If a question below has an answer that makes us look worse, we've written it anyway. That's the point of a page like this — a FAQ that only says flattering things isn't a FAQ, it's an ad.
No, and we won't pretend otherwise. A penetration test is a person actively attempting to break into your systems, with your written permission, usually costing several thousand dollars and taking days.
AegorIQ is a health check of the parts of your website that are publicly visible — your configuration, your DNS and email records, your certificates, your published policies — plus, on Expert, a set of deeper automated checks. It's genuinely useful, and it is not the same thing.
We say this in every report as well, because overclaiming is how this industry lost people's trust.
Free scanners are typically built to check one narrow technical thing and return a score. That can be a useful signal on its own, but a score doesn't tell you what to do next.
We focus on three things. We read the inside of your policies, not just check that a link exists. We tell you what a finding means for your business, not just that a header is missing. And we tell you what to do next, in steps you or your developer can follow.
We're also honest about our limits: if a check can't run, we say so rather than showing you a green tick.
It's a quick read on how ready your website is for AI assistants — the tools behind ChatGPT, Perplexity and Google's AI answers — to find, read and understand your business. We check six on-page signals, like whether AI crawlers are allowed to read your site, whether your content is readable without JavaScript, and whether you publish structured data.
You get a simple "X of 6" score with each signal explained, included in every report at no extra cost.
No. AI Readiness is shown for your awareness only — it doesn't affect your TrustScore, and a missing signal is an opportunity, not a fault. Your security and compliance results are what's scored; AI Readiness sits alongside them as a separate, informational readout.
It helps — but honestly, no scan can promise that, and we won't pretend otherwise. The six signals we check are the on-page half: making sure an AI can actually read and understand your site.
Whether an AI then recommends you is driven mostly by things off your website — being mentioned on other reputable sites, consistent business listings, and reviews. We show you where you stand on the part we can measure, and in the Expert report, what else to work on.
No. Never. We don't ask for logins, admin access, FTP, or hosting credentials, and you should be suspicious of any website security service that does before you've even bought anything.
Everything we check is either publicly visible or published in public records — the same things any visitor, customer or attacker can already see. That's deliberate: it means a scan can't break anything, and it means we never hold keys to your business.
No. We fetch a small number of pages, the way an ordinary visitor would, and we look up public DNS records. We don't hammer your server, we don't attempt to log in, and we don't try to exploit anything.
No. Every scan requires you to confirm you own the site or are authorised by the owner to check it.
We don't scan uninvited, we don't build a database of other people's weaknesses, and we don't run "surprise audits" as a sales tactic. If you manage websites for clients, you're welcome to scan them with your client's authorisation — that's what the confirmation is for.
Before you pay, we run a pre-flight check to see whether we can actually read your site. Some sites are built entirely in JavaScript, or sit behind protection that blocks automated readers. If we can't deliver a complete report, we tell you before you spend money, not after.
If a scan is partially limited, your report says exactly which checks we couldn't complete. We would rather hand you a report with honest gaps in it than a complete-looking report with invented answers in those gaps.
Free Scorecard tells you how many issues we found, by category. It's a real scan, not a teaser — but it doesn't name the issues.
Essentials ($109) names every issue, explains what each one means for your business, and gives you step-by-step fixes for anything critical.
Expert ($309) adds a set of deeper automated checks, step-by-step fixes for every finding, and a human review — a senior security practitioner reads your report before you do and writes what actually matters for your site.
The full check-by-check breakdown is on the pricing section. No "and more", no asterisks.
Often it is — and we'll say so. If you have a straightforward site with no logins or online payments, and you're comfortable reading a report and doing the fixes yourself, Essentials is a complete, honest picture. It names every issue, explains why each one matters, and gives you the steps for anything critical.
