Home  ›  Why audit
Why audit

Why bother auditing your website?

Because the things that quietly cost you customers, or put you offside with Australian law, are invisible from the outside — and nobody tells you about them until something goes wrong.

The difference

We don't just check that your privacy policy exists.
We open it and read it.

Anyone can confirm a link isn't broken. We tell you which Privacy Act elements your policy never mentions, and where your refund wording strays into language the ACL doesn't allow. Then we do the same for the hacker's view and the customer's — security, compliance and experience, in one report. Most checks only ever look for the hacker.

See pricing
What a tick-box scan tells you
“Privacy policy: found. Terms: found.” A list of technical scores, and you're left to work out what any of it means for your business.
What AegorIQ tells you
“Your policy doesn't say how someone makes a privacy complaint, or whether data goes overseas. Your terms contain blanket ‘no refunds’ wording that can be unlawful under the ACL.” Then: what to do about it — reviewed by a security professional on the Expert tier.
Why one report, not two

Compliance is what you promise.
Security is whether you can keep it.

Most of this market sells you half an answer — a security scanner that knows nothing about Australian law, or a compliance consultant who never looks at your server. The firms that do cover both will quote you five figures for it. Neither half works alone, and both halves shouldn't cost more than the business is making.

A privacy policy is a written promise about how you handle someone's data. If your website isn't secure, you haven't just failed to protect that data — you have published a promise you cannot keep. That is a worse place to stand than saying nothing, because the obligation is now documented, in your own words, on your own website.

And this isn't our opinion. The Privacy Act says it: APP 11 requires you to take reasonable steps to protect the personal information you hold. Security is not adjacent to your compliance — it sits inside it. A beautiful privacy policy on an unpatched website isn't compliance. It's a document contradicting itself.

It runs the other way too. You can have flawless security — every certificate current, every plugin patched — and still lose the business, because nobody outside your server ever sees any of it. What a customer sees is your refund page. What a regulator reads is your terms. Get those wrong and you don't get hacked; you just quietly stop being trusted, which takes far longer to notice and far longer to repair.

The most compliant website in Australia is worthless if the data behind it isn't protected. The most secure website in Australia is worthless if nobody trusts the business running it. They aren't alternatives. They're two halves of one question — can this business be trusted with my details? That is why we do one report instead of two.

What Australian law actually requires of your website →

What we read

Three things a tick-box can't tell you.

Every finding comes from a real check on your live site. Nothing is guessed, nothing is invented — and where a judgement is a legal one, we say so rather than pretend an algorithm can rule on it.

01

Your privacy policy — the inside of it

We open the policy and check it against the elements the Australian Privacy Principles expect: what you collect, whether it goes overseas or to third parties, how it's stored, how someone makes a complaint, and when it was last updated.

You get: “Your policy is missing 2 of the 5 elements we check — overseas disclosure, and how to make a privacy complaint.”
02

Your refund terms — against the ACL

We read your terms and refund pages for blanket “no refunds” and “all sales are final” wording. Consumer guarantees can't be excluded, so those statements can be unlawful — and the ACCC actively enforces against them.

You get: the exact wording, where it appears, and a lawful alternative — flagged for professional review, never a legal ruling.
03

Your email — including what's silently broken

SPF, DKIM and DMARC, plus the misconfiguration most checks miss entirely: duplicate records. Publish two DMARC records and receivers ignore DMARC completely — so you look protected while anyone can spoof you.

You get: whether your protection is genuinely working — not just whether a record exists.
The human layer

An automated scan can't make a judgement call.

So we don't pretend it can. Every Expert report is read by a cybersecurity professional before it reaches you — someone who looks at your specific site, writes commentary on what actually matters, and signs their name to it.

Where a question is a legal one — like whether your refund wording breaches the ACL — we flag it for professional review rather than pretending an algorithm can rule on it.

“Two of these findings matter far more than the other six. Fix the refund wording this week — the ACCC actively enforces it. The rest can wait a month.”
Expert-reviewed before delivery
Cybersecurity professional, AegorIQ

Find out what your website is telling people.

The free Scorecard is a real audit, not a teaser. It takes five minutes and we email you the result.

Get my score → Read a sample report