Everything in a StackPatrol report
A clean, shareable map of your third-party stack — built for technical teams and the DPOs they answer to. Free to start, no signup.
The map, on every scan
No account, no credit card. Paste a URL and get a full vendor report in under a minute.
See what loads before consent
The single most decision-relevant signal for a DPO: which advertising, analytics and tracking vendors fire on the very first page load — before the visitor ever answers the cookie banner. First-party services are separated out so the headline count reflects only third-party trackers. A plain-language finding, not a legal verdict.
Detect third-party scripts as they load
Trackers, analytics, tag managers, fonts, CDNs and embeds. A headless browser loads your actual pages and records every outbound request.
Map vendors by region
US, EU, EEA, UK or Unknown for every vendor found.
Discover EU alternatives
Curated European replacements for the most common US tools. Fewer transfer-mechanism questions to answer.
Does the banner actually work?
The findings a visitor can't Google on their own site: what the policy forgot, and whether Reject all is respected. Free scans show the disclosure-gap count; the full findings come with a paid plan.
Compare disclosure sources with observed services
StackPatrol reads your cookie policy, privacy policy and DPA. Paid reports can also inspect the configured vendor view exposed by supported consent managers without saving consent. The report separates exact service matches, qualified provider or parent matches, and observed services with no match. These are technical prompts to review, not legal findings.
Observe what follows a Reject-all interaction
StackPatrol activates an explicit Reject-all control on a clean visit, then separates interaction evidence, stored CMP or TCF state and later network traffic. Paid reports name non-essential services observed after the evidence boundary without claiming that a legally valid rejection was independently confirmed.
Weekly monitoring timestamps when a post-reject signal first appears and when a later scheduled run no longer observes it.
Evidence you can hand over
The provenance, register and infrastructure detail a DPO needs to document a finding — not just a score.
See exactly where each tracker loads
For every vendor, the report shows which page it fired on and whether it ran before or after consent — the evidence a DPO needs to document a finding, not just a score.
Observed external services and transfer review worksheet
Technical observations that can support updates to processing records and vendor registers. Legal and organisational fields require customer verification. The CSV keeps legal and organisational fields empty for the customer to complete.
Check hosting, email & DNS jurisdiction
A site can run its trackers from the EU yet still host itself, its email or its DNS on a US-owned provider. StackPatrol resolves your origin hosting, email (MX) and authoritative DNS (NS) providers, classifies each by ownership region, and flags EU–US Data Privacy Framework certification for US vendors — the sovereignty signals a vendor list alone misses.
See changes at each scheduled check
Turn a one-off scan into a standing watch: weekly re-checks, a durable timeline and email alerts.
Build a dated history of observed changes
StackPatrol re-scans your sites every week and keeps a durable history of what each scheduled run observed: when a service first appeared, when it went away and every score change in between. When a change is detected, you get an email alert and a dated timeline entry for the next audit. Export the history to CSV or JSON.
Watch your privacy & cookie policies for changes
Each monitored scan also finds and fingerprints your privacy policy, cookie policy, DPA and terms — even when they live on a parent-company domain. We track the date each page says it was last updated and detect when the content actually changes. The most useful signal: when your vendor stack shifts but the privacy policy stays frozen, the alert flags a possible documentation gap.
See it on your own site
Every free scan includes what loads before consent, the vendors your policy forgot and a region-classified vendor map. Upgrade any time for monitoring and reports.