Four steps, no agent installed on your infrastructure
Over 80% of sites scanned on Juro had at least one pre-consent tracker. Each finding cites the exact provision with no vague recommendations. 85% of websites globally collect data before any user interaction (PreConsent.io, 10,000+ sites, 2026).
Built for the people who get asked "are we compliant?"
The difference shows up in evidence quality, not feature lists
OneTrust tells you a cookie exists. Juro tells you it fired 2.3 seconds before consent, violating GDPR Art. 6(1)(a). Deep scans produce a signed artifact your DPO can hand to a regulator.
Don't take our word for it. Verify any Juro artifact yourself with the open-source verifier.
| Juro | Legacy compliance suites | Free cookie scanners | |
|---|---|---|---|
| Architecture | Non-custodial, agent-based | Your data uploaded to their cloud | Surface cookies only |
| Frameworks | DPDP + GDPR + DORA | One framework at a time | GDPR only |
| Evidence | Signed, deterministic artifacts | Screenshot-based reports | No evidence output |
| Surface scan | $0, no account required | Sales demo required | Free, email-gated |
| India / DPDP | Purpose-built from day one | GDPR module adapted for DPDP | Not covered |
The exposure is real, and it applies whether or not you've been scanned yet
DPDP, GDPR, and DORA don't wait for a complaint to be credible — the obligations apply from the moment personal data is processed or a financial entity's ICT systems go live. A signed scan just makes the gap visible before a regulator, auditor, or plaintiff does.
Across sites scanned on Juro, the most common gap isn't an exotic misconfiguration — it's an analytics or advertising script that fires before the user has clicked anything on the consent banner. That single pattern touches DPDP Sec. 5, GDPR Art. 6(1)(a), and GDPR Art. 7 at once.
| Regulation | Applies to | Maximum exposure |
|---|---|---|
| DPDP Act 2023 | Any entity processing personal data of people in India | ₹250 crore per instance |
| GDPR | Any entity processing personal data of people in the EU | €20M or 4% of global turnover |
| DORA | Critical ICT third-party providers (Lead Overseer oversight, Art. 35(6)); EU financial entities separately, under each member state's supervisory penalty regime | Up to 1% of average daily worldwide turnover (ICT third parties) · varies by member state (financial entities) |
Evidence you can check yourself, not a badge you take on faith
A scan result is only useful if someone other than us can confirm it hasn't been altered. Every signed artifact is built to be checked independently, not just displayed.
- Ed25519 signatureEach artifact is signed so any single-byte change to a finding invalidates the signature.
- Pinned rule-pack versionEvery finding cites the exact rule-pack version it was evaluated against, so results stay reproducible.
- Independent verificationRun the open-source verifier yourself. No account and no callback to our servers required.
Pay for evidence, not for a dashboard seat
- One signed, verifiable scan artifact
- DPDP + GDPR + DORA coverage
- Full findings with regulatory citations
- Independently verifiable, no account needed
- Everything in Single scan, scheduled
- Re-scanned on a recurring cadence
- Signed artifact history over time
- Rule-pack version pinned per scan
- Tier 3 in-VPC deployment
- Custom rule-pack scope
- Signed evidence for auditors & the Data Protection Board
- Direct engineering support
Working with a DPO consultancy or CA firm?
Juro's signed evidence is built to sit inside an advisory engagement, not replace it. See how DPO consultancies, CA firms, and CISOs use Juro reports with their own clients.
See the partner program →Things people ask before trusting a scan tool
How do I know the scan is accurate?
The scanner doesn't guess. It intercepts actual network requests as a real browser loads your page. If a script fires before the consent interaction, the scanner records the URL, the timestamp, and the exact millisecond offset. That's a deterministic fact, not a heuristic. Deep scans bundle every finding into a signed artifact: the same inputs always produce the same SHA-256 hash, so any auditor can independently verify that the output hasn't been altered after the fact. The public-surface scan produces the same deterministic findings as an unsigned posture score.
What is DPDP compliance and when does it start?
DPDP (Digital Personal Data Protection Act 2023) is India's data protection law. The DPDP Rules 2025 were notified on November 13, 2025, and enforcement is phased. Full compliance obligations become enforceable on May 13, 2027. It requires websites to obtain explicit user consent before collecting personal data, provide clear privacy notices in plain language, and implement data security measures. Fines reach ₹250 crore per violation. Under Section 8(1), the data fiduciary remains responsible for compliance, including for processing carried out by a data processor on its behalf, irrespective of any agreement to the contrary.
How does the compliance scanner work?
A headless Chromium browser loads your URL, intercepts every network request, and records which scripts fire before the consent interaction. Rules then match the observed behaviour against DPDP sections, GDPR articles, and DORA provisions. The result is a deterministic artifact, signed for deep scans: not a screenshot, not a checklist. It maps each finding to the specific provision it relates to and includes remediation steps.
Does the website compliance scanner cost anything to run?
No. The surface scanner is $0 to run and requires no account. It checks website-layer compliance including consent flows, tracker timing, and privacy notice presence. For deeper infrastructure assessments (backend APIs, PII in logs, unencrypted data columns), contact us for a technical readiness assessment.
What is the difference between GDPR, DORA, and DPDP?
GDPR (General Data Protection Regulation) is the EU's data protection law covering all organisations processing EU residents' data. DORA (Digital Operational Resilience Act) is the EU's financial sector cybersecurity regulation that took effect January 17, 2025, covering ICT risk management, incident reporting, and third-party oversight. DPDP (Digital Personal Data Protection Act) is India's data protection law covering processing of digital personal data of Indian residents. The scanner checks for all three simultaneously.
What does the scanner detect on my website?
The scanner detects analytics and advertising scripts that fire before user consent, consent banners without an equivalent "Reject All" button, missing or incomplete privacy notices, forms that collect personal data without a lawful basis, and third-party trackers that transmit data without consent. Each finding cites the exact regulatory provision it maps to.
How is Juro different from OneTrust, Vanta, or cookie scanners?
Juro is non-custodial: your data never leaves your perimeter. Legacy compliance suites like OneTrust and Vanta require you to upload data to their cloud. Free cookie scanners only check surface cookies and do not map findings to regulatory provisions. Juro's VPC-agent scans produce signed, deterministic artifacts that can be independently verified; the public-surface scan is an unsigned starting point. Juro covers DPDP, GDPR, and DORA in a single scan.
Does Juro store or process my website data?
The scanner runs server-side against your public URL. Your page content, cookies, and user data are never written to disk. Only the analysis output is retained, for 90 days, to power the scan cache. For infrastructure assessments, the agent runs inside your VPC with a read-only IAM role and produces signed findings locally. Nothing is uploaded to our cloud.