How it works

Five steps from “probably compliant” to proof.

UserGuard is a workspace built around one conviction: a compliance claim you can’t trace back to evidence is just a hope with a dashboard. Here is the whole lifecycle.

01

Scan

The crawler walks up to 50 pages by default (up to 250 if raised in Scan settings), starting with the ones your visitors actually load, and captures the raw record: Set-Cookie headers, HTTP-only cookies, document.cookie values, scripts, pixels, iframes, storage keys. Nothing is discarded, and nothing is promoted yet.

02

Gate

The evidence gate splits the record in two. Hard cookie evidence becomes your inventory; everything else is filed as context. Your compliance surface stays exactly as big as reality.

On the scan above that is 44 cookies verified, 48 signals kept as context, and 0 guesses — disclosed in their own section, as what they actually are.

03

Review

AI drafts categories, flags risky firing behavior, and writes plain-language descriptions. Every suggestion then waits for your approval before it publishes. AI triage only decides what needs your attention first.

04

Publish

One script ships the banner, the preference center, and (when you switch it on) the accessibility widget. Region-aware defaults, honest categories, every choice logged.

05

Prove

Scan history, consent events, rejected categories, accessibility status, tied to site and banner version, exportable, and readable by someone who bills by the hour.

The shape of the workspace

Small enough to learn in an afternoon.

Three evidence sources feed four cookie categories through four review states. Two compliance modules, privacy and accessibility, share one site list, one account, one bill. That’s the entire object model, and it’s deliberate: compliance tools fail when only one person on the team understands them.

3Evidence sourcesheaders · HTTP-only · browser cookies
4Cookie categoriesnecessary · analytics · marketing · functional
4Review statesneeds a category · proposed · approved · gone
2Compliance modulesprivacy + accessibility

What ships with every site

The modules, plainly.

Evidence-first scanner

Scheduled scans plus manual rescans. Cookies enter the inventory through the evidence gate. Cookies set behind a login can be added by hand, labeled as exactly that.

AI-assisted review

Category suggestions, risk flags, drafted disclosures. Separated from human approvals, always.

Consent banner + preference center

Necessary, analytics, marketing, functional. Plain language, in the visitor’s language. Auto-detected translations (RTL included), region-aware defaults, logged choices.

Accessibility widget

Text size, contrast, motion, and readable-font controls for visitors. A per-site toggle, not a separate product.

Receipt-grade reporting

Consent activity and scan history tied to site and banner version, CSV out. A monthly report for each site adds accessibility status, ready to print for a client.

Workspace administration

Sites, users, roles and two-factor sign-in, client organizations, volume pricing. One boring, competent account layer.

No feature ransom

What every paid site gets — and what is metered.

Scans
monthly, plus manual rescans any time
AI scan review
10 drafts / site / month · you approve every one
Cookie policy
generated draft, versioned to the scan
GPC + geo-targeting
every tier, never gated
Accessibility widget
included per site
Monthly site report
each finished month since the site was added, up to twelve · up to 50 sites per PDF
Before consent
which cookies got past, what likely set them, and how to fix each
Pageviews / traffic
unmetered

Start today

Evidence from day one. Refundable for thirty.

Create an account, drop one script on a site, and the first scan verifies your cookies in minutes. Honest consent UX, consent analytics and accessibility controls, from $10 a site. Thirty days to get your money back if it is not right.

Get started 30-day money-back guarantee · cancel anytime