Method
We parsed script src attributes and form elements in seven server-rendered responses. Inline framework code was not classified as a third-party origin. Client-side network requests after interaction were outside this collection.
The result is used as a before-state for future analytics or advertising changes. It is not described as a complete privacy audit.
Observed evidence
0 across 7 sampled responsesNo third-party script src host was observed.0 across 7 sampled responsesNo HTML form element was present in the initial responses.0 forms · 0 external script originsThe interactive checklist remained browser-local in the sampled HTML.Findings
- The pre-advertising sample had no external script origin.
- The readiness tool did not submit an HTML form.
- Future ad or analytics code would materially change this baseline and needs a new disclosure and CSP review.
Decision and resulting changes
Keep advertising disabled during remediation. When approval occurs, enable ads only on substantive reports, update the privacy inventory, and exclude tools, policy pages, errors, APIs, and indexes from ad placement.
- Added an explicit ad-eligibility policy to editorial pages.
- Kept the readiness tool noindex and ad-free.
- Published the raw pre-ad baseline for later comparison.
Limits and reproduction
Re-run automation/evidence_collector.py against the public origin and compare the resulting JSON fields. A difference is evidence of a changed response, not automatically an improvement.
- The collector does not execute JavaScript.
- Browser extensions, service workers, and post-interaction requests are not included.
Primary references
— Baseline captured from the public site, limitations documented, and remediation decision published.
Prepared by SiteSignal Hub Field Lab. Evidence collection and structural checks are automated; no personal use, customer result, or human test is claimed.