optimisation of ad campaigns in DoubleClick/Google Marketing Suite

Cookie: IDEDomain: .doubleclick.netRetention: 2 years
criticalCookieMarketingX

X cookie "personalization_id" set before consent — Unique value with which users can be identified by X. Collected information is used to be personalize X services, including X trends, stories, ads and suggestions.

Cookie: personalization_idDomain: .twitter.comRetention: 2 years
Bing / Microsoft
Bing / Microsoft2 findings

MUID, MR

Bing / Microsoft
criticalCookieMarketingBing / Microsoft

Bing / Microsoft cookie "MUID" set before consent — Identifies unique web browsers visiting Microsoft sites. These cookies are used for advertising, site analytics, and other operational purposes.

Cookie: MUIDDomain: .bing.comRetention: 1 year
Bing / Microsoft
criticalCookieMarketingBing / Microsoft

Bing / Microsoft cookie "MR" set before consent — Used to collect information for analytics purposes.

Cookie: MRDomain: .c.bing.comRetention: 6 months
Casale Media3 findings

CMID, CMPS, CMPRO

criticalCookieMarketingCasale Media

Casale Media cookie "CMID" set before consent — Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.

Cookie: CMIDDomain: .casalemedia.comRetention: 1 day
criticalCookieMarketingCasale Media

Casale Media cookie "CMPS" set before consent — Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads

Cookie: CMPSDomain: .casalemedia.comRetention: 1 day
criticalCookieMarketingCasale Media

Casale Media cookie "CMPRO" set before consent — Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that the visitor is shown the same advertisement.

Cookie: CMPRODomain: .casalemedia.comRetention: 1 day
openx.net
criticalCookieMarketingopenx.net

openx.net cookie "i" set before consent — Registers user data, such as IP address, geographical location, websites visited and on which advertisements the user has clicked, with the aim of optimizing the display of advertisements based on user relocation on websites that use the same advertising network.

Cookie: iDomain: .openx.netRetention: 1 year
criticalConsent Record

No recognizable consent withdrawal mechanism detected — GDPR Article 7(3) requires users can withdraw consent as easily as giving it (cookie settings link or floating button expected)

Warnings15
Twitter (Social Tracker)
warningNetworkTwitter (Social Tracker)

Twitter (social) loaded before consent

Host: analytics.twitter.comFired: 3688ms after load
vendor logo
warningNetwork

Unknown third-party request to www.glancecdn.net before consent

Host: www.glancecdn.netFired: 2130ms after load
vendor logo
warningNetwork

Unknown third-party request to storage.glancecdn.net before consent

Host: storage.glancecdn.netFired: 2297ms after load
vendor logo
warningNetwork

Unknown third-party request to www.googletagmanager.com before consent

Host: www.googletagmanager.comFired: 3657ms after load
vendor logo
warningNetwork

Unknown third-party request to www.facebook.com before consent

Host: www.facebook.comFired: 5090ms after load
warningStorage

localStorage key "_svsid" written before consent

Key: _svsidType: localStorageFired: 1811ms after load
warningStorage

localStorage key "dummy" written before consent

Key: dummyType: localStorageFired: 1988ms after load
warningStorage

localStorage key "ak_a" written before consent

Key: ak_aType: localStorageFired: 2088ms after load
warningStorage

localStorage key "__akfp_storage_test__" written before consent

Key: __akfp_storage_test__Type: localStorageFired: 2138ms after load
warningStorage

localStorage key "persisted-queue:v1:YhIHGbwsOzNaANEek8UTzMdnEz7lKUIl:event-queue:lock" written before consent

Key: persisted-queue:v1:YhIHGbwsOzNaANEek8UTzMdnEz7lKUIl:event-queue:lockType: localStorageFired: 2538ms after load
warningStorage

localStorage key "persisted-queue:v1:YhIHGbwsOzNaANEek8UTzMdnEz7lKUIl:dest-Segment.io:lock" written before consent

