What we check

Six disciplines. One product. Every customer gets all six.

Most tools are excellent at one of these and silent on the other five. One read-only pass covers all six on every page, which is the only way to know which finding actually matters first.

Reported as a risk band

Privacy & tracking

What is on your pages, what is leaving them, and whether you can name where it goes.

Every third-party tag on your pages is something you are paying for, were sold once, or never authorised. Tags you cannot name still collect from your visitors, and tags that fire before consent can make the data you collect unusable.

What we look at

  • Every outbound request, beacon, cookie and storage write
  • Known trackers, ad pixels, session recorders and fingerprinting
  • Personal-data patterns leaving to third parties, captured in transit
  • Cookies set before any consent was given
  • Third-party scripts writing cookies under your own domain

Where an obligation exists

The HIPAA pixel guidance, state consumer-health privacy laws, GDPR/CCPA consent duties — and the enforcement record behind them.

What we do not claim

We report what we observed in a visit where no consent was given. That is not a measurement of your consent platform, and we never characterise how it is configured — a consent tool cannot audit itself, which is exactly why an independent observation is worth having.

Monitoring watches for a new third party appearing, a tracker reaching a sensitive page, or consent stopping working.

Reported as a 0–100 score

Search & findability

Whether the pages you want found can be found, and read correctly, by search engines and AI crawlers.

Pages that cannot be indexed cannot earn traffic, and pages that are indexed under the wrong title compete with each other. Both mean spend on content that no search result points at.

What we look at

  • Indexability, canonicals, redirects and status codes
  • Titles, descriptions, headings and duplication across pages
  • The gap between the HTML you serve and the page after JavaScript
  • Structured data, sitemaps, robots rules and internal linking
  • Whether AI crawlers may retrieve you — and whether that is separate from training

Where an obligation exists

Thin — but claims made in titles and meta descriptions are still claims, and the trust pack reads them.

What we do not claim

This is TECHNICAL SEO. We do not sell rankings, keyword volume or backlinks: those need a proprietary index costing tens of millions a year, and no cold scan can produce them honestly.

Monitoring watches for a page falling out of the index, a title or canonical changing, or a redirect breaking.

Reported as a risk band

Security posture

What your site tells the outside world about how it is configured — observed without touching it.

Missing transport and header protections are the conditions other problems need in order to become incidents. They are also the first thing a procurement or insurance questionnaire asks about.

What we look at

  • Transport security, certificates and the TLS handshake
  • The response-header set, including CSP and its gaps
  • DNS records: SPF, DMARC, DKIM, CAA
  • Known-vulnerable front-end dependencies
  • Cookie flags and third-party script inventory

Where an obligation exists

PCI DSS 6.4.3 and 11.6.1 for anyone taking card payments, and the security half of every vendor questionnaire.

What we do not claim

We never probe, never attempt to exploit, and never send a request designed to break something. Everything here is what a careful visitor could observe.

Monitoring watches for a certificate expiring, a header being dropped, or a dependency becoming known-vulnerable.

Reported as a 0–100 score

Accessibility

People who use a keyboard, a screen reader, magnification or a phone can finish what your site is for — or they leave.

A control a screen reader cannot name, or a form that cannot be completed by keyboard, ends the visit for that person. The same defects are what demand letters cite.

What we look at

  • Controls, links and fields with no accessible name
  • Form labels, required-field indicators and error handling
  • Contrast, tap-target size, heading structure and landmarks
  • Keyboard reachability signals and focus visibility
  • Media captions, autoplay, motion and zoom locks

Where an obligation exists

ADA Title II and Title III, HHS Section 504 for providers receiving federal funds, and WCAG as a line item in hospital and enterprise procurement.

What we do not claim

We do not issue a VPAT or an Accessibility Conformance Report, and we never say "conformant". Automated testing covers the machine-detectable part of WCAG; the judgement part needs a person, and we say which is which.

Monitoring watches for a new template shipping with unlabelled controls, or contrast regressing.

Reported as a 0–100 score

Speed & mobile

How heavy your pages are to load, and what that does to the visit you already paid for.

Weight and render-blocking work delay the moment a page becomes usable. Paid traffic pays for the click whether or not the visitor waits for the page.

What we look at

  • Page weight, request count and render-blocking resources
  • Lab Core Web Vitals and the audits behind them
  • Caching, compression and protocol version
  • Field data where Google has enough of it for your site

Where an obligation exists

None. This pillar carries no obligation, and we do not invent one.

What we do not claim

Lab measurements are labelled as lab. Real-user monitoring needs a beacon installed on your site, which would destroy the cold, install-free posture the whole suite depends on.

Monitoring watches for a new script blocking render, or page weight climbing after a release.

Reported as a risk band

Claims & trust

What your pages promise, and whether the disclosures around those promises are present.

Claims that outrun what a page substantiates, and subscription terms that are hard to find, are the two patterns that turn marketing copy into a complaint.

What we look at

  • Claim language that outruns what the page substantiates
  • Subscription, renewal and cancellation disclosures
  • Testimonial, endorsement and results framing
  • Policy pages: present, reachable, and what they say they cover

Where an obligation exists

FTC substantiation, FDA promotional rules, ROSCA and the subscription-disclosure line of cases — the corpus’s home turf.

What we do not claim

We report the words on the page and the rule they implicate. We never conclude that a claim is false, deceptive or unlawful — that is a determination for a regulator or a court.

Monitoring watches for new claim language appearing, or a disclosure disappearing in a redesign.

Why one product

The disciplines argue with each other. A single tool sees the argument.

A tracking script that helps marketing is a privacy finding and a performance finding. An image with no alt text is an accessibility defect and a findability one. The same page, read six ways in one pass, is what makes the worklist an order rather than six inboxes.

Accessibility
axe-core, IBM Equal Access, Lighthouse, HTML CodeSniffer
both major open-source engines — axe-core is what most accessibility tools run underneath
Privacy
Blacklight, Disconnect, DuckDuckGo Tracker Radar, WhoTracks.me
+ eight things none of them report: whether the consent banner actually stops the tracking
Security
Internet.nl, SSL Labs, Mozilla Observatory, securityheaders.com, retire.js + OSV.dev
the Dutch government’s standards test — it reaches DNS and the TLS handshake, not just headers
SEO
Screaming Frog, Google Lighthouse
the crawler every SEO knows, measured against its full published issue list
Performance
Google Lighthouse, CrUX field data
the audit set behind PageSpeed Insights and GTmetrix, plus what real visitors actually experienced
Claims & Trust
the FTC / FDA / DOJ enforcement record
the one pillar no other scanner benchmarks at all

Each discipline is measured against the tool that defines it. The full check-by-check comparison is available on request — it belongs in a technical review, not a headline. What a scan cannot determine →

What this is, and isn’t. ClearSite reports observable technical facts about a website with a confidence level for each finding. It does not determine legal compliance, does not assert violations of any law, and is not legal advice. Items we can’t observe from the outside (such as whether a vendor has signed a Business Associate Agreement) are flagged to verify, never asserted. Remediation offers are technical changes, not legal outcomes.

See all six on your own site.

Read-only, minutes, nothing to install.

Free, read-only, results in minutes. By scanning you confirm you’re authorized to scan this site and agree ClearSite retains results for de-identified industry research. See a sample report.