Free for charities. Every Australian registered charity can have the full report at no cost — we cover it. Claim yours →
The Australian website compliance & security check

Your website is read by three people
you never meet.

A customer, a hacker and a regulator — and now a fourth reader that isn't a person at all: an AI. We read your site the way each of them does, and tell you in plain English what they'd each find: the security holes, the Australian compliance gaps, and the things quietly costing you customers.

No credit card. Results emailed to you. We only scan sites you own or are authorised to check.
Your report
Website Risk Review
yourbusiness.com.au
Prepared
11 July 2026
66/ 100
Needs attention — 8 items
Security5.5
Privacy10
Compliance2.5
Performance10
Blanket “no refunds” wording found — flagged for professional review under the Australian Consumer Law
Privacy policy is missing 2 of the 5 elements we check — overseas disclosure, and how to make a complaint
Domain is not transfer-locked — a common domain-hijacking route
Email spoofing protection enforced (SPF, DKIM, DMARC)
AI Readiness: 4 of 6— how ready your site is for AI to discover it
Trusted by Australian business
Circle Finance
Great tool for keeping our website compliant. AegorIQ clearly showed us what needed fixing for compliance and cyber security — highly recommend for any business wanting a proper website health check.
Jenny Budiman Director, Circle Finance Circle Finance is the property purchase partner that manages the whole journey — readiness, finance, due diligence and settlement — from “can we afford it?” to the day you get the keys.
Blackburn Family Dental Care
I had a great experience with the AegorIQ website compliance and security check — straightforward and easy to understand. It identified potential security and compliance issues and gave me greater confidence the necessary areas were being checked. Professional, reliable and helpful — I’d recommend it to anyone who wants to make sure their website is compliant and protected.
Dr Alvin Shee Principal Dentist, Blackburn Family Dental Care Blackburn Family Dental Care has been the trusted dentist in Blackburn North and surrounds for over 60 years, taking pride in the care of your teeth and the quality of their treatment.
The difference

We don't just check that your privacy policy exists.
We open it and read it.

Anyone can confirm a link isn't broken. We tell you which Privacy Act elements your policy never mentions, and where your refund wording strays into language the ACL doesn't allow. Then we do the same for the hacker's view and the customer's — security, compliance and experience, in one report. Most checks only ever look for the hacker.

See pricing
What a tick-box scan tells you
“Privacy policy: found. Terms: found.” A list of technical scores, and you're left to work out what any of it means for your business.
What AegorIQ tells you
“Your policy doesn't say how someone makes a privacy complaint, or whether data goes overseas. Your terms contain blanket ‘no refunds’ wording that can be unlawful under the ACL.” Then: what to do about it — reviewed by a security professional on the Expert tier.
Why one report, not two

Compliance is what you promise.
Security is whether you can keep it.

Most of this market sells you half an answer — a security scanner that knows nothing about Australian law, or a compliance consultant who never looks at your server. The firms that do cover both will quote you five figures for it. Neither half works alone, and both halves shouldn't cost more than the business is making.

A privacy policy is a written promise about how you handle someone's data. If your website isn't secure, you haven't just failed to protect that data — you have published a promise you cannot keep. That is a worse place to stand than saying nothing, because the obligation is now documented, in your own words, on your own website.

And this isn't our opinion. The Privacy Act says it: APP 11 requires you to take reasonable steps to protect the personal information you hold. Security is not adjacent to your compliance — it sits inside it. A beautiful privacy policy on an unpatched website isn't compliance. It's a document contradicting itself.

It runs the other way too. You can have flawless security — every certificate current, every plugin patched — and still lose the business, because nobody outside your server ever sees any of it. What a customer sees is your refund page. What a regulator reads is your terms. Get those wrong and you don't get hacked; you just quietly stop being trusted, which takes far longer to notice and far longer to repair.

