Tracking & Consent · Evidence Guard

A regulator just asked for your consent evidence. Do you have it?

Most companies don’t. Evidence Guard scans your pages whenever you run it — from your own CI, cron or server — captures time-stamped proof of every consent flow, and generates audit-ready evidence packs, so when the question comes, you answer in minutes, not months.

  • Zero code changes
  • Repeatable scans you run from your own CI or cron
  • Audit-ready PDF evidence packs
your-site.comYELLOW
72score
CriticalPre-checked marketing consent
HighNo cookie banner detected
MediumDouble opt-in not detected

Illustrative scan result

This is what’s at stake

Consent failures are the fastest-growing GDPR fine category

“When the regulator asks you to prove a consent flow was compliant on a specific date, a CMP can’t answer — evidence can.”

€4.5B+
in GDPR fines issued — and accelerating.
€850K
average fine for consent violations.
€1.2B
single fine — Meta, for consent failures.

What we check

Every consent signal that has to hold up under scrutiny

A real browser visits your pages and scores each one against a 20-rule, deterministic engine.

Consent capture

Whether opt-in is valid — affirmative, unchecked by default, and clearly worded.

  • Checkboxes unchecked by default (no pre-checked consent)
  • An explicit opt-in mechanism on every data-collection form
  • Consent text present and specific near each form

Cookie & banner compliance

Whether your cookie consent meets ePrivacy expectations.

  • Cookie banner present and detected
  • Consent language beside action buttons
  • Double opt-in where the jurisdiction requires it

Disclosure & dark patterns

Whether disclosures are visible and free of manipulative patterns.

  • Privacy policy link adjacent to every form (Article 13)
  • No dark patterns — no pre-checked or coerced consent
  • Disclosures visible, not vague or buried

Evidence & retention

Whether you can still prove it months later — the whole point.

  • Timestamped screenshots, HTML, and DOM stored immutably
  • Append-only audit trail designed for scrutiny
  • Historical scan trail (30 / 90 / 365-day retention by plan)

How it works

From scan to audit-ready pack

  1. 01

    Scan

    A real browser visits your pages — seeing exactly what your users and regulators see. No code, no script tags.

  2. 02

    Findings

    A 20-rule engine scores each page 0–100. Deterministic — same page, same score, every time.

  3. 03

    Evidence

    Screenshots, HTML snapshots, and DOM consent elements, all UTC-timestamped and stored immutably.

  4. 04

    Report

    An audit-ready PDF evidence pack lands in every stakeholder’s inbox, and each run is comparable with the one before it.

Sample finding

This is what a finding looks like

R-012Critical

Missing privacy link near a data-collection form

Impact

Regulators expect a visible privacy-policy link adjacent to every form that collects personal data. Without it, you have a standing Article 13 disclosure gap — and no defensible record that you ever met the requirement.

Fix

Add a privacy-policy link directly below or beside the form’s submit button, then let the next scan capture timestamped proof that it’s in place.

Full-page screenshotHTML snapshotDOM consent elementsUTC timestamp

What’s in the report

  • Every finding with severity, why it matters, and the exact remediation steps
  • Full-page screenshots, HTML snapshots, and DOM consent elements per scan
  • Deterministic 20-rule score (0–100) with status GREEN / YELLOW / RED
  • UTC timestamps and an append-only audit trail built to withstand scrutiny
  • Historical scan trail (30 / 90 / 365-day retention) and a white-labelable PDF

When the regulator asks, answer in minutes

Find your compliance gaps free — enter a URL and see what a scan captures. No code changes, no developer involvement.

Cancel anytime · Nothing to install

FAQ

Questions, answered

We already have a CMP. Why do we need this?

A CMP collects consent. Evidence Guard proves it’s working correctly. CMPs break silently — after updates, deploys, or vendor changes. When a regulator asks “show me your consent flow was compliant on March 15th,” your CMP can’t answer that. Evidence Guard can.

Does this replace our privacy lawyer?

No — and it’s not trying to. Evidence Guard provides evidence infrastructure, not legal advice: the raw proof your lawyer needs to defend you. We capture and score consent data; your lawyer interprets the legal obligations.

How quickly can we get started?

Under 5 minutes. Enter your URL and choose your scan pages. No code changes, no script tags, no developer involvement required.

How often do scans run?

As often as you run them. Safeliant generates the cron, GitHub Actions or systemd schedule and it executes in your own environment; there is no hosted scheduler. You can also trigger a scan on demand from your dashboard.

What exactly gets stored as evidence?

Full-page screenshots, complete HTML snapshots, DOM consent elements, UTC timestamps, compliance scores, and finding details. Everything is stored securely with append-only audit trails — designed to withstand regulatory scrutiny.

Can agencies white-label reports for clients?

Branded PDF evidence packs (your logo, colour and company name) are supported on the legacy Evidence Guard Professional and Agency plans. Client-facing white-label reporting for the current Agency plans is not built yet and is listed as “Coming later” on the pricing page.

What if a scan finds something critical?

Your scan report highlights critical findings with their severity, why they matter, and the exact steps to fix them, so the fix is a scoped change rather than an investigation.

Do you check cookie banners specifically?

Yes — cookie banner detection is one of our core checks. We scan for cookie banner presence, consent language near action buttons, and compliance signals. Cookie banner failures are the single most common trigger for GDPR fines.

How long is evidence retained?

Evidence is retained for the period set on your plan. Regulatory investigations often look back months or years, so retention is worth confirming before you rely on it — ask us for the figure that applies to yours.

Do I need to install anything on my website?

Nothing. Evidence Guard scans your public pages externally using a real browser — exactly like a regulator would. No code changes, no cookies, no tracking scripts on your site.

What if I’m not satisfied?

You can cancel from the billing portal at any time. Subscription fees are non-refundable except where required by law — see our Terms.

Do you offer a partner or reseller program?

Not yet. There is no commission scheme, wholesale pricing or reseller portal today. The Agency plans already cover a client portfolio, and if you want to package Safeliant into client retainers we would like to hear from you — see the agency section on our pricing page.