All Vendors
dsp

Effinity

Effinity is a DSP vendor with a VRS of 80. Deploys comprehensive behavioral tracking and session recording to feed programmatic advertising campaigns and retargeting audiences.

77 IOCs1 detections100% pre-consent1 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Effinity discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

1 detection across 1 site100% pre-consent activity
CRITICAL

Pre-Consent Activity

Effinity was observed loading and executing before user consent was obtained on 100% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Unknown

Observed Behavior

Requires claims extraction via CDT

Customer Impact

What This Means For You

Customers visiting sites with Effinity face behavioral tracking designed explicitly for programmatic retargeting. Behavioral data including page views, interaction patterns, content engagement, and session replays are captured and processed to build retargeting audiences. These audiences are then available in shared DSP inventory where direct competitors can bid on your qualified visitors using Effinity-derived behavioral signals to inform their targeting strategies.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Effinity

  • Audit Effinity programmatic inventory access and prohibit retargeting audience syndication to competitors
  • Disable Effinity behavioral biometrics and session recording to minimize retargeting data enrichment
  • Review DPA for programmatic audience sharing restrictions and enforce strict competitor exclusion
  • Implement consent-conditional Effinity pixel load to prevent pre-acceptance retargeting pool capture
  • Establish retargeting audience retention limits and require regular purging of visitor behavioral profiles

If You're Evaluating Effinity

  • Question business necessity of Effinity given 90% CAC subsidization from shared programmatic inventory access by competitors
  • Require contractual guarantee that retargeting audiences are never accessible to direct competitors in DSP inventory
  • Verify Effinity does not employ session recording or behavioral biometrics without explicit consent
  • Assess alternative programmatic approaches (contextual targeting, first-party retargeting via Google/Meta) that do not feed shared DSP pools
  • Demand significant pricing concessions or consider platform switch given competitor subsidization risk

Negotiation Leverage

  • VRS 80 classification with 90% CAC subsidization justifies immediate platform review or 50% discount with competitor exclusion guarantees
  • 100% legal tail risk demands indemnification for session recording consent failures and programmatic targeting without adequate legal basis
  • Require contractual guarantee that retargeting audiences include comprehensive competitor exclusion lists
  • Request monthly reporting on DSP inventory access showing which advertisers have bid on segments derived from your visitor data
  • Negotiate private marketplace deals (PMP) that exclude competitor access or revenue sharing from audience monetization in open exchanges
Runtime Detections

Runtime Detections

5 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

Impact: Effinity tracking pixels fire before consent acceptance to maximize retargeting audience pool for programmatic campaigns.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Mouse movements and scroll patterns captured to build engagement scoring models that inform real-time bidding decisions.

BTI-C07Session Recording

Full session replay

Impact: DOM capture used to identify high-intent visitors and prioritize retargeting budget allocation based on interaction quality.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Effinity maintains retargeting pixel tracking after consent rejection to preserve programmatic audience segments.

BTI-C10Fingerprinting

Device identification

Impact: Browser fingerprinting used to reconnect visitors across cookie deletion events for persistent retargeting.

IOC Manifest

IOC Manifest

71 INDICATORS

Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.effinity.fr/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*www.effinity.fr/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-form-move-tracker.js*
Tracking script
TRACK
*www.effinity.fr/wp-includes/js/jquery/jquery.js*
Tracking script
TRACK
*www.effinity.fr/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js*
Tracking script
TRACK
*www.effinity.fr/wp-content/uploads/fusion-scripts/*.js*
Tracking script
TRACK
*www.effinity.fr/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js*
Tracking script
TRACK
*www.effinity.fr/wp-content/plugins/revslider/public/js/libs/tptools.js*
Tracking script
TRACK
*www.effinity.fr/wp-content/plugins/revslider/public/js/sr7.js*
Tracking script
TRACK
*www.effinity.fr/wp-includes/js/wp-emoji-release.js*
Tracking script
TRACK
www.effinity.fr/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js
Auto-extracted from scan
TRACK
www.effinity.fr/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
www.effinity.fr/wp-content/plugins/revslider/public/js/libs/tptools.js
Auto-extracted from scan
TRACK
www.effinity.fr/wp-content/plugins/revslider/public/js/sr7.js
Auto-extracted from scan
TRACK
www.effinity.fr/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js
Auto-extracted from scan
TRACK
www.effinity.fr/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
www.effinity.fr/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-form-move-tracker.js
Auto-extracted from scan
TRACK
www.effinity.fr/wp-content/uploads/fusion-scripts/5228b99a49f513f8086378428f1c877a.min.js
Auto-extracted from scan
TRACK
www.effinity.fr/wp-includes/js/wp-emoji-release.min.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Effinity occupies the programmatic advertising layer, typically deployed alongside other DSPs (The Trade Desk, Google Display & Video 360), ad verification tools (DoubleVerify, Integral Ad Science), and attribution platforms (Adobe Analytics, Google Analytics). The vendor creates retargeting audiences that flow into shared programmatic inventory where competitors access the same visitor pools.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

77 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details