Run our scanner against your own site
The Web Compliance Agent is the module we point at a client's website on day one. It reads what any visitor can read, checks it against accessibility, search and security-header rules, and returns each finding attached to the clause it comes from. It is free, it does not need an account, and there is no call attached to it.
It is also the fastest way to judge whether we know what we are talking about before you spend an hour on a call with us.
Two steps: you ask, then you click the link we email you. Nothing touches the target site until that second step, which is the only thing standing between a free scanner and a traffic generator aimed at whoever somebody types in.
What it looks at
Four groups of checks. Each finding in the report names the rule it came from and what to change, because a list of problems without the clause behind it is just an opinion.
Accessibility
Contrast, focus order, labelling, landmark structure and the alt-text situation, checked against WCAG 2.2 success criteria. Findings name the criterion, not a made-up severity score.
Search and answer visibility
Titles, metadata, canonicals, structured data, sitemap and robots directives — including whether answer engines are allowed to read you at all, which is the part most sites get wrong by accident.
Security headers and transport
Content-Security-Policy, HSTS, frame and content-type options, referrer and permissions policy, certificate and redirect behaviour. Configuration only.
The obvious operational stuff
Broken internal links, mixed content, oversized payloads, missing favicons and manifests. Unglamorous, and consistently the first thing a buyer notices.
What this is not
This is a configuration review of what your site serves publicly. It is not a penetration test, not a security audit, and not a compliance certificate. A clean report means the things it checks are in order — it does not mean your application is secure, and we will not write you a letter saying it is.
The controls behind the scanner, and the four things we have not done, are listed on the security page.
Before you run it
What does the scan not do?
It does not attempt authentication, does not submit forms, does not try inputs against your application and does not look for exploitable vulnerabilities. It reads what a well-behaved visitor can read. That is a configuration review, not a penetration test, and calling it one would be dishonest.
How hard does it hit my site?
Politely. Requests are serialised with a delay between them, robots.txt is respected, and the crawl stops at a page budget. If your server notices at all it will look like one slow human reading a lot of pages.
Why do you ask me to confirm I am authorised?
Because scanning a domain sends real traffic to somebody's infrastructure. We have no way to verify ownership without an account, so we ask you to state it, we log the statement with the request, and we decline anything reported as unwanted. If you need proven-ownership scanning on a schedule, that is the platform module rather than this form.
Why do I have to click a link in an email first?
Because a tick-box costs nothing to lie on. Making the request travel through a working inbox raises the price of pointing this form at a site you do not control, and it means every scan we run has a real address attached to it that we can go back to. Nothing is fetched from the target until you click. The link is good for seven days and using it twice does not start a second scan.
Why is it rate limited?
A free scanner with no limits is a traffic generator pointed at other people's servers. There are two ceilings: one per network per hour, and one per target domain per day — the second is the one that protects other people, since it holds even against somebody with a pool of addresses. If you have a legitimate reason to run more than that, email us and we will run them ourselves.
What happens to my email address?
It is used to confirm the request, send the report, and reply if you ask a question about it. No list, no sequence, no sharing. [email protected] removes it, and the full basis is on the privacy page.
Scanning a domain you are not authorised to test is not something we will help with. If you believe someone has used this form against your site, tell us at [email protected] and we will block the domain from further scans.
Report in hand and still want a second opinion?
Send it to us. We will tell you which findings actually matter for your business and which ones a scanner overweights, at no cost and with no proposal attached.