Key: persisted-queue:v1:YhIHGbwsOzNaANEek8UTzMdnEz7lKUIl:dest-Segment.io:lockType: localStorageFired: 2587ms after load
warningStorage

sessionStorage key "qualtricssessionstoragetestkey" written before consent

Key: qualtricssessionstoragetestkeyType: sessionStorageFired: 3433ms after load
warningStorage

localStorage key "qsi_test_local_storage" written before consent

Key: qsi_test_local_storageType: localStorageFired: 3749ms after load
warningStorage

sessionStorage key "QSI_ActionSetHistory" written before consent

Key: QSI_ActionSetHistoryType: sessionStorageFired: 4246ms after load
warningStorage

localStorage key "Q_INTER" written before consent

Key: Q_INTERType: localStorageFired: 4316ms after load
Info11
Google (Cdn)
infoNetworkGoogle (Cdn)

Google (cdn) loaded before consent

ID: G-GL9JN8SMCEHost: www.google.nlFired: 3384ms after load
Qualtrics (Cdn)
Qualtrics (Cdn)3 findings

zncvgjh8lmjxbkyln-fmrpi.siteintercept.qualtrics.com, siteintercept.qualtrics.com, pdx1.qualtrics.com

Qualtrics (Cdn)
infoNetworkQualtrics (Cdn)

Qualtrics (cdn) loaded before consent

Host: zncvgjh8lmjxbkyln-fmrpi.siteintercept.qualtrics.comFired: 2879ms after load
Qualtrics (Cdn)
infoNetworkQualtrics (Cdn)

Qualtrics (cdn) loaded before consent

Host: siteintercept.qualtrics.comFired: 2927ms after load
Qualtrics (Cdn)
infoNetworkQualtrics (Cdn)

Qualtrics (cdn) loaded before consent

Host: pdx1.qualtrics.comFired: 4265ms after load
OneTrust
OneTrust2 findings

cdn.cookielaw.org, OptanonConsent

OneTrust
infoNetworkConsent MgmtOneTrust

OneTrust (OneTrust) loaded before consent: OneTrust cookie consent management

Host: cdn.cookielaw.orgFired: 2880ms after load
OneTrust
infoCookieConsent MgmtOneTrust

OneTrust cookie "OptanonConsent" set before consent

Cookie: OptanonConsentDomain: .fidelity.com
OneTrust CMP
infoNetworkConsent MgmtOneTrust CMP

OneTrust CMP (OneTrust) loaded before consent: OneTrust geo-lookup — determines which consent banner to show based on user location

Host: geolocation.onetrust.comFired: 3067ms after load
Microsoft (Cdn)
infoNetworkMicrosoft (Cdn)

Microsoft (cdn) loaded before consent

Host: c.bing.comFired: 4032ms after load
Adobe Audience Manager
infoCookieFunctionalAdobe Audience Manager

Adobe Audience Manager cookie "at_check" set before consent — A simple test value used to determine if a visitor supports cookies. Set each time a visitor requests a page.

Cookie: at_checkDomain: .fidelity.comRetention: session
infoCookieFunctional

Akamai bot manager — necessary for site protection

Cookie: _abckDomain: .fidelity.com
infoCookieFunctional

Akamai bot management session — necessary for site protection

Cookie: ak_bmscDomain: .fidelity.com
Compliant2
OneTrust
CompliantCookieConsent MgmtOneTrust

OneTrust cookie "OptanonAlertBoxClosed" set correctly after consent

Cookie: OptanonAlertBoxClosedDomain: .fidelity.com
Akamai
CompliantCookieFunctionalAkamai

Akamai cookie "bm_sv" set correctly after consent

Cookie: bm_svDomain: .fidelity.comRetention: 1 hour or longer

Is this your site?

Run a full multi-page scan with monitoring and get detailed remediation steps

Scan fidelity.com

This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com