The most compliant website in Australia is worthless if the data behind it isn't protected. The most secure website in Australia is worthless if nobody trusts the business running it. They aren't alternatives. They're two halves of one question — can this business be trusted with my details? That is why we do one report instead of two.

What Australian law actually requires of your website →

What we read

Three things a tick-box can't tell you.

Every finding comes from a real check on your live site. Nothing is guessed, nothing is invented — and where a judgement is a legal one, we say so rather than pretend an algorithm can rule on it.

01

Your privacy policy — the inside of it

We open the policy and check it against the elements the Australian Privacy Principles expect: what you collect, whether it goes overseas or to third parties, how it's stored, how someone makes a complaint, and when it was last updated.

You get: “Your policy is missing 2 of the 5 elements we check — overseas disclosure, and how to make a privacy complaint.”
02

Your refund terms — against the ACL

We read your terms and refund pages for blanket “no refunds” and “all sales are final” wording. Consumer guarantees can't be excluded, so those statements can be unlawful — and the ACCC actively enforces against them.

You get: the exact wording, where it appears, and a lawful alternative — flagged for professional review, never a legal ruling.
03

Your email — including what's silently broken

SPF, DKIM and DMARC, plus the misconfiguration most checks miss entirely: duplicate records. Publish two DMARC records and receivers ignore DMARC completely — so you look protected while anyone can spoof you.

You get: whether your protection is genuinely working — not just whether a record exists.

Plain English

Every finding answers three questions.

A scanner hands you a technical string and leaves. We answer the three things you actually need to make a decision — what is wrong, why it matters to your business, and how to fix it. Plain English isn't our tone of voice. It's the product.

What a scanner tells you
Missing header:
Content-Security-Policy
Technically true.
Now what?
What AegorIQ tells you
What
Your site is missing a protection that stops attackers injecting code into your pages. It's a single line of configuration that tells the browser what it's allowed to load.
Why it matters
This is the gap used to skim card details at checkout — malicious code runs on your page and you never see it. The ACSC puts the average cost of a cyber incident for an Australian small business at $56,600.
How to fix it
Add the policy to your site's configuration — about ten minutes for your developer. Your report gives the exact line to paste, and where to put it for your platform.
Essentials names every issue and tells you what to do about it. Expert adds the step-by-step instructions — and a cybersecurity professional's read on which ones actually matter for your site.
Pricing

Pay once. And we don't disappear.

No subscription. No monthly fee for a dashboard you'll never open. You buy one report and you own it — and then we stay with you while you actually fix things. Free re-scans for 90 days, until every issue is closed. A returning-customer price whenever you want a fresh check. Quietly, on your terms, and never locked in.

Founders pricing — Essentials $197 $109, Expert $497 $309. Limited to the first 300 reports.

Below is every single check, in plain English. No "and more", no asterisks.

Essentials
Know exactly where you stand.
AUD $109
$197 Founders price · first 300
One-off · AUD · report within 2 hours
Get Essentials
Choose Essentials now, upgrade later: move up to Expert within 30 days and pay only the $200 difference.
35 checks · including your AI Readiness score · every issue named, in plain English
    Your policies — we actually read them
  • Does the Privacy Act even apply to you?Most small businesses under $3m turnover aren't covered by it — but childcare, allied health and several other industries are, whatever their size. We tell you where you actually stand, instead of assuming the answer that sells more.
  • Privacy policy depth — the 5 elements we checkWe open your policy and name what's missing: overseas disclosure, how to make a complaint, what you collect, how it's stored, when it was last updated. Almost nothing else on the market reads the inside of the document.
  • Refund wording checked against the Australian Consumer LawBlanket "no refunds" can be unlawful and the ACCC enforces it. We read your terms and flag the exact wording.
  • Privacy Policy presentRequired the moment you collect a name or an email address.
  • Terms & Conditions presentThe contract behind every sale you make.
  • Returns & refund policy presentWhat the Australian Consumer Law expects if you sell anything.
  • Shipping & delivery policyDo customers know delivery times and costs before they pay?
  • Can customers trust you're real?
  • ABN & business identityCan people check you're a genuine registered business?
  • Contact details visibleCan customers actually reach you — phone, email, or contact page?
  • Business address / locationCan they see where you're based?
  • Spam Act consent (pre-ticked boxes)A pre-ticked sign-up box isn't valid consent — it can make your whole mailing list unlawfully collected.
  • Can someone pretend to be you?
  • Email spoofing protection — SPF, DKIM & DMARCCan scammers send emails pretending to be you? This is what stops fake invoices reaching your customers.
  • Duplicate SPF / DMARC recordsThe mistake almost nobody checks: publish two records instead of one and your protection is silently switched off completely. You look protected. You aren't.
  • Registrar transfer lockCould someone steal your domain name? A free setting most businesses have never turned on.
  • DNSSECCould someone forge your web address and redirect your customers to a fake site?
  • Domain expiryAn expired domain takes your website and your email offline — and anyone can then buy it.

