A consent platform that doesn’t slow you down.

cmpstack ships a <4KB script, scans your cookies on schedule, and gives agencies a multi-client console — without a tag manager in the middle of it.

Script size
<4KB
4,092 bytes gzipped, async-loaded. Nothing render-blocks.
Layout shift
<0.10
The banner is a fixed overlay. Budget enforced by a headless-Chrome check in CI.
Consent Mode
GCMv2
Advanced Mode. Denied-first defaults set before any Google tag fires.
01 / Pillars

Built around the things most CMPs get wrong

Performance, agency tooling and compliance — chosen because they’re where teams lose money, time and audits. Everything else follows from these.

01

Performance

Smaller script, no layout shift. The tag every page view loads carries only what has to run first — consent signals, script blocking, your visitor's stored choice. The banner itself is a second file, fetched once, only for visitors who have not chosen yet. No SDK underneath, nothing on the page waiting for it, and a headless-Chrome check that fails the build if the banner moves your content.

  • Script size<4KB gzip
  • Exact bytes4,092
  • Layout shift<0.10
  • Render blockingNone
  • Returning visitorNo banner
02

Agency tools

Run every client without a tab for each. One login moves between every client workspace, a banner change rolls across every domain in a single operation, and a client’s own people get scoped access rather than your password.

  • Multi-client consoleRole-based
  • Workspace switcherAll plans
  • Bulk scan & deployPreview, then apply
  • Branded PDF reportsAgency +
  • Rollouts1 click
03

Compliance

Audit-ready out of the box. GDPR, CCPA, DMA and Google Consent Mode v2 Advanced — implemented to spec, with immutable logs and dark-pattern prevention enforced by the UI itself.

  • FrameworksGDPR / CCPA / DMA
  • GCMv2 Advanced ModeAll plans
  • Consent logImmutable
  • Dark patternsBlocked
  • Compliance score0–100
02 / Capabilities

Everything you need to manage consent

Four product surfaces, one platform. Each one removes a specific category of grunt work — and nothing here exists to pad a comparison grid.

01

Consent banner system

Banners that look like your brand. A visual editor over layout, colour, type, radius and copy, full CSS access on Pro+, and region-aware display that only asks where consent is required — previewed on desktop, tablet and phone before anything ships.

Visual editor
Layout, colours, fonts, radii and every string in the banner — no CSS required.
Region-aware display
Visitors in the EEA and UK are always asked. For US visitors you choose: an opt-out notice with a “Do Not Sell or Share” link and Global Privacy Control honoured, the same question as Europe, or nothing. Everywhere else: ask, tell without asking, or nothing.
26 languages built in
Every EU/EEA official language with reviewed wording ready to edit — matched to the page, not the browser.
Dark patterns blocked
Reject is always as reachable as Accept — your CSS is followed by rules that re-assert it.
Custom CSS
Unscoped style hooks so your design system inherits — no shadow-DOM lock-in.
02

Cookie scanner

Knows what you set before you do. A headless crawler walks every public page on a 7-day schedule, classifies every cookie and pixel, and pushes diffs straight to your dashboard.

Auto-discovery
Crawls your public pages on a 7-day schedule — surfaces new trackers as soon as they ship.
Vendor rules
Known cookies and pixels are matched to a category and a named vendor automatically.
Diff alerts
Slack and email pings the moment a previously unseen tracker appears on your domain.
Bulk scan
Queue a scan on many client domains in one batch, with a preview first — on every plan.
03

Analytics dashboard

Consent metrics, not vanity charts. Opt-in rates, banner conversion funnels, geo breakdowns and a compliance score that tells you what to fix — not just what's broken.

Opt-in rates
Per-domain, per-region, per-banner — segmented by device, traffic source and template.
Compliance score
A 0–100 score with prioritized fixes ranked by audit risk and time-to-resolve.
Webhooks
POST consent events to your stack in real time — Segment, Mixpanel, or your own endpoint.
Branded PDF
Exportable monthly reports — agencies can re-skin them and forward to clients verbatim.
04

Integrations

Drops into the stack you already run. Native Google Tag Manager, GA4, WordPress, Shopify and Wix, plus a webhook bus for whatever else lives on your edge.

