An agency built your website. Who looks after it now?
Most web contracts cover building the site and say nothing about the years after. What falls in the gap, where responsibility sits, and what to ask.
Read articleHow email authentication, uptime monitoring, certificates, brand protection and website quality actually work — written for the people responsible for keeping them healthy, in plain language with concrete steps.
Twenty-one plain-language guides across everything TrustCtrl watches — websites and checkout, certificates, email and brand — plus the basics every business owner should know. Thirteen guides on getting found on Google, sixteen on search and AI visibility, and nineteen deeper technical guides follow below.
Most web contracts cover building the site and say nothing about the years after. What falls in the gap, where responsibility sits, and what to ask.
Read articleUsually your domain isn't proving the mail is really from you, or the message trips a spam filter. The common causes — and how to fix each one.
Read articleYour DMARC reports already list every server that used your name — most turn out to be your own forgotten services. How to read them before tightening anything.
Read articleWhat that browser warning means in plain English, why it appears, what it costs you in lost customers, and how to get rid of it for good.
Read articleHow to tell a harmless lookalike from a dangerous one — and the concrete steps to get a fake copy of your site shut down.
Read articleYour homepage can load fine while checkout is quietly broken. How to know before customers can't buy — with test orders and automatic checks.
Read articleDNS is the internet's address book, linking your domain to your server. Why it matters for your site and email — and what breaks when it's wrong.
Read articleA plain-language checklist for small businesses: cookie banner, privacy policy, forms, a secure site and more — no legal jargon, just what to do.
Read articleDead links quietly lose you customers and chip away at your Google rankings. Why they happen — and how to find and fix them.
Read articleYour password plus one more check, usually a code from a phone app. Why it stops most account break-ins, and how to switch it on.
Read articleIt's more than a few lost sales. The real business math — lost orders, wasted ad spend, support and trust — with a worked example.
Read articleMost of your customers browse on a phone. What mobile-friendly really means, how to check yours, and the common problems to fix.
Read articleAnyone can put your domain in an email From field. DMARC is the record that decides what happens next — and its reports show who really sends as you.
Read articleExample records, the 10-DNS-lookup limit and the mistakes that silently break authentication — a working SPF and DKIM setup from scratch.
Read articleA page can return 200 OK while checkout is broken. Content checks, synthetic browser journeys and protocol monitors close the gap.
Read articleMost lookalike domains are harmless parked pages. How to tell the benign ones from an active phishing setup — and when to act.
Read articlePublic TLS certificate lifetimes are heading towards 47 days. What that means for manual renewal routines — and how to stay ahead of expiry.
Read articleLCP, CLS and INP measure how fast your site feels to real visitors. What each metric means for conversion and search — in business terms.
Read articleCSP, HSTS, X-Frame-Options and the rest: what each header protects against and which ones every production site should send.
Read articleWhat GDPR and ePrivacy actually require from a cookie banner — and the common consent mistakes that set trackers before anyone clicks accept.
Read articleThe European Accessibility Act now applies to many businesses selling in the EU. What WCAG conformance involves and how to find your gaps.
Read articleThirteen guides to the questions people actually type — from "why am I not showing up" to what the work costs. Written so you can follow them without a specialist beside you.
Six causes, checked in order. The ten-second search that tells you whether you have an indexing problem or a ranking one — they need opposite fixes.
Read articleNothing to buy, no form to fill in. The four things that actually get a new site discovered and indexed — and the two services still sold that are worth nothing.
Read articleDays for indexing, months for rankings. What sets the speed, and the one-month line where waiting stops being the explanation.
Read articleThree checks, from ten seconds to the full picture. What the site: search can and cannot tell you, and the three reasons a page is left out.
Read articleRule out the measurement artefacts first — most reported drops are one. Then the five technical faults that cause real ones without anybody deciding anything.
Read articleSpam pages served to crawlers and hidden from every visitor. The Search Console signals that reveal them — and the benign explanations to rule out first.
Read articleA 403 that opens fine, a 200 that Google reads as not found, and a list capped at a round number. Verify as a human before acting.
Read articleFour different failures look identical from outside. One free number tells you which one you have, and each has a different fix.
Read articleThe work that moves position, ordered by return. The highest-return half is usually the part nobody has done, and it costs days rather than months.
Read articleTwo disciplines, one shared foundation. What each means, where they genuinely differ, and the afternoon’s work that covers most of both.
Read articleThe map result is won on two fronts. What the Business Profile contributes, and the website faults that quietly undo good profile work.
Read articleFour pricing models and what each honestly suits, the promises that should end a conversation, and the work worth doing before you hire anyone.
Read articleWhere the numbers come from, what is measured versus estimated, and who keeps the Search Console access. A good agency answers all six easily.
