No subscription and no monthly fee for a dashboard you'll never open. You buy one audit and you own it, then we stay with you while you actually fix things, with free re-scans for 90 days.
A full audit against 36 checks (compliance, security and AI readiness): with every issue named in plain English.
Everything in Essentials, plus the 16 deeper security scans, the checks an attacker actually runs against your site.
Everything in Deep Scan, plus the part software cannot do: a professional reads your specific site, then talks it through with you.
That's the complete list,and here's what we don't check, which we think matters just as much. This is a website health check, not a penetration test, and we say so in every report.
* Nearly always well inside 2 hours. Occasionally a document (usually a privacy policy or terms page published in a format our reader can’t open on its own) needs a person to read it. When that happens we email you to say so, and your report follows within one business day. You will never be sent a half-finished report.
Display it on your site if you'd like to. It links to a page anyone can check, and it refreshes on its own each time you re-scan.
Yours the moment your review lands, whatever it finds.
A score of 80 or above, with no critical issues outstanding.
The Expert deep scan run, with nothing left outstanding in it.
A badge is not a certification and not a guarantee. It records that an independent review happened on a date, and what that review found: nothing more. It stays current for 12 months, then it's re-earned from a fresh scan rather than renewed automatically. Displaying it is entirely optional, and you can turn it off at any time. How the badge works →
Most security reports get read once, feel alarming, and then sit in a folder. Not because owners don't care, but because nothing helps them get from "here's what's wrong" to "it's fixed." That gap is the part we stayed for. None of it costs you another cent, and none of it ties you to anything.
Fix something, click re-scan, and we'll confirm it's actually gone. As often as you need, for 90 days. You get a simple progress view: what you've fixed, what's still open.
If a rule changes, or a vulnerability turns up in software we saw running on your site, we may drop you a line, and if we do, we'll explain how to check and fix it yourself, in plain English. It's a courtesy from what we noticed at the time of your audit, not a monitoring service: we don't watch your site, we can't promise to catch everything, and keeping it up to date stays with you.
Redesigned the site? New plugin? Rule change? Come back whenever it suits you and order a fresh check at the price on the day, a new scan of the site as it is then, with its own 90 days of free re-scans. No renewal date and nothing to cancel, because there was never a subscription.
Expert re-scans are automated progress checks, delivered in minutes. Your original expert review stands with your first report.
The audit tells you whether the privacy policy you have says what it should. The builder writes you one, from 115 questions about your business, not a template with your name dropped in.
About the builder →Every tier runs the same accurate scan. What changes is how much you see, and whether we hand you the fix.
Compliance is what you promise. Security is whether you can keep it. Every tier reads for both, because a policy template cannot tell you your site is unpatched, and a security scanner has never read an Australian refund policy. Why they are the same job →
| What we check | Scorecard Free |
Essentials $79 |
Deep Scan $149 |
Expert $497 |
|---|---|---|---|---|
| Compliance. We read your policies | ||||
| Privacy policy depthWhich Privacy Act elements are missing | count | named | named | named + fix |
| Refund wording vs Australian Consumer LawBlanket “no refunds” flagged for review | count | named | named | named + fix |
| Terms, shipping policy, ABN & contact details | count | named | named | named + fix |
| Cookie consent, tracking & sign-up consentRegion-aware, plus Spam Act consent on your forms | count | named | named | named + fix |
| Customer accounts & login credentialsWhether your site holds customer logins, and what the Notifiable Data Breaches scheme then asks of you | count | named | named | named + fix |
| Security | ||||
| Email spoofing: SPF, DKIM, DMARC | count | named | named | + setup steps |
| Duplicate SPF/DMARC recordsSilently switches your protection off | count | named | named | named + fix |
| SSL, security headers, malware blacklist | count | named | named | named + fix |
| Software vulnerabilities (WordPress/CVE) | count | named | named | named + fix |
| Public exposure, CORS & exposed usernamesCommon misconfigurations that leak data or aid break-ins | , | named | named | named + fix |
| Domain security: expiry, transfer-lock, DNSSEC | count | named | named | named + fix |
| Does your site work, and look current? | ||||
| Mobile-friendly, broken links & content freshnessWhether your site works for visitors and doesn't look out of date | count | named | named | named + fix |
| Placeholder & template contentUnrenamed builder templates or filler text that make a site look half-built | count | named | named | named + fix |
| AI Readiness | ||||
| Is your site ready for AI to find you?6 on-page signals AI assistants (ChatGPT, Perplexity, Google) use to discover & understand you: informational, doesn't affect your score | score | named | named | named + plan |
| Deep Scan and Expert | ||||
| 16 deep security scansExposed files, leaked secrets, directory listing, XML-RPC, ports, subdomain takeover, TLS strength, and more | : | : | ✓ | ✓ |
| Performance & SEO (Google Lighthouse) | , | , | ✓ | ✓ |
| Accessibility (WCAG 2.2 AA, automated)Colour contrast, missing image alt text and unlabelled form fields, each barrier named with the number of elements affected. An automated check catches about a third of WCAG 2.2 AA. It is a starting point, never a conformance verdict. | , | , | ✓ | ✓ |
| Admin sign-in exposure & MFA signalsWhether your admin login is reachable from the open internet, whether it hands off to single sign-on, and whether a two-factor plugin is visible. Read-only, we never submit a login form | , | , | ✓ | ✓ |
| Reviewed by a cybersecurity professional | , | , | , | ✓ |
| Step-by-step fix for every issue | , | , | , | ✓ |
| Prioritised remediation roadmapWhat to fix first, and what can safely wait | , | , | , | ✓ |
| 45-minute Trust Review callA person looks at what the scan cannot measure: how your site reads to a customer, and whether an AI can describe you accurately. You leave with a plan and a written summary. | , | , | , | ✓ |
The free Scorecard is a real audit, not a teaser. It takes five minutes and we email you the result.