The short answer
Four of the five sell a consent banner, and the scan exists to feed it. Cookiebot, CookieYes and Termly each turn their scan into a document you publish: a cookie declaration, a cookie policy, or the privacy policy itself. Osano monitors the domain and reports compliance issues against its own rules. All four need an account, a domain you administer, and their script on it. Blacklight is the one that answers about a site you do not own, free and with no signup, and it reports what loads without any reference to what the site says about itself. None of the five opens the privacy policy a site already publishes and reports what loaded against what that document names. If you need a banner on your own site, buy one of the four, because PolicyDrift does not serve one and never will. If you want to see what any site loads, Blacklight is free and tests for things this does not. If what you have is a privacy policy written eighteen months ago and a site that has picked up tags since, that gap is what a check here reports, in both directions, on a URL you can paste in right now.
Side by side
Each cell is the short answer and the host it was read off. The same cell in that product’s own words is in its section below, and every source is listed at the foot of this page with the day it was read.
| Tool | Reads the policy you already published | What it reads | What you go through for a first answer | What it costs | What it is for |
|---|---|---|---|---|---|
| Yes, and in both directions/ | The page in a real browser, then the policy it links to/trackers | A URL in a box. No account, and nothing installed/ | The check is free. $19 or $39, each one payment/pricing | One page, read from outside. No banner and no blocking/guides/what-loads-before-consent | |
| Cookiebot by Usercentrics | It publishes its own cookie declaration insteadcookiebot.com | Your subpages, up to the number your plan coverscookiebot.com | An account, a domain you own, and its script on itcookiebot.com | Free for one small domain, then $8 to $96 a monthcookiebot.com | A consent management platform for a site you owncookiebot.com |
| Osano | It monitors your domain for compliance issuesosano.com | Not stated on the page readosano.com | An account, and a domain you ownosano.com | Free for one domain, $199 a month for threeosano.com | A privacy platform. Consent is one product of severalosano.com |
| CookieYes | It generates a cookie policy from its own scancookieyes.com | Your pages, capped per scan by the plancookieyes.com | An account, a domain you own, and its script on itcookieyes.com | Free, then $10, $25 or $55 a month per domaincookieyes.com | A consent management platform for a site you owncookieyes.com |
| Termly | It writes the policy, then updates it from its own scantermly.io | Your site, on a schedule the plan setstermly.io | An account, and a website you owntermly.io | Free tier, then $10 or $15 a website a month on annual billingtermly.io | Legal document generation with consent management attachedtermly.io |
| Blacklight, by The Markup | No, and the page does not claim tothemarkup.org | The page, in a real browser, from a location you pickthemarkup.org | A URL in a box. No account, and nothing installedthemarkup.org | No price on the page, and nothing is sold on itthemarkup.org | A public inspector, one page at a timethemarkup.org |
Reads the policy you already published. the question this page is about. A scanner lists what a site loads. A generator writes a new cookie or privacy document out of its own scan. Neither of those opens the privacy policy the site already publishes and reports what loaded against what that document names, and that gap is the one thing every column here is measured on first.
What you go through for a first answer. whether the tool needs an account, and whether its script has to be on the site before it can say anything, which is what decides if you can check a site you do not own or a site you have not bought anything for yet.
Cookiebot by Usercentrics
Pick it instead of this when. You need a consent banner running on a site you own, and you want the one with the largest installed base behind it. Cookiebot scans your subpages, categorises what it finds against what its pricing page calls a "Repository of 13,000+ pre-categorized and described trackers", blocks what has not been consented to, and publishes a cookie declaration you embed. Its free plan covers one domain of up to 50 subpages, and the first priced tier is $8 a month for a domain of that same size.
Reads the policy you already published: It publishes its own cookie declaration instead. The premium feature list carries "Cookie declaration" and "Automatic cookies and tracking categorization", which together produce a document generated from its own scan and embedded on your site. The page does not state that it reads a privacy policy you already published, so the comparison of two documents is not something it offers.