Read articleSixteen connected guides on being found — by Google and by the AI assistants. From crawler access and content that survives without JavaScript to the numbers that show whether it is working.
Assistants fetch live pages and name their sources. The three conditions that decide whether yours is one of them — and the settings that quietly rule you out.
Read articleA robots.txt line, a security plugin or a CDN rule can remove you from every AI answer while Google keeps working. How to read what yours actually says.
Read articleWhat to put in it, why it is not urgent — and the server fault that checking for a missing file tends to uncover.
Read articleYour page looks complete because your browser ran the scripts. The crawler may have received an empty shell — and you cannot see it from the inside.
Read articleRanking is not the finish line. The two lines that decide whether a placement becomes a visit, and how to find the pages losing them.
Read articleSitemaps go stale silently. What URLs that redirect, 404 or refuse indexing actually cost you, and a ten-minute check.
Read articleWhy "average position" is not your ranking, why the query totals never add up, and where the quick wins actually are.
Read articleTurning organic traffic into a number a finance director accepts — and why measured and estimated must never be presented as one.
Read articleTwo people ask the same question and hear different brands. Why a screenshot proves nothing, and how to measure AI visibility as a rate — with honest unknowns.
Read articleDentist, doctor, physiotherapist — the volume column comes back empty, not zero. The blank is upstream policy, and your own Search Console is the better instrument.
Read articleA wrong location setting returns plausible numbers from a market you don't sell in. The sanity checks that catch it — and the benign causes behind sudden drops.
Read articleAssistants and snippets lift from pages that answer the question as asked. Your Search Console already holds the real questions — read them raw.
Read articleFollow the measured traffic: a medium problem on the money page beats a low one nobody sees. And a page without data is unknown — never worthless.
Read articleA page can rank brilliantly and bring visitors who will never buy — and research seeded from your own rankings amplifies it. How to read queries against what you sell.
Read articleProduct page, guide, map or AI overview — the shape of the result is Google's statement of what searchers accept. Pick the form before you write.
Read articleFive well-chosen questions in your customers' words beat fifty asked once — and when the answer names someone else, write that name down.
Read articleDeeper material on the software supply chain and vulnerability management — the ground CodeControl and VulnControl cover. Written for whoever will be asked whether the tooling is any good.
Three questions get skipped when AI coding agents arrive: what the agent may reach, what data leaves the building, and who checks the code that ships.
Read articlePermissive, copyleft, and the network clause that catches SaaS. Which licences oblige you to publish your own source — and why it surfaces during due diligence.
Read articleAn abandoned package will never be fixed, so the next vulnerability in it is permanent. How to tell abandoned from finished, and the four options.
Read articleMost software companies are not directly covered and get the requirements anyway — through their customers' contracts. What arrives, and what to have ready.
Read articleCore is well maintained; almost every compromise arrives through a plugin or theme — including ones removed from the directory without telling you.
Read articleAttack one package, reach thousands of companies. The five routes in, what the well-known incidents actually teach, and the defences that hold up.
Read articleA developer needs a task finished, not a security review. Why telling them to be more careful has never worked, and what to do instead.
Read articleAn ingredients label for software: what goes in one, how SPDX and CycloneDX differ, and why the question is arriving in ordinary companies' inboxes.
Read articleAn SBOM says what your software contains. A VEX says what you decided about each known flaw — and why most of them do not affect you.
Read articleCVSS says how bad a flaw would be, not whether anyone is exploiting it. How KEV and EPSS turn 31 findings into 3 that matter this week.
Read articleAI assistants confidently import packages that never existed, and attackers register those names. Why typosquatting checks are blind to it.
Read articleIf your build asks a public registry for an internal package name, anyone can claim it — and your next build may install theirs.
Read articleAttackers publish packages named one keystroke from the real thing and wait. Why the payload usually runs before you import anything.
Read articleA credential removed in a later commit stays readable in git history forever. Why rotation is the only fix that actually works.
Read articleYou declared forty packages and installed six hundred. Where the rest came from, and how to find the single upgrade that fixes the vulnerable one.
Read articleUnpinned actions, pull_request_target with a checkout, and write-all permissions — what each one risks, and how to close it.
Read articleA CVE is a catalogue number, not a severity rating. What the identifier means, how scoring works, and the three questions the numbers can't answer.
Read articleMost false criticals come from one mistake — and the same mistake makes scanners miss real flaws in the other direction.
Read articleAn exposed database breaks nothing, which is why it stays open for years. The services that should never face the public internet.
Read articleTrustCtrl runs more than 80 checks across your domains — email authentication, uptime, certificates, website quality and lookalikes — and explains every finding in plain language.
Not open for sign-up yet · Join the waitlist