No settings to configure. No consultant required. Just the features that make consent automatic.
The right banner model for the right jurisdiction, resolved at the edge before your page loads. California is its own tier — stricter than other US states. No config. No looking up what CPRA requires at 11pm.
If you're on Vanta, we pull your verified certs right into the consent drawer. If not, we link out. If you have nothing, we gently note it. (That's on you.)
We see every tracker that actually fires — including the ones your dev added last Tuesday via a tag manager that nobody told legal about.
"We'd see which pages confuse people, so we can fix them" instead of "we use analytics cookies to enhance the user experience." Your visitors will actually read it.
When a new pixel appears on your site that isn't covered by your consent config, we flag it and block it — not the other way around.
Every consent event logged with a pseudonymous ID, timestamp, policy version, and jurisdiction. The one-click evidence export your auditor actually wants.
AI does the classification once in the control plane, never in the runtime hot path. The snippet your visitors see is a static, geo-resolved file served from the CDN edge — no model calls between them and your page.
Your cookie policy lives at dissentconsent.com/policy/yoursite, gets rewritten the moment your tracker inventory changes, and never asks you to copy-paste anything into your CMS at midnight.
An unclassifiable new tracker, or a privacy-policy mismatch. That's it. No digests, no milestones, no weekly summaries, no "we've missed you" notes. Silence is the default.
The most common dark pattern in cookie consent is relabeling tracking as essential. The product makes that impossible. Known trackers carry their category; the only thing you can configure is what to do with the genuinely unknown ones.
Most startups copy a privacy policy template and never update it. Every month, Claude reads your live privacy policy, cross-references it against your tracker inventory, and flags anything that doesn't match — a marketing tool not disclosed, a data category you claim not to collect. The gap between what your policy says and what your site does is where regulators look first.
CIPA treats session recording and chat interception as wiretapping — all-party consent required. DC detects Hotjar, FullStory, Intercom, Drift, and similar tools, blocks them for California visitors, and names each one in the consent panel before anything activates. To be honest: this is a technical control, not legal advice. CIPA is broad and a lawyer should review your full exposure. What we can guarantee is that nothing records before the visitor says yes.
Free for Vanta customers.