Regulatory infrastructure

Every visitor
arrives at a gate.

Cookie Gate is consent infrastructure that decides — per visitor, per regulation — what loads, what waits, and what you can prove about it afterwards.

The problem

Most consent banners are theatre.

On a typical site, analytics, ad pixels and session recorders fire before anyone has clicked anything. The banner asks; the trackers don’t wait. Regulators in eleven jurisdictions now expect you to prove that they did.

Enforcement

Cookie Gate holds the line.

The SDK intercepts scripts, iframes and tracking pixels and holds them at the gate. Accept, and they pass. Reject, and they never load — and existing cookies are deleted. Consent-before-cookies, enforced in the browser.

01 Scan

See everything first.

A headless browser walks your site — network requests, iframes, even shadow DOM — and classifies every cookie against a database that learns from every scan on the platform.

02 Adapt

Right law, every visitor.

Geo-resolution runs server-side: Mumbai sees DPDPA, Munich sees GDPR, San Jose sees CCPA with the GPC signal honoured. Where laws overlap, the strictest wins.

03 Prove

Keep the receipts.

Every decision becomes a hash-chained, HMAC-signed receipt with the regulation frozen at that moment — exportable, verifiable, ready for an audit.

On the other side:
clarity.

The platform

A compliance engine,
not a banner widget.

Configure once. Cookie Gate decides per visitor what applies, enforces it in the browser, and keeps the receipts.

Consent-before-cookies

Enforcement, not decoration

The SDK intercepts script tags, iframes, pixels and cookie writes, and holds them until consent releases them. Reject means nothing loads — and existing cookies are deleted. Most banners ask politely; Cookie Gate stands in the doorway.

Compliance engine

One tag, eleven regulations

Geo-resolution runs server-side for every visitor: Mumbai sees DPDPA, Munich sees GDPR, San Francisco sees CCPA. Overlapping laws merge strictest-wins, and sub-regional rules like Quebec Law 25 override federal defaults.

Banner studio

Designed in minutes, correct by default

A visual wizard with three modern skins — floating card, slim bar, glass panel — and regulation-aware presets, so a GDPR opt-in and a CCPA opt-out are both right out of the box.

Scanner

Knows your site better than you do

A headless browser walks your pages — network requests, iframes, even shadow DOM — and classifies every cookie against a global database that gets smarter with every scan across the platform.

Consent ledger

Evidence, not screenshots

Every consent becomes a hash-chained, HMAC-signed receipt with the regulation frozen at decision time. Export the chain as JSON, CSV or PDF; verify any receipt on a public endpoint.

DPR desk

Rights requests with a countdown

Thirteen request types — access, erasure, portability, opt-outs and more — shown per regulation, with statutory deadlines computed automatically: 30 days under GDPR, 45 under CCPA, 15 under LGPD.

Jurisdictions

Eleven regulations.
Resolved per visitor.

Each law is modelled — consent model, banner rules, deadlines, authority — and the right one is applied server-side from the visitor’s location. Where laws overlap, the strictest wins.

Evidence

Built to be audited.

Every decision is written as a receipt: hash-chained to the one before it, HMAC-signed with your tenant key, and stored with the regulation as it stood at that moment. Change nothing, prove everything.

  • Tamper-evident — editing any record invalidates every signature after it
  • Exportable as JSON, CSV or signed PDF for your DPO or a regulator
  • Any receipt can be independently checked on a public verification endpoint

Installation

Live before the kettle boils.

  1. Sign up & add your site

    Create a workspace, register your domain, and let the scanner enumerate every cookie and tracker already running.

  2. Review & publish

    Pick your banner skin, review the classified cookies, and publish. Regulation behaviour is already correct per region.

  3. Paste one tag

    Drop the script into your <head>. Geo-detection, blocking, consent, receipts — all live from the next page load.

Your entire integration

<script
  src="https://cdn.cookiegate.io/sdk/v1/loader.js"
  data-site="YOUR_SITE_KEY"
  async
></script>

Works with plain HTML, WordPress, Shopify, or any SPA. An npm package (@cookie-gate/sdk) ships for React and friends.

11 privacy regulations, modelled in full
86 languages in the translation pipeline
13 DPR request types with statutory deadlines
1 script tag to integrate all of it

Comply Ark

Cookie Gate is built by Comply Ark — a DPIIT-recognised startup in ISB’s iVi Cohort 4, founded by a data-protection lawyer who got tired of consent tools that wouldn’t survive their own audit.


Put a gate on it.

Every plan starts with a 15-day free trial — nothing is charged until it ends. Plans from ₹499/month with enforcement, scheduled scans and audit-ready evidence.

15-day full trial on paid plans · no charge until the trial ends · cancel anytime