Skip to main content
Manual Evidence Audit

Manual Evidence Audit for Website Tracking, Cookies & Consent Review

When an automated scan is not enough, Auditzo manually reviews how your website behaves across cookies, trackers, third-party requests, and consent states, then documents the technical evidence in a clear report.

Already ran a scan? You can also start from the pricing page or run a new free audit first.

Focused Manual Review
Starting at $899

Best for a defined website scope where you need human-reviewed technical evidence, not just an automated PDF.

  • 1 website / 1 domain
  • 3 to 5 key pages
  • Consent-state review where applicable
  • Evidence-backed PDF report
Check Availability
What this audit is

A deeper human review of what your website is actually doing

This is not a magic compliance certificate. It is a practical technical audit for teams that need to understand and document what happens on a website before and after consent. We look at real website behavior: cookies, storage, third-party requests, trackers, pixels, and the differences between consent states.

The goal is simple: give your business, developer, agency, privacy consultant, or lawyer a clearer technical evidence package so decisions are not based on guesswork.

Important legal boundary

Auditzo provides technical observations and documentation. We do not provide legal advice, legal certification, legal conclusions, or a guarantee that a website is compliant with any law.

Use this audit to support legal, privacy, or compliance review, not to replace it.

Starting scope

What the $899 focused audit usually includes

This keeps the package clear and affordable. If the scope is bigger, we quote it separately instead of hiding limits.

1 website / 1 domain

A focused review of one website or domain. Multi-domain or multi-brand reviews should move to a custom quote.

3 to 5 key pages

Usually homepage, product/service page, cart/lead form, checkout before payment, and one high-risk page if applicable.

Consent behavior review

We review no-interaction behavior and, where a banner exists, compare reject and accept behavior.

Screenshots + technical evidence

Evidence is documented with screenshots, timestamps, browser/network observations, and structured findings.

Good fit for this package

  • A brand or ecommerce site that wants a human-reviewed tracking and consent audit.
  • A business that received a privacy concern, demand letter, client question, or agency escalation.
  • A privacy consultant, agency, or internal team that needs more clarity than an automated scan.
  • A company preparing for remediation and needing a clear technical baseline first.

Received a CIPA or website-tracking demand letter? Before deciding what technical review is needed, read our guide to verifying website tracking evidence after a CIPA demand letter. It explains how to preserve relevant context, review supplied evidence, and scope allegation-specific testing for counsel review. If the matter involves a Shopify storefront, see the Shopify Demand Letter Technical Evidence Review.

Not the right fit if...

  • You only need a quick automated report - use the Detailed Evidence Report instead.
  • You need legal advice, legal opinion, or legal certification - your lawyer should handle that.
  • You need full fix implementation - choose Website Tracking Remediation after the audit.
  • You need multi-domain, urgent, litigation-style, or custom evidence workflows - request the Law Firm / Enterprise package.
Review areas

What we check during the manual audit

The focus is observed technical behavior, not generic policy text or vague compliance scores.

Cookie and storage behavior

  • Cookies observed during test journeys
  • Local/session storage indicators
  • Cookie domain and category notes
  • Potentially persistent identifiers

Third-party requests

  • Tracker and vendor domains
  • Pre-consent third-party activity
  • Request-level observations where relevant
  • Pixels, analytics, ads, chat, CRM, and marketing tags

Consent state behavior

  • No-interaction page load behavior
  • Reject journey behavior where available
  • Accept journey behavior where available
  • Differences between consent states

Page-level evidence

  • Homepage and high-risk page review
  • Lead form/cart/checkout-before-payment review where applicable
  • Screenshot references
  • Timestamped observations
What you receive

Clear evidence your team can actually use

The report is written to be understandable for business owners, developers, agencies, privacy teams, and legal reviewers.

Evidence-backed PDF report

A human-reviewed report written for business, technical, privacy, and legal review teams.

Findings register

Clear findings with severity/context, observed behavior, affected pages, and why it needs review.

Network/request evidence summary

HAR/browser network-based observations with third-party domains, request behavior, and consent-state notes.

