PRIVACYSCAN v1
NDPA · GAID 2025 · GDPR

Audit any website for privacy, data-protection and security compliance in under a minute.

PrivacyScan crawls public pages non-intrusively, evaluates cookie consent, privacy policy, HTTPS/TLS posture and PII exposure against Nigerian and EU regulation, and returns a findings dashboard with citations, evidence and remediation.

Verify a report

RESPECTS ROBOTS.TXT · NO AUTH BYPASS · SCAN HISTORY IS PRIVATE

scan.session
streaming
82
SCORE · B
18
PASS
4
WARN
2
FAIL
3
N/V
  • ✓ TLS 1.3 · HSTS preload eligible
  • ✓ Consent Mode v2 signals present
  • ⚠ Cookie policy missing purposes table
  • ✕ 3 trackers loaded before consent
  • › Sampling /privacy · /terms · /contact
HTTPS HSTS PRELOAD CSP CONSENT MODE V2 DPO CONTACT DSAR FORM COOKIE INVENTORY PRE-CONSENT TRACKERS PII IN HTML SPF · DMARC · CAA WCAG 2.1 AA SITEMAP CRAWL REPORT SIGNATURE HTTPS HSTS PRELOAD CSP CONSENT MODE V2 DPO CONTACT DSAR FORM COOKIE INVENTORY PRE-CONSENT TRACKERS PII IN HTML SPF · DMARC · CAA WCAG 2.1 AA SITEMAP CRAWL REPORT SIGNATURE
WHAT WE PROBE

Every request, cookie and header — audited against the regulation you care about.

Transport & TLS

HTTPS, HSTS preload, mixed content, form submission channel, SPF · DMARC · CAA.

Cookie consent & CMP

Banner presence, reject controls, pre-checked boxes, non-essential cookies fired before consent.

Privacy policy

DPO, lawful basis, retention, data-subject rights, international transfers, complaint mechanism.

PII & credential exposure

Public emails, API keys, tokens, JWTs and private-key material across sampled pages.

SCOPE OF PUBLIC SCAN

Findings verifiable through public website scanning are marked as such. Findings requiring authorised source code, mobile-application packages, or runtime access (e.g. SharedPreferences storage, SDK initialisation order) are flagged as Not Verifiable — upload artefacts on the Static Analysis screen to complete those checks.

READ THE MANUAL →