Miten skannauspisteet toimivat
Pisteet ovat tekninen heuristiikka siitä, mitä skannatuilla sivuilla latautui. Se ei ole juridinen määritys.
Tällä sivulla
1Scanning architecture
Where scans run. Authenticated and scheduled scans run on the PrivBeacon application host operated by Vassbrekke AS in Norway / EU. Free public scans use the same host but a static HTTP fetch (no headless browser) and a tighter time budget. The Raspberry Pi / on-prem agent is a separate trust boundary: it runs on your network and only talks to PrivBeacon if you set an API key and sync URL.
How browsers are controlled. Cloud scans launch headless Chromium (Playwright). Outbound requests are DNS-resolved, pinned to those addresses, and blocked if they resolve to private, loopback, link-local, or metadata IPs. Heavy resources (images, media, fonts) are skipped. The browser uses a desktop Chrome user-agent, waits for hydration, and scrolls to load lazy content. It does not click Accept/Reject, fill forms, type credentials, or submit personal information.
Pages and interactions. Each scan fetches the URL you add, then discovers privacy, cookie, and legal pages (typically up to 24 additional URLs, fewer on public/fast scans). Optional path exclusions skip prefixes such as /account or /checkout. Authenticated or staging sites that are not on the public internet cannot be reached by the cloud scanner — use the on-prem agent on a network you are authorized to test.
JavaScript. When Chromium launches, JavaScript on the page runs. Trackers injected after load, iframe pixels, and inline snippets (gtag, fbq, _paq) can be observed. If the browser cannot start, the scan falls back to a static HTML fetch and records that limitation. JavaScript-only banners and tags that never appear in HTML or network requests may be missed.
IP addresses. Scans originate from the application host’s provider-assigned public IP in Norway/EU. PrivBeacon does not use a rotating residential proxy pool. The address may change if the host is rebuilt. We do not publish a guaranteed allowlist from this page — email support@privbeacon.com for the current egress IPs if you need to permit our scanner.
Sensitive sites. Do not put real passwords in scan URLs. URLs with embedded credentials are rejected. Do not point the cloud scanner at pages that display other people’s personal data. Use path exclusions for account, checkout, and admin areas. Form fields in stored snippets are stripped; emails and long numbers in snippets are redacted. Never submit real personal information during a scan — the scanner will not fill forms for you.
2Mitä skanneri tarkastelee
PrivBeacon hakee valtuuttamasi julkisen sivuston ja tarkastaa seuraimet, evästeet, suostumussignaalit ja käytäntökielen, jotka oikeasti näkyvät. Suostumusbanneria ei pidetä todisteena siitä, että seuraimet pysyvät estettyinä.
3Miten 0–100-pisteet lasketaan
Pisteytys alkaa 100:sta ja vähentää löydöksiä. Numerot vastaavat tuotemoottoria.
- Aloita 100:sta.
- Korkean vakavuuden seurain: −8 kukin.
- Keskivakavuuden seurain: −4 kukin.
- Matalan vakavuuden seurain: −2 kukin.
- Kriittinen suostumusongelma: −15 kukin.
- Korkea suostumusongelma: −10 kukin.
- Keskisuuri suostumusongelma: −5 kukin.
- Epäonnistuneet lakitarkastukset: −0.8 kukin, enintään 35 yhteensä.
- Tulos rajataan välille 0–100.
4Technical findings vs legal interpretation
Every score point maps to evidence: a tracker request or snippet, a consent issue (banner, pre-consent tags, missing privacy or opt-out link), or a failed keyword check on a policy page. Trackers, cookies, scripts, and network hosts are technical findings. Failed law checks are heuristic presence tests on the text we fetched — they are not a legal conclusion about your contracts, lawful basis, or DPIAs. The score is a PrivBeacon heuristic, not a percentage of legal compliance, and it is not legal advice.
5Monitoring reliability
Schedules. Every paid site that is not on-prem is due for a monthly baseline scan (720 hours). Pro and Enterprise can enable daily or weekly scans per site. Cancelled or unpaid accounts are not scanned. Removed sites are deleted and are not scanned.
Retries. If a scheduled scan fails, the worker retries once after a short delay. Scans left pending after a process restart are re-queued. Scans stuck in “running” for more than 20 minutes are marked failed.
Outages. If the monitor cron or the application is down, due sites are not scanned during the outage. After recovery, sites that are still due are picked up on the next cron run. Missed ticks are not backfilled beyond “is this site due now?”. There is no promised scan SLA.
Alerts. Score drops of more than 5 points and newly detected tracker vendors create in-app alerts. Optional email and HTTPS webhooks are best-effort: one attempt, 10-second timeout, private-IP webhooks blocked. Delivery is not guaranteed and is not an SLA.
Timestamps. Each scan stores created time, completed time (when successful), trigger (manual, scheduled, CI, or agent), and status. Historical complete and failed scans remain in your account until you delete them or the account retention window ends.
Statuses. Not scanned — no scan record yet. Scan queued / scanning — in progress. Scan failed — the fetch did not finish (reason stored). No issue found — a complete scan with no listed trackers, consent issues, or focused law gaps. Issues found — a complete scan that listed at least one finding. “No issue found” is not a legal all-clear.
6Mitä Certified Private tarkoittaa
Sivusto voi näyttää merkin, kun oikea skannaus saa pisteet 75+ ja sertifiointi on aktivoitu. Pisteet 75+ oikeuttavat PrivBeaconin omaan Certified Private -merkkiin oikean skannauksen jälkeen. Se ei ole valtion tai ISO:n sertifiointi.
7Mitä crawler ei näe
Verkkosivuston skannaus ei voi määrittää oikeusperustettasi, sopimuksia, rekisterinpitäjä/käsittelijä-rooleja, siirtomekanismeja, säilytyspäätöksiä, oikeutetun edun arviointeja tai sisäisiä prosesseja. Ne edellyttävät neuvontaa ja omia tietueitasi.
8Tekoälyraportit
Tekoälyyhteenvedot tunnistautuneissa skannauksissa ovat kirjoitusapu. Tuotanto käyttää xAI:ta (Grok) skannauksen metatietoihin. Tunnistus ja pisteytys ovat sääntöpohjaisia. Tekoäly ei ole neuvonantaja.
Luottamus ja tietojen käsittely
PrivBeacon tarjoaa automaattisia tietosuojaskannauksia ja asiakirjamalleja vain tiedoksi. Tämä ei ole oikeudellinen neuvo. Ota yhteyttä pätevään lakimieheen, ennen kuin luotat luotuihin käytäntöihin tai vaatimustenmukaisuuspisteisiin sääntelypäätöksissä.