    Note: we cannot perform this check on .au domains. auDA deliberately withholds expiry dates from the registry (scrapers were using them to send fake renewal notices), so no tool can look it up — ours included. We say so in your report, and show you how to check it yourself in two minutes.
  • Is your site safe for visitors?
  • SSL certificate & HTTPSDoes your site show the padlock — or does the browser say "Not secure"?
  • Security headers (5 checked)The browser protections that stop attackers hijacking your pages or injecting code into them.
  • Malware & phishing blacklistHas Google flagged your site as dangerous? If so, most visitors never get past the red warning screen.
  • Known software vulnerabilities (WordPress core, themes & plugins)Is your website software out of date and known to be hackable? Checked against a live vulnerability feed.
  • Cross-origin (CORS) exposureCan any other website quietly make logged-in requests to yours and read the answers? A common misconfiguration that can leak customer data sideways.
  • Exposed usernames (WordPress)Is your list of login names public? That hands an attacker the hardest half of breaking in — they only have to guess the password.
  • Payment handlingDoes your checkout keep card details off your own servers?
  • Who's watching your visitors?
  • Tracker detectionWhich analytics and advertising tools are running on your site — named, not just counted.
  • Cookie consent noticeAre visitors told about tracking before it starts?
  • Region-aware consent rules (EU / UK)Sell overseas and you're under their cookie law too. We apply it if you tell us you have customers there.
  • Does your site actually work?
  • Broken linksDead links sending your customers to error pages. We crawl your site and test them.
  • Mobile-friendlinessDoes your site work properly on a phone — where most of your customers are?
  • And in your report
  • Your AI Readiness score — how ready your site is for AI to find youSix on-page signals AI assistants like ChatGPT and Perplexity use to discover and understand your business. As more customers find businesses through AI, it's one more blind spot we help you catch — shown for your awareness, it doesn't affect your score.
  • Every issue named — what, where and whyNot "missing Content-Security-Policy header" and good luck. Plain English, every time.
  • Step-by-step fix for anything critical — freeWe won't leave a small business sitting on a serious problem because they bought the cheaper report.
  • Anything we couldn't check, we tell you"Not tested" is a real answer. We never pass a blind spot off as a pass.
30-day money-back guarantee. In addition to your rights under the Australian Consumer Law. Refund policy
Expert reviewed
Expert
Know how to fix it — checked by a human.
AUD $309
$497 Founders price · first 300
One-off · AUD · report within 3 business days
Get Expert
49 checks · a cybersecurity professional reads every report
Everything in Essentials — all 35 checks.Every line on the left, in full. Then all of this on top.
    A human being reads it
  • Expert review by a cybersecurity professionalThey read your specific site before you do, and tell you which two things actually matter this month — and which can wait. No software can make that call.
  • Step-by-step fix for every issueNumbered instructions you can hand straight to your web developer.
  • Prioritised remediation planWhat to fix first, and what can safely wait — so you're not staring at a list of twenty things.
  • AI Readiness action planYour on-page AI Readiness score, plus the specific, prioritised steps to help AI assistants like ChatGPT and Perplexity find and recommend your business — including the off-site factors a scan alone can't fix.
  • 14 deeper scans Essentials doesn't run
  • Exposed sensitive filesAre private config files, admin pages or repository data sitting on your site for anyone to download? Attackers scan for these daily.
  • Directory listingCan a stranger browse and download every file in your folders — backups, spreadsheets, invoices — just by visiting the folder? "Not linked" isn't the same as "not public".
  • WordPress XML-RPC exposureIs the legacy feature that lets attackers try hundreds of passwords in one request — and overload your site — left switched on? Most sites don't need it.
  • Leaked API keys & secrets in your codeAre your passwords or access keys visible in the code your site sends to every visitor's browser?
  • Exposed backup & config filesCan anyone download a full copy of your website — often including your database password?
  • Payment-skimming surface (third-party script integrity)Could a hacked third-party script steal card details at your checkout? This is the attack that hit British Airways and Ticketmaster.
  • Insecure cookiesCould someone hijack a logged-in customer's session?
  • Subdomain takeover riskCould someone claim an abandoned part of your domain and phish your customers from your own web address?
  • Exposed non-production subdomainsAre your test, staging or admin sites publicly visible? They're usually far less protected than your real site.
  • Exposed service portsAre there admin doors left open to the internet? A safe, limited check.
  • TLS / encryption strengthDoes your server still accept old, insecure connections that fail modern standards?
  • Mixed contentAre parts of your secure page loading insecurely — quietly breaking the padlock your customers rely on?
  • Advanced email security (MTA-STS & TLS-RPT)Is your email encrypted on its way to your customers, and are you told when it isn't?
  • Performance & SEO (Google Lighthouse)How fast is your site really, and can Google read it properly? Includes Core Web Vitals.
30-day money-back guarantee. Optional 30-minute walkthrough call available at checkout. Refund policy

