Know What You're Exposed To

Security & Compliance

Missing security headers, cookies set before anyone agrees to them, a key left somewhere public, a privacy policy that doesn't match what the site collects — none of it shows up until someone asks, or something goes wrong. We help in three ways:

  • Security & Compliance Check — a full audit and a plain-English report
  • Check & Fix — the audit, plus we fix what's found and re-check it
  • Processor Agreements — the UK GDPR paperwork for sites you run for clients

FAQ

Do I need this if I already have a website?

If your site collects any personal data — a contact form, bookings, accounts, payments — yes. Most sites have at least one gap the owner doesn't know about — cookies set before consent and missing security headers are the most common.

Is this a legal service?

No — it's a technical and practical compliance check, not legal advice. For contracts or anything high-risk (special category data, large-scale processing) we'll flag where you need a solicitor.

What do I actually get?

A written report: what was checked, what passed, what didn't, and a prioritised fix list. Fixes can be included or quoted separately.

Do you need access to my systems?

The base audit only needs your live URL. A deeper check (database rules, hosting config) needs read access to the relevant dashboard — never your live credentials shared insecurely.

How long does it take?

Standard audit: 3–5 days. Full audit with fixes: 1–2 weeks depending on what's found.

Service 01

Security & Compliance Check

Know what your website is exposing, before someone else does.

Most sites get built for speed and never get a second look at what they're exposing. We run a full check against your live site or app — security settings, cookies and consent, exposed keys, database access and your legal pages — and give you a plain-English report of what's wrong, how serious it is, and exactly what to fix.

Who it's for

Any site that collects personal data — a contact form, bookings, accounts or payments. If your site does any of those, it needs checking.

What's included

  • HTTPS and security headers — HSTS, CSP, Referrer-Policy and more
  • Cookies and consent — nothing non-essential set before consent, and a real “reject all”, as the ICO expects
  • Exposed secrets — API keys, source maps and files that shouldn't be public
  • Database access rules if you're on Supabase or similar
  • Privacy, cookie and terms pages checked against what the site actually collects
  • A written report with a prioritised fix list

How long it takes

A standard audit takes 3 to 5 days. The base check only needs your live web address.

Is this legal advice?

No — it's a technical and practical compliance check. Where you need a solicitor, we'll say so.

How it works, step by step

  1. Send us your web address. For a deeper check, read-only access to your hosting or database dashboard — never passwords sent by email.
  2. We run the audit. Automated checks plus a manual review of your legal pages and how data moves.
  3. Your written report. What's wrong, how serious it is, and what to do about it.
  4. Fix it or hand it on. We can quote to fix it all, or you pass the report to your developer.
Glowing circuit lines on a dark background

Security check prices

Security & Compliance Check

£249

Full audit and written report, one site.

Get a quote

Multi-Site Audit

£199/site

Running several sites? A discount per site from the second one.

Get a quote

Special category data

Quoted

Health, disability or children's data needs a deeper check, scoped individually.

Get a quote

Packages & ongoing support

Ongoing Support

Security & Compliance Retainer

For sites that keep changing — a scheduled re-audit and priority fixes when something needs attention.

£150per month, starting

  • Quarterly re-audit as standard
  • Priority turnaround on anything flagged
  • Dependency & vulnerability checks on every deploy
  • Month-to-month, no long-term contract
Start a Retainer

Service 02

Check & Fix

Don't just find the gaps — close them.

A report is only useful if something changes. With Check & Fix we run the full audit, then implement the fixes ourselves — security headers, database rules, a proper consent banner, updated legal pages — and re-check once it's all live, so you know the gaps have actually closed.

Who it's for

Owners who want it sorted rather than a to-do list — and sites handling bookings, payments or accounts.

What's included

  • The full audit — everything in the Security & Compliance Check
  • Fixes implemented — headers, access rules, consent banner, exposed files removed
  • Legal pages updated to match what the site really collects
  • A re-check once the fixes are live, included
  • Plain-English summary of what changed and why

How long it takes

A full audit with fixes usually takes 1 to 2 weeks, depending on what's found.

How it works, step by step

  1. Audit. The full check, exactly as above.
  2. Fix list and quote. Every fix, in order of risk, with the price in writing.
  3. We fix it. Implemented carefully on your live site, with you kept informed.
  4. Re-check. We run the checks again to confirm every gap is closed.
  5. Keep it current. Sites change — a retainer re-checks every quarter.
A laptop showing a website dashboard

Check & fix prices

Check & Fix

£450+

Audit plus implementing the fixes found.

Get a quote

Platinum

£899

Full clean-up: audit, fixes, processor agreement and re-check.

See packages

Security Retainer

£150/month

Quarterly re-audit and priority fixes.

Start a Retainer

Service 03

Processor Agreements

The paperwork UK GDPR expects, done properly.

If you build or run a website that handles someone else's customer data — as an agency, developer or freelancer — UK GDPR (Article 28) requires a written data-processing contract between you and your client. We draft it for the specific site, so both sides know who is responsible for what.

Who it's for

Web designers, developers, agencies and freelancers who host or manage sites for clients.

What's included

  • An Article 28 processor agreement written for the specific site
  • What data, why and for how long, set out clearly
  • Security measures and sub-processors listed (hosting, email, payments)
  • Breach and deletion responsibilities agreed in writing
  • Ready to sign by both parties

Is this legal advice?

It's a practical template-based agreement. For high-risk processing we'll recommend a solicitor reviews it.

How it works, step by step

  1. Tell us about the site. What it collects, where it's hosted and who does what.
  2. Written quote. The price in writing — usually £150.
  3. We draft it. Tailored to the site and the tools it uses.
  4. Sign and file. You and your client sign; keep it with your records.
A professional reviewing data on office screens

Paperwork prices

Processor Agreement

£150

Written Article 28 contract for a client site you build or run.

Get a quote

Security & Compliance Check

£249

Full audit and written report, one site.

Get a quote

Platinum

£899

Audit, fixes, processor agreement and re-check.

See packages