Cookie and storage tables

Structured cookie/storage observations with domains, names, and practical notes where available.

Screenshots and timestamps

Screenshots and timestamped environment notes to make the audit easier to review and discuss.

Remediation direction

Practical technical direction for what should be fixed, reviewed, or validated next. Full implementation is quoted separately.

Methodology

How the audit is performed

Simple, documented, and repeatable enough for serious review.

01

Scope confirmation

We confirm the domain, target pages, geography/jurisdiction focus, and whether a consent banner is expected.

02

Controlled test setup

We document the browser/test environment and prepare the audit journey so observations are easier to understand later.

03

No-interaction review

We load the selected pages without interacting with consent controls and observe cookies, storage, and network activity.

04

Reject / accept comparison

Where a consent banner is present and testable, we compare reject and accept behavior against the initial page load.

05

Evidence organization

Screenshots, observations, cookie/storage data, and request-level notes are structured into a readable evidence package.

06

Final report delivery

You receive the manual evidence report with findings, technical context, and recommended next steps.

How this fits into Auditzo’s broader methodology

The steps above describe the manual privacy and consent audit path. Auditzo uses different methods for automated reviews, manual evidence audits and WCAG accessibility testing.

Review the complete Auditzo audit methodology
Clear scope boundaries

What is not included

The Manual Evidence Audit is a defined technical evidence engagement based on the agreed website, pages, user journeys and consent states. It does not include unlimited legal, development or ongoing monitoring support unless separately scoped.

  • Legal advice, legal opinion, or legal certification
  • Guarantee that a website is compliant with any law or regulation
  • Full website development or consent-banner implementation
  • Unlimited pages, unlimited domains, or repeated testing rounds
  • Expert witness work, sworn declarations, or litigation support unless separately scoped
  • Deep packet capture using Fiddler/Wireshark-style tooling unless specifically quoted as an add-on
Report preview

Want to see the report style before starting?

You can view the Detailed Evidence sample now. For manual evidence audits, we can share a redacted sample format or walk you through what the evidence package will look like based on your use case.

After the report

What happens after the manual evidence audit?

The audit gives you a clean baseline. From there, you can fix, monitor, or move into a custom evidence workflow.

Need fixes after the audit?

Move into technical remediation for consent banners, GTM, pixels, scripts, and post-fix verification.

Website Tracking Remediation
Need ongoing visibility?

Monitor cookies, trackers, third-party requests, and consent behavior changes every month.

Monthly Privacy Monitoring
Need a law firm or enterprise scope?

For custom evidence workflows, multiple domains, urgent timelines, or special report formats.

Law Firm / Enterprise Package
Questions

Manual Evidence Audit FAQs

Straight answers before someone pays or requests a proposal.

No. This is a technical evidence audit. Auditzo documents observed website behavior, cookies, storage, requests, and consent-state differences. Legal interpretation should be handled by your lawyer or privacy counsel.

The $899 starting scope is designed for one website/domain and roughly 3 to 5 key pages. Larger sites, multiple domains, urgent timelines, special evidence formats, or deeper network tooling are quoted separately.

Yes, where the website has a consent banner and those journeys are testable. We usually compare no-interaction, reject, and accept behavior so the difference is easier to understand.

The manual audit is built around screenshots, timestamps, browser/network observations, cookie/storage tables, and request-level summaries. Raw evidence handoff can be scoped depending on the client need.

For the focused $899 package, we normally use browser/network evidence and HAR-style observations. Fiddler/Wireshark-style packet capture is more specialized and should be quoted as a custom add-on when truly needed.

Yes. Fix implementation is handled under Website Tracking Remediation. That can include consent banner configuration, GTM/pixel cleanup, third-party script blocking, Consent Mode review, and post-fix verification.

A focused manual evidence audit usually takes 3 to 5 business days after scope confirmation and access/details are provided. Larger or urgent projects are scheduled separately.

Need human-reviewed evidence, not just a scan?

Share your website and what you are worried about. We will confirm if the $899 focused audit is enough or if you need a custom scope.