For clinics, firms and any business that collects information about its clients. We measure what your site transmits, we fix it, and we install your AI tools on your side. Every step is proven in writing.
Or see the packages, from CA$497 →
Or read what it looks at first — it's all below.
We found this on our own site, in September 2026:
Our privacy policy stated that, until a visitor clicked “Accept”, no data was sent to Google.
That was false. The fonts loaded from Google's servers on every page — including the privacy policy page itself. Every visitor sent their IP address before choosing anything.
Nobody had decided it. Nobody had seen it. It has since been fixed.
BEFORE ANY CONSENT
The report gives you this diagram for your site, with the exact timing of each transmission.
If it happened to us — and we build these systems — it happens to everyone.
What the report looks like. Every line carries its evidence, and can be re-checked without us.
What goes to third parties before consent. Which requests, to which domains, at exactly which moment during loading.
What your policy promises, next to what your site does. Quotation against observed fact.
Publicly accessible files that nobody decided to publish: backups, working documents, configuration files.
Regulated vocabulary in your published content. Every profession has its own — section 31 of Quebec's Medical Act for healthcare, mandatory disclosures elsewhere.
Past dates shown as upcoming. The most common flaw, and the most visible to a client.
Every line is verified by a request, and the report writes down which one. See what a line of the report looks like.
No IT department. No lawyer upstairs. No compliance officer. You have a website someone built two years ago, a privacy policy found somewhere, and a business to run.
This isn't negligence. It's that nobody's job is to watch it.
The outcome is almost always the same: you find out the day someone tells you. A client, a colleague, your professional order. Always too late, and always with an audience.
A free automated tool will tell you which cookies leave. That's useful, and you should do it.
It won't read your privacy policy to tell you it promises the opposite. And it will never see what is missing: we found 25 pages loading a booking tool that none of them used — spotting that means looking for the absence of a use, not the presence of a call.
A scan tells you the door is open. We close it.
Ten sites online today. Four belong to clients who authorised us to show them, six are ours — including the one you are reading. You can open every one of them and check for yourself — all ten were tested one by one on 12 September 2026.
These are sites we built and maintain, not reports we sold: the report is a new offering, and we say so rather than let you assume otherwise.
Any business that collects anything about its clients — a newsletter email is enough. In Quebec, Law 25 makes no distinction between a clinic and an online store.
Private clinics: physiotherapy, psychology, nutrition, osteopathy, dentistry. You collect health information: your professional order adds to the law, and this is where we come from.
Firms: accountants, financial planners, notaries, lawyers. Social insurance numbers, finances, estates: little information is more sensitive.
Service businesses that keep files: recruitment, property management, private schools, non-profits. You have a website, a form, perhaps online payments. Each of these sends something to someone.
What they share: nobody's job is to watch it. No IT department, no lawyer, no compliance officer. That's what the report is for.
Enter your website address. In seconds you'll see which external domains your page's code calls — a first look at what may be sent before any consent — and whether files are sitting where they shouldn't be. No email required.
Check my site — freeThree fixed prices, no quotes, and one installation by quote. You choose what you want: to know, to have it fixed, or to have it installed.
The written record of what your site transmits, with the evidence. Delivered in 5 business days. You fix it yourself, or hand it to your web developer.
The report, then we fix it. You get a repaired site and a line-by-line record of what was done.
If you already have a report — ours or an automated tool's — we fix what it found.
Fixed-price repair covers classic sites and simple WordPress — the number of pages changes nothing, the technology is what counts. A site heavy with plugins, a consent banner to build from scratch, or a policy to rewrite are quoted separately. The report tells you before, never after — it's what reveals which case you're in. See the repair.
AIVOS, from CAD 3,500, by quote. Your AI agents and automations installed on your side, with compliance laid down from the start and a written audit at delivery. See AIVOS.
You do nothing during those five days. No access to give us.
No call is needed. No access is requested. We never touch your client data: we look at what a visitor sees, nothing else.
No, and that's deliberate. We are not lawyers. The report records measurable facts; the legal reading belongs to your own adviser. That is precisely what makes the report useful to them: it starts from facts, not impressions.
Then the report will show it, and you'll have a dated document that proves it. We have no interest in finding problems that don't exist: every line of the report is reproducible, and you can re-check all of it yourself.
Because a free report is a sales pitch in disguise. This one stands on its own: you can take it, fix things yourself, and never contact us again. That is a perfectly legitimate use.
The report stands on its own. Many people stop there, fix things themselves, and that is perfectly fine.
For those who would rather have it done: we install AIVOS, your AI agents and automations on your side, with compliance laid down from the start, and a written audit at delivery. By quote, from CAD 3,500, a maximum of two installations per month.
This isn't a marketing limit. It's our actual capacity.