What it reads: Your subpages, up to the number your plan covers. A plan is chosen by subpage count and the page defines the unit: "A subpage is any unique URL on your domain. The total number of subpages determines your plan eligibility." The free plan covers up to 50 subpages on one domain, and the largest priced tier covers 7,000 per domain.
What you go through for a first answer: An account, a domain you own, and its script on it. The page asks for both: "Create an account today and add your first domain. We will scan it to determine which plan you qualify for." The banner is code you add to your own site, so nothing in this product answers a question about somebody else's site.
What it costs: Free for one small domain, then $8 to $96 a month. Five priced tiers read $8, $16, $34, $56 and $96 per month per domain, sized by subpage count, and the free plan covers 50 subpages on one domain. The trial line on the same page: "Try everything free for 14 days first. No credit card needed."
What it is for: A consent management platform for a site you own. Banner templates in 47 or more languages, geotargeting, consent records, script blocking, Google Consent Mode and the IAB TCF 2.3 framework. The scan exists to feed the banner and the declaration, and the banner is the product.
Osano
Pick it instead of this when. You want consent management and the rest of a privacy programme on one account: subject rights requests, vendor risk, data mapping and assessments sit beside it. Its cookie consent plans open with a free tier for one domain and 5,000 monthly visitors, and it is the only paid entry here that also publishes a free scan of a URL, which it describes as a check for "GPC signal recognition, dark patterns, and other issues regulators are actively enforcing".
Reads the policy you already published: It monitors your domain for compliance issues. The plan page describes Compliance Check as "Automatically monitor your website's privacy compliance with regular domain scanning". That is a judgement about the site, not a reading of the privacy policy the site publishes, and the page does not state that any policy text is read.
What it reads: Not stated on the page read. The plan page names Compliance Check and says it scans the domain on a schedule. It does not say how many pages a scan covers, how often the schedule runs, or what the scan records. The page read did not carry it, which is not a claim that no such figure exists.
What you go through for a first answer: An account, and a domain you own. The free tier is sized as "1 Users / 1 Domains" and "5,000 Monthly Visitors", so the unit the product is built around is a domain you administer rather than a URL you are curious about.
What it costs: Free for one domain, $199 a month for three. The plan page reads "$0/mo" for Solo & Freelancers and "$199/mo" for Plus, which covers 2 users, 3 domains and 30,000 monthly visitors. Everything above Plus is priced as Custom and routes to a demo.
What it is for: A privacy platform. Consent is one product of several. The same account carries Subject Rights Management, Vendor Privacy Risk Management, Data Mapping, Assessments and a Unified Consent and Preference Hub. Cookie consent is the entry point rather than the whole product, and the priced jump from free to $199 reflects that.
CookieYes
Pick it instead of this when. You want a banner and a cookie policy on a site you own for as little as possible. The free plan is $0 a month for one domain with 100 pages a scan and 5,000 pageviews a month, and the first priced tier is $10. It also auto-blocks scripts until consent is given, which is the part PolicyDrift only reports on.
Reads the policy you already published: It generates a cookie policy from its own scan. Its free tools list carries a "Cookie Policy Generator" and a "Privacy Policy Generator", so the document is an output of the scan rather than an input to it. The pricing page does not state that an existing privacy policy is read.
What it reads: Your pages, capped per scan by the plan. The plan table meters the scan itself: "100 pages per scan" on the free plan, then 600, 4000 and 8000 on the three priced ones. Scheduled scanning starts on the third tier, monthly, and the top tier scans weekly.
What you go through for a first answer: An account, a domain you own, and its script on it. The page opens with "14-day free trial. $0 till your trial ends. Cancel anytime." The plans are priced per domain and the banner is a script on that domain, so a first answer follows a signup and an install.
What it costs: Free, then $10, $25 or $55 a month per domain. Every tier is priced "/month /domain", and the free one also caps traffic at 5,000 pageviews a month with 5 scans a month. The two middle tiers charge "+ $0.30 per 1,000 extra pageviews" above their included traffic.
