Sealed-browser consent audit · closed beta
Faraday sends a made-up visitor through your site and has her reject tracking. Every tag runs for real inside a sealed browser. Nothing reaches a vendor. Then you see exactly which tags tried to collect her data anyway.
One run, the demo shop
From one full audit of the bundled demo shop, which has five deliberately planted violations. Tags were fetched once from a cache. Vendor endpoints recorded zero hits.
Two regions, four consent states, plus withdrawal and chaos runs
Real tag code, fetched once without cookies or referrer
Every outbound request was caught and answered locally
All five caught, including a skimmer hidden in a fourth-party dependency
The test persona
Foolia is the visitor in every run. Her name, email, phone and card number are fabricated, and each value is a canary tied to that run. If any of it shows up in an outbound payload, Faraday finds it, whether it's sent raw, URL-encoded, base64, hex or hashed.
Both are real findings from the demo shop run.
canary · traceableHow a run works
Faraday won't start a run against any domain until written permission for that domain is on record.
Consent as a test matrix
Findings per cell from the demo run. Saying no in Germany produced as many findings as saying yes, because the planted tags ignore the choice.
| Consent choice | EU-DE | US-CA |
|---|---|---|
| No choice made | 22findings | 20findings |
| Accept all | 26findings | 22findings |
| Analytics only | 26findings | 22findings |
| Reject all | 26findings | 24findings |
What the run caught
Datasheet
Each row is labeled with its real status. Prototype and roadmap rows aren't for sale yet.
| Capability | What it shows | Status |
|---|---|---|
| Consent test matrix | Consent choice × region × GPC × journey, each run compared against what that consent allows | Shipping |
| Storage-layer audit | IDs written to cookies, localStorage or IndexedDB, attributed to the script that wrote them | Shipping |
| Canary PII and skimmer detection | Synthetic email, phone and card values found in any payload: raw, URL-encoded, base64, hex, SHA-256, SHA-1, MD5 | Shipping |
| Payment-field watch | Third-party scripts that read or listen to card fields, with the full load chain | Shipping |
| Withdrawal testing | Traffic after consent is revoked, re-linking to old profiles, and re-identification compared against a control persona | Shipping |
| Consent chaos tests | Consent manager down or slow, corrupted consent state, consent flipped mid-journey, vendor failure | Shipping |
| Dark-pattern score | Accept vs. reject size, clicks needed and time cost of refusing, tied to enforcement precedent | Shipping |
| Tag tree and drift | Script fingerprints and load chain, with an alert when they change without a deploy | Shipping |
| Exfiltration channels | Content-Security and Permissions policies checked against observed traffic, plus DNS, WebSocket and WebRTC leak paths | Shipping |
| Inference risk score | What a vendor could work out about the visitor from the outbound data | Prototype |
| Server-side tags | The server-side leg of tag and conversion pipelines | Roadmap |
| Cross-site view | Whether a partner's ad stack recognizes a persona that opted out somewhere else | Roadmap · legal review |
Under the hood
It runs on your machine or in your CI pipeline. Reports stay with you.
$ faraday audit -c run.json --all --fail-on high ✓ authorization shop.test (SOW §3, on record) ✓ persona foolia · synthetic · canary cr-132370 ✓ sandbox DNS sealed · 80 tag fetches · egress 0 ▸ matrix 16 sessions · replayable ✕ critical 64 card number → stats-cdn.test (base64) ✕ high 81 AdNet beacon before consent choice ! medium 43 hashed email → AdNet (with consent) · low 17 → out/demo/full-audit.html exit 1 (--fail-on high)
Technical specs
audit, diff, drift, verify-replay--fail-onA finding shows what one browser did under one consent choice at one moment. It's evidence for a review, not a legal opinion or a certificate of compliance. Region is emulated by timezone, locale and location, so sites that target by IP need a proxy. Every engagement starts with a check that the consent-banner clicks actually land, because a misconfigured run produces a clean report that means nothing.
Closed beta
Faraday is in closed beta with a small group of privacy, legal and marketing-tech teams. Send me a LinkedIn message with a line about the property you'd test. Pilots run on sites you own or are contracted to audit.
Faraday · closed beta · a working name · Back to hord.brayden · Pixel Lab · Partner brief · Brand · Privacy