Trust

We sell scrutiny, so here is ours.

Everything on this page is checkable from outside, by you, right now — the same standard we hold a customer's site to.

Our own scan

We ran the product against this site. Here is what it said.

Every number below is our own engine's, on this live site, published whether or not it flatters us. Nothing is filtered for looking bad — the open findings are listed by name.

64Findability
86Speed
96Experience
23findings still open

Scanned 2026-08-19 against the live site, over HTTPS, at commit 4e2518d · 11 of 15 discovered pages read (/login, /scan, /demo are excluded by our own robots.txt) · coverage complete. The regulated disciplines report a band, not a number, so they are not shown as scores here.

What is still open

  • HighNo SPF record — anyone can send email as clearsitedigital.comno v=spf1 TXT record on clearsitedigital.com; sends-mail=true
  • HighNo DMARC record — forged email from clearsitedigital.com is delivered uncheckedno v=DMARC1 TXT record at _dmarc.clearsitedigital.com; sends-mail=true
  • Medium11 resource(s) block the page from rendering/: /assets/index-BL15LPy8.css | /refunds: /assets/index-BL15LPy8.css | /how-it-works: /assets/index-BL15LPy8.css | /accessibility: /assets/index-BL15LPy8.css
  • MediumNo DKIM signature found for clearsitedigital.comno DKIM TXT at common selectors (google/selector1/selector2/default/…) for clearsitedigital.com
  • MediumRecurring/auto-renewing charges with no cancellation information — verify the terms are disclosedrecurring/auto-renew offer with no cancellation info on: /terms
  • MediumNo separate consumer-health-data privacy policy found — verify state health-privacy obligationsno consumer-health-data policy link; forms present
  • MediumA free trial that converts to a paid plan — verify the conversion terms and consentfree trial + recurring charge on: /
  • MediumA minimum commitment / non-refundable term — verify it is disclosed clearly up frontminimum-commitment/non-refundable language with a recurring charge on: /refunds, /pricing
  • Low3 static file(s) are re-downloaded on every visithttps://clearsitedigital.com/assets/index-BL15LPy8.css, https://clearsitedigital.com/assets/index-CAHTKckZ.js, https://clearsitedigital.com/assets/index-CZ8RQhjC.js
  • Low4 page title(s) are too short or too long for search results/ (66 chars), /refunds (25 chars), /terms (28 chars), /privacy (26 chars)
  • LowBusiness structured data is missing key fieldspresent: name, url
  • Low2 page(s) have an H1 longer than 70 characters/how-it-works (73 chars), /build (77 chars)
  • Low1 page(s) redirect using JavaScript/: https://clearsitedigital.com/
  • Low8 meta description(s) are outside the ideal length/ (179 chars), /how-it-works (192 chars), /accessibility (175 chars), /pricing (189 chars), /build (179 chars)
  • Low2 subheading(s) run longer than 70 characters/pricing, /what-we-check
  • LowSmall tap targets on 2 page(s)/build (4), /company (4)
  • LowNo CAA record — any certificate authority can issue certs for clearsitedigital.comno CAA record for clearsitedigital.com
  • LowOCSP stapling is not enabledno stapled OCSP response during the handshake
  • Low2 page(s) appear to have no internal links pointing to them/what-we-check, /company
  • LowNo business address found on the siteno "City, ST ZIP" address pattern found on the 11 of 15 discovered pages this scan reached
  • LowNo tap-to-call phone link detectedno tel: links found
  • LowHTTP compression is enabled on a page that carries a login formcontent-encoding: br; login surface observed at /, /refunds, /how-it-works
  • LowNo simple/self-serve cancellation is indicated — verify cancellation is easyrecurring offer, no self-serve cancel indicator on: /trust, /what-we-check

What we filtered out

This run scanned the live site over HTTPS. Nothing is excluded: every finding the scan produced is listed above.

Don’t take our word for any of it: point our scanner at this domain yourself and read what comes back. Scan clearsitedigital.com →

The deliverable

What the report actually looks like.

