The 10 Trusted Site checks
Eight core checks decide Trusted Site. Two advisory checks never block the badge. The report always uses this order and these names.
Core vs advisory
A Trusted Site passes every core check. Images and Accessibility are advisory. They appear on the report so you can see picture and WCAG risk. They never decide the badge.
1. Tracker Inventory (core)
A named list of tracking technology in source and in the live capture: provider, category, endpoint, first-party vs third-party, and whether it fired. PASS if nothing transmitted before consent, including tags that exist in HTML but were blocked. ATTENTION if tags sit in source with no working banner. FAIL if tags sent visitor data before a choice.
2. Pre-Consent Behavior / Run A (core)
A fresh browser, California visitor profile, no stored cookies, no prior consent. Full network capture from the first byte for about 30 seconds before any click. This is the check free scans still run live. It answers what transmitted before yes or no.
3. Post-Accept Behavior / Run B (core)
After a recorded Accept, analytics and marketing should load only after that event and bind to a timestamped receipt. Free scans usually lock this row. Do not treat “blocked on first load” as a Post-Accept PASS. Paid Site Audit runs it live.
4. Post-Decline Behavior / Run C (core)
After an explicit Decline, navigate and confirm non-essential tags stay off, including on the next page. A decline that is ignored is a common litigation pattern. Free scans often lock this row.
5. Banner Conformance (core)
A real banner, not a decorative notice: present on scanned pages, blocks non-essential tags before a choice, Accept and Decline equally prominent, persistent settings control, optional categories default off. “Banner in source” on a preview is a hint, not a pass. Runtime looks for detected and working.
6. Consent Records (core)
Receipts for every visitor choice: timestamp, categories, banner version, policy version, region, retention. Free scans typically ATTENTION / locked. Receipts exist once SiteTrust Consent is installed on a plan. See Consent records.
7. AI Disclosure (core)
A published AI Policy reachable without login, plus disclosure of AI tools or chat. PASS if the policy is found. FAIL if none. ATTENTION if a SiteTrust account exists but the live site does not show the policy yet (often the badge is not installed or the page is not linked).
8. Images (advisory)
Visual-asset risk: licensing, missing alt text, leftover EXIF. On free scans this is usually locked or coming-soon depth. It does not block the badge.
9. Accessibility (advisory)
A WCAG 2.0 A/AA look: missing alt, unnamed inputs, empty links, contrast and keyboard issues the live pass can see. Guidance, not a badge blocker. Paid evidence can include the live accessibility pass.
10. Legal Pages (core)
Five written pages. Legal Pages PASSes only if all five pass. One miss fails check 10:
- Privacy Policy (link or detection).
- AI Policy (same published policy as check 7).
- Terms and Conditions.
- Copyright Notice.
- DMCA agent / designated takedown path.
Reviews & Testimonials is not one of the 10 checks. Privacy Policy is not a separate numbered check. It lives inside Legal Pages.
Need help?
Email wecare@sitetrust.com with your site URL and platform. One business day response, Monday through Friday.