The Business Growth Audit
What the audit actually looks at
Fifty automated checks against your public website, sixty questions about the parts of the business no scan can see, and a scoring method that refuses to pretend it measured something it could not. This page describes what exists today — not a roadmap.
Three kinds of evidence, kept apart
Most audits blend measured facts, owner recollection and vendor assumption into one confident-sounding document. This one keeps them in separate buckets, because the difference between them is usually where the problem is hiding.
Automatically detected
Fifty checks run against your public website and DNS. Every result is stored with the raw evidence that produced it — the header that was returned, the tag that was found, the URL that responded. Nothing in this tier depends on anyone's opinion, and you can be shown exactly why each check landed the way it did.
Self-reported
Sixty questions covering the things a scan physically cannot see: what you actually spend, whether anyone follows up an enquiry, who holds the admin passwords, whether last month's revenue can be pulled up in five minutes. These are recorded as your claims, stored separately from measured evidence, and never presented as if they were measured.
Connected-account data
Some questions can only be settled by looking inside the accounts themselves — Google Analytics, Search Console, Google Ads, Meta, your CRM. There is no live OAuth connector for these in the product today. In the full audit engagement this is handled by exporting the reports and importing them: the platform accepts an uploaded report, maps its columns, and normalises the metrics. Anyone telling you a one-click connector exists here would be describing something that is not built.
What is detected automatically
Fifty checks run against the public site and its DNS. No access, no credentials and no cooperation from your developer is required — everything here is visible to anyone, which is precisely why it matters.
Security & trust
Does the domain resolve, is HTTPS enforced, is the SSL certificate valid, are standard browser security headers sent, is a secure page loading insecure assets, is a privacy policy linked, are contact details findable.
Search & SEO
Page title and its length, meta description and its length, canonical URL, H1, heading order, robots.txt, XML sitemap and how many URLs it lists, whether made-up URLs correctly return a 404, whether the www and non-www addresses settle on one canonical address, language targeting tags, internal link count.
AI readability
Whether the page's content is in the raw HTML or only appears after JavaScript runs, whether a recognised business schema type is declared, whether robots.txt blocks search and AI crawlers, whether an llms.txt file is published.
Content & structure
Word count, image alt text, Open Graph tags, favicon, declared page language, whether an FAQ page exists.
Tracking & analytics
Google Analytics 4, Google Tag Manager, and whether advertising is running with no analytics behind it.
Advertising
Which advertising and remarketing tags are actually on the page — Google Ads, Meta, TikTok, LinkedIn, Pinterest, Snapchat, X, Microsoft (Bing) UET.
Performance & platform
PageSpeed score, mobile viewport tag and its configuration, CDN in front of the site, and hints about the framework, hosting and database platform in use.
A check that cannot be completed — a request that times out, an endpoint that refuses to answer — is recorded as unknown, with the reason it failed. It is never quietly converted into a failure.
What you have to answer yourself
Sixty questions across eleven areas. Most are deliberately blunt and answerable in a few seconds — the useful signal is usually in which ones you cannot answer at all.
The kind of question it asks
- “If your web developer or agency disappeared tomorrow, could you personally log in and take control of your domain name and website?”
- “If asked which marketing channel made you the most money last month, could you say for certain — with numbers to back it up?”
- “When someone submits a form or makes a booking on your website, does that information land directly in your CRM without anyone re-typing it?”
How findings are scored
Weighted, not counted
Every check carries a weight and a severity. A missing SSL certificate and a missing llms.txt file are not the same event, and a score that treats them as one each is not telling you anything. A pass earns full weight, a warning earns half, a failure earns none.
What could not be measured is excluded, not failed
This is the part most tools get wrong. If a check could not be completed, its weight is removed from the denominator entirely rather than counted against you. A score is a statement about what was actually measured — inflating the failure count with things nobody could see would make the number meaningless in exactly the cases where it matters most.
So that this cannot be used to hide anything, a separate coverage figure is reported alongside the score: how much of the total possible weight was measurable at all. A high score with low coverage is a signal to look harder, and you can see that immediately instead of having to work it out.
Two checks are reported but never scored
Language targeting tags are only relevant if you run separate versions of the site for different countries, and llms.txt is an emerging convention with no official backing yet. Both are shown for information and neither is counted against the score.
How recommendations are prioritised
Findings are sorted by severity first — critical, then high, then medium, then low — and by weight within each band. Related findings are then grouped into weak points written in commercial terms rather than technical ones.
Two rules constrain what can be recommended:
- 1
Every weak point must cite the specific checks that triggered it. No recommendation is made without evidence from the scan behind it.
- 2
Every recommended service must exist in the real services catalogue. Recommending something outside it would mean pitching work that cannot be scoped or priced.
What the report contains
The website scan produces its results on screen straight away and as a downloadable PDF. The score in that PDF is recalculated on the server from the findings — a score sent up from a browser is never trusted.
- The score, the coverage figure, and what band the score falls into.
- Every check, grouped, with its status and the evidence behind it — the passes as well as the failures.
- The failing and warning checks ordered worst-first, each written in terms of what it costs the business rather than what the tag is called.
- Weak points, each one citing the specific checks that triggered it.
- Recommended services, each tied to the weak points it resolves, drawn only from the real services catalogue.
- For the full engagement, your own answers alongside the measured findings, so the gap between what is believed and what is true is visible on the page.
What happens after
- 01
You get the findings whether or not you do anything else with signalIQ. The website scan results appear on screen immediately, with no signup and nothing held back pending a reply.
- 02
A conversation about what was found — what it means, which parts matter, and what it would realistically take to fix. Nothing is proposed before there is a finding to base it on.
- 03
Only then does scope and pricing get discussed, against the specific weak points the audit surfaced.
- 04
If signalIQ is not the right fit, or is at capacity, you will be told that directly rather than pitched anyway.