Expert earns its extra $200 in two ways. First, it runs deeper checks Essentials doesn't — things like exposed files, open service ports and advanced email protections — so it covers more of what an attacker would actually probe. Second, and more importantly, a senior security practitioner reads your report before you do: they cut any false alarms, weigh the findings for your specific site, and write plainly what to fix first and what can wait.
That human step is the real difference. An automated scan is accurate, but it hands you twenty findings and leaves you to work out which two actually matter this week. Choose Expert if you take payments or hold sensitive customer data, run WordPress, don't have a tech person, or you'd simply rather someone tell you what to do first — not just what's wrong.
Yes. Within 30 days of your Essentials purchase you pay only the $200 difference — not the full $309 — and receive the complete Expert report: fresh deep scans on your site as it is then, step-by-step fixes for every finding, and a cybersecurity professional's review before delivery.
There's nothing to fill in again — we already have your details — and your free 90-day re-scan window carries over from your original purchase rather than restarting. The upgrade link is in your Essentials report email.
No. What's wrong with your site is determined by real, repeatable checks — never by an AI's guess. Every finding is the output of a specific check against your live site: a real request, a real DNS lookup, a real reading of the page you published. Scan an unchanged site twice and you get the same findings. An AI is never allowed to invent a problem that isn't there.
Where we do use AI is in the writing — turning a technical result into a plain-English explanation of what it means for your business and how to fix it. So the detection is deterministic and repeatable; the explanation is written to be clear. That's the opposite of the easy-to-build version of this product, which points a language model at a website and lets it make up confident-sounding findings — a report you can't trust is worse than no report.
Expert reports are read by a Security Principal Lead — a senior cyber security practitioner who has led security teams on major enterprise projects — before the report reaches you.
We don't publish their name. That's a deliberate professional choice, and we'd rather tell you that plainly than invent a stock photo and a fabricated bio, which is exactly what the operations you're right to be suspicious of tend to do.
What we'll do instead is show you the work: read a real sample report and judge the quality yourself.
It means exactly what it says: we tried to run that check and couldn't complete it.
A check that can't run is a real result, not something to quietly leave out. So "not tested" is a category in its own right in our reports — it appears whenever it's the truth, so a report that looks complete always is. We'd rather show you a gap than let silence read as a pass.
Reply to your report email and tell us. If we got it wrong, we'll correct it and re-issue the report — and we'll fix the underlying check so it doesn't happen to anyone else.
We'd genuinely rather hear it. A false alarm in a security report is not a minor annoyance; it's the thing that makes people stop believing the real ones.
No. We don't do remediation, we don't build websites, and we take no commission from any tool, plugin or developer we recommend.
That's not modesty, it's the point: if we made money fixing what we find, you could never be sure we weren't finding things to fix. If a finding says your developer can resolve it in ten minutes, it's because they can.
Expert runs more checks than Essentials, so it can surface things Essentials doesn't look for — that's what you're paying for, and we list every check on the pricing page so you can see exactly what's added.
But here's the conflict of interest we don't have: we charge the same whether we find twenty problems on your site or none at all. There is no version of this business where we make more money by finding you more problems.
And if something we find is critical, you get the steps to fix it whatever tier you bought. We're not willing to leave a small business sitting on a serious problem because they bought the cheaper report.
Quite possibly not — so it's worth checking rather than assuming, in either direction.
The Privacy Act generally applies to businesses with an annual turnover over $3 million. The OAIC puts it plainly: "Most small businesses are not covered by the Privacy Act, but some are."
The catch is in the "some". You're covered regardless of turnover if you're a health service provider — and the OAIC defines that broadly enough to include childcare centres, private schools, allied health, pharmacies and complementary therapists. Also credit reporting, residential tenancy databases, businesses that trade in personal information, and Commonwealth contractors.
And the turnover test is sticky: it asks whether you exceeded $3 million in any financial year since 2002 — not last year. One strong year a decade ago and you're covered from then on.
No — it's a common misunderstanding, and what actually changed is more specific.
