Because the things that quietly cost you customers, or put you offside with Australian law, are invisible from the outside — and nobody tells you about them until something goes wrong.
Anyone can confirm a link isn't broken. We tell you which Privacy Act elements your policy never mentions, and where your refund wording strays into language the ACL doesn't allow. Then we do the same for the hacker's view and the customer's — security, compliance and experience, in one report. Most checks only ever look for the hacker.
See pricingMost of this market sells you half an answer — a security scanner that knows nothing about Australian law, or a compliance consultant who never looks at your server. The firms that do cover both will quote you five figures for it. Neither half works alone, and both halves shouldn't cost more than the business is making.
A privacy policy is a written promise about how you handle someone's data. If your website isn't secure, you haven't just failed to protect that data — you have published a promise you cannot keep. That is a worse place to stand than saying nothing, because the obligation is now documented, in your own words, on your own website.
And this isn't our opinion. The Privacy Act says it: APP 11 requires you to take reasonable steps to protect the personal information you hold. Security is not adjacent to your compliance — it sits inside it. A beautiful privacy policy on an unpatched website isn't compliance. It's a document contradicting itself.
It runs the other way too. You can have flawless security — every certificate current, every plugin patched — and still lose the business, because nobody outside your server ever sees any of it. What a customer sees is your refund page. What a regulator reads is your terms. Get those wrong and you don't get hacked; you just quietly stop being trusted, which takes far longer to notice and far longer to repair.
The most compliant website in Australia is worthless if the data behind it isn't protected. The most secure website in Australia is worthless if nobody trusts the business running it. They aren't alternatives. They're two halves of one question — can this business be trusted with my details? That is why we do one report instead of two.
Every finding comes from a real check on your live site. Nothing is guessed, nothing is invented — and where a judgement is a legal one, we say so rather than pretend an algorithm can rule on it.
We open the policy and check it against the elements the Australian Privacy Principles expect: what you collect, whether it goes overseas or to third parties, how it's stored, how someone makes a complaint, and when it was last updated.
We read your terms and refund pages for blanket “no refunds” and “all sales are final” wording. Consumer guarantees can't be excluded, so those statements can be unlawful — and the ACCC actively enforces against them.
SPF, DKIM and DMARC, plus the misconfiguration most checks miss entirely: duplicate records. Publish two DMARC records and receivers ignore DMARC completely — so you look protected while anyone can spoof you.
So we don't pretend it can. Every Expert report is read by a cybersecurity professional before it reaches you — someone who looks at your specific site, writes commentary on what actually matters, and signs their name to it.
Where a question is a legal one — like whether your refund wording breaches the ACL — we flag it for professional review rather than pretending an algorithm can rule on it.
The free Scorecard is a real audit, not a teaser. It takes five minutes and we email you the result.