If a question below has an answer that makes us look worse, we've written it anyway. That's the point of a page like this. A FAQ that only says flattering things isn't a FAQ, it's an ad.
No, and we won't pretend otherwise. A penetration test is a person actively attempting to break into your systems, with your written permission, usually costing several thousand dollars and taking days.
AegorIQ is a health check of the parts of your website that are publicly visible (your configuration, your DNS and email records, your certificates, your published policies) plus, on Expert, a set of deeper automated checks. It's genuinely useful, and it is not the same thing.
We say this in every report as well, because overclaiming is how this industry lost people's trust.
Free scanners are typically built to check one narrow technical thing and return a score. That can be a useful signal on its own, but a score doesn't tell you what to do next.
We focus on three things. We read the inside of your policies, not just check that a link exists. We tell you what a finding means for your business, not just that a header is missing. And we tell you what to do next, in steps you or your developer can follow.
We're also honest about our limits: if a check can't run, we say so rather than showing you a green tick.
It's a quick read on how ready your website is for AI assistants (the tools behind ChatGPT, Perplexity and Google's AI answers) to find, read and understand your business. We check six on-page signals, like whether AI crawlers are allowed to read your site, whether your content is readable without JavaScript, and whether you publish structured data.
You get a simple "X of 6" score with each signal explained, included in every report at no extra cost.
No. AI Readiness is shown for your awareness only, it doesn't affect your TrustScore, and a missing signal is an opportunity, not a fault. Your security and compliance results are what's scored; AI Readiness sits alongside them as a separate, informational readout.
It helps, but honestly, no scan can promise that, and we won't pretend otherwise. The six signals we check are the on-page half: making sure an AI can actually read and understand your site.
Whether an AI then recommends you is driven mostly by things off your website, being mentioned on other reputable sites, consistent business listings, and reviews. We show you where you stand on the part we can measure, and in the Expert report, what else to work on.
No. Never. We don't ask for logins, admin access, FTP, or hosting credentials, and you should be suspicious of any website security service that does before you've even bought anything.
Everything we check is either publicly visible or published in public records, the same things any visitor, customer or attacker can already see. That's deliberate: it means a scan can't break anything, and it means we never hold keys to your business.
No. We fetch a small number of pages, the way an ordinary visitor would, and we look up public DNS records. We don't hammer your server, we don't attempt to log in, and we don't try to exploit anything.
No. Every scan requires you to confirm you own the site or are authorised by the owner to check it.
We don't scan uninvited, we don't build a database of other people's weaknesses, and we don't run "surprise audits" as a sales tactic. If you manage websites for clients, you're welcome to scan them with your client's authorisation, that's what the confirmation is for.
Before you pay, we run a pre-flight check to see whether we can actually read your site. Some sites are built entirely in JavaScript, or sit behind protection that blocks automated readers. If we can't deliver a complete report, we tell you before you spend money, not after.
If a scan is partially limited, your report says exactly which checks we couldn't complete. We would rather hand you a report with honest gaps in it than a complete-looking report with invented answers in those gaps.
Free Scorecard tells you how many issues we found, by category. It's a real scan, not a teaser, but it doesn't name the issues.
Essentials ($79) names every issue, explains what each one means for your business, and gives you step-by-step fixes for anything critical.
Deep Scan ($149) adds the 16 deeper security scans Essentials doesn't run, exposed files, leaked keys, payment-skimming surface, TLS strength, accessibility and Lighthouse performance. All 52 checks. No professional review and no prioritised roadmap: those are Expert.
Expert ($497) adds a set of deeper automated checks, step-by-step fixes for every finding, and a human review. A senior security practitioner reads your report before you do and writes what actually matters for your site.
The full check-by-check breakdown is on the pricing section. No "and more", no asterisks.
Often it is, and we'll say so. If you have a straightforward site with no logins or online payments, and you're comfortable reading a report and doing the fixes yourself, Essentials is a complete, honest picture. It names every issue, explains why each one matters, and gives you the steps for anything critical.
If you want more scanning, that's Deep Scan ($149), the same 52 checks Expert runs, without the human layer. Expert ($497) earns its price differently. First, it runs deeper checks Essentials doesn't (things like exposed files, open service ports and advanced email protections) so it covers more of what an attacker would actually probe. Second, and more importantly, a senior security practitioner reads your report before you do: they cut any false alarms, weigh the findings for your specific site, and write plainly what to fix first and what can wait.
That human step is the real difference. An automated scan is accurate, but it hands you twenty findings and leaves you to work out which two actually matter this week. Choose Expert if you take payments or hold sensitive customer data, run WordPress, don't have a tech person, or you'd simply rather someone tell you what to do first: not just what's wrong.
