Audits, optimisation and security

Find out what is slowing down or weakening your website

We analyse existing websites, online stores and web applications for performance, code quality, technical SEO, accessibility and security. You receive clear priorities, recommendations and a basis for targeted remediation.

Choose one audit or the discounted package

01 · FIXED PRICE

Detailed optimisation audit — 1 500 kr excl. VAT

A detailed review of performance, front-end code, technical SEO and accessibility. It also includes a baseline passive security check. Findings are ordered by risk and impact, with recommendations for further work.

02 · FIXED PRICE

Extended cybersecurity audit — 1 500 kr excl. VAT

An extended, non-invasive review of the website's publicly accessible surface and security configuration — without server login or attempts to bypass security controls. It covers agreed checks of TLS, security headers, cookies, CORS, forms, parameters, and public ports and services.

03 · 20% DISCOUNT

Combined audit package — 2 400 kr excl. VAT

A detailed optimisation audit and an extended cybersecurity audit ordered together. The regular price is 3 000 kr excl. VAT, so you save 600 kr. Remediation remains a separately quoted stage.

Performance and user experience

We investigate why the website loads slowly, responds late or behaves inconsistently. The analysis covers mobile and desktop, with separate measurements of selected representative pages when needed.

  • Core Web Vitals and laboratory metrics: LCP, TBT, CLS and available INP data.
  • Server response time, when the main content appears and render-blocking resources.
  • Transfer size, network request count, compression and caching policy.
  • Images, video, fonts, JavaScript and CSS — format, size, order and unused code.
  • DOM complexity, layout stability and load on the browser's main thread.

Technical SEO, accessibility and code quality

The audit is not limited to a score from one tool. We combine measurements with a review of document structure, public URLs and elements that affect visibility, usability and maintainability.

  • Page titles, meta descriptions, canonical, robots.txt, XML sitemap and structured JSON-LD data.
  • Headings, semantic HTML, document language, validation and technical consistency.
  • Alternative text, image dimensions, contrast, accessible names and baseline assistive-technology support.
  • HTTP status codes, redirects, indexability and repeated metadata.
  • Patterns that hinder development: excess CSS, unnecessary JavaScript, complex selectors and repeated code.

Within the detailed optimisation audit, we agree a specific sample before work begins. The report may, for example, cover up to 50 public URLs and separate measurements of up to three heavier or representative pages.

Security audit of the website's public surface

The security review is performed only for the system owner or after authorisation has been confirmed. The scope is agreed before work begins, and the checks are limited and non-destructive.

  • HTTPS, TLS certificate, redirects and supported transport settings.
  • Security headers: HSTS, CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and protection against framing.
  • Cookie security flags, CORS policy and disclosure of technology information.
  • Public forms, GET parameters, visible login surfaces and CSRF signals — without password attempts.
  • Controlled checks for reflected data or query errors when a safe entry point exists within the agreed scope.
  • Limited review of publicly accessible ports and services without login, data access or persistent access.

Clear boundaries

What a non-destructive security audit means

We do not perform brute force, modify or download data, establish persistent access or run code in a user's browser. A reflected parameter does not confirm XSS, an error message does not confirm SQL injection, and an open port is not automatically a vulnerability. Such observations are marked for manual verification.

What you receive after the audit

The report is designed to support decisions, not simply generate a long list of warnings. Each material issue is explained in technical and business terms, with evidence, possible impact and a recommended order of action.

  • Summary of the main findings and high-, medium- and low-priority issues.
  • Measurement results, reviewed URLs and recorded evidence.
  • Description of each issue, its significance and a concrete recommendation.
  • Record of completed checks: no signal, signal found, requires verification, skipped or informational.
  • Method limitations and a proposal for retesting after remediation.

Remediation and optimisation after the audit

Remediation is not included in the audit price. Once the system's condition is known, we select the issues to address and prepare an individual quote. We can improve agreed parts of the code, server configuration, front-end assets or page structure, then verify the result with another measurement.

If we cannot access the technology used, or the fix requires work by the hosting provider, ecommerce platform or a third-party plugin vendor, the report states who should take the next step.

Technical SEO in the audit, ongoing SEO as a separate service

The audit covers technical elements that affect indexing and website quality: metadata, canonical, robots, sitemap, structured data, performance and semantics. Keyword strategy, content creation, link building and full SEO, GEO and AEO remain separate services.

Not sure whether to choose the optimisation audit, cybersecurity audit or the combined package? Describe the website and its main problem, and we will help you choose the right option.

Ask about an audit