FixVibe

// discovery / прожектор

Privacy & Cookie Compliance Markers

GDPR-required pages — present and linked, or you're at risk of a complaint.

Зацепка

Privacy compliance is unglamorous, unforgiving, and increasingly enforced. The EU GDPR, UK GDPR, California CCPA/CPRA, Brazil LGPD, and a growing list of other regulators have settled on a similar set of minimum disclosures — privacy policy, cookie policy, terms, lawful-basis statements, data-controller information. Missing any of those isn't usually a fine in itself, but it's the entry point for complaints that escalate. Regulators tend to start at 'is the basic compliance furniture here?' and move outward; the absence of a privacy policy fast-tracks the investigation. The fix is operationally trivial — write the policy, link it from the footer — and yet startups routinely launch without one because the founder thought lawyers were for later.

Кантип иштейт

We crawl the homepage and look for links to the standard compliance pages: Privacy Policy, Cookie Policy, Terms of Service, Data Processing Agreement (if B2B). We also look for the markup signature of a cookie consent banner — a fixed-position element loading on first visit with accept/reject controls. We grade presence and linkability, not content quality. Whether your privacy policy is well-drafted is a legal review job; whether it exists at all is a deterministic check.

Радиус поражения

GDPR / UK GDPR / CCPA enforcement risk. The ICO (UK), CNIL (France), DPC (Ireland), and equivalent EU member-state regulators have issued fines for missing or hidden privacy pages, ranging from small administrative penalties to seven-figure assessments for repeat offenders. Class actions have been filed in the U.S. over missing CCPA disclosures. Beyond regulatory risk: B2B customers (especially in regulated sectors) gate procurement on these documents being present. Their absence stalls deals.

// what fixvibe checks

What FixVibe checks

FixVibe maps externally visible application surfaces with passive signals and safe metadata checks. Reports summarize the exposed surface and remediation priorities. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.

Железные защиты

Have visible, footer-linked Privacy Policy, Cookie Policy, and Terms of Service from day one. The policies don't need to be perfect on launch — a clear baseline document is better than nothing — but get them in place. Add a compliant cookie consent banner that gates non-essential cookies (analytics, marketing) until consent. The banner needs to offer reject as easily as accept (no 'accept' button styled to dominate), and respect the choice (don't fire trackers on reject). Honor browser-level signals like Sec-GPC. Keep the documents updated; date them; have a process for re-issuing on material changes. For B2B selling into the EU, prepare a Data Processing Agreement template — many enterprise procurement processes require one before signature.

// запусти на своём приложении

Продолжай выпускать продукт, пока FixVibe следит за рисками.

FixVibe прощупывает публичную поверхность твоего приложения так же, как это делает атакующий — без агента, установки и карты. Мы постоянно исследуем новые паттерны уязвимостей и превращаем их в практичные проверки и готовые исправления для Cursor, Claude и Copilot.

Discovery
129
тестов в этой категории
модулей
12
проверок discovery
каждое сканирование
384+
тестов по всем категориям
  • Бесплатно — без карты, без установки, без Slack-уведомлений
  • Просто вставь URL — мы обойдём, проверим и отчитаемся
  • Находки с градацией по серьёзности, без дублей
  • Актуальные AI-промпты для исправлений в Cursor, Claude, Copilot
Запустить бесплатный скан

// актуальные проверки · практичные фиксы · выпускай увереннее

Privacy & Cookie Compliance Markers — Прожектор уязвимости | FixVibe · FixVibe