Public methodology
Useful technical evidence, with the uncertainty left in.
ScanBell observes what a public page does in fresh browser sessions. It is a release-QA aid—not legal advice, certification, or proof of a site’s overall compliance.
The three browser states
Default
A clean Chromium context visits the submitted public URL without interacting with a consent control.
Reject
A second clean context looks for a visible reject or necessary-only label and, when found, attempts one click.
Accept
If time remains, a third clean context attempts the visible acceptance path for comparison.
Compare
Request domains, recognized tracker heuristics, cookie attributes, storage key names, and selected response headers are compared.
What confidence means
Directly observed response headers and final URLs receive high confidence. Cookie attributes and visible controls receive medium confidence. Container-only signals such as Google Tag Manager are labelled low confidence because a container request alone does not prove nonessential tracking.
Known limits
- Geolocation, A/B tests, logins, delayed tags, iframes, shadow DOM, and custom control labels can change the result.
- Recognized tracker domains are an explicit, bounded heuristic set—not a complete vendor database.
- A failed automation click is reported as an unknown interaction outcome, not proof that a human cannot use the control.
- The score is a technical signal summary and has no legal or certification meaning.
Safety and data handling
Only public HTTP(S) URLs on standard web ports are accepted. DNS and every outbound browser connection are restricted to public addresses through a local validating proxy. Operational storage keeps hostname, timing, score, aggregate finding counts, and allowlisted anonymous funnel events. Page content, cookie values, storage values, IP addresses, and user agents are not persisted.
Try the narrow check first
See what a public page exposes before consent and after its visible reject path.
Run the free scan