Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanSoftware business · Marketing site/Scanned 8 Sept 2026, 14:38 UTC/1 browser pass
AI agents cannot discover or access the API, and the network edge blocks crawlers that robots.txt welcomes.
Older scan
This report was produced by an earlier version of the scanner. Some findings may not match how the site is measured now.
Present. Agents lose ground at specific gates, not everywhere.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
3 pieces of evidence and the recommended fix are recorded for this issue, with notes written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
Robots.txt blocks 7 training crawlers (gptbot, claudebot, google-extended, ccbot, applebot-extended, meta-externalagent, bytespider) while welcoming search and agent crawlers.
4 observations recorded.
Programmatic onboarding
No API documentation is linked from the homepage. No OpenAPI spec exists at any of the 6 standard paths checked. No MCP manifest, OAuth metadata, or pricing.md is published.
3 observations recorded.
Pricing legibility
10 prices are readable in raw HTML without JavaScript, ranging from $1 to $15,000. No tier is gated behind a sales contact or demo request. Prices are published on the pricing page with clear per-month or per-seat terms.
1 observation recorded.
Agent-aware instrumentation
No MCP manifest is published at any of the 3 standard paths. Robots.txt blocks 7 AI crawlers by name, including gptbot and claudebot. No ai-plugin.json or llms.txt is present.
4 observations recorded.
Machine-fetchable trust
No security.txt is published at /.well-known/security.txt. The homepage answers automated requests and publishes an Organization schema with a ContactPoint.
2 observations recorded.
Commercial rails
Prices are published in raw HTML on the pricing page. A self-serve signup form is reachable from the homepage in 2 steps and asks for 11 fields, 5 required, with no payment card requested. The form does not gate access to a trial.
2 observations recorded.
Steps to first value
The primary call to action, 'Start testing', is 2 steps from the homepage and leads to a signup form. The form does not require payment or email verification before submission.
1 observation recorded.
Required fields
The signup form has 11 fields total. 5 are required: Email, First name, Last name, Phone number, and Date of birth. The remaining 6 are optional. A visitor must provide personal information to proceed, but the form does not demand company.
1 observation recorded.
Verification walls
No verification requirement is visible on the signup page itself. The form does not display copy about email confirmation, phone verification, or identity checks before submission.
1 observation recorded.
Error recovery
2 of 12 form inputs carry validation rules. The form includes 2 live regions for error messaging. No inline error containers are present on the page.
1 observation recorded.
It got through 6 of 15.
The agent got through 6 of 15 requests, but could not ask whether the door opens for requests carrying the AI crawlers' names. It came up empty on 8 other checks too. That is enough missing for a machine to give up before it reaches a purchase.