Vault JS Enterprise

Website Monitoring: Verify What Your Sites Actually Send

Vault JS Website Monitoring tests every page the way a regulator or plaintiff's expert would, and shows exactly which tags, pixels and scripts send data, to whom, and whether the visitor agreed.

Vault JS Enterprise

Make Sure Your Websites Honor Consent and Privacy Laws

Vault JS Website Monitoring verifies that the data your websites collect matches your visitors’ choices and the law. It loads your pages from the regions you serve, under every consent state, and follows real journeys through search, forms, checkout and logged-in accounts. Nothing is installed on your site.

Icon

Google fined €325 million over cookies

France's privacy regulator found Google placed advertising cookies on people creating accounts without valid consent.

Icon

Kaiser agreed to pay up to $47.5 million

Plaintiffs alleged trackers on Kaiser's websites and patient portals sent health searches to Google, Microsoft and X. The class covers 13.4 million people.

Icon

Sutter Health agreed to pay $21.5 million

Plaintiffs alleged Meta Pixel and Google Analytics on Sutter's patient login page shared health information with advertisers without consent.

How Vault JS Supports Compliance for Websites

Icon

Tag & Vendor Identification

Identifies every pixel, tag, script and cookie, and the company behind it.

Icon

Pre-Consent Tracking Audit

Flags data sent before a visitor has made a choice.

Icon

Real User Journeys

Follows real paths through search, forms, checkout and logged-in pages.

Icon

Consent Variance Testing

Tests every page under accept, reject, no action, GPC and Do Not Sell or Share, across regions.

Icon

Detailed Compliance Reporting

See what data is collected, by whom, and which law it affects.

Icon

Integration & Workflow

Nothing to install. Alerts go to Slack, Jira and your CMP.

Key Website Compliance Capabilities

How we manage risk in a changing environment

Journey-Based Compliance Testing

Vault JS follows the paths real visitors take: searching, filling in forms, adding to cart, checking out, booking an appointment, logging in. Many of the most serious violations, like a pixel capturing form fields or a health search, only appear deep in these journeys, where a homepage scan never reaches.

Test Your Site Like Regulators and Lawyers Do Gradient blur shape
Visualization of third-party scripts, tracking pixels, fingerprinting, and cookie data flows between websites and external vendors Gradient blur shape

Consent and Region Testing

Every page is tested from the regions you serve and under each consent state: accept, reject, no action, Global Privacy Control and Do Not Sell or Share. Vault JS shows whether data stops when a visitor opts out, and flags it when it doesn't. It can also check whether an opt-out made on your site carries through to your apps and CTV.

Comprehensive Visibility

Vault JS records every request your pages make, the data each one carries and the vendor that receives it, then matches each vendor and cookie against its research libraries of more than 10,000 AdTech vendors and 500,000 cookies. Technical teams get the exact tag to fix; legal teams get evidence tied to the statute.

Vault JS Enterprise - Identify Misconfigurations and Shadow Vendors Gradient blur shape
Vault JS Enterprise - Catch Consent Failures Gradient blur shape

Protect Revenue & Reputation

No one wants to become the next news headline or million-dollar cautionary tale. By catching issues early, Vault keeps you ahead of regulators, helping avoid expensive fines, settlements, and reputational damage.

How it Works

1. Setup & Crawling

You tell us which sites, pages, regions and consent scenarios matter. Your Customer Success Manager helps set the page runs so every run goes where it finds the most risk. Vault JS loads your pages from the outside, the way a regulator or a plaintiff’s expert would, with nothing installed on your site.

2. Data Capture

As each page run completes, Vault JS captures every network request, cookie and script, including data sent before the consent banner is answered and data sent by tags that fire other tags. Each request is logged with what was sent, where it went and the visitor’s consent state.

3. Analysis & Classification

Vault JS checks the captured data against rule sets mapped to the laws that apply to you, backed by a legal library of statutes, case law and regulator guidance. For example, it flags a pixel that sends a search term after an opt-out, or a session recorder capturing form fields on a health page, and explains why it matters.

4. Result & Remediation

The platform presents your results in a dashboard: passed tests, flagged issues, and recommended actions. The platform’s output is fully actionable for developers and clear enough for lawyers to understand, bridging the gap between technical data and legal requirements.

Frequently Asked Questions

Website privacy monitoring tests what your live websites actually do with visitor data: which tags, pixels, scripts and cookies load, what they send, to which companies, and whether that matches the visitor’s consent choices and the law. Unlike a one-time audit or a CMP cookie scan, it runs continuously and covers the pages and journeys where violations tend to hide.

Most privacy laws apply to websites directly. In the US that includes CCPA/CPRA and the other comprehensive state laws, CIPA and other wiretap laws used in pixel and session-replay lawsuits, VPPA for pages that play video, HIPAA for health providers and Washington’s My Health My Data Act. Outside the US, GDPR, the ePrivacy Directive, UK GDPR and PECR, and Quebec Law 25 all require consent before non-essential tracking.

A typical enterprise site loads dozens of third-party tags, and those tags load others. Marketing teams add and change them constantly, often outside the CMP. Plaintiffs’ firms run automated scans to find pixels that fire before consent or capture search terms and form fields, which is why CIPA and VPPA lawsuits now number in the thousands.

Vault JS loads your pages from the outside in a real browser, from each region you choose and under each consent state, and follows real journeys through search, forms, checkout and logged-in areas. It captures every request, cookie and script, identifies the vendor behind each one, and checks the results against rule sets mapped to the laws that apply to you.

Yes. Vault JS can sign in with test accounts and walk through account pages, checkout, patient portals and other authenticated journeys, where some of the highest-risk data flows happen.

Identifiers, cookies, email and phone hashes, search terms, page URLs and titles, form field contents, video titles, location and health or financial signals, along with the vendor that received each one and the consent state at the time.

Continuously. Websites change every time a tag is added, a vendor updates its script or a campaign launches, so a quarterly audit misses most of what happens. Vault JS runs on a schedule you set, and your Customer Success Manager helps tune frequency and coverage to where the risk is.

Regulator fines, class-action lawsuits and settlements. California’s Attorney General and privacy agency have fined companies including Sephora, Honda, Todd Snyder and Healthline over website tracking and broken opt-outs, and private CIPA and VPPA suits can carry statutory damages per visitor.

CMP scans list the cookies they find on a sample of pages; tag QA tools check that analytics fire correctly. Vault JS is built for privacy and legal exposure: it tests every consent state across regions and journeys, shows what each vendor actually received, and ties findings to the laws that apply, using research libraries on vendors, cookies and case law.

Yes. A CMP collects and stores consent choices, but it can’t verify that every tag on the page honors them. Vault JS checks what actually happens after a visitor accepts, rejects or sends a GPC signal, and finds the tags the CMP doesn’t know about. In our own scans of sites using a leading CMP, about one in three vendors firing was missing from the CMP’s inventory.

Ready to see what your sites send?