Who it's for
Any site that collects personal data — a contact form, bookings, accounts or payments. If your site does any of those, it needs checking.
What's included
- HTTPS and security headers — HSTS, CSP, Referrer-Policy and more
- Cookies and consent — nothing non-essential set before consent, and a real “reject all”, as the ICO expects
- Exposed secrets — API keys, source maps and files that shouldn't be public
- Database access rules if you're on Supabase or similar
- Privacy, cookie and terms pages checked against what the site actually collects
- A written report with a prioritised fix list
How long it takes
A standard audit takes 3 to 5 days. The base check only needs your live web address.
Is this legal advice?
No — it's a technical and practical compliance check. Where you need a solicitor, we'll say so.
How it works, step by step
- Send us your web address. For a deeper check, read-only access to your hosting or database dashboard — never passwords sent by email.
- We run the audit. Automated checks plus a manual review of your legal pages and how data moves.
- Your written report. What's wrong, how serious it is, and what to do about it.
- Fix it or hand it on. We can quote to fix it all, or you pass the report to your developer.