RiskSignal
Scope & Limitations

RiskSignal scans publicly observable website signals to detect whether a site's conversion tracking is present and sending data, and reports when that changes across a set of client sites it is asked to watch.

All findings are derived from publicly observable signals only. They describe what a visitor's browser can see on a passive visit, not guarantees of revenue impact, conversion outcomes, or commercial performance.

This page is the Scope and Limitations document. It defines the service scope, what the scan can and cannot see, and the exclusions that apply to every RiskSignal engagement. The Terms of Service incorporates it by reference.

RiskSignal provides external scan output and alerting only. It does not include penetration testing, legal advisory, or implementation work, and it does not fix what it reports.

Coverage

What we monitor

Conversion tracking, and nothing else. For each domain on your roster we record:

  • whether known analytics and advertising tags are present on the page, for example Google Analytics, Google Tag Manager, the Meta pixel, and the TikTok pixel
  • whether a tag that is present actually transmits anything when the page loads
  • whether a consent banner is suppressing tags that would otherwise transmit

A scan covers the site's home page and a small number of pages reachable from it by ordinary links. Pages behind a login, a purchase, or a completed form are never reached.

The scan observes other properties of a site in passing, such as page speed and security headers. Those are deliberately never reported to you as alerts. This service is narrow on purpose.

The honest boundary

What we can and cannot detect

This is the most important section on this page. We reliably detect two conditions:

  • a tracking tag that was present before and is now absent
  • a tracking tag that is present but transmits nothing when the page loads

The following are real tracking failures that we do not detect. Please do not rely on this service to catch them:

  • conversion events that fire but carry wrong or missing values
  • purchase or lead events that fail only at the final step, which sits behind a checkout or login we never reach
  • duplicate or double-counted conversions
  • consent configuration that transmits but is set up incorrectly
  • server-side and first-party tracking setups, where events are sent from the site's own servers and are invisible to a visitor's browser. Where we can identify such a setup, we suppress alerts for that site rather than report a failure we cannot confirm.
  • attribution, audience, or reporting problems inside an ad platform or analytics account
  • anything only observable while logged in

We report what a visitor's browser can observe from outside. We do not audit a tracking implementation and we do not certify that tracking is correct. No alert means we observed nothing broken. It is not a statement that everything is working.

Method

Method and its limits

Point in time. Each finding reflects a scan at a single moment. A site can break minutes after a clean scan.

Confirmation before notification. A difference seen in a single scan is never sent. We wait for a second scan to agree with it. This means a real break reaches you within a couple of days rather than within the hour, and that delay is deliberate: a false alarm about your client's website costs you more than a slow true one.

Human review. A person checks every candidate by hand before it reaches you. Nothing is sent automatically.

No guarantee of detection. Websites vary. Some block automated visits, some render differently for different visitors, and some tracking setups are invisible from outside. We do not warrant that every tracking failure will be detected, or that any particular failure will be detected within any particular time.

Unscannable domains. If a domain consistently blocks our scan we will tell you and remove it from the roster rather than leave it on the list appearing to be watched. A domain that looks covered and is not is the worst outcome available, so we will not keep one on the list to hold a count up.

Weekly coverage note. Once a week you receive a short note stating how many domains on your roster were checked and identifying any that could not be reached, with the reason. It reports coverage and carries no scan data. A domain we could not scan is never quietly left inside the covered count.

No alert volume is promised. This service is insurance. A month with no alerts is a month in which nothing broke, and that is the expected outcome. We will never quote you an expected number of alerts, and a quiet period is not a failure of the service.

Data

Data and access

What you give us. A list of domains. Nothing else is required and nothing else should be sent.

No credentials, ever. We do not ask for and will not accept logins, API keys, analytics access, ad account access, or any other credential belonging to you or your clients.

Contact data is not retained. If a roster list arrives with names, emails, or other contact columns alongside the domains, only the domains are used. Contact columns are not stored and are not rejoined to any output.

What we store. For each domain, the technical observations from each scan, so today's scan can be compared with yesterday's. That record is what makes the service possible.

Your clients are not contacted. We never approach the businesses whose sites are on your roster. The relationship is with you.

Domain names and company names are public facts. Aggregate, non-identifying observations across all sites we have scanned may inform published research. Nothing identifying you, your agency, or a specific client site is ever published. Full detail is in the Privacy Policy.

Exclusions

What is not included

  • fixing anything. We report; repairs are yours or your client's.
  • engineering, development, or implementation work
  • marketing, analytics, or strategic consulting
  • legal advice or compliance certification of any kind, including GDPR, CCPA, and accessibility conformance
  • security testing. These are external observations of a public page, not penetration testing, and no attempt is made to probe, bypass, or stress any system.
  • uptime or availability monitoring
  • a dashboard, a login, or a reporting portal. The service is delivered by email.
Your side

Your responsibilities

  • Provide an accurate list of domains you are authorised to have monitored on your clients' behalf.
  • Keep that list current. Tell us when a client leaves or joins.
  • Tell us in advance about planned site migrations or tracking changes, so an intentional change is not investigated as a break.
  • Act on alerts. We report a problem; resolving it with your client is yours.
Commercial

Billing and cancellation

Monitoring is a monthly subscription priced by roster size. Pricing is provided on request.

Billing is monthly in advance. You can cancel at any time and monitoring continues to the end of the period you have paid for. There are no minimum terms and no cancellation fees.

If your roster grows past the limit of your tier, we will tell you before anything changes.

The full terms are on the Terms of Service page, which incorporates this page by reference.

Ready to have your client sites watched?