The Privacy area covers 178 providers: consent management, data subject rights, data classification, PII detection, and the privacy-first analytics tools that grew up around GDPR. The median Kin Score across the 176 that are scored is 31.25. Ten are exemplar and 19 strong. The rest fall into developing (38), thin (36), emerging (43) and minimal (30).
The finding sits in the agent-readiness record. The agent-readiness rubric includes a consent identity dimension. It reads whether a provider publishes its own terms for automated clients, through AI preference signals, Content-Signal, Web Bot Auth or HTTP message signatures. In the privacy area, one provider lights it: the Confidential Computing Consortium, a Linux Foundation project that scores 31.5 overall. None of the consent-management vendors do.
The consent vendors
| Provider | Kin Score | Band | Agent Readiness |
|---|---|---|---|
| Didomi | 81.0 | exemplar | 30.4 |
| OneTrust | 72.7 | exemplar | 55.9 |
| Sourcepoint | 57.5 | strong | 30.8 |
| Osano | 54.4 | strong | 31.5 |
| TrustArc | 52.5 | developing | 38.7 |
| Transcend | 52.2 | developing | 26.1 |
| Usercentrics | 44.9 | developing | 19.0 |
| Ketch | 39.3 | developing | 17.3 |
| TrueVault | 32.5 | thin | 5.4 |
Didomi’s 81.0 is the top score in the area. OneTrust pairs 37 APIs with the best agent-readiness among the consent vendors. These are good API records. What none of them does is apply its own product to the agents calling it.
Fairness first
This is not a privacy-industry failure. Consent identity is a frontier dimension, which means only the provider can produce the evidence. Across the full catalog, 102 of 29,172 providers light it. Privacy’s one in 178 is slightly better than the catalog as a whole. The standards behind it are new, and most of the web has not adopted them.
The irony still holds. A consent-management platform’s whole product is a machine-readable statement of what a visitor has agreed to, and how that statement is enforced downstream. The same companies do not publish a machine-readable statement of what an automated visitor may do with their content. They also do not verify which agent is asking.
What the rest of the area says
Privacy-first analytics holds up much of the top of the table. Swetrix (77.0), Matomo (70.0), Pirsch (68.5) and Rybbit (68.2) are all exemplar. These are small, open, cookieless analytics tools with clean public APIs, and they outscore most of the enterprise privacy suites.
The regulator is agent-native. The California Privacy Protection Agency scores 55.4, strong, and reads agent-native on Agent Readiness. A state agency publishes a more agent-ready surface than most of the companies selling compliance with its rules.
Most of the area is human-only. 74 of 178 read human-only, and 64 more agent-aware. 29 list an MCP server in the catalog.
Takeaway
Privacy vendors already build consent signals for a living. Publishing one for their own developer surface, and verifying the agents that arrive there, would lift the dimension this area should lead on. It would also make the category the first to live by its own standard.
Explore the area at privacy.apievangelist.com, or browse its providers on apis.io/areas/privacy/.