Cookie consent your compliance team can
audit
Consent your compliance team can audit: it runs on your own site, and no visitor data ever leaves your institution.
Andes Consent is a 15 KB consent script with zero dependencies that you host on your own infrastructure. It blocks tracking until the visitor says yes, and it works under strict security policies.
The Core
Problem
The banner that weakens your site security
Many commercial consent platforms require unsafe-inline or eval and load their code from someone else's servers, exactly what a strict security policy forbids. The script meant to protect privacy ends up opening a door.
Tags that fire too early
When a pixel or analytics tag runs before the visitor agrees, you have a compliance problem on every visit. State privacy laws and pixel-tracking lawsuits have made that risk concrete for US credit unions and agencies.
How we solve it
Hosted by you
Delivered as a package with integrity hashes (SRI) that lives on your infrastructure. No per-visit fees and no calls to third-party servers.
Works under strict CSP
Tested with nonce and strict-dynamic, and with Trusted Types. No eval, no HTML injection, and a closed list of allowed origins.
Real blocking before yes
Third-party scripts and iframes are marked in the HTML and only run with consent, keeping their load order and integrity hashes.
Receipts on your own server
Each decision can produce a consent receipt sent to an endpoint you control. Andes hosts no record of your visitors.
Google Consent Mode v2 and GPC
Passes the decision to Google, honors Global Privacy Control, runs opt-in or opt-out, and deletes cookies when a visitor withdraws consent.
Real-World
Applications
Credit unions and community banks
Member-facing sites that need to show they don't track anyone before consent, in English and Spanish.
Insurance and finance agencies
Lead-generation sites where forms and tracking pixels need to respect state privacy laws, including Texas.
Platforms with strict security policies
Portals and online banking where the security team won't accept a banner that asks for unsafe-inline.
Why we are different
No data leaves your institution
Receipts go to your server and the script runs on your domain. Andes doesn't see or store anything about your visitors.
Auditable end to end
Small code, no dependencies, integrity hashes for every release, and 245 tests across Chromium, Firefox and WebKit.
Accessible and on brand
A banner in English and Spanish, with five layouts and brand themes, and WCAG 2.2 AA checked on every integration.
How we built Andes Consent
The security problem behind it, the technical decisions, and what we left out on purpose, like the IAB TCF framework used in programmatic advertising.
Frequently asked questions
Andes Consent is a cookie consent script built by Andes Development: 15 KB, zero dependencies, hosted on your own site. It blocks analytics and third-party content until the visitor agrees, and passes that decision to Google through Consent Mode v2.
Yes, that's why it exists. It's tested with nonce-based CSP, strict-dynamic and Trusted Types, with no eval and no injected HTML.
It's designed for GDPR and ePrivacy, CCPA/CPRA, the Texas Data Privacy and Security Act, and the laws of Brazil, Mexico, Chile, Colombia and El Salvador, in opt-in or opt-out mode. Each site's final configuration is set with your legal team.
No. The script runs on your domain and consent receipts go to an endpoint you control. Andes doesn't host a consent service or receive any visitor data.
With a free review of your public website: we tell you which tags run before consent, without access to your systems. From there we set the configuration and the installation plan.
Do you know what fires on your site before visitors consent?
We'll review your public website for free and tell you which tags run before consent. We don't need access to your systems.