How This Briefing Works
This report opens with key findings, then maps the gaps between what Partnerize discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.
Key Findings
Analysis pending. Findings will appear here once intelligence collection is complete.
Claims vs. Observed Behavior
pending
“Awaiting scanner verification”
No scanner data available for Partnerize JavaScript tag behavior
data_collection
“Does not collect PII from end consumers”
IP addresses, browser fingerprints, and device identifiers are collected — classification as PII varies by jurisdiction (GDPR considers IP addresses personal data)
consent
“First-party tracking is privacy-compliant”
First-party cookie strategy is engineered specifically to circumvent ITP/ETP browser privacy protections
What This Means For You
What To Do About It
Role-specific actions based on observed behavior
Recommended Actions for Partnerize
- →Audit Partnerize JavaScript tag deployment to confirm it fires only AFTER valid consent collection, particularly in GDPR jurisdictions where the first-party cookie strategy may conflict with user browser privacy preferences.\n2. Review your Partnerize Data Processing Agreement to understand data retention periods, subprocessor chains, and whether transactional data is used for Konnecto's competitive benchmarking products.\n3. Implement server-to-server tracking instead of client-side JavaScript tags where possible to reduce client-side attack surface and eliminate browser fingerprint collection.\n4. Monitor Partnerize's tag behavior for scope creep — verify it only fires on designated conversion pages, not across your entire site, and confirm no additional data collection beyond what is contractually agreed.\n5. Negotiate contractual restrictions on cross-advertiser data use, specifically addressing whether your conversion and transaction data feeds into Konnecto's competitive intelligence or benchmarking products.
Negotiation Leverage
- →Key leverage points for Partnerize procurement: (1) The ITP circumvention strategy is a regulatory liability in the EU — use this to negotiate enhanced data processing commitments and indemnification clauses. (2) Demand explicit contractual language prohibiting your transaction data from feeding Konnecto competitive intelligence products. (3) Request a complete subprocessor list with data flow documentation showing exactly where conversion and transaction data is stored and processed. (4) Push for server-to-server tracking as the default implementation to minimize client-side data collection. (5) Negotiate data portability clauses ensuring you can export full attribution history if switching platforms. (6) Request annual third-party audits of data segregation between advertisers, particularly given the Konnecto acquisition expands Partnerize's analytics capabilities. The affiliate tracking market is competitive (Impact, CJ Affiliate, Rakuten, Awin) — use alternatives as leverage on pricing and data governance terms.
IOC Manifest
Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.
Ecosystem & Supply Chain
Evidence Artifacts
Artifacts collected during analysis, available with evidence-tier access.
Complete network capture with all requests and responses
239 detection signatures across scripts, domains, cookies, and network endpoints