New DXComply release enables privacy, GRC and security teams to verify whether native apps honor user consent choices without SDK integration or code changes.
Toronto, Canada, September 23, 2026: Feroot Security Inc. today announced expanded native mobile application consent auditing capabilities in DXComply, enabling enterprises to verify whether iOS and Android apps honor users’ consent choices without requiring SDK integration or changes to application code. The enhancement extends DXComply’s continuous consent auditing capabilities with a code-free approach to native apps, giving privacy, GRC and security teams visibility into consent behavior without adding development work or instrumentation to the applications being audited.
DXComply works alongside an organization’s existing consent management platform (CMP) to verify what happens after a user makes a consent choice. Findings connect the consent choice with observed vendor activity and the destination of resulting requests, giving teams evidence to identify, investigate and remediate consent gaps across their websites and mobile apps.
The announcement follows research commissioned by Feroot and conducted by Censuswide among 800 privacy, security and GRC leaders. The research found that only 24% of organizations continuously verify that consent controls are enforced, while 89% reported experiencing a vendor changing its data collection practices without notice. Separately, Feroot conducted technical consent audits across 92 companies and found that 93% of websites tested continued loading advertising or tracking vendors after a visitor exercised the Global Privacy Control browser signal.
A recorded consent choice alone does not establish that downstream scripts, SDKs, and vendors continue to honor that preference. As digital experiences change, third-party technologies can introduce new data collection behavior that may not align with the user’s choice. Continuously auditing that behavior across websites, applications and jurisdictions can be difficult to perform manually at scale. Native mobile applications add another layer of complexity, as verifying consent behavior has traditionally required source code access, SDK integration or manual instrumentation.
“A consent management platform can be perfectly configured, but recording a consent choice alone does not show what actually happens on the page or mobile screen,” said Ivan Tsarynny, CEO of Feroot Security. “With this release, DXComply expands its native mobile capabilities with external auditing that requires no SDK integration or changes to application code. Combined with internal auditing, teams get a more complete view of whether user choices are actually honored, along with evidence of the vendor activity and request destinations observed after a choice is made.”
DXComply: Code-Free Mobile Consent Audit and Expanded Compliance Capabilities
The enhanced DXComply platform includes:
- Code-free native app consent auditing: Audit consent behavior across supported iOS and Android user journeys without SDK integration or changes to application code.
- Verifiable consent evidence: Connect user consent choices with observed vendor activity and request destinations to show what occurred after a choice was made.
- Prioritized findings: Surface consent gaps and provide context to help privacy, engineering and legal teams determine what to investigate and remediate first.
- Integrated remediation workflows: Route findings into existing workflows through integrations with tools such as Jira, ServiceNow and Slack.
- Cross-border data flow visibility: Trace where observed data requests travel, providing visibility beyond a vendor’s stated country of registration.
DXComply preserves dated, exportable evidence behind findings, including observed consent behavior, vendor activity, request destinations and supporting session data. This gives teams a record they can use to investigate consent gaps, support remediation and demonstrate how consent controls are operating across their digital experiences.
Availability
The enhanced DXComply consent audit, including native mobile application auditing without SDK integration or code changes, is available now. DXComply is one of three products within the Feroot Digital User Experience Security and Compliance Platform, alongside DXSecure, which protects against malicious scripts and data exfiltration, and PaymentGuard, which automates PCI DSS 4.0.1 compliance.
To learn more about DXComply or request a demo, visit feroot.com/dxcomply.
About Feroot Security
Feroot Security Inc. provides an AI-powered digital user experience security and compliance platform. Its products, DXComply, DXSecure and PaymentGuard, protect sensitive user data and automate compliance across websites and mobile applications, supporting more than 70 global regulations, frameworks and standards, including PCI DSS 4.0.1 Req. 6.4.3 and 11.6.1, HIPAA, GDPR and CCPA. More information is available at www.feroot.com.