Features
Five things, and they only matter together.
A list of businesses is a commodity. A scan is a commodity. What is not is the join: knowing which business is in trouble, being able to prove it against a published standard, and having something to say about it that quotes the proof.
The five
Find
A trade and a city in, a deduplicated list of real businesses out, discovered across business directories and public listings.
Measure
Every check in the engine, run live against the site, each one reporting whether it ran, found nothing, failed, or was never available here.
Rank
11 weighted categories into one number and a letter grade, with the weights set by the service line you sell.
Explain
A 17-section report written for the person who owns the business, not the person who built the site.
Open
A short draft quoting the worst measurement, held in a queue until you approve it and sent from your own inbox.
Discovery
The half of the funnel every scanner is missing.
Every competing tool waits for somebody to arrive and paste a URL, which means it only ever sells to people who already suspect they have a problem. This starts from the other end.
- Deduplicated and verified
- Multiple directory sources combined and deduplicated, so you get a complete list without doing the manual legwork.
- Two segments, two pitches
- Businesses with no website at all are a separate list from businesses with a website in trouble, because they are separate conversations.
- You choose what gets measured
- Discovery and audit are deliberately separate actions. Nothing is scanned because it appeared in a list.
- Saved searches
- A search worth running once is usually worth running monthly. Schedule it and the new businesses arrive on their own.
Everything that ends up on a prospect record
The audit is one of six things measured about a business. The rest is what turns a row in a list into a conversation you can open.
Reviews, read rather than counted
The public review corpus with its sentiment, the complaints that come up more than once, and what customers praise. A star count is not a finding; "four people mention the phone going unanswered" is.
Local search visibility
How well the business is surfaced in local results, verified directories, and map listings, giving you concrete pitch angles.
Contacts from their own site
Email addresses and social profiles read off the homepage and the pages it links. Ordinary HTTP, with no data broker, no purchased list, nothing that requires logging in to a platform.
Two segments, two pitches
A business with no website at all is a different conversation from one whose website is in trouble, and they are separate lists. Each also carries what it is standing on instead: a social page, a directory, a builder.
What built it, and what hosts it
Fingerprinted separately, because they are separate facts. The report then speaks in the terms of the tool the owner actually used rather than in terms of a stack they have never heard of.
Local Grid
One rank is an average. A grid is an argument.
Ask where a business ranks and the honest answer is "it depends where you are standing". A single map-pack check picks one point and calls it the answer. The Local Grid measures a lattice of coordinates around the business and returns a rank for every one of them, which is the picture that shows an owner they are invisible four streets from their own door.
See how we measure- A rank per coordinate, not per city
- Odd-sized grids from 3x3 to 15x15, spaced in metres you choose, centred on the business. Odd because the business then sits in a centre cell rather than on a corner between four.
- Run when you ask, never on a schedule
- This exists to produce the artefact you put in a proposal, not to become rank monitoring you have to resell. Nothing runs in the background and nothing accrues cost while you are not looking.
- Re-run it to show the work
- The same grid after the retainer has been running for a quarter is the single most persuasive slide there is, because it is the same measurement rather than a new one chosen to flatter.
- A hole is drawn as a hole
- A coordinate the source refused is left visibly empty rather than filled with "does not rank". Handing a client a picture of failure that is really a picture of our own transport error is the one outcome worth engineering against.
Your name is on this report
A check that could not run is not a check that passed.
You put your logo on this and send it to a client. So when something could not be measured, the report says so, in one of five states per check, printed, every time. The alternative is a green tick you cannot stand behind in the room.
48 checks ship in the engine. Which of them run against a given site depends on the plan, on what the site turns out to be, and on what the deployment has installed, so the report says which, every time.
- ok
- It ran and it produced a measurement.
- empty
- It ran, and there was nothing to report. Clean, not absent.
- failed
- It tried and could not finish. The only one of the five that means something is wrong at our end.
- missing
- The tool behind it is not installed on this deployment, so the check was never available.
- skipped
- Deliberately excluded, either by the plan tier or by the gate that stops a heavy scan running against a domain with no site on it.
What gets measured
11 categories, each against something published.
Grouped into five tabs here for reading; the report scores each category separately. Every number in it is a live measurement of the site in question, checked against a standard the reader can go and look up, and that constraint is what makes a diagnostic arguable rather than merely assertive.
