PrivBeacon
Commencer
Méthodologie

Comment le score d’analyse fonctionne

Le score est une heuristique technique de ce qui s’est chargé sur les pages analysées. Ce n’est pas une détermination juridique.

Sur cette page
  1. 01Scanning architecture
  2. 02Ce que le scanner examine
  3. 03Comment le score 0–100 est calculé
  4. 04Technical findings vs legal interpretation
  5. 05Monitoring reliability
  6. 06Ce que signifie Certified Private
  7. 07Ce qu’un crawler ne peut pas voir
  8. 08Rapports IA

1Scanning architecture

Where scans run. Authenticated and scheduled scans run on the PrivBeacon application host operated by Vassbrekke AS in Norway / EU. Free public scans use the same host but a static HTTP fetch (no headless browser) and a tighter time budget. The Raspberry Pi / on-prem agent is a separate trust boundary: it runs on your network and only talks to PrivBeacon if you set an API key and sync URL.

How browsers are controlled. Cloud scans launch headless Chromium (Playwright). Outbound requests are DNS-resolved, pinned to those addresses, and blocked if they resolve to private, loopback, link-local, or metadata IPs. Heavy resources (images, media, fonts) are skipped. The browser uses a desktop Chrome user-agent, waits for hydration, and scrolls to load lazy content. It does not click Accept/Reject, fill forms, type credentials, or submit personal information.

Pages and interactions. Each scan fetches the URL you add, then discovers privacy, cookie, and legal pages (typically up to 24 additional URLs, fewer on public/fast scans). Optional path exclusions skip prefixes such as /account or /checkout. Authenticated or staging sites that are not on the public internet cannot be reached by the cloud scanner — use the on-prem agent on a network you are authorized to test.

JavaScript. When Chromium launches, JavaScript on the page runs. Trackers injected after load, iframe pixels, and inline snippets (gtag, fbq, _paq) can be observed. If the browser cannot start, the scan falls back to a static HTML fetch and records that limitation. JavaScript-only banners and tags that never appear in HTML or network requests may be missed.

IP addresses. Scans originate from the application host’s provider-assigned public IP in Norway/EU. PrivBeacon does not use a rotating residential proxy pool. The address may change if the host is rebuilt. We do not publish a guaranteed allowlist from this page — email support@privbeacon.com for the current egress IPs if you need to permit our scanner.

Sensitive sites. Do not put real passwords in scan URLs. URLs with embedded credentials are rejected. Do not point the cloud scanner at pages that display other people’s personal data. Use path exclusions for account, checkout, and admin areas. Form fields in stored snippets are stripped; emails and long numbers in snippets are redacted. Never submit real personal information during a scan — the scanner will not fill forms for you.

2Ce que le scanner examine

PrivBeacon récupère le site public que vous autorisez et inspecte les trackers, cookies, signaux de consentement et formulations de politique qui apparaissent réellement. Un bandeau de consentement n’est pas traité comme une preuve que les trackers restent bloqués.

3Comment le score 0–100 est calculé

Le scoring part de 100 et soustrait les constats. Les chiffres correspondent au moteur du produit.

  • Départ à 100.
  • Tracker de gravité élevée : −8 chacun.
  • Tracker de gravité moyenne : −4 chacun.
  • Tracker de gravité faible : −2 chacun.
  • Problème de consentement critique : −15 chacun.
  • Problème de consentement élevé : −10 chacun.
  • Problème de consentement moyen : −5 chacun.
  • Contrôles légaux échoués : −0,8 chacun, plafonné à 35 au total.
  • Le résultat est borné entre 0 et 100.

4Technical findings vs legal interpretation

Every score point maps to evidence: a tracker request or snippet, a consent issue (banner, pre-consent tags, missing privacy or opt-out link), or a failed keyword check on a policy page. Trackers, cookies, scripts, and network hosts are technical findings. Failed law checks are heuristic presence tests on the text we fetched — they are not a legal conclusion about your contracts, lawful basis, or DPIAs. The score is a PrivBeacon heuristic, not a percentage of legal compliance, and it is not legal advice.

5Monitoring reliability

Schedules. Every paid site that is not on-prem is due for a monthly baseline scan (720 hours). Pro and Enterprise can enable daily or weekly scans per site. Cancelled or unpaid accounts are not scanned. Removed sites are deleted and are not scanned.

Retries. If a scheduled scan fails, the worker retries once after a short delay. Scans left pending after a process restart are re-queued. Scans stuck in “running” for more than 20 minutes are marked failed.

Outages. If the monitor cron or the application is down, due sites are not scanned during the outage. After recovery, sites that are still due are picked up on the next cron run. Missed ticks are not backfilled beyond “is this site due now?”. There is no promised scan SLA.

Alerts. Score drops of more than 5 points and newly detected tracker vendors create in-app alerts. Optional email and HTTPS webhooks are best-effort: one attempt, 10-second timeout, private-IP webhooks blocked. Delivery is not guaranteed and is not an SLA.

Timestamps. Each scan stores created time, completed time (when successful), trigger (manual, scheduled, CI, or agent), and status. Historical complete and failed scans remain in your account until you delete them or the account retention window ends.

Statuses. Not scanned — no scan record yet. Scan queued / scanning — in progress. Scan failed — the fetch did not finish (reason stored). No issue found — a complete scan with no listed trackers, consent issues, or focused law gaps. Issues found — a complete scan that listed at least one finding. “No issue found” is not a legal all-clear.

6Ce que signifie Certified Private

Un site peut afficher le badge après qu’une analyse réelle ait obtenu un score de 75+ et que la certification soit activée. Un score de 75+ qualifie pour le badge Certified Private propre à PrivBeacon après une analyse réelle. Ce n’est pas une certification gouvernementale ou ISO.

7Ce qu’un crawler ne peut pas voir

Une analyse de site ne peut pas déterminer votre base juridique, vos contrats, vos rôles responsable du traitement/sous-traitant, vos mécanismes de transfert, vos décisions de conservation, vos analyses d’intérêt légitime ni vos processus internes. Cela nécessite un conseil juridique et vos propres registres.

8Rapports IA

Les synthèses IA sur les analyses authentifiées sont une aide à la rédaction. En production, xAI (Grok) est utilisé sur les métadonnées d’analyse. La détection et le scoring sont fondés sur des règles. L’IA n’est pas un conseil juridique.

Confiance et traitement des données

PrivBeacon fournit des analyses automatisées de confidentialité et des modèles de documents à des fins d'information uniquement. Il ne s’agit pas d’un avis juridique. Consultez un conseiller juridique qualifié avant de vous fier aux politiques générées ou aux scores de conformité pour les décisions réglementaires.