The audit — our credibility, in writing

Before you trust us with your site, see us prove it on one.

The audit is how SDG earns the work. It's an independent, evidence-led assessment of a website — every finding reproducible, every consequence sourced to a named standard or statute. We don't ask you to take our competence on faith. We show it.

Proof, not promises

We built a site, audited it, fixed it, and published the receipts.

The Horizon Football Festival site is our own work. We ran the same audit we sell against it, then fixed what it found and re-ran it — so the improvement is measured, not asserted.

  • Critical findings1 → 0
  • High severity11 → 8
  • Medium severity54 → 30
  • Low severity73 → 56

Read the full story → Read the actual audit →

Our own scorecard

It would be hypocritical to charge for this if our own site failed it.

We run the same audit against sdgservices.com.au and publish what it returns, live. Every line is reproducible from any internet-connected host.

See our live scorecard →

What the audit catches

A document you can actually act on.

Not a generic checklist, not a sales pitch dressed as a report. A specific document about your website — what's broken, what's risky, what's actually working, and what each finding costs you if it stays unfixed.

The deliverable

A 12–18 page branded PDF, delivered to your inbox within 48 hours of commissioning. Structured around five sections:

  1. What's working — we open with what you're getting right. Most audits open with criticism; ours opens with credit. It matters.
  2. What we noticed — security, compliance, SEO, UX, content quality. Grouped by category, ordered by severity, each with concrete evidence (the URL, the version number, the exact phrase).
  3. What happens if these aren't fixed — realistic consequence per finding, with the cost band sourced from named publications (OAIC reports, ASD Cyber Threat Reports, AHPRA guidelines, etc.).
  4. What improvements would deliver — for each finding we name the fix, the effort, and the realistic impact. Honest about what's measurable and what's directional.
  5. The pattern — what the findings together suggest about how the site has been cared for, and what ongoing care would look like.

What we test for

Our audit covers 900+ test dimensions across:

  • DNS & email authentication (SPF, DKIM, DMARC enforcement strength)
  • TLS configuration (cipher suites, HSTS, certificate transparency)
  • HTTP security headers (CSP, X-Frame-Options, all of them)
  • Source-code & config exposure (.git, .env, backup files, phpinfo)
  • Admin interface exposure (cPanel, WHM, phpMyAdmin, third-party logins)
  • CMS & plugin fingerprinting with EOL status & known CVE histories
  • Privacy compliance — Privacy Act 1988, the APPs, the NDB scheme
  • Industry compliance — AHPRA, AFSL, NSW Fair Trading, ACECQA, REINSW
  • Core Web Vitals (LCP, INP, CLS) from Google's own tooling
  • SEO basics — title, meta, schema, sitemap, robots
  • Accessibility (WCAG 2.1 AA)
  • Copy quality — spelling, grammar, Lorem Ipsum, AU vs US English drift
  • Multi-page consistency — opening hours, phone numbers, content duplication

What we don't claim

Reproduced here because it's the heart of what makes the audit credible:

  1. We don't claim your site has been compromised. We describe observable exposures.
  2. We don't quantify revenue loss for specific findings without baseline data — we say so explicitly when we're inferring.
  3. We don't make claims about competitors' security postures unless we've audited them with the same methodology.
  4. We don't attest that the site is or isn't compliant with a specific law — we describe observable indicators and cite the relevant statute. Your legal advisers make the compliance call.
  5. We don't represent ourselves as a regulator.
  6. We don't test credentials, submit forms, or attempt unauthorised access. The audit is observational.
  7. We don't fabricate sources. Every cost figure, statistic, or regulatory framing traces back to a named primary source.

Read the full methodology →

The audit credit

How the AU$497 fee turns into "free".

The audit costs AU$497 (AU$697 for regulated verticals — health, legal, financial, real estate, childcare).

If, after reading the audit, you'd like us to fix what we found and keep watching — the audit fee is fully credited against your first 12 months of managed care.

So you have three honest paths:

  1. Read the audit, fix it yourself (or pass it to your current developer). You've paid AU$497 for an independent assessment you can act on. We never hear from you again.
  2. Read the audit, engage us to fix everything in one project. Fixed-price scope drawn from the audit itself.
  3. Read the audit, sign up for managed care. The AU$497 is credited against your first months of care. Then ongoing.

The fee makes the assessment serious. The credit makes it risk-free if you go further. The choice is yours.

Commission your audit

Three things to share. Forty-eight hours to your inbox.

We accept commission via email. Send the domain, your name and role, and any specific concern — we reply within one business day with a payment link and a delivery date.

Email [email protected]