Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanSoftware business · Marketing site/Scanned 8 Sept 2026, 14:12 UTC/1 browser pass
Gusto blocks automated clients at the door while publishing pricing behind the same wall, forcing agents to browse as humans or abandon the evaluation.
Older scan
This report was produced by an earlier version of the scanner. Some findings may not match how the site is measured now.
Wide. Agents are dropping out well before humans do.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
1 piece of evidence and the recommended fix are recorded for this issue, with notes written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
Gusto publishes llms.txt and allows major AI crawlers in robots.txt, but the homepage and pricing page both refuse HTTP clients while serving real browsers normally.
4 observations recorded.
Programmatic onboarding
No API surface exists. The documentation at docs.gusto.com contains 755 characters of text but no credentials, endpoints, code samples, or authentication details.
3 observations recorded.
Pricing legibility
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Agent-aware instrumentation
No MCP manifest is published at any of the three standard paths. No OpenAPI spec, OAuth metadata, or Web Bot Auth signals are present. An agent has no machine readable way to understand what Gusto offers or how to interact with it.
4 observations recorded.
Machine-fetchable trust
No security.txt file is published. The homepage refuses automated clients outright with HTTP 403, blocking any agent from fetching trust signals. A real browser is served the page, but trust verification requires HTTP access.
2 observations recorded.
Commercial rails
A self serve signup form is reachable from the homepage in 2 steps and asks for 9 fields, 7 required. No payment is collected on signup. The form accepts Google single sign on.
2 observations recorded.
Steps to first value
The signup form is 2 steps from the homepage. The form collects first name, last name, work email, company name, employee count, password and password confirmation. No verification step appears on the form itself.
1 observation recorded.
Required fields
7 of 9 fields on the signup form are required: first name, last name, work email, company name, employee count, password and password confirmation. Google single sign on is offered as an alternative to email.
1 observation recorded.
Verification walls
No verification requirement appears on the signup form. Email verification, phone verification or identity checks are not mentioned. Google single sign on bypasses email entry entirely.
1 observation recorded.
Error recovery
8 of 16 form inputs carry validation rules. 2 live regions are present for error messaging. No inline error containers are documented. An agent or human can see that some fields have constraints, but error recovery flows are not fully.
1 observation recorded.
It got through 4 of 15.
The site refused automated access at gusto.com, so the agent could not reach the site at all.