A real report from a real 2026 scan of a medical practice’s public site, produced by the same renderer a customer’s PDF comes from. The practice is not named and every direct identifier — domain, phone, email — has been replaced.

The report cover: the site, the overall risk band, the date, pages reviewed and scan mode.
The cover states the band, the date, how many pages were reviewed and the scan mode.
Inside the report: the ordered worklist and the evidence chapter, grouped by what each finding does to the business.
Inside: the ordered worklist, then the evidence grouped by what it does to the business.

Download the full sample report (PDF) the same document, all of it, redacted the same way.

These pages load nothing from anyone else.

No analytics, no tag manager, no session recorder, no font CDN, no chat widget. The typeface is served from this origin. Open devtools on any public page here and the third-party request list is empty — which is the only version of that claim worth making, because you can check it in about ten seconds.

This was not always true. Until 2026-08-18 this site tried to load its web fonts from Google, and our own Content-Security-Policy blocked the request on every page — so the fonts silently never loaded for anyone. We found it by rendering the built site and looking at it, which is the same method the product uses on yours.

Response headers on every page

Content-Security-Policy
Scripts and styles load from this origin only. No CDN, no tag manager, no analytics vendor.
Strict-Transport-Security
Two years, includeSubDomains, preload. HTTPS is not optional here.
X-Frame-Options / frame-ancestors
This site cannot be framed by anyone else.
X-Content-Type-Options
nosniff.
Referrer-Policy
strict-origin-when-cross-origin — outside services never receive the full path you were reading.
Permissions-Policy
Camera, microphone, geolocation, payment and USB are switched off at the browser level.

How we handle your data

In plain English, with the policy behind it.

What a scan stores

The URL you submitted, the signals the crawler observed, and the report we assembled from them. That is what makes a report re-openable and a change report possible.

The research grant

Anonymous free scans carry a retention grant: we keep the results for de-identified aggregate research and published industry statistics. Your own report stays yours and stays private; what we aggregate is the shape of the web, not you.

Who can see your reports

Your account, and the operator when supporting you. Reports are never shared with another customer, and we do not sell scan data.

Deleting it

Email support and we remove the account and its scans. If a subscription is live we will ask you to cancel first rather than deleting the record behind an active charge.

Payments

Stripe processes payments. We never see or store your card details.

Email

Alerts come from our own domain with SPF and DKIM in place. You can turn alerts off without cancelling, and cancelling is self-serve.

The binding versions are the Terms, the Privacy Policy and the Refund Policy. They are marked draft while counsel reviews them, and we would rather publish them marked draft than publish nothing.

Authorization

What we will and will not do to a website.

Read-only by default

We load public pages the way a visitor’s browser does. We never submit a form, never sign in, never attempt to exploit anything, and never send a request designed to break something.

Deeper testing is a permission, not a purchase

Interactive testing — clicking a consent banner and recording what fires anyway, for instance — runs only on domains whose ownership you have verified. Verification is free and always will be. Money buys breadth and frequency; permission buys depth.

We are polite to your server

We honour robots.txt and crawl-delay, cap our own request rate, and stop when a site signals it has had enough. A scan should never be something your ops team notices.

Report a vulnerability

Email support@clearsitedigital.com. The machine-readable version is published at /.well-known/security.txt, which is where a scanner looks for it — our own security pack flags a site that does not publish one.

Accessibility

We publish our own defects.

We scan this site with our own engine and fix what it reports. The current state, the standard we work to, and the known issues are on the accessibility statement — which is a statement of posture, not a conformance report, because an automated scan cannot produce one.

What this is, and isn’t. ClearSite reports observable technical facts about a website with a confidence level for each finding. It does not determine legal compliance, does not assert violations of any law, and is not legal advice. Items we can’t observe from the outside (such as whether a vendor has signed a Business Associate Agreement) are flagged to verify, never asserted. Remediation offers are technical changes, not legal outcomes.