Our methodology
A useful audit tells you what it actually checked, and also what it could not check. This page explains the scope, the method and the limits of our examination.
Measured, not declared
We don’t take a site’s claims about itself for granted. Whenever something can be measured or observed, the report relies on that observation.
We open each page in a browser, just as a visitor would, and record what actually happens: what loads, what appears, what gets sent to third parties.
An outside view
We look at your pages as an outside visitor would, with no access to your back office and without changing anything on your site.
Nothing is installed and nothing is required from you: no code to add, no extension, no hosting access, no password. The report describes what your customers, partners and search engines see, not what privileged access might reveal.
What we actually test
When an interaction can be tested without changing anything on your systems, we separate what we actually triggered from what we only observed.
No access attempts, no forms sent, no accounts created, no orders placed: your site only sees read-only visits. What happens after a form is submitted is therefore not checked, and the report says so.
Limits are part of the result
Anything we cannot reach from outside is never declared compliant. It is marked as unverifiable or out of scope, as the case may be.
What “compliance” means here
The audit checks the elements and mechanisms, visible from outside, that can contribute to meeting the obligations that apply: the information required about the publisher and the host, cookie consent as it actually works, the privacy policy, and what gets sent to third parties.
Internal elements that cannot be seen from outside stay out of scope: processing records, processor contracts, procedures. The report records facts, measurements and observable signs. It is not a compliance certification, legal advice or a penetration test.
On a phone as much as on a computer
Speed is measured twice: once under phone conditions (mobile network and throttled processor, like a visitor on the move), once under desktop conditions. The same site can feel fine on one and far too slow on the other, so the report gives both figures.
Layout is checked at three widths: phone, tablet, computer. Some faults only show at certain widths: a button pushed off screen with no horizontal scrolling to signal it, a menu that no longer opens, a control covered by a banner.
What the server sends, and what the browser shows
We read the same page twice: the raw response your server sends, then the page as the browser displays it. What counts is the gap between the two. A title, a description or a canonical address built by the browser alone may never be visible to search engines or other automated systems.
How pages are selected
You don’t pick the pages we analyze, and we don’t pick them at random. The scope follows the real structure of your site, in this order:
- Survey. Sitemap and internal links: the page inventory is drawn up before any measurement.
- Grouping by type. Home page, product pages, articles, service pages, contact pages… Grouping helps us read the site’s structure and interpret the findings. It sets no number of pages per type.
- Legal obligations. Pages the law requires us to check come first: legal notice, privacy, terms of sale.
- Navigation. Next come the pages your navigation puts forward: home page, purchase or contact journey.
- Link frequency. Then the pages most often linked from the rest of the site.
- Final scope. Your plan covers the highest-ranked pages, up to its page limit.
- Exact list. The report lists the pages analyzed; pages not examined stay distinct from the audited scope.
Languages
Your main language is the one your site serves by default, or the one you name when you order. The plan’s page limit applies to it.
Each extra language is an option. It is analyzed like the main language, up to the same number of pages, and we go looking for its translated versions even when no link leads there: on many sites the language switcher is a form that ordinary crawlers never get past. We then check that the versions declare each other, that the page served is the one requested, and that the content is translated rather than copied.
Without the option, the audit covers one language, and the methodology note names those that were not examined. The page count is a maximum: a site sometimes declares a language on a hundred pages and only serves it on thirty, and the report says what it actually found.
The language of the report is a separate choice: French or English, when you order, whichever languages we analyze.
A version published on another domain name is another site, and so another audit. Language prices are on the pricing page.
Scoring
The score is a summary tool built from the findings recorded during the audit. It lets you compare the pillars under a documented grid, but it is not a universal measure of website quality.
Each pillar gets a score out of 100 under documented, stable scoring, applied to the facts recorded during the audit. The 9 pillars don’t necessarily carry the same weight: the weighting depends on the type of site.
On a brochure site, search visibility carries 18% of the overall score and security 10%. On an application where people log in, those weights are reversed: search 4%, security 25%. On a public-sector site, accessibility becomes the largest item, at 24%. The report always states which weighting produced your score, and each pillar page publishes its weight.
References
When a point rests on a law, a standard or a specification, the report cites it. We only cite a reference when it genuinely matches the point audited; the user experience and reliability pillar has none, and the report says so.
| Pillar | On what basis |
|---|---|
| Security & encryption | TLS (RFC 9325) · security.txt (RFC 9116) |
| Performance | Core Web Vitals |
| SEO & search visibility | schema.org · RFC 9309 |
| Accessibility | WCAG 2.2 AA · RGAA · EU Directive 2019/882 |
| Compliance & privacy | GDPR · ePrivacy Directive · French LCEN · CNIL guidance |
| Domain & network | SPF (RFC 7208) · DKIM (RFC 6376) · DMARC (RFC 9989) · DNSSEC |
| Independence & resilience | GDPR · CLOUD Act |
| Content & trust | Google Search guidance on E-E-A-T · schema.org |
| User experience & reliability | no dedicated standard: measured facts and human review |
Automated systems, and what AI adds
We also check whether the important information on your pages is clearly worded and properly structured for automated systems to understand, without claiming that any particular file or markup guarantees visibility in AI-generated answers.
Measurements come from deterministic tools. An AI-assisted review can cross-check observations against each other and across pages, to surface gaps no single check can see, but it does not invent measurements or set scores.
Method versions
The method evolves. When its rules change, the version used for your audit is stated in the report. If your site is measured again later, the comparison uses the same weighting, so a change in score reflects a real change.
The same method in every plan
Four plans by number of pages, delivered in 5 working days up to 60 pages, payment collected on delivery.