How Our Checks Work

For the business
and the team behind it.

You get a clear picture of where your site loses trust — and findings written so you can hand them directly to whoever needs to act. Your developer, your legal adviser, your ops team. No translation needed.

No jargon. Every term on this page is explained in plain language.

Why does this even matter for a small L&D business?

When a company is about to hire you, someone on their team googles you. Sometimes it's the HR director, sometimes it's procurement, sometimes it's an IT person. They are checking one thing: can we trust this vendor with our people and our data?

Most small coaching businesses and L&D teams fail that check not because they are untrustworthy, but because the right signals are not visible. No privacy page, no mention of how you use AI tools, contact form without basic security. Buyers move on without saying why.

A trust check surfaces those gaps so you can fix them, often in a day or two, before they cost you the next deal.

Think of it like this: if you are running a coaching practice from a professional office, you naturally have a reception desk, a sign on the door, maybe a certificate on the wall. These are not legal requirements but they make a client feel safe walking in.

Your website is that office. A trust check is the equivalent of walking in with fresh eyes and asking: does this look like somewhere I would hand over my team's personal details?

The Translation System

Three layers. You only need to care about one.

Every result you see in plain language is backed by a chain of expert thinking. Here is how it works, starting from what you see and going down to the expert foundations.

1
Business Layer
What you see
Four areas written in plain English. No jargon. Results any business owner can understand and act on, even without any technical or legal background.
User Experience
How clear and trustworthy your site feels to a visitor. Does it feel like a real, professional business?
Transparency
Do you clearly explain what you do, who you are, and how you handle people's information?
Safety and Security
Does your site have the basic protections a buyer would expect before trusting you with their team's details?
AI Trust
If you use AI tools in your work, do you say so? Buyers are increasingly asking this question before they sign.
Each business result maps to expert principles
2
Principles Layer
How we think about it
Established design and engineering principles that experts have developed over decades. We use these as the backbone of our checks so results are grounded in real knowledge, not opinion.
Privacy by Design
Building privacy in from the start rather than bolting it on. Developed by privacy expert Ann Cavoukian in the 1990s, now adopted globally.
Security by Design
Building basic protections into how a system works rather than treating them as an afterthought.
Accessible and Inclusive UX
Design principles that make sites work for everyone, which also signals professionalism and care to buyers.
Ethical AI Principles
Guidelines for using AI fairly, transparently, and in ways that respect the people whose data it touches.
Principles map to real frameworks and regulations
3
Compliance Layer
What it maps to
Our proprietary simplified risk framework maps to global legal and industry standards. You never see this layer directly, but your results are always grounded in it. When a buyer's legal team asks questions, your fixes will hold up.
GDPR
The EU data protection regulation. Applies to anyone handling EU residents' personal data, including UK-based businesses post-Brexit.
SOC 2
A widely recognised security and trust standard often requested by enterprise buyers before they will sign a vendor contract.
ISO 27001
An international information security standard. Our checks are aligned to its core principles even if you are not formally certified.
WCAG and OWASP
Accessibility and web security guidelines. OWASP defines the most common website security risks every business site should address.
You only ever deal with Layer 1.

We do the translation for you. When we say "your AI usage is not disclosed anywhere visible," we have already checked that against the principles and frameworks below it. You just get the plain-language result and the fix.

The Four Business Areas

What we actually check in each area

Select an area to see exactly what we look at, what it means for your business, and a real-world example of why it matters to buyers.