To Deep Scan, yes. Within 30 days of your Essentials purchase you pay the $70 difference and get all 52 checks, the 16 deeper security scans run on your site as it is then. There's nothing to fill in again, and your free 90-day re-scan window carries over rather than restarting. The link is in your report email.
To Expert, no: and it's worth saying why. Expert isn't a bigger Deep Scan. The difference is a cybersecurity professional reading your specific site, writing a prioritised roadmap, and spending 45 minutes going through it with you. That person's time is the same whether or not you've bought anything before, so there's no “difference” to charge: Expert is $497, bought on its own terms.
As a rule the Privacy Act 1988 (Cth) applies to businesses with an annual turnover of more than $3 million. Below that you are generally a “small business operator” and outside the Act.
That is where most articles stop, and it is where most owners get it wrong. The exemption has carve-outs that catch ordinary small businesses: you provide a health service and hold health information (whatever your turnover); you are an AUSTRAC reporting entity, since 1 July 2026 that includes real estate agencies, accountants, lawyers, conveyancers and dealers in precious metals, though only for the personal information they handle for those anti-money-laundering obligations, not for the whole business; you buy or sell personal information; you are a contracted service provider under a Commonwealth contract; you are related to a larger covered business; or you have opted in.
This is general information about Australian law, the same for every reader. It is not advice about your situation, and we are not a law practice.
APP 1.4 sets out the minimum: what personal information you collect and hold, how you collect it and why, how someone can ask for access or correction, how to make a complaint and how you will handle it, whether you disclose anything overseas, and to which countries.
Beyond that list, a policy that is actually about your business has to deal with the things the list does not name: cookies, analytics and tracking, how long you keep information, and the Notifiable Data Breaches scheme where it applies to you.
It is 115 questions, and it is not a five-minute form. A full run takes about 15 to 20 minutes, longer if you need to check on something. Questions that do not apply to you are skipped.
We would rather say that up front than have you find out after paying. A policy is only about your business if something asks how your business works: what you collect, who you give it to, whether anything leaves the country, how long you keep it. If you want a quick generic template, this is not the right product for you.
No. They are two different products and neither replaces the other.
The builder ($59) writes the policy. The audit (from $79) reads your live website and tells you whether what is published there matches what you actually do, along with the security and Australian Consumer Law side of it.
A policy that says one thing while the site does another is the problem the audit exists to find.
Yes. For 30 days after purchase you can reopen your builder link, change any answer and generate the policy again at no extra cost. The link is emailed to you when you buy, so you do not need to keep the tab open.
Your answers themselves are not stored, so the questionnaire is best completed in one sitting.
No. The finished policy is emailed to you and written nowhere else: not to our database, not to a log, not to disk. The only copies that exist afterwards are yours and the one in your inbox.
We do keep your name, your email address and a record of what you agreed to at the start, which is what lets us send the policy and show consent if it is ever questioned.
No. AegorIQ is not a law practice and nothing the builder produces is legal advice. It writes a document from the answers you give about your own business.
If your circumstances are unusual, or you are unsure whether the Act applies to you, a lawyer or your accountant can tell you, and a lawyer can review what the builder produces.
PDF, Word (.docx), Word (.doc) and HTML. The HTML is the one to hand a web developer to publish on your site; the Word versions are there for anyone who needs to edit it afterwards.
From 10 December 2026, yes, but only if all three limbs of APP 1.7 are met. Personal information has to be used in a computer program; the program has to play a material role in making a decision; and the decision has to be one that could reasonably be expected to significantly affect someone's rights or interests.
It is broader than AI. A scoring tool, an eligibility rule or an automated approval can all count, and a person reviewing the output does not put the system out of scope. The OAIC counts the program's output whether it is advisory or determinative. The third limb is what keeps ordinary software out: a spam filter and a booking-slot allocator decide things about people and reach nobody's rights or interests.
If it applies, APP 1.8 requires three separate things in the policy: the kinds of information those programs use, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something materially relevant to a decision a person makes. The builder asks all three limbs, because asking only the first produces a formal disclosure for businesses that do not owe one.
Probably, and it is the section most often missing. Since 1 July 2026, providing a designated service listed in section 6 of the AML/CTF Act (with a geographical link to Australia under section 6(6)) makes you a reporting entity. The Privacy Act then treats a reporting entity as an organisation whatever its turnover, for the personal information it handles for those services.
So the $3 million exemption does not help you there: a two-person conveyancing practice is inside the Act for its client identity records. The privacy disclosure covers the identity documents you collect, that you cannot provide the service without them, how long you keep the verification records, and that you report to AUSTRAC without needing consent: including that you are not permitted to tell someone a suspicious matter report has been made about them.
This is a privacy disclosure, not a compliance program. Your AUSTRAC obligations are a separate regime and nothing in a privacy policy discharges them.
APP 1.4 does not require anything about breaches, which is why most policies say nothing. But the Notifiable Data Breaches scheme in Part IIIC has applied since 2018, and a policy that is silent is describing a business with no plan for one.