Core Web Vitals, lab and field
Measured in a real headless browser and, where enough real visitors exist for it, against the field data Google collects from them. Server response time, render timings, layout stability, and the weight of what the page is actually shipping.
Read-only, first-party, GET requests
Response headers graded, TLS protocol and certificate chain, configuration files and debug surfaces left reachable, credentials matched inside the JavaScript the site publishes, and known vulnerabilities in the client-side libraries it loads. Nothing is written and no payload is injected. Email authentication scores here too, not as a category of its own: SPF, DKIM, DMARC and BIMI, and whether the sending domain has ended up on a mail blacklist. "Your invoices are going to spam" costs money this month in a way a missing header does not, and no other tool in this category looks at it.
For search engines and for answer engines
Titles, headings, canonicals, structured data and sitemap validity. Then the two AI questions separately, because they are two questions: whether an answer engine is allowed to read the site at all, and whether there is anything on it worth citing when it gets in, which is authorship, dates, citations and a defined business entity.
The business, not just the website
The Google Business Profile scored on its own: claimed or not, hours, categories, photos, and whether the listing says the business has closed. Beside it the public review corpus with its recurring complaints, and how well the business surfaces in map results across the area it actually serves. For a business with no website at all this is the only part of the audit that can produce a score, and an unclaimed listing is the one fix that unlocks every other fix there is.
Whether a visitor can use it, and what it is made of
WCAG 2.1 AA failures counted on the rendered page by severity, alongside the practical things: whether there is a call to action, whether the form works, whether a phone number can be tapped, and what stands between a visitor and an enquiry. Then what built the site and what hosts it, fingerprinted separately because they are separate facts, and the build-quality signals a hurried site leaves behind: JavaScript errors thrown at real visitors, dead-code bloat, and placeholder copy still on the page.
The report
17 sections, and none of them assume a developer is reading.
The web report and the PDF are always identical: what you show on a call matches what you email. On a paid plan it carries your logo, your colour and your name.
What is in a report- Why, what it costs, how to fix
- Every warning carries all three, in plain sentences, with an effort estimate you can price.
- A confidence label per finding
- High where it was measured, medium where it was inferred, and the report says which.
- A shareable link and a PDF
- Unguessable, no login, opens on a phone. Views are counted, because a prospect re-reading a report is a signal.
- Before and after
- Re-audit later and the two are diffed, which is how you show a client what they paid for.
From finding to fixed
A diagnosis nobody can act on is a document, not a deliverable.
Most of this category stops at the finding. The gap between "your SPF record is wrong" and a client with a working SPF record is where an agency actually earns, so the report closes as much of it as it can.
- The fix, already written
- The nginx block, the schema snippet, the SPF record for the mail provider they are actually on. Paste it, do not translate it.
- And a prompt for their AI agent
- Every fix also ships as a paste-ready instruction for the assistant that will make the change. Nobody else in this category does this, and it is increasingly how the work gets done.
- What it plausibly costs them
- A monthly figure, with every assumption behind it returned in the same breath rather than buried. A number you cannot show your working for is a number that loses the room.
- Three grades a buyer already asks for
- AI readiness, email security, and compliance, each A to F, each naming exactly which factors are missing. Plus an external attack-surface grade from what is reachable from outside.
The part nobody else ships
Every fix also comes as a prompt for the agent that will make it.
A findings list assumes a developer reads it and translates. Increasingly nobody does: the person fixing the site opens an assistant and describes the problem badly. So each finding ships a third form beside the explanation and the snippet, written to be pasted straight into a coding agent, carrying the measured value and the constraint rather than a vague instruction. It is the difference between a report that gets read and one that gets acted on the same afternoon.
Add a DMARC record to example.com.
Current state, measured 2026-09-06: SPF passes, DKIM passes,
no _dmarc TXT record exists. Mail provider is Google Workspace.
Add this TXT record at _dmarc.example.com:
v=DMARC1; p=none; rua=mailto:dmarc@example.com; fo=1
Start at p=none so nothing is rejected while you read the
reports. Do not move to p=quarantine until the aggregate
reports show every legitimate sender aligned, which is
usually two to four weeks.
Do not change the existing SPF or DKIM records. Both pass.
Outreach
Drafting is automated. Sending is a decision.
