Skip to content
StackPatrol
For agenciesand independent consultants

Ship a privacy audit before the kickoff call ends.

Scan a client site for third-party scripts, trackers, CDNs and non-European vendors. Walk in with a shareable report, walk out with a remediation engagement. Weekly monitoring on every paid plan, co-branding on Agency Starter and white-label PDFs on Agency.

Use in client deliverablesWhite-label PDFs on AgencyWeekly monitoring per client

Prefer to start yourself? The free front-page scanner is available below.

The agency workflow

Turn technical evidence into client work.

StackPatrol supports the evidence layer. Your agency adds the judgement, implementation and client relationship.

  1. 01Scan

    Establish the baseline

    Client deliverable: A dated inventory across the client sites in scope.

  2. 02Find

    Prioritise the evidence

    Client deliverable: A short findings list tied to requests, vendors and consent states.

  3. 03Fix

    Plan the remediation

    Client deliverable: An implementation brief for tags, consent controls and disclosures.

  4. 04Verify

    Re-run the checks

    Client deliverable: Before-and-after evidence showing what changed in the next observation.

  5. 05Document

    Package the result

    Client deliverable: A client-ready report for the DPO, project owner or board.

  6. 06Monitor

    Keep the work current

    Client deliverable: A recurring change record with scheduled checks and alerts.

Why agencies run this audit

Most clients have no idea what their own website is loading. The tag manager has been touched by three agencies, four interns and a marketing consultant. StackPatrol turns the resulting network activity into a reviewable report.

Client says

What's loading on the site?

Their answer

I think we have Google Analytics. Maybe Hotjar?

Client says

Did you remove Facebook Pixel?

Their answer

We removed it last year. I think.

Client says

How many vendors total?

Their answer

Three? Maybe five? Actually… I'm not sure.

A manual network review often uncovers services the team has forgotten. StackPatrol automates that first evidence pass and produces a shareable report you can use in a proposal.

The 8-point checklist

Run a StackPatrol scan, open the report, and walk the client through these eight items.

#1

What third-party domains is the front page contacting?

Look for the unfiltered request list. Anything you can't instantly identify is a candidate for removal.

#2

Which vendors are US-owned?

For European clients, US-owned vendors may require additional transfer review — a transfer impact assessment, supplementary measures, sometimes a cookie-banner update — depending on Data Privacy Framework participation, the contractual setup and the data involved. StackPatrol flags them so you know where to look.

#3

Where is the site hosted, and who runs its email and DNS?

A site can serve EU-only trackers yet still sit on US-owned hosting, email (MX) or DNS (NS). StackPatrol resolves all three and flags EU–US Data Privacy Framework certification for US vendors — infrastructure risk a vendor list alone misses.

#4

Which vendors are unmatched?

Usually a small regional tool, a CDN nobody documented, or a leftover from a campaign that ended years ago. Each one is a question to ask.

#5

Are there duplicate vendors?

It is common to find two analytics tools, two tag managers, two consent platforms. Each duplicate costs money and slows the page.

#6

Are there European alternatives worth proposing?

For each US vendor StackPatrol surfaces, check the suggested European alternative. Many clients will switch if you do the evaluation work for them.

#7

Does “Reject all” actually stop the trackers?

On paid plans StackPatrol activates an explicit Reject-all control in a clean browser context and records non-essential services observed after the evidence boundary. The report separates control interaction, stored consent state and network traffic. Continued requests are a concrete technical finding to review, not proof that a service ignored a legally valid rejection.

#8

Do the disclosure sources match the observed services?

StackPatrol separates exact service matches, qualified provider or parent matches and services with no match in readable policies. Paid reports can also inspect a supported consent manager's configured vendor view without saving consent. Cookie durations can be compared when a structured policy table provides an exact cookie name. These are technical prompts to review, not legal findings.

Common findings

Patterns we see on most European sites.

!

Google Tag Manager loading a US chatbot, which loads a Cloudflare worker, which writes a cookie set by a US fraud-detection vendor. The dependency tree is the story.

!

"EU-region" Google Analytics that still phones home to google-analytics.com on first request.

!

Old Facebook Pixel from a past campaign, still sending requests even though the team thought it had been removed.

!

Three font providers when one would do: Google Fonts + Adobe Fonts + a self-hosted leftover.

Example client package

One finding can support three engagements.

Charge for the analysis, implementation and ongoing oversight your team provides. The scan is the evidence underneath the work.

  1. 01

    Audit report

    Initial delivery

    A defined site scope, prioritised technical findings and a report the client can review with its DPO or implementation team.

  2. 02

    Remediation sprint

    Project work

    An implementation brief, support for tag and consent changes, then a verification scan against the agreed findings.

  3. 03

    Ongoing monitoring

    Recurring service

    Scheduled observations, change alerts and a dated evidence trail for the client sites that stay under management.

Frequently asked questions

Can I use StackPatrol scans in client deliverables?

Yes. Reports are shareable via a public URL (/r/<id>) and PDF audit reports are available for €79 each. The Agency plan (€149/month) includes white-label PDF reports you can hand directly to clients. Attribution is appreciated but not required.

Can I monitor client sites over time?

Yes. Pro (€39/month) monitors up to 5 sites weekly. Agency Starter (€89/month) covers 10 sites, Agency (€149/month) covers 30, and Agency Pro (€299/month) covers 100. Each run repeats the policy comparison and Reject-all network test. New post-reject signals and later clear scans are timestamped, giving you dated before-and-after evidence from StackPatrol's scheduled observations without claiming the exact moment a wider consent issue started or was resolved.

Does StackPatrol find vendors that only appear on internal pages?

The free scan covers the front page. Pro and Agency Starter scan up to 5 pages per run; Agency and Agency Pro scan up to 20. You can pin up to 3 custom paths on Pro or 5 on any Agency tier, useful for checkout, account or thank-you pages. The separate one-time PDF report (€79) also scans up to 20 pages.

Is this enough for a Schrems II / Transfer Impact Assessment?

No. StackPatrol gives you a fast, accurate inventory of front-end vendors and their ownership region, plus where the site is hosted and who runs its email (MX) and DNS (NS) — and, for US vendors, whether they hold an EU–US Data Privacy Framework certification. The boring discovery step, done. The legal analysis (lawful basis, SCCs, supplementary measures) is your job.

How does this compare to BuiltWith or Wappalyzer?

Those are sales-intelligence tools. They tell you which technologies a site uses so you can pitch products to it. StackPatrol is a privacy and digital-sovereignty tool: it classifies vendors and the site's hosting, email and DNS infrastructure by ownership region, explains the jurisdictional risk, and suggests European alternatives.

Try it on a client site now.

Free and no signup. Run the front-page scan and use the shareable report in your next proposal.

Need a full site audit?

No account required Shareable report link EU alternatives included