Features

Every layer of compliance, uncovered.

From surface-level cookie detection to deep data flow mapping — Gretelfy gives you the full picture.

L1Discovery Scan

See everything. Miss nothing.

Gretelfy loads your page in a clean, headless browser with zero prior state. We capture every cookie dropped, every script executed, every network request fired — all before a single pixel of your consent banner is interacted with.

Full Cookie Inventory

Every first-party and third-party cookie, with name, domain, path, expiry, secure flag, and SameSite attribute.

Script Origin Mapping

Identify every JavaScript source loaded on the page, grouped by domain and classified by purpose.

Network Request Log

Complete log of all HTTP requests including trackers, pixels, beacons, and API calls — with timing data.

Technology Fingerprinting

Detect which analytics, ad-tech, and CMP platforms are active on your site.

L4Continuous Monitoring

Compliance drifts. We catch it.

A single scan is a snapshot. Websites change daily — new tags, plugin updates, third-party script changes. Gretelfy runs automated scans on your schedule and alerts you the moment compliance degrades.

Scheduled Scans

Set daily, weekly, or monthly automated scans per domain. No manual effort required.

Regression Detection

Automatic comparison against previous scans. New violations are flagged immediately.

Email & Slack Alerts

Get notified within hours when your Gretel Score drops or new violations appear.

Compliance Trending

Track your score over time. Demonstrate continuous improvement to auditors and regulators.

L5Data Flow Intelligence

Where does the data actually go?

Beyond cookies and scripts, Layer 5 maps the full data flow: which third parties receive personal data, where servers are located, and whether cross-border transfers comply with Schrems II requirements.

Cross-Border Transfer Mapping

Identify which third-party servers receive data and their geographic locations. Flag non-EU transfers without adequacy decisions.

PII Leak Detection

Detect when email addresses, phone numbers, or other personal data is passed to third-party scripts via URL parameters or request payloads.

Vendor Dependency Chains

Trace script loading chains to reveal hidden fourth-party dependencies your privacy policy may not cover.

Schrems II Compliance

Automatically flag data transfers to countries without EU adequacy decisions. Identify high-risk vendors requiring additional safeguards.

——Report Preview

Your Gretel Score at a glance.

Compliance Report
example-store.com
Scanned Feb 14, 2026 · 14:32 UTC · EU-West
62/100

Gretel Score

Needs Improvement

4 Violations Found
3 marketing cookies set before consenthigh
Google Analytics active without consent signalmedium
Reject button has lower visual prominencemedium
Cookie policy link not accessible from bannerlow
18 Cookies Found
Necessary
6
Analytics
4
Marketing
5
Functional
2
Unknown
1
Consent Banner
OneTrust detected
1 banner compliance issue
Top Recommendation

Block marketing cookies before consent

Add Facebook Pixel and Google Ads scripts to your CMP blocking configuration and assign them to the Marketing category.

Every plan includes independent compliance scanning

All plans include Layers 1-3. Professional and above unlock continuous monitoring and data flow intelligence.

LayersMonitor€49/moProfessional€149/moAgency€349/mo
Layer 1: Discovery Scan
Layer 2: Banner UX Audit
Layer 3: Consent Validation
Layer 4: Continuous Monitoring
Layer 5: Data Flow Intelligence

Start with a free scan

See what Layer 1 reveals about your website in under a minute. No signup required.

https://