Skip to content
Digital Trust Audit

The Digital Trust Audit

An independent assessment of what a customer, a bank, a procurement team or an AI answer engine can establish about your business without asking you. Eleven areas, each checked against a live source on a stated date, every finding flagged, and a written report that separates what was verified from what could not be. £1,200 plus VAT.

What you get

A report, issued within five working days of the assessment starting, as a private web page you can read on a phone and a designed PDF you can download from it and send on. Both carry the same content, from the same assessment record.

  1. An overall score out of 100 and a band, on the cover, with the count of findings at each flag.

  2. The eleven areas scored individually, so a single weak area is visible rather than averaged away.

  3. Every finding stated in full: the flag, a plain statement of what was found, and the evidence line — the source, the value and the date it was checked.

  4. A closing table of everything that could not be established from outside, each with the question that would settle it and who in your business is likely to hold the answer.

  5. The capture conditions, so anybody reading the report knows exactly what was and was not checked, and under what conditions.

The eleven areas

The eleven areas checked in a Digital Trust AuditEleven small hexagons in a row, one for each of the eleven areas the audit checks.
  1. Company record — the registered name, number, registered office and filing status, and whether the address itself tells a checker anything.

  2. One business or several — whether the trading names, brands and legal entities a visitor encounters resolve to the company they think they are dealing with.

  3. Machine-readability — whether the site states, in a form a machine can extract, what the business is, where it is and what it sells.

  4. Navigability — whether a visitor and a crawler can reach everything the business claims to publish.

  5. Email authentication — SPF, DKIM and DMARC, and whether the domain can be impersonated.

  6. Contactability and identification — whether the published contact routes reach the business, and whether the business is identifiable from them.

  7. Proof — whether case studies, figures and claimed accreditations reconcile against the registers that issue them.

  8. Presence away from the site — what independent sources say, and whether they agree with the site.

  9. Domain ownership — who holds the domain, how it renews, and how close it is to expiry.

  10. Legal pages and company particulars — whether the statutory disclosures are present and name the correct entity.

  11. Accessibility — conformance against the published standard, checked rather than fixed.

Each area is checked against a live source on the day of the assessment — Companies House, the DNS and mail records, the site itself, the registers behind any accreditation the site claims, and the public sources that mention the business. The area headings are published. The individual checks are not, because an assessment with a public checklist measures preparation for the checklist.

The criteria are in the published standard → /standard/

Why there is no fix list

The report tells you what was found and what the standard requires. It does not tell you what to buy.

A remediation plan is priced, in a buyer’s mind, against the number of problems in it, which gives whoever writes it a reason to find more. We do not sell remediation, we take no commission from anyone who does, and we do not name a supplier. That is what makes the finding worth reading, and it is the one thing in this market that cannot be copied without giving up revenue.

What you receive is specific enough to act on. “Your DMARC policy is p=none. The standard requires quarantine or reject with a reporting address.” Any competent supplier can work from that, and you choose who.

A human carries out the assessment

Every Digital Trust Audit is carried out and signed by a person. Automated tools gather the raw data; a human reconciles it, resolves the contradictions, decides each flag, and is accountable for the result on the date it was issued.

That is the reason this assessment can carry an accreditation and an automated score cannot. A continuously re-scanning tool cannot certify anything, because its own result moves every day. A certificate needs a point in time, a stated scope, a person who stood behind it and a date it stops being true.

What happens, and when

  1. You send the request from your business address, with your usual signature. We reply within one working day with the scope and confirmation of the fee.

  2. The assessment runs. We need nothing from you to start — that is the point of an outside-in assessment.

  3. We ask for what we could not see. A short list of questions covering the items that could not be confirmed from outside. Answering is optional; unanswered items are excluded from the score and listed in the report.

  4. The report is issued within five working days of the assessment starting.

  5. Accreditation, where the result meets the criteria → /accreditation/

What it costs

Digital Trust Audit

£1,200

+ VAT

Eleven areas, human-verified, report in five working days.

£1,200 plus VAT. One assessment, one report, one business, one domain. Additional domains or trading entities assessed at the same time are £450 plus VAT each.

Quarterly re-assessment is Digital Trust Monitoring, £395 plus VAT per quarter → /monitoring/

Requesting an audit

Send an email from your business address to audit@digitaltrustaudit.co.uk and include:

  1. The company’s registered name and its website address.
  2. The name and role of the person who can answer questions about the company’s records.
  3. Confirmation that you are authorised to request an assessment of this business.
  4. Your usual email signature, unchanged.

We reply within one working day with the scope, the fee and what happens next.

Email audit@digitaltrustaudit.co.uk

Frequently asked questions

Digital Trust AuditVerified from the outside in.

Want to know whether AI answer engines recommend you too? See the AI Visibility Audit.

No. The assessment is carried out entirely from public sources. Nothing needs to be granted, installed or opened.

It is flagged as could not be confirmed, excluded from the score rather than counted against it, and listed in the report's closing table with the question that would settle it.

The eleven areas are published in full in the standard. The individual tests inside each area are not, because an assessment with a public checklist measures preparation for the checklist.

We tell you what was found and what the standard requires. We do not issue a work plan, name a supplier, or take a commission from anyone who does the work.

An SEO audit measures how a site performs in search. This assessment measures whether what a business publishes about itself reconciles with what the public record says, and whether either can be verified by a customer or a machine.

Ask for the assessment.

One business, one domain, one report in five working days.

Request an audit