A customer, a hacker and a regulator — and now a fourth reader that isn't a person at all: an AI. We read your site the way each of them does, and tell you in plain English what they'd each find: the security holes, the Australian compliance gaps, and the things quietly costing you customers.
Great tool for keeping our website compliant. AegorIQ clearly showed us what needed fixing for compliance and cyber security — highly recommend for any business wanting a proper website health check.
I had a great experience with the AegorIQ website compliance and security check — straightforward and easy to understand. It identified potential security and compliance issues and gave me greater confidence the necessary areas were being checked. Professional, reliable and helpful — I’d recommend it to anyone who wants to make sure their website is compliant and protected.
Anyone can confirm a link isn't broken. We tell you which Privacy Act elements your policy never mentions, and where your refund wording strays into language the ACL doesn't allow. Then we do the same for the hacker's view and the customer's — security, compliance and experience, in one report. Most checks only ever look for the hacker.
See pricingMost of this market sells you half an answer — a security scanner that knows nothing about Australian law, or a compliance consultant who never looks at your server. The firms that do cover both will quote you five figures for it. Neither half works alone, and both halves shouldn't cost more than the business is making.
A privacy policy is a written promise about how you handle someone's data. If your website isn't secure, you haven't just failed to protect that data — you have published a promise you cannot keep. That is a worse place to stand than saying nothing, because the obligation is now documented, in your own words, on your own website.
And this isn't our opinion. The Privacy Act says it: APP 11 requires you to take reasonable steps to protect the personal information you hold. Security is not adjacent to your compliance — it sits inside it. A beautiful privacy policy on an unpatched website isn't compliance. It's a document contradicting itself.
It runs the other way too. You can have flawless security — every certificate current, every plugin patched — and still lose the business, because nobody outside your server ever sees any of it. What a customer sees is your refund page. What a regulator reads is your terms. Get those wrong and you don't get hacked; you just quietly stop being trusted, which takes far longer to notice and far longer to repair.
The most compliant website in Australia is worthless if the data behind it isn't protected. The most secure website in Australia is worthless if nobody trusts the business running it. They aren't alternatives. They're two halves of one question — can this business be trusted with my details? That is why we do one report instead of two.
Every finding comes from a real check on your live site. Nothing is guessed, nothing is invented — and where a judgement is a legal one, we say so rather than pretend an algorithm can rule on it.
We open the policy and check it against the elements the Australian Privacy Principles expect: what you collect, whether it goes overseas or to third parties, how it's stored, how someone makes a complaint, and when it was last updated.
We read your terms and refund pages for blanket “no refunds” and “all sales are final” wording. Consumer guarantees can't be excluded, so those statements can be unlawful — and the ACCC actively enforces against them.
SPF, DKIM and DMARC, plus the misconfiguration most checks miss entirely: duplicate records. Publish two DMARC records and receivers ignore DMARC completely — so you look protected while anyone can spoof you.
A scanner hands you a technical string and leaves. We answer the three things you actually need to make a decision — what is wrong, why it matters to your business, and how to fix it. Plain English isn't our tone of voice. It's the product.
No subscription. No monthly fee for a dashboard you'll never open. You buy one report and you own it — and then we stay with you while you actually fix things. Free re-scans for 90 days, until every issue is closed. A returning-customer price whenever you want a fresh check. Quietly, on your terms, and never locked in.
Below is every single check, in plain English. No "and more", no asterisks.
That's the complete list — and here's what we don't check, which we think matters just as much. This is a website health check, not a penetration test, and we say so in every report.
Most security reports get read once, feel alarming, and then sit in a folder. Not because owners don't care — but because nothing helps them get from "here's what's wrong" to "it's fixed." That gap is the part we stayed for. None of it costs you another cent, and none of it ties you to anything.
Fix something, click re-scan, and we'll confirm it's actually gone. As often as you need, for 90 days. You get a simple progress view: what you've fixed, what's still open.
