Skip to content

Services / Comply

Compliance & Security

Most EU websites track users before they consent, and most teams find out from a lawyer. We find it first, fix it, and keep it fixed.

consent gateConsent Mode v2 · OneTrust
google-analyticsfiredblocked
meta-pixelfiredblocked
doubleclick/adsfiredblocked
hotjarfiredblocked

declined consent respected · evidence attached

who

Who it is for. Companies operating in the EU or serving EU visitors, teams facing a legal review, a client security questionnaire, or an incident. And agencies whose clients ask questions they cannot answer in house.

privacy

Privacy Compliance

Audit and diagnosis

  • Pre-consent leakage testing: which tags, pixels and scripts fire before the visitor consents
  • Cookie audit and classification against your declared policy
  • CMP verification: whether your banner actually blocks what it claims to block
  • Third party and embed review (video, maps, chat widgets, ad pixels)
  • Cross-checking your privacy policy and cookie notice against what the site really does

Implementation

  • Google Consent Mode v2, Basic and Advanced
  • CMP setup and configuration (OneTrust, Cookiebot, Complianz, CookieYes, Usercentrics)
  • Tag by tag consent gating in Google Tag Manager
  • Geo based logic for EU and non EU visitors
  • Consent state persistence and correct signal ordering on first load
  • Consent handling in server side tagging setups

Verification and proof

  • Structured three scenario test protocol: page load, decline, accept
  • Evidence report with data layer snapshots, network logs and screenshots
  • Compliance verification document written for legal teams, not for developers
  • Re-test and sign off after every change

Remediation and support

  • Fixing setups that look compliant and are not
  • Recovering analytics data quality after a consent implementation goes wrong
  • Written explanations your legal counsel or client can act on
  • Ongoing monitoring so a plugin update does not quietly break compliance
This is the only service where the deliverable is evidence rather than a claim.
security

Security & Resilience

Audit and assessment

  • Security and hosting review with a findings report by topic area
  • Access review: who has what, and why
  • Plugin, theme and dependency audit
  • Completing client security questionnaires and vendor assessments on your behalf

Access and identity

  • MFA enforcement across systems
  • Roles, permissions and least privilege
  • Documented onboarding and offboarding process
  • SSH and API key lifecycle and rotation

Hardening

  • Hosting and server hardening
  • WAF, rate limiting and bot mitigation (Cloudflare, Sucuri)
  • Form and endpoint protection
  • Update policy and patch cadence

Resilience

  • Backup strategy plus tested restores, not backups that merely exist
  • Disaster recovery runbook
  • Uptime and integrity monitoring with alerting
  • Incident response plan with named owners and order of operations

After an incident

  • Compromised site cleanup and root cause analysis
  • Post incident report and remediation plan
scope

Where the line is

We cover application, hosting and operational security for web properties. We do not run penetration tests, we do not operate a SOC, and we do not issue ISO 27001 or SOC 2 certification. For those we work alongside specialist partners.

proof

The deliverable is a document, not a promise

Every consent engagement is tested in three isolated scenarios, page load, decline and accept, and written up with data layer snapshots, network logs and screenshots. Legal can read it. So can a developer.

consent-scan-report.pdf
3 working days
tags before consent
cookies set pre-choice
consent mode init
on decline: blocked
network evidence · screenshots · severity ordered
evidence
engage

How we work

EngagementScopeTimeline
Free Consent ScanPre-consent check, short evidence report3 working days
GDPR Tracking AuditFull audit, evidence report, prioritised fixes5 days
Consent Mode v2 ImplementationGating, CMP config, verification document2 to 3 weeks
Security & Hosting ReviewFindings report by topic area5 to 7 days
Hardening ImplementationScoped from audit findingsvaries
Incident ResponseCleanup, root cause, reporturgent, hourly
Compliance & Security MonitoringMonthly checks, patching, quarterly access reviewretainer
  • GDPR Tracking Auditfrom 1,200 EUR
  • Consent Mode v2 Implementationfrom 2,500 EUR
  • Security & Hosting Reviewfrom 1,500 EUR
  • Monitoring retainerfrom 500 EUR per month

Compliance & Security Monitoring

One monthly line, two risks covered. Monthly checks, patching, and a quarterly access review, so a plugin update does not quietly break compliance and nothing drifts out of date. From 500 EUR per month.

stack

Stack

Google Tag ManagerConsent Mode v2OneTrustCookiebotComplianzCookieYesUsercentricsserver-side GTMCloudflareSucuriWP EngineGitHub Actions

contact

Start with a free Consent Scan