Skip to content
App

Getting started

Run your first scan

A complete walkthrough: add a site, verify ownership, configure the crawl, launch the scan and read the first report.

This guide takes a brand-new workspace through a full compliance scan end to end. Budget about fifteen minutes, most of which is waiting for DNS verification to propagate.

Before you begin

You need a CheckLegal workspace and the ability to publish a file, meta tag or DNS record on the domain you want to scan.

1. Add the website

Open the application, go to Websites and choose Add website. Enter the canonical origin you want monitored — include the scheme, and use the host visitors actually land on.

text
https://example.com        ✅ canonical origin
https://www.example.com    ✅ if www is the primary host
example.com/pricing        ❌ paths are discovered by the crawler

Choosing subdomains

Add marketing subdomains such as blog or help as separate sites. Each site keeps its own score, evidence trail and monitoring schedule, which keeps a noisy blog from dragging down your product score.

2. Verify ownership

Verification proves you control the domain before deep crawling starts. Pick whichever method you can ship fastest — both are checked automatically every few minutes.

html
<!-- Option A: add to the <head> of your homepage -->
<meta name="checklegal-verification" content="YOUR_VERIFICATION_TOKEN" />
dns
# Option B: add a TXT record at your DNS provider
TXT  _checklegal.example.com  checklegal-verification=YOUR_VERIFICATION_TOKEN

DNS can lag

TXT records may take up to an hour to propagate. If verification is still pending after that, confirm the record on the _checklegal subdomain rather than the apex.

3. Configure the crawl

Scan settings decide how much of the site is inspected and which rules the findings are graded against.

SettingDefaultWhen to change it
Page limit100 pagesRaise it for large content sites; lower it for a quick smoke test.
JurisdictionsEU (GDPR) + ePrivacyAdd UK, Swiss or US state rules if you serve those markets.
Consent simulationReject allSwitch to Accept all to audit what loads after consent.
Authenticated areasOffEnable only with a dedicated test account, never a real user.

4. Launch the scan

  1. 1Press Start scan on the site detail screen.
  2. 2The crawler discovers pages from your sitemap and internal links.
  3. 3Each page is loaded in a real browser, twice: pre-consent and post-consent.
  4. 4Cookies, trackers and third-party requests are recorded as evidence.
  5. 5Findings are graded and rolled up into a 0–100 compliance score.

You can close the tab — scans run server-side and you get an email when the report is ready. Typical runtimes are two to four minutes for 100 pages.

5. Read the report

Open the report and work top-down. Findings are ordered by regulatory exposure, not by how many pages they appear on, so the first item is always the one worth fixing first.

  • Critical — trackers firing before consent, or a missing privacy policy.
  • High — consent banner without a reject option, or undeclared third-party processors.
  • Medium — stale policy dates, missing cookie descriptions.
  • Low — cosmetic or best-practice improvements.

Evidence for every finding

Expand a finding to see the exact page URL, the request that triggered it and the timestamp within the page load. Evidence is what makes a report defensible in a regulator conversation.

6. Fix and rescan

Ship your fixes, then rerun the scan from the report header. The new run is diffed against the previous one so you can see exactly what closed and what regressed.

bash
# Optional: trigger a rescan from CI after a deploy
curl -X POST https://api.checklegal.ai/v1/sites/SITE_ID/scans \
  -H "Authorization: Bearer $CHECKLEGAL_API_KEY"

Next step

Once your first report is clean, turn on weekly monitoring so regressions surface before your customers or a regulator find them.

Was this page helpful?