What it is for: A consent management platform for a site you own. Its own line is "Cookie consent management platform built for all websites". Cookie auto-blocking is on every tier including the free one, and the higher tiers add geo-targeting, sub-domain consent sharing, scanning behind a login and static IP scanning.
Termly
Pick it instead of this when. You need the policy written rather than audited. Termly generates the legal documents and runs the banner on the same plan, so a site with no privacy policy at all ends up with one. Its free tier carries one policy, a banner, script auto blocking and quarterly cookie scans, and Starter is $10 a website a month billed annually.
Reads the policy you already published: It writes the policy, then updates it from its own scan. The feature table lists "Website Scan: Scan your site to discover and automatically categorize your website's cookies and tracking mechanisms" beside "Auto-updated policies". The policy is its own output, so the two documents it would take to disagree are one document here.
What it reads: Your site, on a schedule the plan sets. Scheduled scans are quarterly on the free plan, monthly on Starter and weekly on Pro+. Subdomains are a paid boundary: "Subdomain scanning is included in the Pro+ plan."
What you go through for a first answer: An account, and a website you own. Plans are licensed "Per website/month" and the free tier is entered through "Continue Free", so a first answer follows a signup. The banner and the hosted policies are code on your own site.
What it costs: Free tier, then $10 or $15 a website a month on annual billing. Starter reads $10 billed annually and $14 billed monthly. Pro+ reads $15 billed annually and $20 billed monthly. Both are per website. The free tier carries 1 basic legal policy and 10,000 banner views a month.
What it is for: Legal document generation with consent management attached. Privacy policy, terms, cookie policy, disclaimer and the rest come out of its generators, and the same account serves the banner, the preference centre and a "Cookie script auto blocker". It sells the document and the control over it, not an audit of either.
Blacklight, by The Markup
Pick it instead of this when. You want to see what a site loads, free, right now, on a site you do not own, published by a newsroom with nothing to sell you. Blacklight runs seven named tests including keystroke capture and tracking that evades cookie blockers, neither of which PolicyDrift tests for, and it can run the page from Ohio, California or Europe, as mobile or desktop. The Markup also publishes Blacklight Query, a command line version, as open source.
Reads the policy you already published: No, and the page does not claim to. The page lists exactly what it tests: ad trackers, third-party cookies, "Tracking that evades cookie blockers", session-monitoring scripts, keystroke capturing, and data sent to Facebook, TikTok, Twitter/X and Google Analytics. A privacy policy is not among them.
What it reads: The page, in a real browser, from a location you pick. The options on the form are Location, set to Ohio, California or Europe, Device, set to mobile or desktop, and Inspection Caching, set to cached results or a forced request. The page states the run takes "between 30 seconds and one minute".
What you go through for a first answer: A URL in a box. No account, and nothing installed. The form reads "Enter a URL for Blacklight to scan" and the page says "Enter the address of any website, and Blacklight will scan it". It is the other entry here that answers about a site you do not control.
What it costs: No price on the page, and nothing is sold on it. There is no plan, no account and no figure anywhere on the page. It is published by The Markup, whose own control beside the tool reads "Your contributions help us investigate how technology influences our society."
What it is for: A public inspector, one page at a time. It reports what a site loads and who receives the data. It writes no document, serves no banner, blocks nothing, and has no notion of your policy. The Markup published a command line version in 2024: "Launching Blacklight Query, a Tool to Scan Websites for Privacy at Scale".
Questions
Which cookie scanner checks a privacy policy against what a site actually loads?
PolicyDrift does, and on the five pages read on 2026-09-19 none of the other five states that it does. Cookiebot publishes a cookie declaration generated from its own scan. CookieYes and Termly generate the policy documents themselves, so the scan writes the document rather than being checked against one. Osano's plan page describes Compliance Check as monitoring the website with regular domain scanning and does not mention policy text. Blacklight reports what a page loads and makes no reference to any policy at all. Reporting the loaded third parties against the published policy, in both directions, is the one axis where this product is alone on the grid.
