How This Briefing Works
This report opens with key findings, then maps the gaps between what CookieYes discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.
Key Findings
Pre-Consent Tracking
55.6% pre-consent tracking rate across monitored sites. 5 vendors loading pre-consent on own website
Pre-Consent Activity
CookieYes was observed loading and executing before user consent was obtained on 57% of sites where it was detected.
Undisclosed Vendors
8+ vendors on website not in subprocessor list including Clarity, DoubleClick, Google Ads, Hotjar, Bing Ads, TrenDemon, Pubrio, Ahrefs
Advertising Data Flows
Google Workspace disclosed for productivity, but DoubleClick and Google Ads (advertising) undisclosed
Undisclosed Party
Not in privacy policy
Claims vs. Observed Behavior
Pre-Consent Tracking
“GDPR/CCPA compliant consent management”
55.6% pre-consent tracking rate across monitored sites. 5 vendors loading pre-consent on own website
intel_detections query shows pre_consent_pct=55.6 for vendor_slug=cookieyes. Scan of cookieyes.com shows Clarity, DoubleClick, Google Ads, GA4, Slack with pre_consent=true
Undisclosed Vendors
“Transparent subprocessor disclosure”
8+ vendors on website not in subprocessor list including Clarity, DoubleClick, Google Ads, Hotjar, Bing Ads, TrenDemon, Pubrio, Ahrefs
Comparison of /sub-processors-list/ content vs runtime detection on cookieyes.com
Advertising Data Flows
“Subprocessors listed for specific purposes”
Google Workspace disclosed for productivity, but DoubleClick and Google Ads (advertising) undisclosed
Runtime detection shows doubleclick.net and google-ads domains active on cookieyes.com
What This Means For You
What To Do About It
Role-specific actions based on observed behavior
If You Use CookieYes
- →Audit your own site for pre-consent tracking — CookieYes may not be blocking vendors as expected given their 55.6% failure rate
- →Request their SOC2 report — they claim infrastructure certifications but not their own platform certification
- →Compare your detected vendors against the CookieYes-supposed-to-block list to verify actual enforcement
- →Implement server-side consent verification as a backstop — do not rely solely on CookieYes client-side blocking
If You're Evaluating CookieYes
- →Test CookieYes in staging and verify consent blocking actually works for all your vendors
- →Compare with OneTrust, Cookiebot, and Osano on their own site pre-consent behavior
- →Request documented evidence of consent blocking effectiveness, not just configuration capabilities
- →Verify CookieYes does not introduce its own tracking scripts on your properties
Negotiation Leverage
- →CMP credibility gap: A consent management platform with 55.6% pre-consent rate across monitored sites — use this to negotiate enhanced SLAs with consent blocking guarantees and financial penalties for failures
- →Advertising on a CMP: DoubleClick, Google Ads, and Bing Ads detected on cookieyes.com — a CMP running ad platforms pre-consent undermines the core product promise; leverage for price negotiations
- →Missing SOC2: CookieYes claims AWS and data center certifications but not their own SOC2 — require independent security audit documentation
- →8 undisclosed vendors: Vendors on cookieyes.com not in subprocessor list — require complete vendor disclosure and verify CookieYes is not introducing undisclosed scripts on your properties
Runtime Detections
BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.
Keystroke/mouse tracking
Full session replay
Identity stitching
Ignoring CMP signals
PII deanonymization
Container/loader (neutral)
IOC Manifest
Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.
Ecosystem & Supply Chain
Evidence Artifacts
Artifacts collected during analysis, available with evidence-tier access.
Complete network capture with all requests and responses
128 detection signatures across scripts, domains, cookies, and network endpoints