WebTrustEngine
TREN
WEBSITE AUDIT, IMPROVEMENT AND DEVELOPMENT SERVICES

We audit your website, fix it, or build it correctly from the ground up.

WebTrustEngine measures security, accessibility, performance, SEO, structured data, privacy and AI visibility. It delivers a leadership-ready report, actionable fixes and a verified website through one evidence chain.

ENGINE CONTRACTEvery finding ships with its evidence file80CORE CHECKS+268GRANULAR CHECKS= 348 DETECTABLE CHECKSCLASSIFIED ACROSS 10 GOVERNANCE DOMAINSR5001Security02TLS·HTTPS03Technical SEO04Structured Data05Accessibility06Performance07AI·GEO·AEO08Cookies09Code Security10Delivery80 Core Checks · 268 Granular Checks · 68 Security Patterns26 SafeFix Generators · 21 Runtime Verification Bridges24 External Action RecipesEVIDENCE CHAINZIP and content hashes — the r20260829-01 baseline packageZIP 8c1d97d4…f29f · content 55e5c4c6…ef8201REVIEW02SAFE FIX03BUILD04DEPLOY-VERIFY

What this means for you: every finding arrives with file-level evidence — leadership reads the report, your technical team verifies the annexes.

See what the audit produces: a sample executive report from a real run →

ENGINE CONTRACTEvery finding ships with its evidence file80CORE CHECKS+268GRANULAR CHECKS= 348 DETECTABLE CHECKSCLASSIFIED ACROSS 10 GOVERNANCE DOMAINSR500102030405060708091001 Security02 TLS·HTTPS03 Technical SEO04 Structured Data05 Accessibility06 Performance07 AI·GEO·AEO08 Cookies09 Code Security10 DeliveryR50 NUMBER ARCHITECTURE80 Core Checks268 Granular Checks68 Security Patterns26 SafeFix Generators21 Runtime Verification Bridges24 External Action RecipesEVIDENCE CHAINZIP and content hashes — the r20260829-01 baseline packageZIP 8c1d97d4…f29f · content 55e5c4c6…ef8201REVIEW02SAFE FIX03BUILD04DEPLOY-VERIFY

WHY GOVERNANCE?

The web is no longer a one-off project

A website is now a human storefront plus a machine surface.

The page a visitor sees is simultaneously the input of dozens of automated readers. A page flawless for humans can carry missing headers, broken schemas and unclear identity signals for machines.

Even with great design, machine readability can be weak. Visual redesign projects rarely touch the meta layer, security headers or structured data; the site looks new while its audit surface stays old.

WHO USES IT

Who uses it, and when?

Four typical moments: an evidence-based snapshot before a corporate site renewal; independent acceptance of an agency delivery; a recurring governance round; and quick due diligence before a merger or transfer.

The full use-case set lives on the Review page

WHAT IS R50?

Every published figure — counted from code

R50 is WebTrustEngine's public capability set. Its distinguishing trait is number discipline: every published figure is counted from code; different units are never merged into one total.

NUMBER CONTRACT
348
detectable checks
80 core + 268 granular
R50
68
security patterns
static detection
R50
26
SafeFix generators
reversible
R50
21
runtime bridges
bind to live tools
R50
24
external recipes
platform actions

Claim safety

Every published claim is tied to code and an evidence file; no figure is written by hand — source-level gates enforce it.

FOUR MODES

Review → SafeFix → Build → Deploy-Verify

Each mode produces its own evidence; no mode issues a live pass.

  1. Review

    An evidenced baseline without touching a file: 10-domain score plus classified findings.

    score + findings
  2. SafeFix

    Low-risk fixes in a working copy; every change is written to a manifest.

    fix manifestreversible
  3. Build

    A schema-ready static surface: meta, canonical, hreflang, JSON-LD, accessibility skeleton.

    static surfacereversible
  4. Deploy-Verify

    Post-upload live header pulls and independent-tool recipes; producing files is not enough.

    live proof

The 10-domain score model

Each domain with its one-line scope; evidence, sample findings and boundaries live on the Score Model page.

01

Security Headers

HSTS · CSP · nosniff

02

TLS / HTTPS

encrypted transport

03

Technical SEO

meta · canonical · sitemap

04

Structured Data

JSON-LD identity

05

Accessibility

alt · label · heading

06

Performance

static readiness

07

AI / GEO / AEO

readability

08

Cookies

tracker visibility

09

Code Security

secrets · exposure · patterns

10

Delivery

deployment hygiene

Go deep on every domain →

SAFEFIX

Not a rebuild — a safe improvement

Evidence package visual of six deliverable cards.
The SafeFix evidence package: six delivery items.

The evidence package: files, not a score

A changed-files list, a rollback manifest and a before/after score ship together. Every change reverts in a single step.

See the process
changed_filesFlat list of every touched path.
fix_manifestPer-file before/after hashes.
rollback_manifestThe single-step way back.