The market ran the fully autonomous experiment in 2025 and it did not work: reply rates collapsed, sender reputations went with them, and the survivors all went back to a human in the loop. This was built that way from the start.
How outreach works- Researched, then written
- What the business does, who it sells to and what it worries about, established first, so the draft is about them rather than about us.
- Anchored to one finding
- Declarative severity rules pick the angle. The email quotes a number that is in the report, and links to the report.
- Your inbox, your domain
- Connect Gmail or Outlook. Replies land where you already work and your reputation is the one at stake.
- Suppression at draft time
- Not just at send time. Somebody who opted out never reaches the review queue in the first place.
What a scanner does not do
Not a feature count. Six places where this behaves differently from the thing you are probably also evaluating, each of them a decision rather than a gap somebody has not got round to.
| Capability | SiteAssay | A typical audit tool |
|---|---|---|
| Finding the businesses | A trade and a city in, a deduplicated list of real ones out | You paste a URL you already had |
| A check that could not run | One of five states, printed on the report | Counted as a pass |
| After the finding | A draft quoting the measurement, held until you approve it | A CSV you write the email from |
| Email deliverability | SPF, DKIM, DMARC, BIMI, and whether the domain is blacklisted | Not looked at |
| Their competitors | The prospect and up to three rivals, same pass, same scale | One site at a time |
| From an AI agent | An MCP server that can start the audit, not only read one | Read-only, where it exists at all |
| Whose name is on it | Yours: logo, colour and footer. Ours disappears entirely | Theirs, with your logo in a corner |
And the parts that make it a business rather than a tool
None of these is the reason anybody signs up. Collectively they are the reason an agency is still using it in month six.
White-label
Your name, logo, colour and footer across the web report and the PDF. Ours disappears entirely.
Monitoring
Re-audit a site on a schedule and get told what changed. A report is read once; a monitor is a reason to open the product again.
A verifiable badge
A small SVG a business you have fixed can embed, linking back to a page that confirms the claim it makes.
API, MCP and webhooks
Start an audit from your own code or from a coding agent, and get told when it finishes.
Side by side with their rivals
Audit the prospect and up to three competitors in the same pass, on the same scale. The most persuasive slide in the deck is the one where they are third.
A shortlist at once
Audit a selection or an uploaded CSV in one go, on a queue of its own so a hundred sites never hold up the one you are on a call about. The allowance is quoted before it starts.
Searches that run themselves
A search worth running once is usually worth running monthly. Schedule it and only the businesses you have not seen before arrive.
A pipeline, not a spreadsheet
New, contacted, meeting, proposal, negotiation, won or lost, with a deal value on each and a nudge when one has gone quiet for too long.
Your whole team
Owners, admins and members, leads assigned to a person, and seat counts that include the invitations you have sent but nobody has accepted yet.
Take the data with you
Export to a spreadsheet whenever you want. Everything stays visible, filterable and auditable on every plan; getting it out is the paid part.
A scanner on your own site
A small script that puts a "check your website" box on your marketing page. Visitors audit themselves and land in your workspace as prospects.
Told when it matters
A prospect re-reading their report, a monitored site that moved, and one daily digest of the hottest leads. Everything else stays out of your inbox.
AI shipped it. Nobody checked the deploy.
A distinct and growing segment: sites assembled quickly by somebody who is not a developer, working through an assistant. They are usually well designed and they frequently publish things that were never meant to leave the server. Each of these is also a free tool on this site, so you can run one against a site you already know before you take our word for any of it.
Keys in the bundle
Provider credentials matched inside the JavaScript the site hands to every visitor. Published, not hidden.
Rows anyone can read
A database with row-level security never switched on, read using the public key the app ships itself. Read-only requests, nothing written.
Source maps in production
The file that turns a minified bundle back into the code somebody wrote, left reachable on the live site.
Scaffolding left in
Placeholder copy still on the page, the visible half of the same haste that left the rest of this list behind.
Which builder made it
Builder and host fingerprinted separately, so the report speaks in the terms of the tool the owner actually used rather than a stack they have never heard of.
Can an answer engine read it
Whether AI crawlers are allowed in at all, and whether there is anything quotable when they arrive. Generated sites are frequently one and not the other.
Try it on a site you already know
The fastest way to judge an audit engine is to point it at a website whose problems you can already list, and see how many of them it finds.