How it works
No install, no tag, no access to your hosting, no credentials. Here is exactly what happens between typing your domain and reading the report — including the parts a scan cannot answer.
Chromium, from the outside, with no credentials and nothing installed. We follow your links and your sitemap across the site rather than reading one URL, and we record what the browser records: every request and beacon, cookies and browser storage, response headers, the DNS and TLS configuration, the HTML your server sent and the DOM after JavaScript ran.
Read-only by default. We never submit a form, never sign in, and never change anything.
Every page we try lands in one of two buckets: it answered, or it failed. A remainder would mean we abandoned visits, so the report says how many pages were reached, how many returned an error status, and how many were discovered but not visited — with the reason (budget, timeout, or a robots rule we honoured).
A scan that cannot say what it covered cannot support a conclusion. We would rather publish "partial" than imply completeness.
Collection and analysis are separate by design. The crawler gathers industry-neutral signals; the rule packs read those signals and emit findings. That is why the same scan can be read through a general lens or a regulated one without re-crawling you, and why adding a discipline never changes what we collect.
Ten customer-facing rule packs across six disciplines.
What we saw — the observable fact, with the page and the element, request or header behind it. Why it matters — in plain English, or in the counsel-adjacent register where the finding touches an obligation. What to do — a technical next step. And how sure we are — a severity, a confidence out of 100, and whether the fact was observed or inferred.
If we did not observe it, it is not a finding.
Regulations move. We track each one we cite with a status (in force, proposed, vacated, superseded) and a review clock, and a build fails when a citation goes stale. Where a public enforcement action has cited the same observable pattern on some other site, we attach it as context.
Context from the public record. Never a verdict on your site, and never a prediction about your exposure.
Findings are ordered into a worklist by what actually moves the verdict. Make the change and re-scan: each item then reads closed, partly done or still open — scored against the plan you were handed rather than a fresh one, so the work you finished does not vanish from the report because you finished it. Where a re-scan could not cover the same ground the item reads not checked, which is the absence of a verdict rather than a fourth one.
Monitoring repeats this weekly and tells you when something new appears or a fix regresses.
The anatomy of a finding
This is a real one, in the product’s own words, from a 2026 scan of a medical practice’s public site. The site is not named.
Form fields without labels on 1 page(s) — unusable with a screen reader
/contact — 1 field with no programmatic label (no <label>, aria-label, or equivalent).What we are measured against
These are the tools that define each discipline. Each is single-purpose and mostly looks at one page at a time; we benchmark check-by-check against each one’s own published catalogue, across every page, in one pass — and CI re-verifies those claims on every build.
We hold a measured, check-by-check coverage figure for every tool named here, and we will walk you through it — including the places where a number went down when we moved to a harder reference tool. That belongs in a technical review rather than on a marketing page, so ask and we will send it.
Limits
Every scanner has this list. Most do not publish it. Ours is the same list the report itself carries, because a buyer who discovers a limit after paying has been sold something else.
A read-only scan sees what a visitor sees. Member areas, patient portals and admin screens are out of scope unless you verify ownership and authorize a deeper tier — and that is a permission you grant, never something you buy.
We can see that a form posts to a third-party vendor. We cannot see whether you have a Business Associate Agreement or a data-processing agreement with them. Those findings say verify, and they say it every time.
We observe the outside of the building. Configuration we cannot reach, code we cannot read, and internal process are all outside what a scan can support.
Automated testing detects part of WCAG. Whether alt text is meaningful, whether a flow can actually be completed with a keyboard, whether an error message helps — those need a person. We report the machine-detectable subset and label it as such. We do not issue a VPAT or an Accessibility Conformance Report, and no automated tool can.
We report what is on your site and what the public record contains. Nobody can tell you what an agency or a plaintiff will do next, and any tool that puts a number on that is selling you a guess.
What this is, and isn’t. ClearSite reports observable technical facts about a website with a confidence level for each finding. It does not determine legal compliance, does not assert violations of any law, and is not legal advice. Items we can’t observe from the outside (such as whether a vendor has signed a Business Associate Agreement) are flagged to verify, never asserted. Remediation offers are technical changes, not legal outcomes.
Read-only, minutes, nothing to install.
Free, read-only, results in minutes. By scanning you confirm you’re authorized to scan this site and agree ClearSite retains results for de-identified industry research. See a sample report.