Skip to content

FAQ

The questions people actually ask first.

Including the two nobody puts on a page like this: what the scanner touches when you point it at a live site, and what we refuse to claim we can measure.

About the product

What does SiteAssay actually do?

Five things that only matter together. It finds local businesses from a trade and a city; measures each website live against published standards; ranks them by the work you sell; writes a report the business owner can read without a developer; and drafts the outreach that quotes the worst thing it measured. A list of businesses is a commodity and a scan is a commodity. The join between them is not.

Who is it built for?

Agencies and freelancers who sell web design, SEO and content, security and IT maintenance, or local reputation work. The scoring weights are a profile you choose, so the same audited site sorts differently depending on what you sell, so a security consultant and a web designer get different rankings out of identical measurements.

Can I try it without an account?

Yes. The free tools run against any address with no account and no card: a full Tier 0 website audit, and single-purpose checkers for exposed API keys, source maps, security headers, email deliverability and Supabase row-level security. The free plan itself also has no card and does not expire.

Whose inbox does the outreach leave from?

Yours. Connect Gmail or Outlook over OAuth and approved messages leave your own domain, with your sending reputation behind them and replies landing where you already work. Without a connected mailbox it sends through the platform instead. Bounce detection is weaker on the mailbox path, and we say so next to the connect button rather than in a footnote.

Is there a way to make it send automatically?

Only for follow-ups, and only after you have already started the conversation. The first message in any sequence always needs a person to approve it. Auto-send also refuses to switch on until you have configured a postal address, because a bulk commercial email without one is not legal to send in most of the markets this is used in.

Is there an API?

A REST API that starts audits rather than only reading them, an MCP server your coding agent can drive with the same token, SARIF 2.1.0 output for GitHub code scanning, and HMAC-signed webhooks with an event id so a retry cannot be counted twice. Two things are deliberately absent: there is no discovery endpoint and no outreach endpoint. Sending is not scriptable, on purpose.

Can my whole team work in one account?

Yes: owners, admins and members, with leads assignable to a person and a pipeline board everyone shares. Seat counts include invitations you have sent but nobody has accepted yet, so the number on the billing page is the number of seats you are actually holding.

What is the badge for?

A small SVG that a business whose site you have fixed can embed on their own page, linking back to a page that confirms the grade it claims. It is deliberately the one thing that is never white-labelled: a verification whose issuer name has been swapped for the issuer's customer is a self-issued certificate, and worth nothing to the person reading it.

About the audit

Is it safe to point at a client's production site?

The default checks make ordinary GET requests for pages and files the site already serves to anybody, and read what comes back. Nothing is written, changed or deleted, and nothing is fetched that a browser would not fetch on its own. Audits are throttled, sequenced one at a time per host, and identify themselves in the user agent. The handful of checks that actively probe anything are switched off by default.

Why does a check say "missing" or "skipped"?

Because neither of those is a pass and neither is a failure, and printing them as either would be a lie. A check ends in one of five states: it ran and measured something; it ran and there was genuinely nothing to report; it tried and could not finish; the tool behind it is not installed on this deployment; or it was deliberately excluded, by your plan tier or by the gate that stops a heavy scan running against a domain with no site behind it. The report prints which, every time.

What does the free scan leave out?

The free tools run the quick checks: HTTP, DNS, TLS, redirects, SEO, structured data, AI visibility, conversion readiness, cookies, email authentication and platform fingerprinting. The full audit in your workspace adds deep Core Web Vitals lab and field performance measurements, WCAG accessibility conformance analysis, and multi-page crawl verification.

What does "AI visibility" actually measure?

Two separate things, because they fail independently. Whether an assistant can reach and read the site at all, meaning what robots.txt says about GPTBot, ClaudeBot, PerplexityBot and the rest, whether there is structured data describing the business, whether anything is shaped as an answer. And whether it would cite the site once it has read it: authorship, dates, outbound citations, extractable structure, a clearly defined business entity. A site that blocks the crawlers cannot be recommended however good its content is, so that finding caps the category rather than averaging into it.

What will you not claim to measure?

How often an assistant mentions a business. Nobody can measure that from outside the assistant, and anyone selling you the number is selling you a sample of prompts they chose. We also check for an llms.txt file and say plainly on the report that no major assistant has committed to reading one, and selling a client an llms.txt as an AI strategy is selling them a deliverable rather than an outcome.

How is the score worked out?

11 categories, each scored 0 to 100 against something published you can go and look up, then weighted by the service line you sell and combined into one composite with a letter grade. Every finding also carries a confidence label: high where it was measured, medium where it was inferred. The difference is printed rather than smoothed over.

Can I show a client what changed after we fixed it?

Re-audit and the two runs are diffed, classified by why the change is material rather than by which number moved. Put a site on a monitor, daily, weekly or monthly, and you are told when a critical finding appears, when the score moves, or when a batch of things change at once. That alert is usually the reason for the next conversation.

How long does a shared report link stay live?

It depends on the plan: a month on Free, three months on Solo, and from Agency upward the link does not expire. The links are unguessable and need no login, so a prospect can open one on a phone, and because they are unlisted rather than public, the whole path is kept out of search indexes.

Still the fastest way to judge it

Point it at a website whose problems you can already list, and count how many of them it finds.