SentriRail

Trust & transparency

Methodology

Privacy test protocol executed by SentriRail — automated browser or limited HTML scan depending on configuration.

Automated technical assessment. Not a legal certification.

An automated browser (Playwright, flag privacy_monitor_v2) runs public journeys: cookies, network requests, scripts and consent signals. Without the flag, a limited HTML scan still matches the known tracker catalog.

  1. First Visit
  2. Reject All
  3. Consent State
  4. Tracker Requests

Scan a website

SentriRail Privacy Test Protocol v2.0

Versioned protocol of scenarios actually executed. Methodology changelog below.

  • v2.0 · 2026-09-15

    • Each browser scenario records coverage, observation, redacted evidence, confidence and assessment separately.
    • Serious findings require reproduction in an independent browser context before Action required/high confidence.
    • Generic CMP and static HTML fallbacks stay Review, Unknown or Limited coverage; technical failures are not findings.
    • Deterministic browser environment, adapter telemetry, scenario error categories and shadow rollout are persisted.
  • v1.0 · 2026-09-14

    • Documented scenarios actually executed: First Visit, No Action, Reject All, Custom Consent, Withdrawal, Logged In (vault).
    • Network observation is redacted (no Authorization headers, POST bodies, form contents or identity).
    • CMP adapters: SentriRail, Cookiebot, Didomi, Axeptio, Usercentrics, iubenda, generic.
    • Statuses: Healthy, Review, Action required, Unknown — technical assessment only.

What SentriRail does not do

Browser scenarios

P0: FIRST_VISIT, NO_ACTION, ACCEPT_ALL, REJECT_ALL, WITHDRAW.

Extended: CUSTOM_SELECTION, RETURN_VISITOR, CONSENT_EXPIRED, MULTI_PAGE, MOBILE. LOGGED_IN is skipped unless a vault is configured.

Network observation

Host, path, resource type, tracker classification. Authorization headers, sensitive cookies and POST bodies are redacted. No form contents, keystrokes or identity capture.

Tracker classification

Versioned catalog data/trackers.json: domain, script patterns, category. Confidence varies. An unknown vendor stays a technical alert, not a legal qualification.

CMP adapters: legaldesk, axeptio, cookiebot, didomi, usercentrics, iubenda, onetrust, generic.

Evidence

A significant run can produce a timestamped record, a chained hash and an exportable bundle. Screenshots are opt-in, CMP only, 14-day retention.

What Healthy means

Healthy: no known technical issue on checks with sufficient coverage. Review: an observation needs review or was not reproduced. Action required: a serious finding reproduced in two independent browser contexts. Unknown: technical failure or insufficient data.

Limits

Not every user journey, rare conditional script, geography, or internal network is covered. The public scanner refuses localhost, private IPs and excessive volume. Failed scenarios become Unknown/Limited coverage and do not create or close an incident.

SentriRail is a drafting and monitoring aid. It does not certify a website, replace a lawyer, or claim to detect every tracker. You remain responsible for whether generated documents fit your situation.

SentriRail is a drafting aid. It is not legal advice. You are solely responsible for whether generated documents fit your situation. When in doubt, consult a privacy lawyer.

Methodology | SentriRail