Getting started
Run your first scan
A complete walkthrough: add a site, verify ownership, configure the crawl, launch the scan and read the first report.
This guide takes a brand-new workspace through a full compliance scan end to end. Budget about fifteen minutes, most of which is waiting for DNS verification to propagate.
Before you begin
You need a CheckLegal workspace and the ability to publish a file, meta tag or DNS record on the domain you want to scan.
1. Add the website
Open the application, go to Websites and choose Add website. Enter the canonical origin you want monitored — include the scheme, and use the host visitors actually land on.
https://example.com ✅ canonical origin
https://www.example.com ✅ if www is the primary host
example.com/pricing ❌ paths are discovered by the crawlerChoosing subdomains
Add marketing subdomains such as blog or help as separate sites. Each site keeps its own score, evidence trail and monitoring schedule, which keeps a noisy blog from dragging down your product score.
2. Verify ownership
Verification proves you control the domain before deep crawling starts. Pick whichever method you can ship fastest — both are checked automatically every few minutes.
<!-- Option A: add to the <head> of your homepage -->
<meta name="checklegal-verification" content="YOUR_VERIFICATION_TOKEN" /># Option B: add a TXT record at your DNS provider
TXT _checklegal.example.com checklegal-verification=YOUR_VERIFICATION_TOKENDNS can lag
TXT records may take up to an hour to propagate. If verification is still pending after that, confirm the record on the _checklegal subdomain rather than the apex.
3. Configure the crawl
Scan settings decide how much of the site is inspected and which rules the findings are graded against.
| Setting | Default | When to change it |
|---|---|---|
| Page limit | 100 pages | Raise it for large content sites; lower it for a quick smoke test. |
| Jurisdictions | EU (GDPR) + ePrivacy | Add UK, Swiss or US state rules if you serve those markets. |
| Consent simulation | Reject all | Switch to Accept all to audit what loads after consent. |
| Authenticated areas | Off | Enable only with a dedicated test account, never a real user. |
4. Launch the scan
- 1Press Start scan on the site detail screen.
- 2The crawler discovers pages from your sitemap and internal links.
- 3Each page is loaded in a real browser, twice: pre-consent and post-consent.
- 4Cookies, trackers and third-party requests are recorded as evidence.
- 5Findings are graded and rolled up into a 0–100 compliance score.
You can close the tab — scans run server-side and you get an email when the report is ready. Typical runtimes are two to four minutes for 100 pages.
5. Read the report
Open the report and work top-down. Findings are ordered by regulatory exposure, not by how many pages they appear on, so the first item is always the one worth fixing first.
- Critical — trackers firing before consent, or a missing privacy policy.
- High — consent banner without a reject option, or undeclared third-party processors.
- Medium — stale policy dates, missing cookie descriptions.
- Low — cosmetic or best-practice improvements.
Evidence for every finding
Expand a finding to see the exact page URL, the request that triggered it and the timestamp within the page load. Evidence is what makes a report defensible in a regulator conversation.
6. Fix and rescan
Ship your fixes, then rerun the scan from the report header. The new run is diffed against the previous one so you can see exactly what closed and what regressed.
# Optional: trigger a rescan from CI after a deploy
curl -X POST https://api.checklegal.ai/v1/sites/SITE_ID/scans \
-H "Authorization: Bearer $CHECKLEGAL_API_KEY"Next step
Once your first report is clean, turn on weekly monitoring so regressions surface before your customers or a regulator find them.
Was this page helpful?