Three things are worth stating: that you assess a suspected eligible breach promptly and within 30 days. The clock starts on reasonable grounds to suspect, not on certainty; that if serious harm is likely you notify both the person and the OAIC as soon as practicable; and that if you can prevent the harm before it occurs, notification may not be required. That last one is a real part of the scheme, and leaving it out makes a policy promise more than the business can keep.
No. We're not an accreditation body, we don't audit against a published standard, and nobody should treat the badge as one.
What it is: a dated record that an independent review happened, and what that review found. It links to a page anyone can open to see the detail, including the checks we couldn't complete.
We're strict about this because the badge is only worth displaying if it means exactly what it says.
Committed. You had your website independently reviewed and you're acting on what it found. You get this with any paid review, even if the review found serious problems. It doesn't claim your site is problem-free.
Reviewed. Your score is 80 or above and no critical issues were outstanding at the review date.
Reviewed in depth, the Expert deep scan ran and nothing was left outstanding in it.
Every level says what was found, never what we promise about your business.
No. Expert runs the deeper checks that make the top level reachable, but it doesn't grant it. An Expert customer with findings still open sits at Reviewed until those are addressed, and "addressed" means a re-scan no longer finds them, not that you've told us they're fixed.
A level you can buy isn't evidence of anything, which would make the whole thing worthless to the businesses who did earn it.
Yes, and that's deliberate. The badge reflects your most recent scan. If something breaks (a certificate lapses, a policy comes down, a new critical issue appears), the level can drop.
It moves both ways without you doing anything. We'll email you when it goes up. When it goes down you'll see it on your re-scan page rather than getting an email about it.
Twelve months from your paid review. After that it stops displaying: it disappears quietly rather than putting anything negative on your website, and the page it links to says the review has expired.
There's no auto-billing and nothing to cancel. When you come back for a fresh review, the level is worked out again from that new scan: it isn't carried over.
Not at all, and nothing is public unless you switch it on. Until you do, the badge shows nothing and no page about your business exists on our site.
If you turn it on and change your mind, it's one click to turn off. Plenty of businesses at the Committed level prefer to wait until they've worked through their findings, which is a perfectly reasonable call.
It's a single small image with a link: never a script. We don't put tracking code on your site, and we can't see your visitors.
It's served from our servers rather than copied onto yours, which is what lets it update itself when your level changes, and stop displaying when the review expires.
How the trust badge works, in full → · Where it sits in the Trust Playbook →
No. What's wrong with your site is determined by real, repeatable checks: never by an AI's guess. Every finding is the output of a specific check against your live site: a real request, a real DNS lookup, a real reading of the page you published. Scan an unchanged site twice and you get the same findings. An AI is never allowed to invent a problem that isn't there.
Where we do use AI is in the writing, turning a technical result into a plain-English explanation of what it means for your business and how to fix it. So the detection is deterministic and repeatable; the explanation is written to be clear. That's the opposite of the easy-to-build version of this product, which points a language model at a website and lets it make up confident-sounding findings. A report you can't trust is worse than no report.
Expert reports are read by a Security Principal Lead (a senior cyber security practitioner who has led security teams on major enterprise projects): before the report reaches you.
We don't publish their name. That's a deliberate professional choice, and we'd rather tell you that plainly than invent a stock photo and a fabricated bio, which is exactly what the operations you're right to be suspicious of tend to do.
What we'll do instead is show you the work: read a real sample report and judge the quality yourself.
It means exactly what it says: we tried to run that check and couldn't complete it.
A check that can't run is a real result, not something to quietly leave out. So "not tested" is a category in its own right in our reports, it appears whenever it's the truth, so a report that looks complete always is. We'd rather show you a gap than let silence read as a pass.
Reply to your report email and tell us. If we got it wrong, we'll correct it and re-issue the report, and we'll fix the underlying check so it doesn't happen to anyone else.
We'd genuinely rather hear it. A false alarm in a security report is not a minor annoyance; it's the thing that makes people stop believing the real ones.
No. We don't do remediation, we don't build websites, and we take no commission from any tool, plugin or developer we recommend.
That's not modesty, it's the point: if we made money fixing what we find, you could never be sure we weren't finding things to fix. If a finding says your developer can resolve it in ten minutes, it's because they can.
Expert runs more checks than Essentials, so it can surface things Essentials doesn't look for, that's what you're paying for, and we list every check on the pricing page so you can see exactly what's added.
But here's the conflict of interest we don't have: we charge the same whether we find twenty problems on your site or none at all. There is no version of this business where we make more money by finding you more problems.
And if something we find is critical, you get the steps to fix it whatever tier you bought. We're not willing to leave a small business sitting on a serious problem because they bought the cheaper report.
Quite possibly not, so it's worth checking rather than assuming, in either direction.
