PrivBeacon
Kom i gang
Metodikk

Slik fungerer skannepoengsummen

Poengsummen er en teknisk heuristikk for det som ble lastet inn på skannede sider. Det er ikke en juridisk avgjørelse.

På denne siden
  1. 01Scanning architecture
  2. 02Hva skanneren ser på
  3. 03Hvordan 0–100-poengsummen beregnes
  4. 04Technical findings vs legal interpretation
  5. 05Monitoring reliability
  6. 06Hva Certified Private betyr
  7. 07Hva en crawler ikke kan se
  8. 08KI-rapporter

1Scanning architecture

Where scans run. Authenticated and scheduled scans run on the PrivBeacon application host operated by Vassbrekke AS in Norway / EU. Free public scans use the same host but a static HTTP fetch (no headless browser) and a tighter time budget. The Raspberry Pi / on-prem agent is a separate trust boundary: it runs on your network and only talks to PrivBeacon if you set an API key and sync URL.

How browsers are controlled. Cloud scans launch headless Chromium (Playwright). Outbound requests are DNS-resolved, pinned to those addresses, and blocked if they resolve to private, loopback, link-local, or metadata IPs. Heavy resources (images, media, fonts) are skipped. The browser uses a desktop Chrome user-agent, waits for hydration, and scrolls to load lazy content. It does not click Accept/Reject, fill forms, type credentials, or submit personal information.

Pages and interactions. Each scan fetches the URL you add, then discovers privacy, cookie, and legal pages (typically up to 24 additional URLs, fewer on public/fast scans). Optional path exclusions skip prefixes such as /account or /checkout. Authenticated or staging sites that are not on the public internet cannot be reached by the cloud scanner — use the on-prem agent on a network you are authorized to test.

JavaScript. When Chromium launches, JavaScript on the page runs. Trackers injected after load, iframe pixels, and inline snippets (gtag, fbq, _paq) can be observed. If the browser cannot start, the scan falls back to a static HTML fetch and records that limitation. JavaScript-only banners and tags that never appear in HTML or network requests may be missed.

IP addresses. Scans originate from the application host’s provider-assigned public IP in Norway/EU. PrivBeacon does not use a rotating residential proxy pool. The address may change if the host is rebuilt. We do not publish a guaranteed allowlist from this page — email support@privbeacon.com for the current egress IPs if you need to permit our scanner.

Sensitive sites. Do not put real passwords in scan URLs. URLs with embedded credentials are rejected. Do not point the cloud scanner at pages that display other people’s personal data. Use path exclusions for account, checkout, and admin areas. Form fields in stored snippets are stripped; emails and long numbers in snippets are redacted. Never submit real personal information during a scan — the scanner will not fill forms for you.

2Hva skanneren ser på

PrivBeacon henter det offentlige nettstedet du gir tillatelse til og inspiserer sporere, informasjonskapsler, samtykkesignaler og retningslinjetekst som faktisk vises. Et samtykkebanner behandles ikke som bevis på at sporere forblir blokkert.

3Hvordan 0–100-poengsummen beregnes

Poengsetting starter på 100 og trekker fra funn. Tallene samsvarer med produktmotoren.

  • Start på 100.
  • Sporer med høy alvorlighet: −8 hver.
  • Sporer med middels alvorlighet: −4 hver.
  • Sporer med lav alvorlighet: −2 hver.
  • Kritisk samtykkeproblem: −15 hvert.
  • Høyt samtykkeproblem: −10 hvert.
  • Middels samtykkeproblem: −5 hvert.
  • Mislykkede lovsjekker: −0,8 hver, tak på totalt 35.
  • Resultatet klemmes mellom 0 og 100.

4Technical findings vs legal interpretation

Every score point maps to evidence: a tracker request or snippet, a consent issue (banner, pre-consent tags, missing privacy or opt-out link), or a failed keyword check on a policy page. Trackers, cookies, scripts, and network hosts are technical findings. Failed law checks are heuristic presence tests on the text we fetched — they are not a legal conclusion about your contracts, lawful basis, or DPIAs. The score is a PrivBeacon heuristic, not a percentage of legal compliance, and it is not legal advice.

5Monitoring reliability

Schedules. Every paid site that is not on-prem is due for a monthly baseline scan (720 hours). Pro and Enterprise can enable daily or weekly scans per site. Cancelled or unpaid accounts are not scanned. Removed sites are deleted and are not scanned.

Retries. If a scheduled scan fails, the worker retries once after a short delay. Scans left pending after a process restart are re-queued. Scans stuck in “running” for more than 20 minutes are marked failed.

Outages. If the monitor cron or the application is down, due sites are not scanned during the outage. After recovery, sites that are still due are picked up on the next cron run. Missed ticks are not backfilled beyond “is this site due now?”. There is no promised scan SLA.

Alerts. Score drops of more than 5 points and newly detected tracker vendors create in-app alerts. Optional email and HTTPS webhooks are best-effort: one attempt, 10-second timeout, private-IP webhooks blocked. Delivery is not guaranteed and is not an SLA.

Timestamps. Each scan stores created time, completed time (when successful), trigger (manual, scheduled, CI, or agent), and status. Historical complete and failed scans remain in your account until you delete them or the account retention window ends.

Statuses. Not scanned — no scan record yet. Scan queued / scanning — in progress. Scan failed — the fetch did not finish (reason stored). No issue found — a complete scan with no listed trackers, consent issues, or focused law gaps. Issues found — a complete scan that listed at least one finding. “No issue found” is not a legal all-clear.

6Hva Certified Private betyr

Et nettsted kan vise merket etter at en ekte skanning scorer 75+ og sertifisering er aktivert. Poeng 75+ kvalifiserer til PrivBeacons eget Certified Private-merke etter en ekte skanning. Det er ikke en myndighets- eller ISO-sertifisering.

7Hva en crawler ikke kan se

En nettstedskanning kan ikke fastslå behandlingsgrunnlaget ditt, kontrakter, roller som behandlingsansvarlig/databehandler, overføringsmekanismer, lagringsbeslutninger, vurderinger av berettiget interesse eller interne prosesser. Det krever juridisk rådgivning og dine egne registre.

8KI-rapporter

KI-sammendrag på autentiserte skanninger er et skrivehjelpemiddel. Produksjon bruker xAI (Grok) på skannemetadata. Deteksjon og poengsetting er regelbasert. KI er ikke juridisk rådgiver.

Tillit og datahåndtering

PrivBeacon gir automatiske personvernskanninger og dokumentmaler kun for informasjonsformål. Dette er ikke juridisk rådgivning. Rådfør deg med kvalifisert juridisk rådgiver før du stoler på genererte retningslinjer eller overholdelsespoeng for regulatoriske beslutninger.