How This Briefing Works
This report opens with key findings, then maps the gaps between what Adquality discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.
Key Findings
Disclosure Gap
31 distinct third-party vendors detected on site
Pre-Consent Activity
Adquality was observed loading and executing before user consent was obtained on 2% of sites where it was detected.
No-Share Claim Violation
31 vendors receive data from site visitors
Undisclosed Party
Not in privacy policy
Undisclosed Sharing
Hidden data recipients
Claims vs. Observed Behavior
Disclosure Gap
“Privacy policy mentions only generic web hosting provider”
31 distinct third-party vendors detected on site
Runtime scan of adquality.fr detected DoubleClick, GoogleAds, GA4, TrenDemon, HGInsights, Firmable, and 25 other vendors
Pre-Consent Tracking
“GDPR compliant (Conformément au RGPD)”
2.3% pre-consent tracking rate
DoubleClick, GoogleAds, GoogleAnalytics4 fire before consent obtained
What This Means For You
What To Do About It
Role-specific actions based on observed behavior
If You Use Adquality
- →Request complete list of all third-party vendors they deploy on your properties
- →Audit your site for undisclosed trackers after their implementation
- →Require contractual disclosure obligations for all data recipients including TrenDemon, HGInsights, and Firmable
- →Review data processing agreement scope against 31 detected vendors
If You're Evaluating Adquality
- →Request complete vendor list and compare against the single generic disclosure before signing
- →Verify the no data sharing claim against runtime evidence showing 31 third-party vendors
- →Compare with other French agencies on vendor transparency and GDPR compliance
- →Require contractual representations matching their no data sharing marketing claim
Negotiation Leverage
- →No data sharing claim: AdQuality claims no third-party data sharing while 31 vendors detected — use this direct contradiction to negotiate contractual representations with penalties
- →Competitive intelligence vendors: TrenDemon, HGInsights, and Firmable on adquality.fr — use this to negotiate restrictions on campaign intelligence flowing to competitive tools
- →31-vendor disclosure gap: Only generic web hosting mentioned — require complete named vendor disclosure as a contract condition
- →BAE Groupe subsidiary: Data flows may extend beyond AdQuality — negotiate restrictions on data sharing within the BAE Groupe corporate family
Runtime Detections
BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.
Evasion infrastructure, auditor bypass
Keystroke/mouse tracking
Full session replay
Ignoring CMP signals
Device identification
Container/loader (neutral)
IOC Manifest
Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.
Ecosystem & Supply Chain
Evidence Artifacts
Artifacts collected during analysis, available with evidence-tier access.
Complete network capture with all requests and responses
189 detection signatures across scripts, domains, cookies, and network endpoints