Every file in the evidence pack, explained →

DEPLOY-VERIFY

Producing files is not enough

Upload, cache purge, live header pulls and independent-tool recipes: evidence completes in production.

Seven-step deployment verification flow.
The Deploy-Verify loop: seven steps from upload to the diff report.
  • Live header pull
  • robots/sitemap live
  • OG card refresh
  • Search Console submit
  • SSL Labs run

SECURITY BOUNDARY

Not a pentest — and it says so

In short: the engine sends no requests to your site; it looks for security signals in your files and never attempts an attack. This boundary is deliberate and stated in writing.

A static security review is security analysis over source, configuration and output files without touching the target system. WebTrustEngine's security layer stays within this definition and has four blocks: secret scan (key/password/token leakage), exposed files (.env, backups, .git, config exposure), client-side risky patterns (eval, document.write, dangerous sinks) and server-side SAST classifications (SQLi/command/traversal/deserialization/SSRF/XXE markers).

SCA/CVE logic accompanies these: risky ranges of known library versions are flagged; but no 'this version is exploitable' claim is made — the flag binds to an update recipe. CSP/HSTS readiness and OWASP mapping put findings into a shared language.

When is it not a pentest? Always — in this product. No active payloads, no live port scans, no authentication-bypass attempts, no exploit generation. Any DAST-class behaviour requires written authorization, ownership verification and a separate scope document. This legal and ethical boundary is not a weakness; it is trust discipline: the client knows exactly what they bought and what must be ordered separately.

Boundary glossary — what does static scanning cover?
  • secret scan
  • exposed files
  • JS sink patterns
  • SCA/CVE flags
  • CSP/HSTS readiness
  • OWASP mapping
  • DAST = authorization + scope

Boundary

Active testing requires written authorisation; the engine offers static security review.

Clear boundaries make starting easy: get an evidenced snapshot without a single file being touched.

Prepare an audit request

VISUAL SYSTEM

The brand speaks its own visual language

Dark navy executive dashboard with three decision cards on top and a ten-domain strip below.Five-layer AI readability stack.Capability map of six large stat cards.Two panels separating static review from authorization-required active testing.Four-step bridge flow diagram.Four-stage content system flow.Five-step technical handoff flow.

Brand Center: 32+32 visuals, 24 banner sizes, logos →

Circular loop of four modes with a Deploy-Verify node at the center.
The governance loop: Review, SafeFix, Build and Monitor around a Deploy-Verify core.

Critical questions — quick answers

Q: How do we start?

A: You share your site address or a site package (ZIP); the first review produces an evidenced snapshot without changing a file. Scope and schedule are settled on that snapshot.

The request flow lives on the contact page

Q: What is delivered?

A: An executive brief plus a technical-annex report (DOCX/PDF) and a machine-readable evidence pack: changed files, manifest, checksums, rollback plan. Scanning and reporting are automated.

Every file in the evidence pack, explained in the Evidence Hub

Q: Why is there no price on the site?

A: Quotes follow scope: one site or a multilingual estate, with or without live verification. A fixed list price is therefore not published; the rule that every published figure must be provable applies to pricing too.

Scope components on the contact page

Q: What can it see without touching the live site?

A: All in-file signals in ZIP/local input: meta, schema, header readiness, accessibility markers, static security patterns.

Full answer in the FAQ

Q: ZIP vs live-URL analysis?

A: ZIP shows file truth; live URL shows response truth; headers and redirects finalize only live.

Full answer in the FAQ

Q: What if the site breaks after SafeFix?

A: The rollback manifest reverts in one step; the backup dir ships in the package.

Full answer in the FAQ

Q: How is the rollback manifest used?

A: Copy files back from the backup dir; the changed/created lists guide you.

Full answer in the FAQ

Q: Which changes are the owner's commercial call?

A: Meaning-changing content, brand/voice preferences and legal text are commercial decisions; the live publish decision also belongs to the owner.

Full answer in the FAQ

Q: Why are the figures never summed?

A: Checks, patterns, bridges, fixers and recipes count different kinds of work; different units are never merged into one total. Inflating a headline figure is deliberately rejected.

Full answer in the FAQ

Q: How is the 348 figure counted?

A: Counted from code by the CLI; the quality gate and the build ledger must agree with the same figure, so inflation is structurally impossible.

Full answer in the FAQ

WHY WEBTRUSTENGINE?

Quick preview: against the four closest products

These four differentiators are what matter for an evidence-bound decision file. The full table is 12 products × 16 capabilities on a separate page; every competitor cell is bound to an official product page, with no unsourced green or red.

  • URL, ZIP and local-folder input — no equivalent found on hosted crawlers.
  • Hashes, manifests and number provenance — the same input yields the same number.
  • Reversible fixes with a rollback manifest.
  • Local, controlled data processing.

Open the full comparison

Ready for the first review?

Get an evidenced baseline without touching a file; scope and quotes are settled via contact — pricing is not published on this site. Until a verified direct channel is published, requests travel through the topic lanes on the contact page as a scoping exchange.