Early access · consent enforcement at the origin
Does your site leak before consent?
What pre-consent leakage is
Pre-consent leakage is every request a page sends to a third party before the visitor has agreed to it. The analytics beacon that fires on load, the pixel in the footer, the font or widget fetched from a vendor's CDN: each carries the visitor's IP address and often a cookie, before the visitor has agreed. Consent audits commonly look at exactly this: what left the browser before the click.
Why tag managers get it wrong
In a tag manager, consent gating is configuration layered on top. One trigger with the wrong condition, one vendor script that loads its own dependencies, one template updated upstream, and a tag fires before consent again. A tag manager's report reflects its configuration, which can differ from what the browser actually sent.
What origin-side enforcement would do differently
The pack would have the interceptor rewrite third-party tags inert at the server, so they stay inactive until the consent cookie grants their category, and inject Consent Mode defaults ahead of page scripts. Its inventory would list the third parties as observed in the responses your server sent.
Status
None of these packs ships today. The interceptor they would run on does. Early access means
you hear first when there is a build to try, and your input shapes it.
Tell us you need this
Leave an email and, if you like, the site. We email you if there is a build to try.
All early-access directions are on the transform packs page.