This is a sample. A real Expert report, anonymised to a fictional business. Every finding, explanation and fix below is genuine output from our engine — nothing here is mocked up for marketing.
Sample Expert report
Read the whole thing before you spend a cent.
Below is a real AegorIQ Expert report — the actual deliverable, exactly as a customer receives it, anonymised to a fictional clinic. Most companies describe their work; we'd rather show you ours and let the quality speak. Every finding, explanation and fix is genuine output from our engine.
Tier: Expert ($309)
Business: fictional (Northbridge Physiotherapy)
Findings shown: abridged — 6 of 21
Sample
AegorIQ
Expert · Reviewed
Website Risk Review
Prepared for Northbridge Physiotherapy — northbridgephysio.com.au · 11 July 2026
64
/ 100 TrustScore
Needs attention
Security6.0
Privacy4.5
Compliance5.5
Performance9.0
2
Critical
7
Needs attention
12
Passing
🤖AI Readiness: 4 of 6 signals presentHow ready your site is for AI assistants (ChatGPT, Perplexity, Google’s AI answers) to discover and understand it. Informational — it doesn’t affect your TrustScore.
Expert review
“Two of these findings matter far more than the other seven. Fix the refund wording this week — you're a clinic taking bookings and payments, and the ACCC actively enforces against blanket no-refund terms. Second, your privacy policy doesn't say how a patient makes a complaint; for a health-adjacent business that's the one an OAIC enquiry would land on first. The missing security headers are worth doing, but they can wait a month. Everything else on this list is housekeeping.”
Reviewed by a Security Principal LeadRead and signed off before delivery · 11 July 2026
Compliance
Blanket “no refunds” wording found — flagged for professional reviewCritical
What
Your website contains wording that reads as a blanket “no refunds” statement. Under the Australian Consumer Law, consumer guarantees cannot be excluded, so blanket no-refund statements can be unlawful. We flag this for professional review — an automated scan cannot make a legal determination about your specific terms.
“no refunds” — on your terms page
context: “…cancellations within 24 hours of an appointment are non-refundable. No refunds. Payment is required at the time of…”
Why it matters
The ACCC actively enforces against blanket no-refund signs and terms, and customers who know their rights lose trust in a business that displays them. For a clinic taking prepaid bookings, this is the term most likely to be challenged.
How to fix it Expert
Locate the flagged statement on your terms page using the context shown above.
Replace the blanket wording with a lawful version that preserves consumer guarantees — for example: “We do not offer refunds for change of mind. Nothing in these terms limits your rights under the Australian Consumer Law.”
Check your booking confirmation emails, invoices and any reception signage for the same wording.
Have the final wording reviewed by a professional before publishing.
Privacy policy is missing 2 of the 5 elements we checkNeeds attention
What
We read your published privacy policy and checked it against the elements the Australian Privacy Principles expect a policy to cover. Two are missing.
✗ how to contact you or make a privacy complaint
✗ whether information is disclosed to third parties or overseas
✓ what personal information you collect
✓ how information is stored, secured or retained
✓ a last-updated or effective date
Why it matters
A policy that doesn't tell people how to complain is the gap an OAIC enquiry lands on first — and you handle health-adjacent information, which raises the bar. Penalties for serious or repeated interference now reach $50 million.
How to fix it Expert
Add a “Contact us / Making a complaint” section naming who to contact, how, and the expected response time.
State that complaints can be escalated to the Office of the Australian Information Commissioner (OAIC) if unresolved.
Add a section stating whether personal information is shared with third parties (your booking software, payment processor) and whether any of it is stored overseas.
Update the “last reviewed” date once published.
Security
Multiple DMARC records found (2) — your DMARC is being ignoredCritical
What
Your domain publishes two separate DMARC records. The standard allows only one: when receivers find more than one, they ignore DMARC completely. So despite having DMARC set up, your domain currently has no working protection against email spoofing at all.
This is the most dangerous kind of misconfiguration — you appear protected, but you aren't. Anyone can send email that looks like it comes from your clinic: fake appointment confirmations, fake invoices to patients. This is the mechanism behind most invoice-fraud scams.
How to fix it Expert
Delete both existing _dmarc TXT records at your DNS provider.
