CHEQ

CHEQ

CHEQ is an ad fraud prevention and go-to-market security platform. Its scripts analyze visitor behavior, device fingerprints, and network signals in real time to detect bot traffic, invalid ad clicks, and fake form submissions, blocking fraudulent interactions before they corrupt analytics data.

Overview

CHEQ is a go-to-market security and ad fraud prevention platform. Its scripts are deployed on advertiser and publisher websites to analyze incoming traffic in real time, distinguishing human visitors from bots, scrapers, and invalid click sources. CHEQ is commonly found on landing pages, paid-search destinations, and lead generation forms where fraudulent traffic causes direct financial harm to advertisers.

What This Script Does

The CHEQ script (typically cheq.js or loaded from a *.cheqzone.com domain) executes behavioral and environmental analysis in the browser immediately on page load. It collects a wide range of signals to build a risk assessment for each visitor session.

Signals analyzed include: browser fingerprint characteristics (user agent, canvas rendering, WebGL renderer, installed fonts, screen dimensions), mouse movement patterns and interaction velocity, network characteristics (IP address, ASN, whether the connection appears to be a proxy or datacenter), page referrer, and timing of user interactions relative to page load. These signals are submitted to CHEQ's real-time classification API, which returns a risk verdict used to allow, flag, or block the visitor.

CHEQ may set a session cookie or a short-lived identifier to avoid re-analyzing the same browser within a session. Device fingerprinting is a core component of CHEQ's detection methodology and does not rely on cookie consent to function — fingerprints are computed from browser environment properties without writing to persistent storage.

The CHEQ script operates primarily as a fraud-signal collector; it does not display content or modify the page for legitimate visitors.

Consent & Compliance

CHEQ's consent posture is nuanced. The fraud-prevention function has a legitimate business rationale, but the technical implementation involves extensive device fingerprinting, which regulators — particularly the CNIL and the ICO — have determined requires consent when used for any purpose beyond strictly necessary security functions.

Under ePrivacy Article 5(3), any reading of or writing to a user's terminal equipment requires consent unless strictly necessary. CHEQ argues its processing falls under the security necessity exemption, but this position is contested when the same fingerprint data is used to enrich advertiser analytics dashboards or retargeting suppression lists, rather than solely blocking individual bot sessions.

Under GDPR, the legal basis for real-time fraud detection is typically legitimate interest (Article 6(1)(f)), provided the processing is genuinely limited to security purposes and a balancing test is documented. If CHEQ data feeds marketing or attribution reporting, the legitimate-interest basis becomes harder to defend.

Under CCPA/CPRA, device fingerprinting data constitutes personal information. Security-purpose processing may be exempt from opt-out rights, but only if the data is not used for advertising or commercial profiling.

The consent category is mixed (essential/analytics). Pure bot-blocking is essential; analytics enrichment requires consent.

Should You Block This Without Consent?

Conditional. If CHEQ is deployed strictly for real-time bot blocking and invalid-click prevention with no data feeding marketing or analytics pipelines, it can be treated as essential and loaded without prior consent. If CHEQ data contributes to analytics dashboards, retargeting lists, or ad-performance attribution, it must be gated behind analytics or marketing consent. Review your CHEQ data processing agreement to determine which use cases are active.

Is CHEQ GDPR compliant?

CHEQ typically loads analytics trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So CHEQ can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads CHEQ, not on CHEQ itself.

Visit website

Consent Categories

Also Known As

cheq ad fraudcheq bot detectioncheq trackingcheq go-to-market securitycheq invalid clicks

Industries

Computers Electronics and TechnologyBusiness and Consumer ServicesMarketing and AdvertisingFinance

Tracked Domains (1)

cheq.aiEssential

cheq.ai is an essential domain operated by CHEQ, used to keep the site working, including security, load balancing, and sessions.

Frequently Asked Questions

Related Vendors

Clearpay
Clearpay
Clearpay embeds buy-now-pay-later payment widget scripts on product and checkout pages. Scripts render installment payment options, verify eligibility, and process transaction data to facilitate Clearpay's deferred payment service.
Human Security
Human Security
Human Security (formerly White Ops) is a cybersecurity company protecting websites from bot attacks, ad fraud, and account takeover. Scripts collect browser integrity signals and behavioral telemetry to distinguish human visitors from automated traffic.
Clym
Clym
Clym is a privacy compliance and consent management platform. Its scripts display cookie consent banners, store visitor consent preferences in cookies, manage granular consent categories, and facilitate data subject access requests in accordance with GDPR and other privacy regulations.
Directus
Directus
Directus is an open-source headless CMS and data platform that serves structured content via APIs. Its backend delivers content to frontend applications through REST or GraphQL endpoints. Directus does not typically load tracking scripts in the browser, functioning primarily as a server-side content source.
Axeptio
Axeptio
Axeptio is a cookie consent management platform based in France. Its scripts display interactive consent banners, record visitor cookie preferences, and conditionally load or block third-party scripts based on consent choices. Visitor decisions are stored in cookies to maintain preferences across visits.
ImageKit
ImageKit
ImageKit is an image CDN and optimization service that serves transformed images from edge servers. Its scripts handle URL-based image transformations including resizing, format conversion, and lazy loading. ImageKit makes network requests to its CDN endpoints but does not typically set tracking cookies.

Manage consent for CHEQ

ConsentStack automatically detects and manages CHEQ trackers so your site stays compliant with global privacy regulations.