That's the complete list — and here's what we don't check, which we think matters just as much. This is a website health check, not a penetration test, and we say so in every report.

After the report

We don't monitor your website.
We just don't disappear.

Most security reports get read once, feel alarming, and then sit in a folder. Not because owners don't care — but because nothing helps them get from "here's what's wrong" to "it's fixed." That gap is the part we stayed for. None of it costs you another cent, and none of it ties you to anything.

01

Free re-scans for 90 days — until it's fixed

Fix something, click re-scan, and we'll confirm it's actually gone. As often as you need, for 90 days. You get a simple progress view: what you've fixed, what's still open.

Because the point was never the report. It was the fixed website.
02

We tell you when something changes

A rule changes, or a vulnerability lands in software your site was actually running — we email you. Not a newsletter blast: we check it against the components we found on your site, and we tell you how to check and fix it yourself, in plain English.

Rarely. Only when it's real. We will never email you to manufacture urgency.

Want more than that — guides, tips, what's changing? Follow us on LinkedIn or Instagram. That's your choice to make, not ours.
03

Come back whenever — at a returning price

Redesigned the site? New plugin? Rule change? Come back for a fresh check at $147 (Essentials) or $397 (Expert) — because we already know your site and we don't have to find you again. Your code arrives before your free re-scans close, and it's good for two years.

No renewal date. No auto-billing. Nothing to cancel.

Expert re-scans are automated progress checks, delivered in minutes — your original expert review stands with your first report.


Compare

Same engine. Different depth.

Every tier runs the same accurate scan. What changes is how much you see — and whether we hand you the fix.

