Product

The Agentic Web Scanner: It Reads Your Privacy Policy Now

Every version of the Web Scanner has measured something new. It started with the third-party scripts running on your pages. Then the cookies and storage identifiers those scripts set, grouped by the company behind them and tagged with the consent category each one falls under. Then your Content Security Policy, parsed per hostname against the domains actually loading, so you can see which requests your own policy never authorized. Then automated accessibility checks against WCAG on every page it renders, because the team writing your patient-facing pages is usually the team accountable for both.

Each of those is a measurement. A scan tells you what is there, and then a person decides what it means. Someone opens the privacy policy in a second tab, reads fourteen paragraphs, and works out whether the scan's results match the policy.

That comparison is the whole job, and it has always been a person's job, which is why so few companies have someone do it more than once a year.

The Web Scanner makes that comparison itself now. It finds the privacy policy governing each hostname it crawls, reads what the policy actually discloses, and checks that disclosure against the third parties that ran during the scan. What comes back is not an inventory. It is an answer to the question a regulator would ask: not "What is on your site?" but "Does your site do what you said it does?"

The shift is worth naming, because it is where the whole product is going. A scanner that inventories hands you evidence and leaves you to do the reasoning yourself. A scanner that reads your own commitments and checks your behavior against them takes on the reasoning for you; inventory stops being the output and becomes the input. Your privacy policy is the first document we taught it to read. It will not be the last.

Being able to prove that your site does what you said it does is becoming increasingly important, as evidenced by a recent complaint from the Federal Trade Commission (FTC).

Here's what's new:

What the Web Scanner Does With Your Policy

It finds every policy you have, including the ones you forgot. Most healthcare organizations do not run one website. They run a marketing site, a patient portal on subdomain, a scheduling tool on another, and a microsite an agency stood up in 2023. The scanner reports which hostnames are covered by which policy, and which hostnames are covered by nothing at all. The uncovered list is rarely empty, and the hostnames on it are usually the ones nobody remembers owning.

It reads the policy and gives you a verdict. Aligned, gaps found, the policy is too thin to judge, or there is no policy to judge. You run the analysis when you want it rather than on every crawl.

It quotes your own document back to you. Every gap cites the passage from your policy that the network activity contradicts, next to the hostnames the scan actually saw doing it. Not a score. Not "you may have a compliance issue." A sentence you published, and the request that disagrees with it.

Policies, the hostnames each one covers, and the hostnames covered by nothing live on a Privacy tab in the Web Scanner now, alongside resources, cookies, and accessibility. The readable text of each policy is captured and kept, so the document you are being held to sits next to the evidence instead of in somebody's browser tab. For more info, check out the Web Scanner docs and what the scanner detects.

Every Tracker, Attached to the Vendor Behind It

Reading your policy only helps if the other side of the comparison is legible, too. A scan result that reads connect.facebook.net is a hostname. A scan result that reads "Meta, advertising, high risk" is a decision you can make. The scanner resolves the hostnames it finds against a curated vendor database covering hundreds of tracker hostnames, so findings arrive with a company name, a category, and a risk level attached.

A Recommended fix panel on a Facebook Pixel finding, explaining that the pixel shares visitor activity with Meta before consent and that Meta will not sign a BAA, then pointing at the server-side Conversions API destination.

The risk levels answer the question a covered entity actually has to answer, which is not: "How invasive is this script?" High risk covers vendors that will not sign a Business Associate Agreement, and vendors whose main business is advertising. Medium covers vendors that will sign one. Low covers utility infrastructure like content delivery and fonts. That rubric is specific to healthcare, which is why a general-purpose cookie scanner cannot give you the same answer.

Findings carry written guidance on what to change. When we know the specific vendor, you get the fix for that vendor. When we know only the category, you get the fix for the category. Our team writes and reviews that guidance, and coverage widens every week as new hostnames turn up across scans.

You will disagree with a classification sometimes, and you should be able to. A vendor you have a Business Associate Agreement with is not a finding for you, even though it may be one for everyone else. Clearing a finding with a reason keeps your own context in the scan instead of making you mentally filter the same row every week. Recommended fixes.

What a Scan Cannot See

It's important that you understand there are two limits to any scan:

First, a browser-based scan sees browser-side tracking. A connection from your own server to an advertising platform is invisible to any scanner, ours included.

Second, the Web Scanner cannot track every statement you or your affiliates make about your privacy position. We're working on updates to the Web Scanner that would enable it to scan your website for language that contradicts your privacy policy, but no crawler is going to be able to read the caption on, say, an influencer's Instagram post.


Also New

A destination your consent rules cannot stop. Consent enforcement works by matching a category's rules and then checking that the category actually lists the destination. A destination sitting in no category is dispatched unconditionally, whatever a visitor consented to. Global Data Governance now flags exactly those destinations, and the same warning appears before you publish a version, so the gap surfaces while you are making the change rather than during a review six months later. Warehouse and Audience destinations are excluded, since neither dispatches events. (Global Data Governance docs)

Scan on your own cadence. Each monitor has its own schedule now: manual, daily, weekly, or monthly. Cadence advances on calendar days, so a weekly monitor lands on the same day every week instead of drifting an hour later each run. (Scan schedule docs)

Reports you can hand to someone. Both the Web Scanner results and the Progress Report export as formatted PDFs, built in your browser. What you send to a buyer, an auditor, or your own leadership looks like a report rather than a screenshot. (Web Scanner FAQs)

What's Next

Policy discovery reaches the hostnames a crawl can reach, so extending it behind a login, where the patient portal actually lives, is the next piece of scanner work. Tying the analysis to your consent configuration is the piece after that: the scanner already tags each cookie with the consent category it falls under, and the version of this feature we want reads your policy, your categories, and your network traffic as one question rather than three.

The larger direction is the one worth watching. Your privacy policy is one document you have published that your website is supposed to honor. Your consent banner is another. So is the language in your patient intake flow, and the commitment in the security questionnaire you filled out for a health system last quarter. Each of those is a promise, each is checkable against what your site actually does, and a scanner that reads is what makes checking them continuous rather than annual.

A regulator comparing your promises against your network traffic should not be the first party to run that comparison. If you want it run against your own site, book a demo.

Share Article

Book a Demo

Health systems and digital health companies use Ours Privacy to run essential marketing tools like Google Ads and GA4 while maintaining HIPAA compliance.

Related Articles

Newsletter

Stay up to date

Subscribe for privacy news, feature updates, events, etc.

Start the conversation

Healthcare marketers tell us every day about the challenges of flying blind, navigating compliance, and dealing with ad restrictions. Talk with one of our experts to see if Ours Privacy is the right fit for your organization.

Start the conversation

Healthcare marketers tell us every day about the challenges of flying blind, navigating compliance, and dealing with ad restrictions. Talk with one of our experts to see if Ours Privacy is the right fit for your organization.

Start the conversation

Healthcare marketers tell us every day about the challenges of flying blind, navigating compliance, and dealing with ad restrictions. Talk with one of our experts to see if Ours Privacy is the right fit for your organization.