The first engagement · £150 fixed

Outside-in Analysis

This is where the work starts. I examine an agreed public surface of your business the way your buyers and your systems actually meet it, from the outside, and I write down what I find. It is a fixed price of £150, agreed before anything begins.

The guarantee

If the analysis tells you nothing you didn’t already know, tell me and the invoice is cancelled.

You decide whether it told you something. I do not arbitrate that.

What it does not require

  • No credentials. I do not ask for a password, an API key or a login, and there is nothing for you to issue.
  • No access to your accounts. I am not inside your shop, your email platform, your analytics or your admin.
  • No meeting. You send the scope, I send the report. Nothing here depends on getting you on a call.

That is the point of putting this rung first: you can buy it without deciding to trust me first.

What I examine

The surface is agreed in writing before I start, so you know exactly what you are paying for and I cannot quietly widen it. A typical scope is a defined set of public pages on one domain, together with the public records that sit behind them:

  • The served markup of the agreed pages, as any visitor’s browser receives it.
  • Their forms, read and never submitted. Nothing enters your systems.
  • Their outbound links, redirects and HTTP response headers.
  • The domain’s public email-authentication records: SPF, DKIM and DMARC.
  • What your published claims and your published policies say, read against each other.

Read-only, GET and HEAD requests only, under the same published conduct standard as my scanner. Nothing is logged in to, nothing is probed, nothing non-public is touched.

What you get back

One named written report, delivered to you and to nobody else. Every finding in it is labelled, and the labels are the substance of the thing:

  • Observed. What I saw, with the URL, the date and the exact response.
  • Reproduced. The steps for you to see the same thing yourself, in your own browser, without me. A finding without a reproduction path is a claim, and I mark it as one.
  • Inferred. What I think it means, marked as inference and never dressed as fact.

Severity is described at most as worth checking. Frightening you into a purchase is not a business I want, and it is the fastest way to lose the only thing I am selling.

How it ends, always

The last section of every report states what cannot be established from outside. That section is never omitted and never left thin, because an absent check reported as a clean result is the exact failure this work exists to prevent.

From outside I cannot see your suppression lists, your account settings, your integration logs, your order data or anything behind a login. If the honest answer is that the public surface is sound and the interesting question is inside, the report says so plainly. A clean result is the deliverable, not a consolation.

What it is not

It is not an SEO report, a conversion-rate audit or a website critique, and I am not going to tell you your buttons are the wrong colour. It is not a proposal in disguise: there is no obligation to do anything afterwards, and I would rather you bought this and stopped than bought it and felt managed into the next step.

It also is not the inside view. Where the report cannot answer a question from outside, the honest next rung is the £750 inspection, which is read-only, bounded to one named workflow, and priced separately. That step is yours to decline.

How to start

  1. You write to me with your domain and the surface you want examined, from a work email address at that domain.
  2. I confirm the scope and the price in writing before any work begins. If what you need is outside what I can do from outside, I say so then, and there is no invoice.
  3. You receive the report, and the invoice with it.

Ask for the analysis

If the email domain and the site domain differ, I will ask you to place a one-line meta tag on the page temporarily, so this cannot be used to examine somebody else’s business. Your details are used to reply to you and to invoice you, and nothing else: see the privacy notice.

Why the report is re-checked by hand

Every finding is re-verified by hand, in a browser, immediately before the report is sent. I learned why the expensive way. The first time my scanner’s output was trusted at face value it produced three findings, and on hand re-verification all three were wrong: a DMARC record that did reproduce after all, a Cloudflare email-obfuscation endpoint misread as a broken link, and an uninterpolated JavaScript template literal misread as a broken link. The re-check caught all three before they reached a stranger, and the full account is on the scanner page. The check, not the tool, is the product.