All 30 codes.
16 BTI-C · 14 BTI-X.
The vocabulary the BTI framework uses. Each code names a class of vendor behavior. Advisories cite codes; codes don't cite vendors.
BTI-C codes describe observable runtime behaviors. BTI-X codes describe contextual claims-vs-reality patterns.
BTI-C codes
The mechanisms of taking. Behaviors observed directly in vendor code at runtime — data collection, fingerprinting, consent bypass, exfiltration, evasion.
Defeat Device
“They take your ability to see what they're taking.”
Storage Exfiltration
“They take your first-party data and monetize it.”
Supply Chain Risk
“They take a cut for every undisclosed vendor they load.”
Behavioral Biometrics
“They take your users' behavior patterns and fingerprint them.”
Session Recording
“They take your UX research and conversion insights.”
Cross-Domain Sync
“They take your visitor identity and connect it everywhere.”
Consent Bypass
“They take data before your users can say no.”
Fingerprinting
“They take device signatures to track users who block cookies.”
CMP Manipulation
“They take control of your consent UI to get the answer they want.”
Persistence
“They take permanent residence in your users' browsers.”
Identity Resolution
“They take your anonymous visitors and sell them as leads to your competitors.”
Tag Manager
“They don't take anything directly. They're the gun, not the bullet.”
Real-Time Exfiltration
“They take your traffic signals and stream them live to buyers.”
DOM Harvest
“They take your page content, pricing, and competitive intelligence.”
Identifier Propagation
“They take your click IDs and leak them through exit links.”
Client-Side Manipulation
“They take control of your page and modify it for their benefit.”
BTI-X codes
The deception that obscures the take. Patterns where what a vendor claims contradicts what runtime behavior shows — undisclosed parties, marketing mismatches, opt-out failures.
Undisclosed Party
“They hid who else is taking.”
Undisclosed Sharing
“They hid where your data goes after they take it.”
Retention Violation
“They keep taking value from data they promised to delete.”
Marketing Mismatch
“They lied about what they take.”
Compliance Claim Mismatch
“Their compliance badges are cover for the take.”
Jurisdiction Violation
“They take your data across borders you didn't authorize.”
Opt-Out Failure
“They keep taking after users say stop.”
Scope Creep
“They take more than you agreed to give.”
Data Security Discrepancy
“They lied about how they protect what they take.”
CMP Disclosure Mismatch
“They take through vendors not shown in consent UI.”
Contract/DPA Breach
“They take in ways that breach your agreement.”
Assurance Gap
“They won't prove they're not taking.”
Observability Regression
“They reduced visibility AFTER being caught taking.”
Ecosystem Misinformation
“They poison the discourse to normalize the take.”
Codes are the vocabulary. Advisories are the findings. BTSS is the severity score. The framework explainer lives on /methodology.