Questions a sceptic should ask

These are the questions people actually have when a stranger emails them about their own website. They deserve straight answers.

1. How did you get my email address?

From your own company’s website, or from Companies House. I write only to named people at UK limited companies and LLPs, at addresses the company itself publishes, and I record where and when I found each one. I do not buy lists, scrape social networks or use data brokers. Before any email is sent I verify the company on Companies House, because the law treats sole traders differently and I do not email them at all. The full detail, including your right to make me stop, is in the privacy notice.

2. Are you saying we are breaking the law?

No, and I am careful about this for a reason. I am an engineer, not a lawyer, and a public website cannot prove a legal conclusion. What I report is a specific, observable fact and its reproduction path: wording that matches no authorised claim I can find on the GB register, or a review app configured to publish sample data. Where the fact is arithmetic against a published register, as with a 13% level against a 15% floor, I will say what the register says. Whether anything follows from it legally is for whoever owns compliance in your business, checking against things I cannot see, like the product label. My emails never quote maximum fines at you, because frightening people into buying is not a business I want.

3. What exactly did your scanner do on our site?

It read public pages, the same ones any customer’s browser sees, identifying itself honestly as HigherSelfScan, at a polite rate, honouring robots.txt. It never logs in, never guesses credentials, never submits forms, never probes for hidden endpoints and never sends any kind of payload. Every run is logged, and if you want to know exactly what it fetched from your site, ask and I will show you the log. The full specification, including the exact user agent string and how to block it, is at /scanner.

4. Will you publish what you found about us?

No. Findings go to you and stop there. They are not published, not screenshotted, not used as case studies, not shown to other prospects, not posted when you decline to reply. The findings described on this site are the one exception, and they follow the rule that governs it: anonymised, no client named, nothing published beyond what each finding itself needs. A private weakness should never become a supplier’s marketing asset, and if I broke that rule for a client you would have to assume I would break it for you.

5. What evidence do you have that this works?

At present, not a conventional reference set. There is one private engagement with a British supplement business below the size I now accept, and selected work inside Sofema Aviation Services, a €3 million EASA-regulated aviation training business. I did not win that work in open competition, so it shows what I can build inside a regulated operation; it does not show independent client selection, adoption or outcomes. The private work shows the diagnostic method, not a customer send, revenue or retention result. That is the honest state of the evidence. It is also why the first proof I offer you is a fact about your own site that you can reproduce in your own hands.

6. Is this mass-generated AI spam?

Agents help me prepare the research; each email I send reports what I checked on the recipient’s own site that morning, by hand, in a browser. Usually that is a clean result, because most brands are sound from the outside; where I do find something, the finding and the steps to reproduce it are in the email whether or not anyone replies. I send a handful a week, personally, and I answer every reply myself, within one working day. There is no sequence software, no tracking pixel, no open-rate dashboard, and at most two follow-ups before I stop writing. You can test this cheaply: reply with a question about what I checked. Software cannot answer it. I can.

7. What is “one page, read properly”?

The free way to test the method without a cold email and without a conversation. You send one public URL from your own site and I read it by hand: the markup, the forms, the headers and the domain’s email authentication. Within two working days you get either a specific verified problem with the steps to reproduce it, or an honest account of what was checked and what was clean, including what I could not see from outside. One page per organisation, no sequence, nothing stored beyond the correspondence. The full terms are on the one-page page.