Demonstrate your commitment to quality with a professional website audit or application safety assessment. Receive a detailed report, official certificate, and an embeddable badge to showcase your standards.
Website audits from $499 | certificate & badge included | PayPal accepted
For websites, our audit engine performs 298 individual checks across 12 critical categories, covering security, performance, SEO, compliance, and more. Applications use a separate safety engine — see below.
TLS/SSL configuration, certificate validity, protocol versions, HSTS, OCSP stapling, cipher strength, and encryption analysis.
Content Security Policy, X-Frame-Options, HSTS, CORP, COEP, COOP, Permissions Policy, Referrer-Policy, and clickjacking protection.
Secure, HttpOnly, SameSite attributes, cookie prefixes, session fixation, and cookie naming analysis.
SPF, DKIM, DMARC records, DNSSEC, CAA, MX configuration, and DNS lookup analysis.
Server headers, technology leaks, directory listing, backup files, config files, source maps, debug indicators, and WordPress detection.
Login form security, CSRF protection, password policies, rate limiting, CAPTCHA, session management, OAuth, and account lockout.
JavaScript vulnerabilities, eval/innerHTML usage, SRI, postMessage security, localStorage, outdated libraries, and open redirects.
Response times, page size, compression, caching, HTTP/2, lazy loading, DOM size, render-blocking resources, and font optimisation.
Meta tags, robots.txt, sitemap, canonical URLs, headings, alt text, mobile viewport, and analytics detection.
DNS resolution, redirect chains, response variance, custom 404, CDN detection, TTFB, keep-alive, and error codes.
Web app manifest, service worker, icons, start URL, display mode, theme colour, Apple meta tags, offline capability, and app shortcuts.
Privacy policy, terms & conditions, cookie consent, GDPR, CCPA, payment security (PCI), plus site-type checks for gambling, healthcare, finance, and more.
Upload an APK, EXE, DLL, JAR, IPA, or similar package. Our application safety engine performs heuristic and signature-based analysis (binaries are never executed) and produces a separate Application Safety Score (0–1000) — never mixed with the website score.
File hashes, digital signature artefacts, extension/content mismatch, deceptive double extensions, and trusted publisher indicators.
High entropy/packing signals, suspicious API imports, malware-like strings, ransomware/miner indicators, C2 endpoints, anti-analysis patterns, and weak/misused crypto heuristics.
Dangerous permissions and risky combinations, exported components without protection, accessibility/overlay abuse, SMS/call access on non-messaging apps, tapjacking/task-affinity signals, sharedUserId, and package-visibility sprawl.
APK signing completeness, debug/test flags left on, PE anomalies, archive nesting risk, native ABI anomalies, and backup enabled with sensitive-data hints.
Tracker/ad SDK density, hardcoded secrets and API-key patterns, cleartext traffic / network-security-config signals, WebView JS-bridge risks, and aggressive PII collection hints.
Suspicious naming, missing version/publisher metadata, size anomalies, and overall end-user trust signals — plus auditor manual red flags when needed.
Website audits and application safety scans each start at 1,000 points. Points are deducted for each failed check, weighted by severity. Scores map to a letter grade — but the two systems are kept completely separate.
Each category contributes a weighted portion of the total 1,000 points
Every audit includes a comprehensive package designed to help you understand, improve, and showcase your website's standards.
A detailed document covering all findings, categorised by severity, with specific recommendations for remediation.
A professional certificate confirming your website has been audited and meets our standards. Perfect for compliance documentation. Each certificate includes a unique reference number that can be verified online.
A professional badge in two styles (with or without grade) that you can add to your website to show visitors you've been audited.
Every website plan includes our full 298-check multipage audit engine, verifiable certificate, and report artefacts. Tiers differ by expert review depth, retests, multi-site coverage, and ongoing support.
Email us with your website URL and any specific requirements. We'll respond within 24 hours.
Our engine runs 298 checks across 12 categories. We review results and prepare your report.
Get your detailed PDF report, certificate, and your embeddable badge.
Implement our recommendations. Your audit includes 1 free retest to verify improvements.
Verify the authenticity of an existing AS Online Services audit certificate. Enter the reference number (found on your certificate) to confirm its validity.
Verify a CertificateOur audit engine runs 298 individual checks across 12 categories: Transport Security, Security Headers, Cookie Security, DNS & Email Security, Information Exposure, Authentication & Forms, Client-Side Security, Performance, SEO & Accessibility, Reliability, Progressive Web App, and Legal & Compliance.
Our Starter plan is $499 and includes the full 298-check audit, PDF report, verifiable certificate, and 1 embeddable badge. The Professional plan is $1,299 and adds manual expert review, a priority fix list, and 2 retests. Enterprise plans start from $2,999 for multi-site and ongoing audits. Application Safety Testing is custom-quoted.
Yes. We certify websites and applications. Application safety testing covers APK, EXE, DLL, JAR and related packages with a separate Application Safety Score that is never mixed with website scoring.
The app engine runs heuristic and signature-based checks across integrity, malware indicators, permissions (including dangerous combinations, exported components, overlay/tapjacking, and package visibility), packaging (debug/test flags, native ABI anomalies, backup risk), privacy/tracking (secrets, cleartext/NSC, WebView bridges, tracker density), and reputation. Binaries are not executed. The score shows where an app stands on safety signals — it is not a recommendation to install or avoid the app.
Every website starts at 1,000 points. Points are deducted for each failed check, weighted by severity. Your final score maps to a letter grade from A+ (950–1000, Outstanding) down to E (0–549, Critical).
Results are delivered within 24 hours. You'll receive a detailed PDF report, your official certificate, and embeddable badge codes.
Yes. Every certificate includes a unique reference number that can be verified at asonlinesvc.dev/verify to confirm authenticity.
Yes. The Starter plan includes 1 free retest, Professional includes 2, and Enterprise offers unlimited retests so you can verify improvements.
Website certification from $499 — detailed report, verifiable certificate, embeddable badge, and retest included. Pay securely via PayPal. Send us your website URL and we'll provide a quote within 24 hours.
View Our Portfolio