Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanUnclassified · Blog property/Scanned 8 Sept 2026, 13:50 UTC/1 browser pass
A document signing platform with open machine access but no machine-readable API specification or integration hooks.
Older scan
This report was produced by an earlier version of the scanner. Some findings may not match how the site is measured now.
Present. Agents lose ground at specific gates, not everywhere.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
3 pieces of evidence and the recommended fix are recorded for this issue, with /.well-known/security.txt written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
No AI crawler is blocked by robots.txt; the site explicitly allows gptbot, claudebot, perplexitybot and others. A real browser is served the page normally. The sitemap lists 1656 URLs across multiple child sitemaps.
4 observations recorded.
Programmatic onboarding
Not scored: a blog is not measured on this.
Pricing legibility
Not scored: a blog is not measured on this.
Agent-aware instrumentation
No MCP manifest, developer documentation describes an API, but only in prose.
4 observations recorded.
Machine-fetchable trust
No security.txt file is published at /.well-known/security.txt. The homepage answers automated requests with HTTP 200 and serves structured data. No Web Bot Auth signals are present. Trust metadata is minimal.
2 observations recorded.
Commercial rails
Not scored: a blog is not measured on this.
Steps to first value
The primary call to action is 'Try for Free', reached in 2 steps from the homepage. The signup form is 2 steps away. No payment is requested on the entry path. A visitor can reach a working signup form quickly.
1 observation recorded.
Required fields
The signup form contains 2 fields, and 0 of them are marked required. A visitor can submit the form with minimal data entry. Of 8 total inputs on the form, only 1 carries a validation rule, so error prevention is minimal.
1 observation recorded.
Verification walls
No verification requirement (email confirmation, phone verification, or CAPTCHA) appears on the signup page itself. The form accepts submission with no stated verification step visible before account creation.
1 observation recorded.
Error recovery
Of 8 inputs on the signup form, only 1 carries a validation rule (a constraint attribute). No inline error containers are present. Live regions total 6, suggesting some error messaging infrastructure exists.
1 observation recorded.
It got through 7 of 13.
The agent got through 7 of 13 requests, but could not read the site's own guide for language models. It came up empty on 5 other checks too. That is enough missing for a machine to give up before it reaches a purchase.