Know what every vendor script on your site actually collects
In short
Most sites accumulate third-party scripts, chat widgets, heatmap tools, and ad pixels, faster than anyone tracks them, leaving no current answer to what data leaves the site and to whom. Webclat runs OneTrust's cookie and tag discovery to build a living, auto-refreshed inventory of every script and vendor touching a domain. New scripts get flagged on arrival, so the inventory stays current instead of being rebuilt from memory before each review.
The situation
“Someone added a chat widget, a heatmap tool, and three ad pixels over the years, and nobody has a current list of what's actually running.”
The pain
You can't answer what data leaves your site and to whom with confidence - and that's exactly the question an auditor, a partner's security review, or a regulator asks first.
What we implement
We run a full site scan and configure OneTrust's cookie and tag discovery to build a living inventory of every script, cookie, and vendor touching your domains - a form of data mapping.
What you get
A current, exportable list of every third-party script on the site, refreshed automatically instead of rebuilt from memory before each review.
Vendor scripts classified by what they actually do, so a guess of "it's probably just analytics" becomes a documented answer.
New scripts added later get flagged instead of quietly joining the page unreviewed.
Illustrative scenario
A team that discovered a legacy retargeting pixel still firing two years after the campaign ended might see that kind of surprise close permanently once new scripts get flagged on arrival. (Illustrative scenario - not a measured result.)
Common questions
Does this cover scripts added through Google Tag Manager, not just the page directly?
Yes. The scan covers both directly embedded scripts and ones fired through tag managers.
What happens when you find something we didn't know was there?
It gets classified and flagged for your team's decision. We don't remove anything without sign-off.
Related use cases
Talk through how this applies to your OneTrust setup.
We scope every engagement in discovery, before implementation - no assumptions about your stack.