Glass Box methodology

    Evidence you can trace. Boundaries we do not blur.

    A public check shows what buyers, partners, and regulators can already see — so you are not surprised by their first impression. It is not a full compliance audit. Every finding is Detected, Inferred, or Needs confirmation, so the report never pretends private operations are visible from the web.

    The three lanes

    Every public finding sits in one lane

    Same labels on the scan landing page, in your report, and in product — no renaming between marketing and output.

    Seen directly

    Detected

    A public signal is visible without a login.

    • Privacy policy link
    • TLS/HTTPS state
    • Public Companies House or ICO register match

    Likely, not final

    Inferred

    A conclusion from public behaviour — useful, never a substitute for internal proof.

    • Tag and script inventory on the page
    • Mail-auth record posture (SPF/DMARC/DKIM)
    • Absent notices where a policy is expected

    Cannot be proven outside-in

    Needs confirmation

    Anything that needs contracts, access rules, or operational records to prove.

    • Signed processor or sub-processor agreements
    • Retention schedules and operational deletion evidence
    • Incident logs and follow-through

    What we can inspect from the outside

    Three buckets cover the public surface without overlap: visitor-facing disclosures, register-backed identity, and technical or DNS-visible signals — before any connector or document upload.

    Disclosure & consent

    • Privacy policy visibility and on-site data notices
    • Cookie banner and consent before non-essential cookies
    • Visitor-facing statements about how personal data is handled

    Registered identity

    • Companies House match where the register is reliable
    • ICO registration match where reliable
    • Trading name, contact point, and domain consistency

    Technical & network surface

    • HTTPS, transport security, and browser-facing security headers
    • DNS records for mail authentication (SPF, DMARC, DKIM)
    • Subresources, embeds, and third-party calls the page makes

    What public scanning cannot see

    Think of it as looking through the shop window: you can see what is on display, not how the kitchen runs. We are explicit about that gap so we never over-claim.

    • Supplier contracts and signed processor DPAs
    • Staff access permissions and operating responsibilities
    • Retention, deletion and DSAR handling evidence
    • Incident records, audit trails and real-world policy use

    How each lane shows up in your report

    The public scan landing page previews the six signal areas with the same colour logic. Your results carry that through — no bait-and-switch.

    Detected

    Emerald-labelled items — signals a stranger could screenshot from your public site.

    In the report: Treated as firm public evidence in your scan output.

    Inferred

    Amber-labelled — reasonable conclusions from public behaviour (scripts, DNS, gaps), not the last word.

    In the report: Flagged so you can confirm or correct without guesswork.

    Needs confirmation

    Sky-labelled — only internal records or contracts can prove the full story.

    In the report: Never scored as if we had proof we do not have.