Website compliance scan

See where your website and legal pages drift apart.

Normio scans public policy pages, cookies, third-party tools, and GDPR signals so teams know what changed, why it matters, and which document needs review.

normio scan

public-site review
82%

Meta Pixel detected

Processor missing from disclosure.
review

Cookie retention mismatch

Policy says 30 days. Live cookie resolves to 180.
drift

Privacy policy sections found

Retention, rights, transfers, and processors indexed.
ready
0
tracking script required
4
checks from one domain
1
focused review feed

The problem

Compliance drift is quiet until it becomes expensive.

01

Your stack changes

Analytics, payments, auth, support, embeds, and vendors keep moving.

02

Your legal pages lag

Privacy policies, cookie notices, and processor lists stay static.

03

The gap stays invisible

Nothing crashes. The mismatch only appears during review, audit, or complaint.

How it works

From domain to review list in four checks.

01

Add a domain

Start from the public website you own or manage.

02

Scan the surface

Normio checks policy pages, cookies, scripts, embeds, and known third parties.

03

Compare signals

Detected behavior is matched against privacy text and GDPR-related disclosures.

04

Review the drift

Your team gets a short list of mismatches with source, context, and owner hints.

Scan preview

A short, actionable feed instead of another noisy dashboard.

Normio groups website evidence into review work: the source, the mismatch, the likely owner, and the legal page that needs attention.

Start a scan
Drift review3 open
drift

Google Analytics consent category changed

Banner labels analytics as necessary, while the policy still says optional analytics.

legal
review

New data processor found

support.examplecdn.com loads on help pages but is not listed in public disclosure.

product
vendor

Stripe terms updated

Vendor terms page changed. Payment processor disclosure may need review.

ops

Trust model

Built for background checks, not attention theater.

No ad-network behavior

Normio checks sites and documents. It is not built to profile visitors.

GDPR-relevant evidence

Focus on processors, cookies, retention, transfers, rights, and policy pages.

Quiet by default

Silence is useful. Normio surfaces changes when there is something to review.

Early access

Know what needs review before an audit finds it for you.

Start with one public domain. Normio will scan the visible surface and show where website behavior and legal text disagree.

FAQ

Practical answers before you point Normio at a domain.

What does Normio monitor?

Public policy pages, scripts, embeds, cookies, vendors, processors, consent categories, and the places those signals should be disclosed.

Is this legal advice?

No. Normio surfaces operational compliance drift and review evidence. Legal decisions stay with your counsel, DPO, or privacy lead.

Do I need to install a script?

Not for the first public-site scan. Normio can start from public pages, detected scripts, cookies, and policy URLs.

Who is Normio for?

SaaS teams, founders, privacy leads, agencies, and compliance operators who need to know when website reality drifts from legal text.