A site everyone can cross, and no regulator can fault.
Two fears sit under every corporate website, and most agencies sell the answers separately. One is a privacy fine — for tracking a visitor before they agreed to it. The other is an accessibility lawsuit — for a site a person with a disability cannot use.
Both are provable in a courtroom from the outside, by anyone, without permission. A banner that looks compliant and a site that looks usable are not the same as being either.
Threshold handles both together, because the same site carries both risks and the same audit can see both. It reads what the site actually does — which trackers fire and when, which barriers block a screen reader, which legal pages are missing or stale — and returns evidence, not reassurance.
It runs on Beacon's engine, the same report discipline the rest of the family uses, pointed at compliance and legal exposure.
Two exposures, one audit.
The privacy fine
If a site fires tracking cookies before a visitor consents, or keeps tracking after they click Reject All, that is a live violation of consent law — the ePrivacy prior-consent rule, GDPR's consent basis, the disclosure gaps CCPA and its state cousins police.
The audit measures exactly this: what fires before consent, and what refuses to stop after a rejection.
The accessibility lawsuit
Courts treat a commercial website as a place of public accommodation. A confirmed, machine-detectable barrier — poor contrast, missing alt text, broken labels, bad heading order — is the kind of gap that drives an ADA web-accessibility suit.
The audit runs the site against the WCAG 2.1 AA standard and ranks every violation from critical to minor.
What the audit finds
Eighteen trackers before a single click. Then zero.
On a real engagement, the audit found eighteen tracking cookies firing before any consent decision, and twenty-three tracking requests still firing after a visitor clicked Reject All. A banner was present the whole time. It changed nothing underneath.
That is the pattern a regulator or a plaintiff looks for, and it is invisible from the front of the site. Remediation drove both numbers to zero, verified by re-running the same audit — the before and the after measured the same way.
8
checks across consent, accessibility, and legal pages — each a risk flag anchored to real evidence, never a legal verdict the audit invents
2
assertions proven on every cookie fix — the leak is closed and the analytics survived, weighted equally
0
changes made to a live site without a verified backup and a person approving the edit
The honesty line
Fixing the leak without breaking the analytics.
There is a naive way to pass a cookie audit: gate everything so aggressively that the trackers stop — and the site's own analytics stop with them. On one engagement that mistake collapsed a client's analytics by ninety-three percent. They gained compliance and lost their data in the same afternoon.
Every Threshold cookie remediation proves two things, not one: the leak is closed, and analytics still survive under a denied consent. Both are pass-or-fail gates, and a fix that closes the leak but kills the data is refused, not shipped.
Where a site has no consent platform at all, Threshold can deploy Daylit's own free consent tool rather than putting the client on a paid vendor seat.
Three ways to run it.
The read-only diagnostic: the full consent, accessibility, and legal-page scan, with before evidence captured the same way the after will be.
It changes nothing and is safe on any site. A baseline audit is a real deliverable even before access is arranged — every check reads honestly rather than guessing.

A project that edits the live site: consent gating that survives analytics, the automatable accessibility fixes, and legal-page language drafted for counsel to review.
Every step is backed up first and human-gated. Anything a machine cannot safely fix is surfaced to a person rather than force-applied.

A retainer: a scheduled re-audit, alerts when the site drifts back out of compliance, and a periodic report showing the current verdict per pillar.
It is monthly and evidence-driven, not real-time monitoring — a steady compliance pulse a stakeholder can rely on between reviews.

Asked in every first meeting.
Straight answers to the questions that decide whether an audit is worth running at all — the same ones every compliance-worried team asks first.
The questions that come up first.
No. The Audit is read-only.
It loads the site as a real visitor would, records what tracks before and after consent, runs the accessibility scan, and checks the legal pages — and makes zero changes. Only the Remediation tier edits the live site, and only after a verified backup.
No, and Threshold never claims it is. An automated scan catches the machine-detectable barriers, but keyboard operability and screen-reader experience need a human to actually test them. That check is always run by a person and is never auto-passed.
The report is a risk flag for counsel, not a certification the audit issues on its own.
Because the same site carries both risks, the same visit can measure both, and a corporate owner carries both fears at once. Splitting them into two vendors and two invoices serves the agency, not the client.
They keep working. The single most common way a consent fix goes wrong is over-gating that silently kills analytics.
Threshold treats analytics survival as a hard pass-or-fail gate on every remediation and refuses to ship a fix that fails it.
Not necessarily. If a site already has one, Threshold works with it.
If it has none, Threshold can deploy Daylit's own shipped, free consent tool instead of routing the client onto a paid vendor seat.
What lands on your desk
One report a non-lawyer can read end to end.
Every tracker found before consent, every accessibility failure with the page it lives on, evidence attached and the jargon translated — a fix list a team can actually act on.
Priced to sit under the risk it removes.
Threshold is delivered as a service — compliance craftsman work and proprietary tooling together, run on Daylit's own infrastructure rather than sold as a stack of vendor seats.
Watch starts at around $250/month to keep a site audited and monitored for drift. The one-time Audit is $3,500 per site, and Remediation is scoped and quoted against what the audit finds.
Every tier holds the same line: the audit changes nothing, a fix is backed up before it touches a file, and the report is always a risk flag for counsel — never a legal verdict the tool pretends to render.



