That is a visitor de-anonymization tool, and it is doing exactly what it was bought to do. A script on your pages sends a signal about each visitor to a vendor, the vendor matches it against an identity graph assembled from other sources, and a name, company, or email address comes back to your CRM or Slack.
The short answer
These are marketed as website visitor identification, and the category includes both company-level tools (which resolve an IP address to an organization) and person-level tools (which return an individual's name and often a work email). The distinction matters enormously and is frequently blurred in the sales pitch — company-level resolution is a long-standing B2B practice, while person-level identification of someone who never submitted anything to you is a different proposition.
If nobody on your team can say which one you have, that is the thing to establish first, before the consent question.
The giveaway is usually not in the browser, it is in your notifications: a Slack channel or CRM feed announcing that a named person from a named company visited a specific page, for people who never submitted a form. In the network tab, look for a small script loading early and posting page-view payloads to a vendor domain — rb2b, vector, clearbit, koala, 6sense, demandbase and similar all appear as ordinary third-party requests.
Frequently nobody currently on the team installed it. It arrived with a growth consultant, a previous marketer, or as a bundled feature of an ABM platform.
You are answering three questions: what is installed, is it company-level or person-level, and does it run before consent.
What a healthy result looks like: You should be able to name the vendor, describe in one sentence what it transmits, say whether it identifies individuals, and say whether it waits for consent.
These tools are cheap, install in one script tag, and produce immediately visible results — a named lead in Slack within an hour. That combination means they often skip whatever review process a larger purchase would trigger.
Account-based marketing and intent-data suites include visitor identification as a feature. The buyer evaluated the platform; the identification component came along and was enabled by default.
A visitor-identification script is not obviously analytics, advertising, or functional. Consent platforms often leave it uncategorized, and uncategorized frequently defaults to allowed.
The tool changed what personal information the site collects and, potentially, how it is shared — but the policy, the notice at collection, and the opt-out mechanism were written for the previous stack.
California's Invasion of Privacy Act (CIPA), Penal Code § 631, prohibits intercepting a communication without the consent of all parties. Since 2022, plaintiff firms have applied that decades-old wiretapping statute to websites — arguing that transmitting a signal about each visitor to a vendor that matches it against an identity graph and returns the person's identity before the visitor consents is an intercepted communication. Statutory damages under § 637.2 run up to $5,000 per violation, and plaintiffs argue each affected visitor session is a separate count, which is why even small sites receive demand letters. Similar all-party-consent statutes in Pennsylvania (WESCA), Florida (FSCA), and Massachusetts have produced parallel filings.
Two things are worth separating. The pre-consent timing question is the same as for any tracker. The second question is specific to this category: identifying a visitor by name involves personal information obtained from sources other than the visitor, which is the territory of California's rules on notice, opt-out rights, and — for the vendors themselves — data broker registration with the CPPA.
To be precise about what a network log can tell you: a tracker firing before consent is a technical finding — it establishes when a script transmitted data, not whether any law was broken. But timing is exactly what these claims are built on, which is why fixing the timing is the practical response.
Terminology bridge
Vendors call this website visitor identification, visitor de-anonymization, or identity resolution; the matching database behind it is an identity graph, and the practice sits inside account-based marketing (ABM) and intent data. The important distinction is company-level (reverse IP lookup to an organization) versus person-level (an individual's name and email). In California's vocabulary, a company that collects personal information about consumers with whom it has no direct relationship, and sells it, may be a data broker required to register with the CPPA — a public registry you can search.
A scan can tell you a de-anonymization script is present and when it runs. It cannot tell you where the vendor's matching data came from, whether their sourcing is lawful, or whether your use of it is — those answers come from the vendor's documentation, their contract, and your attorney. This page is general information, not legal advice.
RegSentry loads your site in a real browser, records when each third-party tracker first contacts its server, and flags everything that fires before consent — with the fix for each one. Continuous monitoring re-runs it and emails you when something new appears.
Free real-browser scan
See every pre-consent tracker on your site — free, 30 seconds, no signup.
Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.