Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanUnclassified/Scanned 8 Sept 2026, 14:14 UTC/1 browser pass
The site blocks both automated clients and real browsers from reading its homepage or pricing, making it impossible for machines or agents to discover what is offered.
Older scan
This report was produced by an earlier version of the scanner. Some findings may not match how the site is measured now.
Severe. Your human funnel and your agent funnel are different products.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
1 piece of evidence and the recommended fix are recorded for this issue, with notes written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
No AI crawler is blocked, a real browser is refused or served a stripped page, which is how assistant shopping arrives, no sitemap, no schema.org markup, the homepage turns a real browser's own request away, so the wall sits below HTTP.
4 observations recorded.
Programmatic onboarding
No API surface was found in the documentation linked and fetched from the homepage. The product needs no account at all, so programmatic signup does not apply.
3 observations recorded.
Pricing legibility
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Agent-aware instrumentation
No MCP manifest.
4 observations recorded.
Machine-fetchable trust
Security.txt could not be checked because automated access was refused. The homepage refuses automated clients outright with HTTP 429, blocking trust signals from being published or read.
2 observations recorded.
Commercial rails
Pricing page exists but is walled behind HTTP 429 for automated clients. No procurement paths, OAuth server, or pricing.md were reachable. A visitor cannot discover pricing or act on it without a browser that bypasses the wall.
2 observations recorded.
Steps to first value
The product is usable immediately with no account and no signup. No entry path was found on the homepage, and the entry_path probe confirmed no CTA, no form, and zero steps to the product.
1 observation recorded.
Required fields
Nothing is asked of a visitor because there is no form. The entry_path probe counted zero required fields.
1 observation recorded.
Verification walls
There is no account system, so there is nothing to verify. The site needs no email confirmation, phone verification, or identity checks.
1 observation recorded.
Error recovery
There is no form to get wrong. A visitor cannot make an error in signup because signup does not exist. Error recovery is not applicable, but the absence of friction scores high.
1 observation recorded.
It got through 2 of 14.
The site refused automated access at pandadoc.com, so the agent could not reach the site at all.