How This Briefing Works
This report opens with key findings, then maps the gaps between what Bionic Ads discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.
Key Findings
Pre-Consent Activity
Bionic Ads was observed loading and executing before user consent was obtained on 4% of sites where it was detected.
Undisclosed Party
Not in privacy policy
Undisclosed Sharing
Hidden data recipients
Claims vs. Observed Behavior
Disclosure Gap
“Privacy policy mentions generic third-party ad servers”
22+ specific vendors detected including intent data brokers, behavioral analytics, and programmatic advertising platforms
Runtime scan of bionic-ads.com detected DoubleClick, GoogleAds, HubSpot, LinkedIn, Wistia, Intentdata, Rockerbox, Semcasting, TrenDemon, and 13+ additional vendors
Pre-Consent Tracking
“Offers NAI/DAA opt-out for behavioral advertising”
6 vendors load before any consent mechanism is presented (4.2% pre-consent rate)
Pre-consent vendors: DoubleClick, GoogleAds, GoogleAnalytics4, HubSpot, LinkedIn, Wistia
Policy Staleness
“Privacy policy provides current disclosure”
Policy last updated September 2019 - over 6 years outdated
Policy header states Last Updated: September 1, 2019
What This Means For You
What To Do About It
Role-specific actions based on observed behavior
If You Use Bionic Ads
- →Request current third-party vendor list and compare to privacy policy disclosures
- →Ask for data processing addendum covering GDPR and CCPA obligations — none currently available
- →Verify what data flows to intent data partners Intentdata, Rockerbox, Semcasting, and TrenDemon
- →Update your own privacy policy to disclose Bionic's actual vendor chain if they process your data
If You're Evaluating Bionic Ads
- →Request a formal DPA before any trial — the absence of one is a compliance red flag
- →Audit Bionic's site to understand the intent data vendor ecosystem you would inherit
- →Compare with media planning alternatives that have transparent subprocessor disclosures
- →Require contractual guarantees on data isolation from intent data syndication
Negotiation Leverage
- →Intent data vendor exposure: Intentdata, Rockerbox, Semcasting, and TrenDemon detected on bionic-ads.com — use this to negotiate restrictions on intent data sharing from your campaign data
- →Generic disclosure gap: Privacy policy mentions only generic third-party ad servers while 22+ specific vendors detected — require named vendor disclosure as a contract condition
- →Missing DPA: No formal GDPR/CCPA data processing addendum available — require one before any engagement
- →20+ year profitability claim: Bionic claims 20+ years of profitability — leverage this stability expectation against the need for modern privacy compliance infrastructure
Runtime Detections
BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.
Evasion infrastructure, auditor bypass
Keystroke/mouse tracking
Full session replay
Ignoring CMP signals
Device identification
IOC Manifest
Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.
Ecosystem & Supply Chain
Evidence Artifacts
Artifacts collected during analysis, available with evidence-tier access.
Complete network capture with all requests and responses
33 detection signatures across scripts, domains, cookies, and network endpoints