User Experience
How professional and clear your site looks to a first-time visitor. A buyer often makes a gut decision about trust in under 10 seconds. This area checks whether those first impressions are working in your favour.
What we check
  • Does your site load quickly and work on mobile?
  • Is it clear what you do and who you help, within a few seconds?
  • Is there an easy way for a buyer to contact you or find out more?
  • Does the site look current and actively maintained?
  • Can someone with a visual impairment use it? (Accessibility)
Why this matters to a buyer
A procurement manager at a large company is comparing three L&D providers. Your site loads slowly on her phone and the nav menu doesn't work. She moves on before she even reads your services page. You never knew you were in consideration.
How we think about it (Principles Layer)
Accessible and Inclusive Design
Sites that work for people with disabilities also load faster and rank better in search. Accessibility is not a nice-to-have, it is a signal of quality.
Maps to: WCAG 2.1ISO 9241
Clear Communication Principles
Plain language, logical structure, and visible contact information are all established UX best practices that build immediate credibility.
Maps to: Nielsen Norman Heuristics
Performance and Reliability
A slow or broken site signals to both buyers and search engines that the business is not on top of its operations.
Maps to: Core Web Vitals
Transparency
How open and honest your business looks. Buyers need to feel they understand who they are dealing with, what you do with their information, and that you have nothing to hide. This does not require legal expertise. It requires honesty, clearly displayed.
What we check
  • Do you have a privacy page, and is it easy to find?
  • Does it explain in plain terms what data you collect and why?
  • Do you explain what happens to information submitted through contact forms?
  • Are your terms and conditions (if you have them) accessible?
  • Are you clear about who owns your company and where you are based?
Why this matters to a buyer
A corporate HR lead needs to sign off on any vendor who will access employee data. She looks for a privacy policy and cannot find one. She flags it to procurement. The deal stalls. All you needed was a single plain-language page in your footer.
How we think about it (Principles Layer)
Privacy by Design
Privacy is built in from the start rather than added as a legal afterthought. Developed by Ann Cavoukian, now embedded in GDPR and most modern data regulations.
Maps to: GDPR Article 25CCPAPIPEDA
Transparency and Openness
Being clear about data practices is not just good ethics, it is a legal requirement under GDPR and a core expectation in enterprise procurement.
Maps to: GDPR Article 12-14ICO Guidelines
Purpose Limitation
Only collecting data you actually need, and being clear about why. Buyers want to see this is stated, not assumed.
Maps to: GDPR Article 5
Safety and Security
Whether your site has the basic protections a buyer would expect before trusting you with their team's information. Think of it like locking the front door to your office. Most of these are set-and-forget. Most small businesses are missing at least two.
What we check
  • Is your site served over HTTPS (the padlock in the browser bar)?
  • Are basic security headers in place on your forms?
  • Do the third-party tools you use (Zoom, HubSpot, etc.) have their own trust policies you reference?
  • Is your site free of known malware flags or mixed content warnings?
  • Do you mention how long you keep client information?
Why this matters to a buyer
An IT security manager at a mid-sized company runs a quick check on every new vendor's website before approving a contract. Your contact form is missing a basic protection called CSRF. He flags it. The deal goes on hold. A developer could have fixed it in 30 minutes.
How we think about it (Principles Layer)
Security by Design
Building basic protections into how a site works, rather than relying on hope. Established by Carnegie Mellon's Software Engineering Institute and now standard practice.
Maps to: OWASP Top 10NIST CSFCyber Essentials
Minimum Necessary Access
Only collecting the information you actually need, secured appropriately. A contact form that asks for a date of birth is a red flag.
Maps to: ISO 27001GDPR Article 5
Third-Party Risk Awareness
Understanding and communicating that the tools you use (Zoom, payment processors, etc.) also touch your clients' data.
Maps to: SOC 2 CC9ISO 27001 A.15
AI Trust
This is the newest and fastest-growing trust question in B2B. Enterprise buyers are increasingly asking: do you use AI in your work, and if so, how? A single honest sentence on your website can answer the question before it is even asked.
What we check
  • Do you mention anywhere visible whether you use AI tools?
  • If you use AI, do you explain what for, and what you do not use it for?
  • Do you explain how client or learner data is handled in AI tools?
  • Is there a human in the loop for any AI-assisted advice or content?
  • Do you reference any AI ethics principles or guidelines you follow?
Why this matters to a buyer
A learning director at a financial services firm is reviewing your proposal. She asks her compliance team to check your website. They search for any mention of AI. They find nothing. She now has to ask you directly, which adds a delay. You use AI for session summaries only and could have answered this in two sentences on your services page.
How we think about it (Principles Layer)
AI Transparency and Explainability
Being open about when and how AI is used. One of the core principles in the EU AI Act and most enterprise AI governance policies.
Maps to: EU AI ActUNESCO AI EthicsNIST AI RMF
Human Oversight
Keeping a human accountable for AI-assisted decisions. Especially important when AI touches learning content, coaching notes, or assessments.
Maps to: EU AI Act Article 14ISO 42001
Data Minimisation in AI Systems
Not feeding more personal data into AI tools than necessary. This is the most common gap we see in small L&D businesses.
Maps to: GDPR Article 5ISO 42001
The Three-Step Process

Check. Treat. Strengthen.

Three steps from "I'm not sure where I stand" to "trust is our edge." One shared view for every stakeholder who needs to act.

1
Step 1
Check

Enter your URL and answer a few short questions about your business, your clients, and your current data setup. We combine a live public-site walkthrough with your context to score you across four trust pillars.

What you do
  • Enter your website URL — no account needed
  • Answer ~10 short questions (about 5 minutes)
What you get
  • A trust score out of 100 with a plain-English label
  • Your top gaps — what they are and what's at risk
2
Step 2
Treat

Every finding comes with plain-language fix guidance written for each person who needs to act. No translation required — your developer gets technical steps, your legal contact gets compliance context, your ops lead gets a prioritised to-do. One report. Every perspective.

For each gap we find
  • A plain-English description of the issue
  • Fix steps for your developer
  • Legal context for your compliance contact
  • Priority rating + region flags (CCPA / GDPR)
Example findings
  • "Cookie banner doesn't block tracking on Reject — here's the fix"
  • "Privacy policy doesn't mention AI tools — here's the clause to add"
3
Step 3
Strengthen

Trust is not a one-time fix. It's a direction. Re-scan monthly to track progress, export a trust proof PDF for proposals and procurement, and watch your score across all four pillars improve over time. The goal isn't perfection — it's visible, communicable progress.

What you get to use
  • Trust proof PDF for proposals and procurement packs
  • Monthly re-scans to track what's closing
  • Progress dashboard across all four pillars
What changes
  • You lead with trust instead of defending it
  • No more last-minute scramble when procurement asks
  • Your team and buyers see the same picture
Our AI Partner

AI insights powered by Papaya

We use Papaya to power the AI layer of our trust checks. Papaya helps us translate what we find on your site into clear, specific findings and prioritised recommendations, without exposing your data or making opaque decisions.

We chose Papaya because they share our values around explainability and ethical AI use. Every insight Papaya generates can be traced back to a specific check on your site. There are no black box scores.

Try the free check
Papaya's AI analyses your site's publicly visible trust signals and maps them to our framework. You get results that are specific, traceable, and explained in plain language.
Every AI finding is explained, not just scored
No personal data is used to train AI models
Scans are not stored unless you choose to save results
Human review available on all Co-Pilot findings