Is there a free way to check a website I do not own?
Two of the six. Blacklight takes a URL with no account and runs seven tests on it, including ones this product does not run, such as keystroke capture and tracking that evades cookie blockers. PolicyDrift takes a URL with no account and reports every third party against the policy that page links to. The other four are all priced per domain and need their script on the site, so they can only answer about a site you administer. Osano also publishes a free compliance scan of a URL beside its paid plans.
What is the cheapest cookie consent banner?
CookieYes and Osano both publish a free tier, and the two free tiers are metered differently. CookieYes is $0 a month for one domain with 100 pages a scan, 5 scans a month and 5,000 pageviews a month, then $10, $25 and $55 a month per domain. Osano is $0 a month for 1 user, 1 domain and 5,000 monthly visitors, and the next tier is $199 a month. Cookiebot's free plan covers one domain of up to 50 subpages and its priced tiers run $8 to $96 a month per domain. Termly's free tier carries one policy and 10,000 banner views a month, with Starter at $10 a website a month billed annually. Every figure was read off those pricing pages on 2026-09-19.
Does PolicyDrift block trackers or show a consent banner?
No to both, and neither is planned. It puts no code on the site it checks, so it cannot block a script or serve a banner, and it stores no consent records. Cookiebot, CookieYes, Termly and Osano all do that part, and a site that needs a banner needs one of them. What this reports is the state a visitor who never touches the banner actually gets, which is a network fact rather than a fact about the banner.
What does PolicyDrift not do?
It does not generate your privacy policy: Termly and CookieYes do that and this does not. It does not block scripts or serve a banner. It reads the one URL you give it rather than crawling every subpage, so it is not a site-wide audit the way a per-plan page allowance is. It does not rule on whether a configuration satisfies a specific law, and it does not click accept or reject to see what changes afterwards. The paid part is one written artefact, the corrected third-parties section for your policy, at $19, or $39 with a monthly re-check for six months.
What was read, and when
| Product | Page read | What it supplied | Read on |
|---|---|---|---|
| PolicyDrift | policydrift.thecompound.tech/ | Reads the policy you already published, What you go through for a first answer | 2026-09-19 |
| PolicyDrift | policydrift.thecompound.tech/trackers | What it reads | 2026-09-19 |
| PolicyDrift | policydrift.thecompound.tech/pricing | What it costs | 2026-09-19 |
| PolicyDrift | policydrift.thecompound.tech/guides/what-loads-before-consent | What it is for | 2026-09-19 |
| Cookiebot by Usercentrics | www.cookiebot.com/en/pricing/ | Reads the policy you already published, What it reads, What you go through for a first answer, What it costs, What it is for | 2026-09-19 |
| Osano | www.osano.com/plans/cookie-consent | Reads the policy you already published, What it reads, What you go through for a first answer, What it costs, What it is for | 2026-09-19 |
| CookieYes | www.cookieyes.com/pricing/ | Reads the policy you already published, What it reads, What you go through for a first answer, What it costs, What it is for | 2026-09-19 |
| Termly | termly.io/pricing/ | Reads the policy you already published, What it reads, What you go through for a first answer, What it costs, What it is for | 2026-09-19 |
| Blacklight, by The Markup | themarkup.org/blacklight | Reads the policy you already published, What it reads, What you go through for a first answer, What it costs, What it is for | 2026-09-19 |
Prices and limits move, so each source is printed with the day it was read rather than one date at the foot of the page. scripts/verify-alternatives.mjs re-fetches every one of these URLs and fails when the literal string a figure came from is no longer on it. It last ran on 2026-09-19 and all 30 checks passed.
Check a site from the console, read what loads before consent, or see the 54 vendors the registry recognises. The check and the drift report are free and need no account.