What we check
Most tools are excellent at one of these and silent on the other five. One read-only pass covers all six on every page, which is the only way to know which finding actually matters first.
Reported as a risk band
What is on your pages, what is leaving them, and whether you can name where it goes.
Every third-party tag on your pages is something you are paying for, were sold once, or never authorised. Tags you cannot name still collect from your visitors, and tags that fire before consent can make the data you collect unusable.
The HIPAA pixel guidance, state consumer-health privacy laws, GDPR/CCPA consent duties — and the enforcement record behind them.
We report what we observed in a visit where no consent was given. That is not a measurement of your consent platform, and we never characterise how it is configured — a consent tool cannot audit itself, which is exactly why an independent observation is worth having.
Monitoring watches for a new third party appearing, a tracker reaching a sensitive page, or consent stopping working.
Reported as a 0–100 score
Whether the pages you want found can be found, and read correctly, by search engines and AI crawlers.
Pages that cannot be indexed cannot earn traffic, and pages that are indexed under the wrong title compete with each other. Both mean spend on content that no search result points at.
Thin — but claims made in titles and meta descriptions are still claims, and the trust pack reads them.
This is TECHNICAL SEO. We do not sell rankings, keyword volume or backlinks: those need a proprietary index costing tens of millions a year, and no cold scan can produce them honestly.
Monitoring watches for a page falling out of the index, a title or canonical changing, or a redirect breaking.
Reported as a risk band
What your site tells the outside world about how it is configured — observed without touching it.
Missing transport and header protections are the conditions other problems need in order to become incidents. They are also the first thing a procurement or insurance questionnaire asks about.
PCI DSS 6.4.3 and 11.6.1 for anyone taking card payments, and the security half of every vendor questionnaire.
We never probe, never attempt to exploit, and never send a request designed to break something. Everything here is what a careful visitor could observe.
Monitoring watches for a certificate expiring, a header being dropped, or a dependency becoming known-vulnerable.
Reported as a 0–100 score
People who use a keyboard, a screen reader, magnification or a phone can finish what your site is for — or they leave.
A control a screen reader cannot name, or a form that cannot be completed by keyboard, ends the visit for that person. The same defects are what demand letters cite.
ADA Title II and Title III, HHS Section 504 for providers receiving federal funds, and WCAG as a line item in hospital and enterprise procurement.
We do not issue a VPAT or an Accessibility Conformance Report, and we never say "conformant". Automated testing covers the machine-detectable part of WCAG; the judgement part needs a person, and we say which is which.
Monitoring watches for a new template shipping with unlabelled controls, or contrast regressing.
Reported as a 0–100 score
How heavy your pages are to load, and what that does to the visit you already paid for.
Weight and render-blocking work delay the moment a page becomes usable. Paid traffic pays for the click whether or not the visitor waits for the page.
None. This pillar carries no obligation, and we do not invent one.
Lab measurements are labelled as lab. Real-user monitoring needs a beacon installed on your site, which would destroy the cold, install-free posture the whole suite depends on.
Monitoring watches for a new script blocking render, or page weight climbing after a release.
Reported as a risk band
What your pages promise, and whether the disclosures around those promises are present.
Claims that outrun what a page substantiates, and subscription terms that are hard to find, are the two patterns that turn marketing copy into a complaint.
FTC substantiation, FDA promotional rules, ROSCA and the subscription-disclosure line of cases — the corpus’s home turf.
We report the words on the page and the rule they implicate. We never conclude that a claim is false, deceptive or unlawful — that is a determination for a regulator or a court.
Monitoring watches for new claim language appearing, or a disclosure disappearing in a redesign.
Why one product
A tracking script that helps marketing is a privacy finding and a performance finding. An image with no alt text is an accessibility defect and a findability one. The same page, read six ways in one pass, is what makes the worklist an order rather than six inboxes.
Each discipline is measured against the tool that defines it. The full check-by-check comparison is available on request — it belongs in a technical review, not a headline. What a scan cannot determine →
What this is, and isn’t. ClearSite reports observable technical facts about a website with a confidence level for each finding. It does not determine legal compliance, does not assert violations of any law, and is not legal advice. Items we can’t observe from the outside (such as whether a vendor has signed a Business Associate Agreement) are flagged to verify, never asserted. Remediation offers are technical changes, not legal outcomes.
Read-only, minutes, nothing to install.
Free, read-only, results in minutes. By scanning you confirm you’re authorized to scan this site and agree ClearSite retains results for de-identified industry research. See a sample report.