What actually happened on 1 July 2026 is narrower: tranche 2 of the AML/CTF reforms commenced, bringing real estate professionals, lawyers, conveyancers, accountants and dealers in precious metals and stones under the Privacy Act — but only for the personal information they handle for their AML obligations, such as customer due-diligence records. Not their whole business.
The blanket removal of the small-business exemption has been recommended, not legislated. As things stand, a sub-$3 million café that collects email addresses is still outside the Act.
Reform in this area is expected over time, which is a good reason to keep your privacy practices in good shape. But as the law stands today, a business that isn't otherwise covered remains outside the Act.
Australia doesn't mandate a cookie banner the way the EU does. But it becomes effectively required the moment you have EU or UK visitors, and disclosing what you track is good practice regardless.
If you do add one, the thing that matters is that non-essential cookies are actually blocked until the visitor accepts. A banner that merely announces tracking isn't consent — and "Reject" has to be as easy as "Accept". Regulators look specifically for that.
No, and we're careful about the line. Where something is a legal judgement — whether your refund wording breaches the Australian Consumer Law, say — we flag it for professional review rather than ruling on it. An automated scan doesn't get to decide that, and we won't pretend otherwise.
What we can do is tell you exactly what your site says, where it says it, and why a lawyer might want to look at it.
No, and we don't put you on a subscription either. Three things happen, none of which cost you anything:
Your report email has a re-scan link. Click it, and we re-run the checks and show you a simple progress view: what you've fixed, what's still open, and anything new.
Your original report isn't changed or replaced — it stays exactly as delivered. And an Expert re-scan doesn't go back into the human review queue; it's an automated progress check, delivered in minutes.
No. We don't have a newsletter and we're not planning one.
You'll get your report, a reminder near the end of your 90 days, and an alert only if something genuinely affects the software we found on your site — capped at one such email a week even in a bad week. That's it.
If you want more from us — guides, updates, what's changing — that's your choice to make, not ours: follow us on LinkedIn or Instagram.
Then nothing happens, and we won't nag you about it. Plenty of findings are genuinely low priority for a given business, and you're the one who knows your priorities.
We'd rather you fixed the two things that matter and ignored the rest than felt guilty about a list of twelve.
Nothing, other than give them to you. Your findings are never published, shared or sold. They're not aggregated into a public league table, not passed to insurers or marketers, and not used to embarrass you into buying anything.
Your report sits behind a private link that only you have.
Scan findings and your site's technical details: 24 months. The minimal purchase record — name, business, email, amount, date: 5 years, because Australian tax law requires it. Free Scorecard details, if you never proceed: 24 months.
These aren't aspirations. A scheduled job enforces them, and you can ask us to delete your information sooner at any time — everything except the purchase record, which we're legally required to keep. Full detail in the privacy policy.
Never. That is the single most common opening line of a website scam, and we will not use it.
We don't do outbound alarm emails and we don't cold-call about "vulnerabilities we detected". You come to us — always. If you ever receive a message claiming to be AegorIQ that does this, it isn't us.
30 days, money back, no questions asked — whether we found problems or confirmed your site is solid. That second half matters: a report that tells you you're in good shape is a legitimate outcome, and you shouldn't feel cheated by it.
This guarantee is in addition to your rights under the Australian Consumer Law. Full terms in the refund policy.
Prices are in Australian dollars. We don't charge GST — WNMC Holdings Pty Ltd isn't currently registered for it, so no GST is added and none is buried in the price. What you see is what you pay.
You'll get an invoice for your records. It won't be a tax invoice, because there's no GST on it for you to claim — and we'd rather tell you that than hand you a document that looks like one and isn't.
AegorIQ is a trading name of WNMC Holdings Pty Ltd, ABN 55 698 239 502, based in Melbourne. If we register for GST later, prices will say so clearly and this page will change with them.
A real person reads every email. If your question belongs on this page, we'll add it.