A rule changes, or a vulnerability lands in software your site was actually running — we email you. Not a newsletter blast: we check it against the components we found on your site, and we tell you how to check and fix it yourself, in plain English.
Redesigned the site? New plugin? Rule change? Come back for a fresh check at $147 (Essentials) or $397 (Expert) — because we already know your site and we don't have to find you again. Your code arrives before your free re-scans close, and it's good for two years.
Expert re-scans are automated progress checks, delivered in minutes — your original expert review stands with your first report.
Every tier runs the same accurate scan. What changes is how much you see — and whether we hand you the fix.
| What we check | Scorecard Free |
Essentials |
Expert |
|---|---|---|---|
| Compliance — we read your policies | |||
| Privacy policy depthWhich Privacy Act elements are missing | count | named | named + fix |
| Refund wording vs Australian Consumer LawBlanket “no refunds” flagged for review | count | named | named + fix |
| Terms, shipping policy, ABN & contact details | count | named | named + fix |
| Cookie consent, tracking & sign-up consentRegion-aware, plus Spam Act consent on your forms | count | named | named + fix |
| Security | |||
| Email spoofing — SPF, DKIM, DMARC | count | named | + setup steps |
| Duplicate SPF/DMARC recordsSilently switches your protection off | count | named | named + fix |
| SSL, security headers, malware blacklist | count | named | named + fix |
| Software vulnerabilities (WordPress/CVE) | count | named | named + fix |
| Public exposure — CORS & exposed usernamesCommon misconfigurations that leak data or aid break-ins | — | named | named + fix |
| Domain security — expiry, transfer-lock, DNSSEC | — | named | named + fix |
| Does your site work — and look current? | |||
| Mobile-friendly, broken links & content freshnessWhether your site works for visitors and doesn't look out of date | count | named | named + fix |
| Placeholder & template contentUnrenamed builder templates or filler text that make a site look half-built | count | named | named + fix |
| AI Readiness | |||
| Is your site ready for AI to find you?6 on-page signals AI assistants (ChatGPT, Perplexity, Google) use to discover & understand you — informational, doesn't affect your score | score | named | named + plan |
| Expert only | |||
| 14 deep security scansExposed files, leaked secrets, directory listing, XML-RPC, ports, subdomain takeover, TLS strength, and more | — | — | ✓ |
| Performance & SEO (Google Lighthouse) | — | — | ✓ |
| Reviewed by a cybersecurity professional | — | — | ✓ |
| Step-by-step fix for every issue | — | — | ✓ |
So we don't pretend it can. Every Expert report is read by a cybersecurity professional before it reaches you — someone who looks at your specific site, writes commentary on what actually matters, and signs their name to it.
Where a question is a legal one — like whether your refund wording breaches the ACL — we flag it for professional review rather than pretending an algorithm can rule on it.
We never ask for your password, your hosting login, or access to anything. Everything we read is already visible to the outside world — which is exactly why it's worth reading.
We check straight away whether we can actually read your site properly. If we can't deliver a complete report, we tell you before you pay — not after.
Your configuration, your certificates, your DNS and email records, your links — and the inside of your privacy policy, terms and refund pages. Every finding comes from a real check.
What's wrong, why it matters for your business, and what to do about it — in plain English. On Expert, a security professional reads it before you do.
A plain-English website compliance & security checklist for Australian small businesses — the same ground our report covers, as a one-page PDF you can work through yourself. No scan, no payment, just useful.
Charities hold donor details and volunteer records, usually with nobody looking after the website. So if you're on the ACNC register, we'll check your site and send you the full Essentials report at no cost — no catch, no sales call. We cover it ourselves; paying customers are what let us keep doing it.
Know a charity that could use one? We never email charities out of the blue, so someone telling them is the only way they hear about it.
The free Scorecard is a real scan, not a teaser. It tells you how many issues we found and where they are — and you can stop right there if that's all you need.