GTM & GA4
Native triggers, custom templates and pre-built consent variables — paste-and-go.
CMS plugins
A WordPress plugin you download from your panel, and a one-line install for Shopify themes that also feeds Shopify's own consent API.
Works with your server container
Consent Mode is set in the browser before anything loads, so a server-side GTM container you already run follows the visitor's decision — nothing to change on your side.
Webhooks & API
REST API + outbound webhooks for consent events, audit logs and config changes.
03 / Performance

4,092 bytes. Measured.

Script weight is a budget here, not an aspiration. The file every page view loads carries only what has to run first; the banner is a second file that a visitor downloads once, and only if they have not chosen. No SDK underneath either, and a headless-Chrome check fails the build if the banner shifts your layout. Every number below comes out of that pipeline.

Every page view
4,092 B
Banner, first visit only
5,636 B
Our ceiling
4,096 B

Gzipped bytes of cmpstack-script/dist/cmpstack.js and cmpstack-ui.js, against the 4KB ceiling the build holds the first one to. We don’t publish figures for other vendors’ scripts, because we don’t measure them.

Every page view
<4KB
4,092 bytes gzipped. Repeat it: gzip -nc dist/cmpstack.js | wc -c.
First visit
+5,636 bytes
The banner is a second file, fetched once, only for visitors who have not chosen yet — and never on the render path.
Layout shift
<0.10
The banner is a fixed overlay and never moves your content. Enforced in CI.
Render blocking
None
One async tag. The banner waits for the DOM; nothing on the page waits for it.
Returning visitors
No banner
A stored decision is read from the cookie and applied from a per-site cache — no banner, no render, and no request except a once-a-day background refresh of your blocking rules.
04 / Integrations

Plays nicely with the rest of your stack

13 integrations we speak to directly, across tag management, analytics, advertising, e-commerce and CMS — plus 18 more third-party scripts the tag recognises and holds back until the visitor allows their category, and webhooks for whatever is on neither list.

  • WordPressCMS
  • ShopifyCMS
  • Google Tag ManagerTag Management
  • Google Analytics 4Analytics
  • Google AdsAdvertising
  • Meta PixelAdvertising
  • TikTok PixelAdvertising
  • LinkedIn InsightAdvertising
  • MixpanelAnalytics
  • AmplitudeAnalytics
  • HotjarAnalytics
  • HubSpotCRM & Marketing
  • SalesforceCRM & Marketing
  • MailchimpCRM & Marketing
  • WooCommerceEcommerce
  • MagentoEcommerce
  • BigCommerceEcommerce
  • SegmentData / Tagging
  • TealiumData / Tagging
  • Server-side trackingData / Tagging
  • WebhooksDeveloper / API
  • REST APIDeveloper / API

Or wire it up yourself, with the REST API ↓

05 / For developers

Implementation that doesn’t make you angry

A REST API, a no-config snippet, and Google Consent Mode v2 wired correctly the first time. No support ticket required.

Drop-in snippet
A two-line Consent Mode default, then one async script tag, in <head>. No sync loaders, no IIFE wrappers, no CSP exemptions.
REST API access
Programmatic banner config, consent record export and analytics, under /v1.
GCMv2 Advanced Mode
Denied-first consent defaults are set before any Google tag can fire, then updated on choice.
Cookie-scoped decisions
The choice is stored on your root domain, so subdomains share it and returning visitors see nothing.
What the tag does, before you touch anythingconsent-mode.js
// Set synchronously, before any Google tag can fire.
gtag('consent', 'default', {
  ad_storage: 'denied',
  analytics_storage: 'denied',
});

// …then updated from the visitor's choice.
gtag('consent', 'update', { analytics_storage: 'granted' });

Ship a faster banner this afternoon

7 days, every feature. Setup in under ten minutes. No credit card, no sales call, no migration headache.

GDPR · CCPA · DMA · Google Consent Mode v2