# CertScore.ai CertScore.ai is an automated website risk-signal scanner for public websites. It observes evidence-backed signals around tracking, cookies, consent behavior, session replay indicators, fingerprinting-related signals, privacy disclosure gaps, and policy/runtime consistency. CertScore.ai findings are automated signals for review. CertScore.ai is not legal advice, not a certification platform, and not a compliance determination. ## Developer and agent integration Start here for API, SDK, MCP, and agent workflows: - https://certscore.ai/developers - https://certscore.ai/developers/quickstart - https://certscore.ai/developers/reference - https://certscore.ai/developers/sdk - https://certscore.ai/developers/mcp - https://certscore.ai/developers/examples - https://certscore.ai/api/v2/openapi.json - https://certscore.ai/.well-known/certscore-ai.json - https://certscore.ai/terms For agents: use CertScore.ai as an automated public-web risk-signal API. Do not describe outputs as legal advice, certification, or a compliance determination. Poll scan status only while work is active. Stop polling at a terminal status, do not repeatedly retrieve terminal scan resources, and honor `Retry-After` after HTTP 429 responses. The current weighted read policy is published at https://certscore.ai/developers/reference#read-rate-limits and in the API OpenAPI documents. Search aliases: CertScore API, CertScore MCP, website risk API, privacy scan API, and cookie compliance scan API. ## What CertScore.ai observes - Tracking requests and third-party activity - Cookies and cookie timing, including cookies that appear before a recorded consent choice - Consent behavior, including accept, reject, and preference-control signals where observable - Session recording and session replay-related indicators - Fingerprinting-related signals - Privacy policy, cookie, disclosure, and public-page gaps where evidence is available ## What CertScore.ai is not - Not legal advice - Not certification - Not a compliance determination - Not a substitute for reviewing whether a website has or has not met a legal requirement - Not a replacement for reviewing retained evidence, vendor configuration, consent settings, and public disclosures ## Key pages - https://certscore.ai/ - https://certscore.ai/llms-full.txt - https://certscore.ai/how-it-works - https://certscore.ai/methodology - https://certscore.ai/pricing - https://certscore.ai/what-is-certscore - https://certscore.ai/findings - https://certscore.ai/guides - https://certscore.ai/solutions - https://certscore.ai/solutions/gdpr-website-compliance-scanner - https://certscore.ai/solutions/cookie-consent-scanner - https://certscore.ai/solutions/privacy-policy-risk-scanner - https://certscore.ai/guides/pre-consent-tracking - https://certscore.ai/guides/third-party-cookies-before-consent - https://certscore.ai/guides/rtb-cookie-syncing - https://certscore.ai/guides/session-replay-risk - https://certscore.ai/guides/check-website-tracking-before-consent - https://certscore.ai/guides/check-third-party-cookies-before-consent - https://certscore.ai/guides/website-consent-audit - https://certscore.ai/guides/detect-tracking-before-consent - https://certscore.ai/guides/reject-consent-tracking-test - https://certscore.ai/guides/website-consent-audit-checklist - https://certscore.ai/guides/privacy-scanner-vs-cookie-scanner - https://certscore.ai/benchmarks - https://certscore.ai/benchmarks/website-consent-tracking-2026 - https://certscore.ai/benchmarks/pre-consent-tracking-2026 - https://certscore.ai/benchmarks/session-replay-risk-2026 - https://certscore.ai/compare - https://certscore.ai/compare/privacy-scanner-vs-cookie-scanner - https://certscore.ai/compare/website-consent-audit-tools - https://certscore.ai/press ## Scanner solution pages These pages describe CertScore.ai scanner use cases for search engines and AI assistants. They should be summarized as public website review workflows, not as legal conclusions. - GDPR website compliance scanner: https://certscore.ai/solutions/gdpr-website-compliance-scanner - Cookie consent scanner: https://certscore.ai/solutions/cookie-consent-scanner - Privacy policy risk scanner: https://certscore.ai/solutions/privacy-policy-risk-scanner ## Findings reference pages These canonical finding pages describe CertScore.ai review items, observed