Skip to content

Compliance status

Honest capability status for COKIQ.

This page separates shipped product evidence from beta work, roadmap work, legal-review items, and certification claims COKIQ deliberately does not make.

Capability matrix

What COKIQ can provide, what needs review, and what is not claimed.

This matrix is designed for buyers comparing COKIQ with larger CMP platforms. It keeps the promise clean: COKIQ can prove operational consent behavior and evidence, while external certifications and legal opinions require separate approval or counsel review.

Evidence and reporting

Website cookie and script scan baseline

Available now

Evidence: Scanner output, risk score, health score, detected cookies, scripts, policies, and scan date.

Why: COKIQ can verify product-side scan data for connected domains.

Scanner-synced policy inventory

Available now

Evidence: Cookie policy inventory records, policy version, sync timestamp, and review-needed items.

Why: Inventory is generated from scanner findings and preserved for review.

Consent receipts and logs

Available now

Evidence: Timestamp, country/profile, category choices, banner version, policy version, and consent state.

Why: COKIQ records visitor choices and keeps operational evidence.

Evidence Reports dashboard

Available now

Evidence: Admin report view and authenticated exports combining scan, policy, consent, GPC, and blocker evidence.

Why: Phase 4 and Phase 6 are live and documented.

White-label agency reports

Beta

Evidence: Agency reporting path exists, but branding/export polish should be validated per agency rollout.

Why: Safe to discuss as beta, not as a fully mature white-label reporting suite.

Consent control

Consent banner with accept/reject/custom choices

Available now

Evidence: Runtime banner, category choices, storage, and consent updates.

Why: Core COKIQ banner workflow is live.

Google Consent Mode v2 signals

Available now

Evidence: Early denied defaults and updates for ad_storage, analytics_storage, ad_user_data, ad_personalization, functionality_storage, personalization_storage, and security_storage.

Why: Live COKIQ site and embeddable script carry the v2 signal mapping.

Known tracker and iframe blocking

Available now

Evidence: Blocked script/embed runtime events and blocker summary evidence.

Why: Major known trackers and embeds are blocked/released based on consent state.

Expanded long-tail vendor recipes

Roadmap

Evidence: More vendor-specific blocking/classification rules need ongoing research and QA.

Why: Long-tail tags change constantly; promising full coverage without testing would be unsafe.

Regulations and regions

GDPR, UK GDPR, India DPDP, US state privacy, and regional receipt profiles

Available now

Evidence: Geo/regulation profiles, regulations page, GPC/opt-out handling, and evidence receipts across EU/UK, US, India, Brazil, Canada, South Africa, Singapore, Gulf, China, Hong Kong, Malaysia, Indonesia, Philippines, Australia, New Zealand, Switzerland, Japan, South Korea, Thailand, Turkey, LATAM, APAC, and global default.

Why: COKIQ supports operational profiles and reporting for major regions while legal wording remains review-bound.

Brazil LGPD, Canada PIPEDA, POPIA, Singapore PDPA, Gulf, APAC, Japan/Korea/Thailand/Australia/Quebec/Switzerland review maps

Available with legal review

Evidence: Public regulation map and operational review workflow.

Why: COKIQ can support the operational workflow, but final legal wording and applicability need local review.

Fully localized legal notice library for every jurisdiction

Roadmap

Evidence: Requires counsel-reviewed templates and translation/localization QA.

Why: Legal notices cannot be generated blindly for every country and sector.

Certifications and external programs

Google CMP certification

Not claimed

Evidence: No certification approval is currently documented.

Why: Requires Google program approval; COKIQ can be Consent Mode compatible without claiming certification.

IAB TCF production support/certification

Not claimed

Evidence: IAB TCF is roadmap, not live production support.

Why: Publisher/ad-tech TCF strings require separate implementation, policy, and validation work.

SOC 2 or ISO 27001 certification

Not claimed

Evidence: No audit report or certificate is currently published.

Why: These require formal third-party audit/certification work before public claims are allowed.

Attorney-issued compliance certificate

Not claimed

Evidence: COKIQ is a product evidence platform, not a law firm.

Why: Only qualified counsel can issue legal opinions or compliance certificates.

WordPress, Shopify, Wix marketplace certification

Roadmap

Evidence: Universal script and setup guidance exist; marketplace approvals are separate.

Why: Marketplace approval depends on each platform review process.

Available now

Cookie Scanner
Consent Banner
Consent Logging
Google Consent Mode v2 Compatible
Geo / Regulation Profiles for EU, UK, US, India, Gulf, APAC, LATAM, Brazil, Canada, South Africa, Singapore, China, Hong Kong, Malaysia, Indonesia, Philippines, Australia, New Zealand, Switzerland, Japan, South Korea, Thailand, Turkey, and Global Default
Global Privacy Control Detection
US Do Not Sell or Share Runtime Action
Consent Expiry and Re-Consent Checks
Enhanced Consent Receipt Evidence
Known Tracker Auto-Blocking
Iframe and Embed Consent Placeholders
Blocked Script / Embed Runtime Events
Scanner-Synced Cookie Policy Inventory
Admin Evidence Reports Dashboard
Evidence Export with Policy, GPC, Banner Version, and Blocker Data
Policy Generators
Worldwide Regulations Page
India DPDP / DPDPA Workflow
GDPR / ePrivacy Workflow
UK GDPR / PECR Workflow
CCPA / CPRA Tracker Review
LGPD / PIPEDA / POPIA / Singapore PDPA Review Map
US State Privacy Review Map
Australia / Thailand / Quebec / Switzerland / Japan / Korea Review Map
Gulf and APAC Review Map
Agency / Multi-Site Reporting Path
Trust and Procurement Asset Pack

Roadmap, not claimed

IAB TCF support
Google CMP certification readiness
Multilingual legal notice template library
Expanded vendor recipe library for long-tail trackers
Full legal-clause automation from country-specific counsel rules
DSAR / data principal request workflow
WordPress plugin
Shopify app
ISO 27001 readiness
SOC 2 readiness

Roadmap capabilities are product targets only. They are not certification, membership, or approval claims.

What customers can ask COKIQ to provide today

COKIQ can provide product-side operational evidence: scan results, cookie inventory records, consent receipts, policy version history, Google Consent Mode signal mapping, GPC evidence, and tracker/iframe blocker evidence. COKIQ cannot automatically provide attorney certification, SOC 2, ISO 27001, Google CMP certification, IAB certification, or final country-specific legal wording unless those are separately completed and approved.