Konsent by Kayzen
A banner vendor that audits banners is both judge and party: independence was the product.
- Year
- 2026
- Stack
- Next.js · React · TypeScript · Tailwind · Vercel
- Positioning
- Design
- Development
- Technical SEO
- Copywriting

- public, versioned rulesframework 2026.08.2, viewable without an account
- 139
- recipients described in Frencheach traced back to its ultimate parent company
- 69
- phases per scanbefore consent, after refusal, after acceptance
- 3
- cookies or third-party domains on loadmeasured on the home page
- 0
What needed solving.
The background
Konsent is Kayzen Web's GDPR audit platform. It is aimed at website owners who have installed a consent management platform — Axeptio, Didomi, OneTrust, Cookiebot, tarteaucitron — and have no way of checking what their site actually sets behind that banner. The website is the product's shop window and the entry point for the free audit.
The constraint
The compliance market sells fear: it shows the €20 million ceiling and leaves it at that. The target audience — SME managers, DPOs, agencies — has learnt to be wary of this, and a DPO checks sources. So we needed a site that sells a compliance product without using the very tactics that product exposes, and that stays readable for a manager who is neither a lawyer nor a developer.
The response
A single rule shaped the site: assert nothing the visitor cannot verify for themselves. The framework of 139 rules can be consulted without an account, each rule carrying its legal article and its known limitation. Amounts are never given on their own — the legal ceiling always appears alongside the range actually imposed under the simplified procedure and the cost of fixing the issue. And the site applies to itself what it measures: zero cookies, zero third-party domains.
Every design choice, and the reason for it.
Light, where the sector is dark
Security and compliance tools almost all come in a dark theme, in imitation of the terminal. Konsent takes the opposite stance: white background, #1F2937 ink, a single terracotta accent. The audit report is a document that gets read at length, printed and passed on to a lawyer — here, the conventions of the document win over those of the tool.
The scan trace as the central argument
The hero section does not show an illustration of a padlock but a console scrolling through an audit trace: loading phase, tracker set, recipient's jurisdiction. The block carries its own disclaimer — “demonstration trace, representative of real observations” — because a demonstration presented as a real reading would be precisely the tactic the product criticises in others.
Three figures, never just one
The exposure simulator always shows the legal ceiling under Article 83(5), the range observed under the simplified procedure and the estimated cost of compliance. Showing the ceiling on its own would sell better in the short term; it is also what makes a DPO close the tab, knowing that the simplified procedure handles most cookie cases.
Typography shared with the rest of the group
Outfit for headings, Plus Jakarta Sans for body text: the same families as kayzen-lyon.com. The in-house products are recognisable as a range without resorting to a “by Kayzen” banner in the header, and both fonts are served from the domain, with no call to Google Fonts.
Project palette
Paper
#FFFFFF
Page background
Ink
#1F2937
Body text and headings
Terracotta
#B74831
Primary action and accents
Type system
Display
Outfit
Body text
Plus Jakarta Sans
The Kayzen group's two families, served from the domain. The scan trace uses the system monospace stack: no additional font is downloaded to display it.
What's under the bonnet.
- Next.js
- React
- TypeScript
- Tailwind
- Vercel
Next.js with static rendering
Pages are generated at build time and served from Vercel's CDN. A product showcase whose content only changes with each version of the rule framework has nothing to compute per request: permanent server rendering would only add latency and attack surface.
Zero cookies and zero third-party domains, verified
Measured when the home page loads: no cookie written, no local or session storage entry, and a single network origin called — konsent.kayzen-lyon.com. For a tool that measures the trackers set by others, it is the first thing a technical prospect will open the Network tab to check.
Security headers closed by default
Content-Security-Policy with default-src 'self', with no third-party origin allowed for images or fonts; two-year HSTS with preload; X-Frame-Options set to DENY; a Permissions-Policy that shuts off camera, microphone and geolocation, and explicitly refuses interest-cohort and browsing-topics. Refusing cohort-based targeting is a matter of consistency, not decoration.
Two engines, and the site says which one ran
The static engine reads the served document, the HTTP headers, the DNS chains and the legal pages, without executing JavaScript. The browser worker replays the full protocol in a driven Chromium, in an ephemeral container, with a fresh context for each phase. Every report states the mode used and the list of rules that mode could not evaluate — an unchecked rule is never counted as passed.
How the site makes itself findable.
The objection as the search query
“Cookies set before consent”, “undocumented transfers outside the EU”, “is my cookie banner enough?”: mid-funnel searches, driven by strong intent and precise vocabulary. Targeting “GDPR” would have put the site in head-on competition with law firms and the CNIL (France's data protection authority) itself, for traffic with no purchase intent.
The rule framework as an indexable surface
139 published rules, each with its article, its ruling and its specific point, viewable without an account. It is both the product's argument for independence and a corpus that search engines and AI assistants can cite rule by rule — whereas a framework behind a login produces no visibility at all.
A dated, status-labelled regulatory watch
Every text on the Watch page carries its status — in force, case law, draft, withdrawn. The “Digital Omnibus” package appears there as a proposal not yet adopted. Language models readily repeat announced reforms as if they applied: a source that explicitly distinguishes the two is the one they cite when the question is about the law in force.
Usable by everyone.
Since June 2025, the European Accessibility Act has required digital accessibility from a large share of online services. We build it in at the design stage rather than retrofitting it.
An audit readable without colour
The severity of a finding is conveyed by its label — [CRIT], [WARN], [INFO] — and not just by a coloured dot. A compliance report that could only be read in colour would fail WCAG criterion 1.4.1, which would be hard to defend for a tool sold to compliance teams.
An audit form usable by keyboard alone
The journey's only field — the address of the site to scan — carries its label, its expected format and an error message associated with the field, reachable by tabbing from anywhere on the page. It is the site's only conversion path: it could not depend on the mouse.
What was delivered.
- Home — the findings, the simulator, the free audit
- Features — engines, rule framework, recipient database
- Monitoring — comparison against a baseline scan
- Rule framework — the 139 rules, sourced and versioned
- Regulatory watch — what applies, what is under debate
- Free tools and pricing
What we are often asked.
More of our work
Offensive cybersecurity & SaaSSentinel by Kayzen
Selling a security product to engineers: every claim had to be demonstrable.
Data & weather serviceMétéo Climat France
358 indexable pages, a map animated over 72 time steps — and not a single line of framework.
Trades & constructionBTP EA Rénovation
Six fields, not one more: the form is the product.
The same high standards, for your website.
A free audit of your current site, a quote within 24 hours and written reasoning — like the case study you have just read. Pay in three interest-free instalments; local funding schemes checked before you sign.