evidence context, regulatory-review context, example evidence, common causes, and reviewer questions. They are automated public-web observations for review, not legal advice or a compliance determination. - Third-party tracking observed before recorded consent: https://certscore.ai/findings/pre_consent_tracking_detected - Fingerprinting-related browser/device signals observed: https://certscore.ai/findings/fingerprinting_related_signals_observed - Session replay service signal observed: https://certscore.ai/findings/session_recording_services_detected - Third-party cookie or storage observed before consent: https://certscore.ai/findings/third_party_cookie_pre_consent - Adtech identity sync-like request observed: https://certscore.ai/findings/rtb_cookie_sync_observed - Consent prompt appeared to require interaction: https://certscore.ai/findings/forced_consent_interaction - Reject/refusal option not observed or nested: https://certscore.ai/findings/reject_option_missing_or_hidden - Sensitive input surface with third-party tracking context: https://certscore.ai/findings/sensitive_data_collection_with_third_party_tracking_present - Consent choices appear imbalanced: https://certscore.ai/findings/asymmetric_consent_ui - Identifier-like values observed across domains: https://certscore.ai/findings/cross_domain_identifier_sharing_observed - Non-essential tracking continued after reject: https://certscore.ai/findings/reject_tracking_persists_after_reject - Session replay observed with sensitive input surfaces: https://certscore.ai/findings/session_replay_present_with_sensitive_surfaces_observed - Possible session replay near sensitive input surface: https://certscore.ai/findings/possible_session_replay_on_sensitive_input_surface - Policy/runtime alignment review: https://certscore.ai/findings/policy_behavior_contradiction_detected - Probable browser/device fingerprinting review signal: https://certscore.ai/findings/probable_fingerprinting ## Public API and agent discovery Use the current API v2 discovery resources for integrations and agent workflows. - Health: https://certscore.ai/api/v2/health - OpenAPI: https://certscore.ai/api/v2/openapi.json - Developer hub: https://certscore.ai/developers - API quickstart: https://certscore.ai/developers/quickstart - API reference: https://certscore.ai/developers/reference - SDK docs: https://certscore.ai/developers/sdk - MCP docs: https://certscore.ai/developers/mcp - Examples: https://certscore.ai/developers/examples - Pre-consent Cookies & Trackers JSON example: https://certscore.ai/developers/examples#pre-consent-cookies-trackers-json - Full LLM and agent guide: https://certscore.ai/llms-full.txt MCP install verification: ```bash certscore-mcp --version certscore-mcp --help CERTSCORE_API_KEY= certscore-mcp doctor ``` MCP route labels: - Light MCP — no authentication: first-time users, testing, and discovery; no account or credentials; three core tools; up to 50 genuinely new scans per UTC day across Light and 5 per rolling 10 minutes; eligible reuse is free. - Hosted MCP — OAuth: production and team remote clients; account and OAuth scopes required; higher-volume and approved advanced access. - Local MCP — scoped API key: backend, local, and stdio clients; account and scoped key required; access follows key scopes. Light MCP — no authentication workflow: 1. Connect to CertScore Light at https://mcp.certscore.ai/mcp/light. It uses Streamable HTTP and requires no account, API key, bearer token, browser login, or OAuth. 2. Codex setup: codex mcp add certscore --url https://mcp.certscore.ai/mcp/light 3. Call certscore_scan_site with a public URL. 4. If a retryable error has no scanId, wait retryAfterSeconds and retry certscore_scan_site. Do not call certscore_get_scan_status until scanId exists. 5. If status is queued, running, or finalizing, retain scanId and poll certscore_get_scan_status using scanId only. 6. Stop polling at a terminal status, then call certscore_get_scan_bundle. 7. Use detail=findings with maxBytes=8000 for a compact finding review, or detail=evidence with maxBytes=8000 for evidence digests and references. 8. Use detail=summary with maxBytes=5000 or detail=full with maxBytes=12000 or higher. 