The Trust Operations Platform — demonstrate the compliance diligence your stakeholders expect, beyond SOC 2. See how it works →
PrivacyOps · CookiePLUS

Consent that stands up to audit.

CookiePLUS is the consent and preference layer built into the Trust Operations Platform. Scan your site, classify every cookie and tracker, present a compliant banner, and record each choice as tamper-evident evidence — wired to the same audit trail as your DSAR, RoPA and vendor programmes.

Capabilities

CookiePLUS — what's in the box.

+

Automatic cookie discovery

A recurring scan crawls your site and classifies every cookie and tracker into Necessary, Functional, Analytics and Marketing — so your notice reflects what is actually running, not a static list that drifts out of date.

+

Granular, category-level consent

Visitors accept or reject by purpose. Scripts in a category stay blocked until consent is granted, and prior-consent enforcement means tags do not fire before a choice is made.

+

Global privacy signals

Honors Global Privacy Control (GPC) and Do-Not-Track, and applies jurisdiction-aware defaults so an EU visitor and a US visitor see the right experience automatically.

+

Tamper-evident consent records

Every grant, change and withdrawal is logged with timestamp and scope, retained as evidence, and available to the data subject through the Privacy Center — the proof a regulator asks for.

Standards & signals

Built for the frameworks that matter.

+

IAB TCF 2.x

Transparency & Consent Framework support for adtech environments, passing a valid consent string to downstream vendors that expect one.

+

IAB GPP

The Global Privacy Platform string carries consent and opt-out state across jurisdictions from a single integration.

+

GPC & opt-out

Global Privacy Control is treated as a valid opt-out under US state privacy laws, applied automatically without the visitor lifting a finger.

+

Google Consent Mode v2

Consent state is passed to Google tags so analytics and ads adjust behaviour to the visitor's choices, with tags gated until consent is resolved.

How it works

From script tag to defensible record.

+

1 · Drop in one tag

Add a single loader script to your site. No rebuild, no tag-manager surgery. The banner and blocking layer initialise before non-essential scripts run.

+

2 · Scan & classify

CookiePLUS scans your pages on a schedule, classifies what it finds, and keeps the notice current as your site changes.

+

3 · Present & enforce

Visitors see a branded banner and preference center. Scripts stay blocked by category until consent is granted, with jurisdiction-aware defaults.

+

4 · Record & prove

Each choice is written to the platform audit trail and surfaced in the Privacy Center, so data subjects — and auditors — can see the full consent history.

One platform

Consent is part of the same system as everything else.

+

Wired to the Privacy Center

Data subjects log in with an email and consent token to view their consent history and update preferences — the same portal they use to exercise DSAR rights.

+

Feeds your RoPA

Consent as a lawful basis flows into your Records of Processing Activities, so your Article 30 register reflects how you actually collect and use data.

+

Tenant-branded

Logo, colours and copy match your brand; the banner and preference center inherit the same theming as your Trust Center and Privacy Center.

+

One audit trail

Consent events share the platform's tamper-evident audit trail with vendor risk, compliance and privacy — one source of truth, one auditor seat.

Cryptographically auditable

Consent you can prove, mathematically.

+

Hash-chained receipts

Every consent decision becomes an append-only receipt with a SHA-256 hash linked to the previous receipt for that visitor — a tamper-evident ledger, not an editable log.

+

Versioned configurations

Operators draft, preview and publish banner configurations atomically; every receipt records the exact configuration version the visitor saw.

+

Drop-in loader

A single script tag under 15KB gzipped renders the banner and blocks non-essential scripts before they fire — no rebuild, no tag-manager surgery.

+

Cookie scanner

Crawls the property on demand, identifies cookies and trackers, and proposes category assignments — auto-populating the inventory that feeds your notice and RoPA.

Compliance coverage

Built for 2026 enforcement.

+

GDPR Article 7

Consent that is freely given, specific, informed, unambiguous and demonstrable — granular per purpose, with withdrawal as easy as granting.

+

ePrivacy Art. 5(3)

Pre-consent script blocking — non-essential cookies and scripts do not fire until the visitor consents.

+

CCPA/CPRA 2026 symmetry

The reject button is symmetric in prominence with accept — addressing the post-Honda/Sephora/DoorDash enforcement focus — plus a dedicated Do Not Sell or Share entry point.

+

Jurisdictional templates

Pre-built templates for GDPR (EU/UK), CCPA/CPRA, Quebec Law 25, Brazil LGPD and US state laws — the right experience by region, automatically.

Turn your cookie banner into evidence.

CookiePLUS is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat across compliance, vendor risk and privacy.

Explore PrivacyOps See pricing