Watch the reports for two weeks to confirm your legitimate mail (booking software, Microsoft 365) is passing.
Then tighten to p=quarantine, and finally p=reject.
Exposed sensitive files reachable on your website Expert onlyNeeds attention
What
We could reach 2 sensitive paths on your site that shouldn't be public. Attackers scan for exactly these to find credentials or map your site.
/readme.html — WordPress version disclosure (HTTP 200)
/wp-json/wp/v2/users — user enumeration (HTTP 200)
Why it matters
User enumeration hands an attacker a list of valid login names — half the work of breaking into your site. Version disclosure tells them exactly which known exploits to try.
How to fix it Expert
Delete /readme.html from your web root — it serves no purpose in production.
Disable the WordPress REST API user endpoint (most security plugins do this in one toggle).
Re-scan to confirm both now return 403 or 404.
Valid SSL certificate (HTTPS)Passing
What
Your site is served over HTTPS with a valid certificate, so information your patients submit is encrypted in transit.
Keep it that way
Make sure the certificate auto-renews before expiry so visitors never see a security warning.
Performance & User Experience
Website performance & SEO score (Google Lighthouse) Expert onlyPassing
What
Google Lighthouse scored your site on mobile: Performance 91/100, SEO 96/100, Accessibility 88/100, Best Practices 96/100. These are healthy scores — keep them up.
Largest Contentful Paint: 1.9 s
Total Blocking Time: 40 ms
Cumulative Layout Shift: 0.01
🤖 AI Readiness
How ready your site is for AI assistants to discover, read and understand your business — six on-page signals. Informational: it does not affect your TrustScore. This site scored 4 of 6.
Some AI assistants are blocked from your site
What
Your robots.txt blocks GPTBot (the crawler behind ChatGPT). That is a legitimate choice — some businesses keep AI training crawlers out on purpose — so this is a note, not a fault. If you WANT AI assistants to find and recommend you, they need to be allowed in.
Your content is readable without JavaScript
What
Your content is present in the initial HTML, so an AI crawler that does not run JavaScript still sees it — the first thing that has to be true for an AI to read and cite you.
You publish structured data AI can read
What
Your site publishes Schema.org structured data — the machine-readable summary AI assistants and search engines use to understand and represent your business correctly, instead of guessing from your page text.
The full picture — AI readiness is bigger than these 6. AI assistants favour businesses that are secure and clearly legitimate, and several of those signals are already in this report (HTTPS, business identity, contact details, a clean malware record). Beyond what any website scan can see, the biggest driver of whether an AI recommends you is off-site: being cited on other reputable sites, consistent business listings, reviews, and genuinely useful content. The Expert report adds a tailored action plan for these.
15 further findings continue in the full report — including security headers, cookie consent and tracking, ABN and contact visibility, domain expiry and transfer-lock, DNSSEC, broken links, TLS strength, subdomain exposure and third-party script integrity.
Prepared by AegorIQ for Northbridge Physiotherapy · Report date 11 July 2026 · This report is confidential and prepared solely for the named business.
AegorIQ website risk reviews are advisory reports only and do not constitute penetration testing or legal advice. All findings are point-in-time assessments of publicly visible parts of your website and your published policies. Where a matter is a legal question, we flag it for professional review rather than making a determination.
Now do yours
That's the whole product. No surprises.
Start with the free Scorecard — it tells you how many issues we found on your site, and how serious they are. Then decide whether you want them named.
Great tool for keeping our website compliant. AegorIQ clearly showed us what needed fixing for compliance and cyber security — highly recommend for any business wanting a proper website health check.
Jenny BudimanDirector, Circle FinanceCircle Finance is the property purchase partner that manages the whole journey — readiness, finance, due diligence and settlement — from “can we afford it?” to the day you get the keys.
I had a great experience with the AegorIQ website compliance and security check — straightforward and easy to understand. It identified potential security and compliance issues and gave me greater confidence the necessary areas were being checked. Professional, reliable and helpful — I’d recommend it to anyone who wants to make sure their website is compliant and protected.
Dr Alvin SheePrincipal Dentist, Blackburn Family Dental CareBlackburn Family Dental Care has been the trusted dentist in Blackburn North and surrounds for over 60 years, taking pride in the care of your teeth and the quality of their treatment.