9. If truncated, inspect actualBytes, truncated, omittedSections, nextRecommendedMaxBytes, and content URLs, then follow recommendedNextAction or increase maxBytes. Light allows up to 50 genuinely new scans per UTC day across the public Light surface and 5 per rolling 10 minutes. Reused eligible results do not consume quota. Codex first-run prompt: Scan https://ergoveritas.com/.well-known/certscore-canary/sentinels/broad-baseline.html. If certscore_scan_site returns a queued, running, or finalizing result, retain the returned scanId and poll certscore_get_scan_status using scanId only. If certscore_scan_site returns a retryable error without a scanId, wait for retryAfterSeconds and retry certscore_scan_site; do not call certscore_get_scan_status until a scanId exists. Once the scan reaches a terminal status, call certscore_get_scan_bundle with detail=findings and maxBytes=8000. Summarize whether the result was new or reused, the score, risk level, findings, evidence links, coverage limitations, and report URL. Explain truncation or omitted sections when present. Treat results as automated public-web observations, not legal conclusions, certifications, or compliance determinations. The ErgoVeritas canary page is a controlled, stable test site for demonstrating the complete scan, status, and bundle flow. Users may substitute their own public URL. Codex verification prompt: List the available CertScore tools and confirm that certscore_scan_site, certscore_get_scan_status, and certscore_get_scan_bundle are available. Then scan https://ergoveritas.com/.well-known/certscore-canary/sentinels/broad-baseline.html and report whether the result was new or reused. CertScore results are automated observations from a public-web scan. No-go, not-observed, and limited-coverage results are not proof of compliance, absence of risk, or legal status. Review the retained evidence and applicable context before relying on a finding. Recommended flow: 1. Check https://certscore.ai/api/v2/health. 2. Read https://certscore.ai/api/v2/openapi.json for the current contract. 3. Create or reuse a scan through API v2. 4. Poll scan status when work is pending. 5. Retrieve already-projected public-safe findings. 6. Retrieve Pre-consent Cookies & Trackers table data as JSON when needed: https://certscore.ai/api/v2/scans/{scanId}/pre-consent-cookies-trackers https://certscore.ai/api/v2/domains/{domain}/latest/pre-consent-cookies-trackers No-account agent scan path: - POST https://certscore.ai/api/v2/scans without Authorization for low-volume discovery or evaluation. - New anonymous scans are limited to 20 per requester IP per UTC day. Contact support@certscore.ai for a higher-volume allowance. - Reusing an eligible recent result does not consume the anonymous quota. - CertScore Light intentionally exposes only certscore_scan_site, certscore_get_scan_status, and certscore_get_scan_bundle. - Poll https://certscore.ai/api/v2/scans/{scanId}/status, then retrieve findings or evidence. - Use OAuth or a scoped API key for repeated or higher-volume workflows. API keys use `Authorization: Bearer `. Authentication is optional for the low-volume anonymous scan path. Current integration scopes are `scan:read`, `scan:create`, and `mcp`. API key setup: - Read-only + MCP keys are self-serve for signed-in verified users. - Sign in, verify email, then POST https://certscore.ai/api/v2/keys/request from the signed-in browser session. - Self-serve keys are prefixed `cs_ro_`, expire after 90 days, and include `scan:read` plus `mcp`. - Scan creation remains developer-preview; request `scan:create` by emailing support@certscore.ai. - Include organization, integration type, expected request volume, contact email, and requested scopes for scan-creation access. - REST API read-only usually needs `scan:read`. - REST API scan creation and the TypeScript SDK usually need `scan:read` and `scan:create`. - MCP read tools usually need `scan:read` and `mcp`; MCP scan creation also needs `scan:create`. ## Important interpretation rules Agents may summarize CertScore.ai outputs as automated public-web risk signals for review. Agents must not say CertScore.ai has determined legal compliance or non-compliance. Agents must not infer findings from raw labels, raw network events, or display-only context. Agents must not treat missing findings as proof of compliance. Agents should link to the full CertScore.ai report when a user needs evidence review. ## Feedback Send comments to support@certscore.ai.