The Privacy Act generally applies to businesses with an annual turnover over $3 million. The OAIC puts it plainly: "Most small businesses are not covered by the Privacy Act, but some are."
The catch is in the "some". You're covered regardless of turnover if you're a health service provider, and the OAIC defines that broadly enough to include childcare centres, private schools, allied health, pharmacies and complementary therapists. Also credit reporting, residential tenancy databases, businesses that trade in personal information, and Commonwealth contractors.
And the turnover test is sticky: it asks whether you exceeded $3 million in any financial year since 2002: not last year. One strong year a decade ago and you're covered from then on.
No, it's a common misunderstanding, and what actually changed is more specific.
What actually happened on 1 July 2026 is narrower: tranche 2 of the AML/CTF reforms commenced, bringing real estate professionals, lawyers, conveyancers, accountants and dealers in precious metals and stones under the Privacy Act:but only for the personal information they handle for their AML obligations, such as customer due-diligence records. Not their whole business.
The blanket removal of the small-business exemption has been recommended, not legislated. As things stand, a sub-$3 million café that collects email addresses is still outside the Act.
Reform in this area is expected over time, which is a good reason to keep your privacy practices in good shape. But as the law stands today, a business that isn't otherwise covered remains outside the Act.
Australia doesn't mandate a cookie banner the way the EU does. But it becomes effectively required the moment you have EU or UK visitors, and disclosing what you track is good practice regardless.
If you do add one, the thing that matters is that non-essential cookies are actually blocked until the visitor accepts. A banner that merely announces tracking isn't consent, and "Reject" has to be as easy as "Accept". Regulators look specifically for that.
No, and we're careful about the line. Where something is a legal judgement (whether your refund wording breaches the Australian Consumer Law, say) we flag it for professional review rather than ruling on it. An automated scan doesn't get to decide that, and we won't pretend otherwise.
What we can do is tell you exactly what your site says, where it says it, and why a lawyer might want to look at it.
No, and we don't put you on a subscription either. Three things happen, none of which cost you anything:
Your report email has a re-scan link. Click it, and we re-run the checks and show you a simple progress view: what you've fixed, what's still open, and anything new.
Your original report isn't changed or replaced. It stays exactly as delivered. And an Expert re-scan doesn't go back into the human review queue; it's an automated progress check, delivered in minutes.
No. We don't have a newsletter and we're not planning one.
You'll get your report, a reminder near the end of your 90 days, and an alert only if something genuinely affects the software we found on your site: capped at one such email a week even in a bad week. That's it.
If you want more from us (guides, updates, what's changing) that's your choice to make, not ours: follow us on LinkedIn or Instagram.
Then nothing happens, and we won't nag you about it. Plenty of findings are genuinely low priority for a given business, and you're the one who knows your priorities.
We'd rather you fixed the two things that matter and ignored the rest than felt guilty about a list of twelve.
Nothing, other than give them to you. Your findings are never published, shared or sold. They're not aggregated into a public league table, not passed to insurers or marketers, and not used to embarrass you into buying anything.
Your report sits behind a private link that only you have.
Scan findings and your site's technical details: 24 months. The minimal purchase record: name, business, email, amount, date: 5 years, because Australian tax law requires it. Free Scorecard details, if you never proceed: 24 months.
These aren't aspirations. A scheduled job enforces them, and you can ask us to delete your information sooner at any time, everything except the purchase record, which we're legally required to keep. Full detail in the privacy policy.
Never. That is the single most common opening line of a website scam, and we will not use it.
We don't do outbound alarm emails and we don't cold-call about "vulnerabilities we detected". You come to us, always. If you ever receive a message claiming to be AegorIQ that does this, it isn't us.
If we get something wrong, we'll fix it or refund you. If a finding isn't accurate, or we couldn't deliver the audit we promised, tell us within 30 days, we'll re-check it against your live site free, correct the report if we got it wrong, and refund you in full if we can't put it right.
Worth being straight about what that doesn't cover: a report that comes back clean is a legitimate result, not a fault. You're paying for the check, not for us to find problems, and independent confirmation that your site is in good shape is exactly what a lot of people want.
This guarantee is in addition to your rights under the Australian Consumer Law. Full terms in the refund policy.
Prices are in Australian dollars. We don't charge GST, WNMC Holdings Pty Ltd isn't currently registered for it, so no GST is added and none is buried in the price. What you see is what you pay.
You'll get an invoice for your records. It won't be a tax invoice, because there's no GST on it for you to claim, and we'd rather tell you that than hand you a document that looks like one and isn't.
AegorIQ is a trading name of WNMC Holdings Pty Ltd, ABN 55 698 239 502, based in Melbourne. If we register for GST later, prices will say so clearly and this page will change with them.
A real person reads every email. If your question belongs on this page, we'll add it.