What we check Scorecard
Free
Essentials
$197 $109
Expert
$497 $309
Compliance — we read your policies
Privacy policy depthWhich Privacy Act elements are missingcountnamednamed + fix
Refund wording vs Australian Consumer LawBlanket “no refunds” flagged for reviewcountnamednamed + fix
Terms, shipping policy, ABN & contact detailscountnamednamed + fix
Cookie consent, tracking & sign-up consentRegion-aware, plus Spam Act consent on your formscountnamednamed + fix
Security
Email spoofing — SPF, DKIM, DMARCcountnamed+ setup steps
Duplicate SPF/DMARC recordsSilently switches your protection offcountnamednamed + fix
SSL, security headers, malware blacklistcountnamednamed + fix
Software vulnerabilities (WordPress/CVE)countnamednamed + fix
Public exposure — CORS & exposed usernamesCommon misconfigurations that leak data or aid break-insnamednamed + fix
Domain security — expiry, transfer-lock, DNSSECnamednamed + fix
Does your site work — and look current?
Mobile-friendly, broken links & content freshnessWhether your site works for visitors and doesn't look out of datecountnamednamed + fix
Placeholder & template contentUnrenamed builder templates or filler text that make a site look half-builtcountnamednamed + fix
AI Readiness
Is your site ready for AI to find you?6 on-page signals AI assistants (ChatGPT, Perplexity, Google) use to discover & understand you — informational, doesn't affect your scorescorenamednamed + plan
Expert only
14 deep security scansExposed files, leaked secrets, directory listing, XML-RPC, ports, subdomain takeover, TLS strength, and more
Performance & SEO (Google Lighthouse)
Reviewed by a cybersecurity professional
Step-by-step fix for every issue
count — how many issues we found  ·  score — your AI Readiness, out of 6  ·  named — exactly what and where  ·  + fix / + plan — step-by-step instructions to resolve it, and for AI Readiness a tailored action plan
Scorecard results are emailed to you. Essentials and Expert are backed by our 30-day money-back guarantee.
Started with Essentials? You can upgrade to Expert within 30 days of purchase for just the $200 difference — the upgrade link is in your report email.

The human layer

An automated scan can't make a judgement call.

So we don't pretend it can. Every Expert report is read by a cybersecurity professional before it reaches you — someone who looks at your specific site, writes commentary on what actually matters, and signs their name to it.

Where a question is a legal one — like whether your refund wording breaches the ACL — we flag it for professional review rather than pretending an algorithm can rule on it.

“Two of these findings matter far more than the other six. Fix the refund wording this week — the ACCC actively enforces it. The rest can wait a month.”
Expert-reviewed before delivery
Cybersecurity professional, AegorIQ

How it works

Three steps. Nothing to install.

We never ask for your password, your hosting login, or access to anything. Everything we read is already visible to the outside world — which is exactly why it's worth reading.

01

Tell us your website address

We check straight away whether we can actually read your site properly. If we can't deliver a complete report, we tell you before you pay — not after.

02

We read your site

Your configuration, your certificates, your DNS and email records, your links — and the inside of your privacy policy, terms and refund pages. Every finding comes from a real check.

03

You get answers, not a score

What's wrong, why it matters for your business, and what to do about it — in plain English. On Expert, a security professional reads it before you do.

Not ready for a scan? Start with the free checklist.

A plain-English website compliance & security checklist for Australian small businesses — the same ground our report covers, as a one-page PDF you can work through yourself. No scan, no payment, just useful.

Get the free checklist

Every Australian registered charity can have this report free.

Charities hold donor details and volunteer records, usually with nobody looking after the website. So if you're on the ACNC register, we'll check your site and send you the full Essentials report at no cost — no catch, no sales call. We cover it ourselves; paying customers are what let us keep doing it.

Know a charity that could use one? We never email charities out of the blue, so someone telling them is the only way they hear about it.

Free reports for charities
Start with the free one

Find out what your website is telling people.

The free Scorecard is a real scan, not a teaser. It tells you how many issues we found and where they are — and you can stop right there if that's all you need.