How it works

A real browser, one read-only pass, and a finding you can check yourself.

No install, no tag, no access to your hosting, no credentials. Here is exactly what happens between typing your domain and reading the report — including the parts a scan cannot answer.

  1. 1

    We load your pages in a real browser

    Chromium, from the outside, with no credentials and nothing installed. We follow your links and your sitemap across the site rather than reading one URL, and we record what the browser records: every request and beacon, cookies and browser storage, response headers, the DNS and TLS configuration, the HTML your server sent and the DOM after JavaScript ran.

    Read-only by default. We never submit a form, never sign in, and never change anything.

  2. 2

    The crawl states its own coverage

    Every page we try lands in one of two buckets: it answered, or it failed. A remainder would mean we abandoned visits, so the report says how many pages were reached, how many returned an error status, and how many were discovered but not visited — with the reason (budget, timeout, or a robots rule we honoured).

    A scan that cannot say what it covered cannot support a conclusion. We would rather publish "partial" than imply completeness.

  3. 3

    Rule packs read the signals — the crawl does not judge

    Collection and analysis are separate by design. The crawler gathers industry-neutral signals; the rule packs read those signals and emit findings. That is why the same scan can be read through a general lens or a regulated one without re-crawling you, and why adding a discipline never changes what we collect.

    Ten customer-facing rule packs across six disciplines.

  4. 4

    A finding is four things, in order

    What we saw — the observable fact, with the page and the element, request or header behind it. Why it matters — in plain English, or in the counsel-adjacent register where the finding touches an obligation. What to do — a technical next step. And how sure we are — a severity, a confidence out of 100, and whether the fact was observed or inferred.

    If we did not observe it, it is not a finding.

  5. 5

    Where an obligation exists, we name it — and its status

    Regulations move. We track each one we cite with a status (in force, proposed, vacated, superseded) and a review clock, and a build fails when a citation goes stale. Where a public enforcement action has cited the same observable pattern on some other site, we attach it as context.

    Context from the public record. Never a verdict on your site, and never a prediction about your exposure.

  6. 6

    Then you fix it, and we check

    Findings are ordered into a worklist by what actually moves the verdict. Make the change and re-scan: each item then reads closed, partly done or still open — scored against the plan you were handed rather than a fresh one, so the work you finished does not vanish from the report because you finished it. Where a re-scan could not cover the same ground the item reads not checked, which is the absence of a verdict rather than a fourth one.

    Monitoring repeats this weekly and tells you when something new appears or a fix regresses.

The anatomy of a finding

Every finding is built the same way.

This is a real one, in the product’s own words, from a 2026 scan of a medical practice’s public site. The site is not named.

Accessibility · Form accessibilityconfidence 85/100
High

Form fields without labels on 1 page(s) — unusable with a screen reader

What we saw/contact — 1 field with no programmatic label (no <label>, aria-label, or equivalent).
Why it mattersA form is where a visit turns into an enquiry. A field with no label is announced as “edit text”, so someone using a screen reader cannot tell which box wants their phone number — and the enquiry never arrives.
Next stepAssociate every field with a visible <label for=…> (or aria-label where a visible label is impossible); placeholders alone do not count.
Certainty observed · regulatoryRule WCAG 1.3.1 / 4.1.2Verify re-scan after the change
Severity
How much this one matters, on a four-band scale. It never averages with anything.
Confidence
How certain the observation is, out of 100. A pattern we watched happen scores higher than one inferred from configuration.
Certainty cell
Whether the fact was observed or inferred, and what kind of consequence it carries. Severity alone is lossy — it does not say whether we watched it happen.
Evidence
The page, and the element, request or header. Enough to reproduce it in your own browser without taking our word for anything.
Rule
The standard or obligation it touches, where one exists. Some findings touch none, and say so.
Verify
What a re-scan will check once you have made the change.

What we are measured against

Each discipline has a referee, and we run against it.

These are the tools that define each discipline. Each is single-purpose and mostly looks at one page at a time; we benchmark check-by-check against each one’s own published catalogue, across every page, in one pass — and CI re-verifies those claims on every build.

Accessibility
axe-core, IBM Equal Access, Lighthouse, HTML CodeSniffer
both major open-source engines — axe-core is what most accessibility tools run underneath
Privacy
Blacklight, Disconnect, DuckDuckGo Tracker Radar, WhoTracks.me
+ eight things none of them report: whether the consent banner actually stops the tracking
Security
Internet.nl, SSL Labs, Mozilla Observatory, securityheaders.com, retire.js + OSV.dev
the Dutch government’s standards test — it reaches DNS and the TLS handshake, not just headers
SEO
Screaming Frog, Google Lighthouse
the crawler every SEO knows, measured against its full published issue list
Performance
Google Lighthouse, CrUX field data
the audit set behind PageSpeed Insights and GTmetrix, plus what real visitors actually experienced
Claims & Trust
the FTC / FDA / DOJ enforcement record
the one pillar no other scanner benchmarks at all

We hold a measured, check-by-check coverage figure for every tool named here, and we will walk you through it — including the places where a number went down when we moved to a harder reference tool. That belongs in a technical review rather than on a marketing page, so ask and we will send it.

Limits

What a scan cannot determine.

Every scanner has this list. Most do not publish it. Ours is the same list the report itself carries, because a buyer who discovers a limit after paying has been sold something else.

Anything behind a login

A read-only scan sees what a visitor sees. Member areas, patient portals and admin screens are out of scope unless you verify ownership and authorize a deeper tier — and that is a permission you grant, never something you buy.

Whether a contract exists

We can see that a form posts to a third-party vendor. We cannot see whether you have a Business Associate Agreement or a data-processing agreement with them. Those findings say verify, and they say it every time.

Your server, your code, your policies

We observe the outside of the building. Configuration we cannot reach, code we cannot read, and internal process are all outside what a scan can support.

The judgement half of accessibility

Automated testing detects part of WCAG. Whether alt text is meaningful, whether a flow can actually be completed with a keyboard, whether an error message helps — those need a person. We report the machine-detectable subset and label it as such. We do not issue a VPAT or an Accessibility Conformance Report, and no automated tool can.

What a regulator will do

We report what is on your site and what the public record contains. Nobody can tell you what an agency or a plaintiff will do next, and any tool that puts a number on that is selling you a guess.

What this is, and isn’t. ClearSite reports observable technical facts about a website with a confidence level for each finding. It does not determine legal compliance, does not assert violations of any law, and is not legal advice. Items we can’t observe from the outside (such as whether a vendor has signed a Business Associate Agreement) are flagged to verify, never asserted. Remediation offers are technical changes, not legal outcomes.

Run it against your own site.

Read-only, minutes, nothing to install.

Free, read-only, results in minutes. By scanning you confirm you’re authorized to scan this site and agree ClearSite retains results for de-identified industry research. See a sample report.