A serious security assessment costs thousands. A compliance review costs thousands more, and it's a separate engagement, with a separate consultant, producing a separate document you still have to decode. That's a rational price for a company with a security team. It is an impossible one for a café, a physio practice, or a two-person online shop — the businesses with the least to spend and the most to lose.
Cybercrime now costs the average Australian small business $56,571 per incident — up 14% in a single year, on the Australian Signals Directorate's own numbers. The figure for a large business is higher still, but that's rather the point: a large company absorbs a loss like that. A small one often doesn't survive it.
At the same time the rules keep tightening. Privacy Act reform is under way. The unfair trading ban lands in 2027. None of it arrives with an explanation attached, and none of it cares how many hats you're already wearing.
And here is the part almost nobody realises: you may well be exempt from the Privacy Act. You are not exempt from the Australian Consumer Law. The ACL has no small-business carve-out and never has. It governs what your returns page is allowed to say — and the ACCC sweeps online return policies and terms and conditions looking for exactly that. A blanket “no refunds”, or “no refunds on sale items”, or a 72-hour limit on faults, is likely to be misleading — and it is sitting on thousands of Australian websites right now, pasted in from a template years ago by someone who has since moved on.
The penalties are not theoretical. In November 2024 the furniture retailer Koala Living paid $56,340 after ACCC infringement notices over misleading statements about customers' rights to a remedy. In June 2025 the online marketplace Reebelo paid $59,400 for much the same thing. Reports to the ACCC about consumer guarantees rose 20% to more than 38,000 in 2025. Notice the size of those numbers: they land in the same range as the average cybercrime loss. Two entirely different ways to lose the same $56,000.
But the money is rarely the worst of it. Nobody finds out their website was non-compliant on a quiet day — they find out through a complaint, a notice, a customer who feels misled and says so publicly. And the thing that took years to build, the reason people chose you over the cheaper option down the road, can go in an afternoon. Trust is slow to earn and quick to lose, and it is almost always the most expensive thing on the invoice.
So here is the part that's easy to miss: it was never that small business owners didn't care. Every owner we've spoken to cares a great deal — it's their name on the door and their customers' details in the database. What they don't have is a spare $5,000, a spare fortnight, and a working knowledge of DMARC records.
They were not careless. They were left out. The tools existed; they were simply built and priced for someone else.
So that's what AegorIQ is for. One scan, covering both security and Australian compliance, written so a business owner can actually act on it, at a price a small business can actually pay. We want to make security and compliance accessible to every Australian small business — one scan at a time.
Sources. Cybercrime cost: ASD Annual Cyber Threat Report 2024–25 — average self-reported cost per report, small business $56,571 (up from $49,615). Consumer law penalties and reporting figures: ACCC media releases (Koala Living, November 2024; Reebelo Australia, June 2025).
We publish the source for every number on this page, because we ask you to check our findings and it would be strange not to hold our own claims to the same standard. Any figure we can't attribute, we don't print. That rule cost us some more alarming statistics.
AegorIQ reviews the parts of your website the outside world can already see — your security configuration, your DNS and email records, your certificates, your broken links — and then goes a step further: it opens your privacy policy, your terms and your refund page and reads what's actually inside them.
And increasingly, a fourth reader matters: the AI assistants — ChatGPT, Perplexity, Google's AI answers — that more and more customers use to find businesses. So we also check how ready your site is for them to discover and understand you. It's informational, not a grade, and it doesn't affect your score — but it's one more blind spot most sites don't know they have.
Then we explain, in plain English, what each finding means for your business and what to do about it. Not a score. Not a list of acronyms. An answer to three questions: what's wrong, why it matters, and how to fix it.
You pay once. There's no subscription and nothing to cancel. And we don't fix websites, take commission, or sell your data — so there is no version of this business where we make more money by finding you more problems.
The mechanics — what's in each tier, what happens after, what we do with your data — are all answered on the FAQ.
We don't ask anyone to take us on faith. We've made everything transparent: exactly what we check, how every finding is produced, the human who reviews it, and the things we will never do. Read it, then judge for yourself — that's the whole point of this page.
Most companies publish what they will do. In this category, what a business won't do tells you more.
That's the most common opening line of a website scam. You come to us — always.
No uninvited scans, no database of other people's weaknesses, no "surprise audits" as a sales tactic.
Your findings are yours, behind a private link only you have. Not sold to insurers or marketers. Ever.
It isn't one, and we say so in every report. Overclaiming is how this industry lost people's trust.
There is a version of this product that would be easy to build and impossible to trust: point an AI at a website and let it decide what's wrong. We deliberately did not build that. What we found is determined by a real check — never guessed.
Every finding in an AegorIQ report is produced by a deterministic check against your live website. A real request, a real DNS lookup, a real reading of the page you actually published. If a check runs and finds something, we report it. If a check can't run, we tell you it wasn't tested — we don't fill the gap with a plausible guess.
That constraint costs us. It means our reports are sometimes shorter than you might expect, and it means we won't dress up an unverified hunch as a "critical risk". We think that's the right trade. A security report you can't trust is worse than no report at all, because it makes you act on the wrong things.
Every finding comes from a specific, repeatable check against your live site — never from an AI's guess about what might be wrong. Two scans of an unchanged site produce the same findings. Where we use AI, it's to help explain those findings in plain English — not to decide them.
When a check can't complete — an unreachable service, a JavaScript-rendered page we can't read — we say so plainly rather than reporting a false clean bill of health.
Where something is a legal judgement — like whether your refund wording breaches the ACL — we flag it for professional review. An automated scan doesn't get to decide that, and we won't pretend otherwise.
Automation is good at finding things. It is bad at judgement — at knowing which two of eight findings actually matter for your business this month.
Our reviews are led by a Security Principal Lead — a senior cyber security practitioner who has led security teams on major enterprise projects. Every Expert report is read by them before it reaches you, with written commentary on what matters most for your specific site, and what can safely wait.
As we grow, we're building a small bench of vetted cyber security engineers to share that review work. The standard won't change: a human reads your report before you do.
Everything below can be checked independently. That's the point of putting it here.
Read a real report before you spend anything — then run a free Scorecard on your own site and see whether what we tell you is useful.