where data moves and decisions matter · independently verified

Audits and advisory for products that AI agents read and act on

Agent-readiness is the measurable starting point, scored by an independent scanner. The wider work is the data those agents depend on and the decisions you let them make. Both are measured before they are promised.

100/100 · Level 5 · Agent-Native on isitagentready.com · measured 2026-07-20

Business ID 3600281-7 · registered in Finland

turva@audit · verify
turva verify --source isitagentready.com
✓ isitagentready.com · 100/100 · level 5 · agent-native
independent agent-readiness scan of turva.dev scanner: isitagentready.com · 3rd-party · Cloudflare ↗
discoverability100/100
content100/100
bot access control100/100
api, auth, mcp & a2a100/100
commerce100/100
verified 100/100 Level 5 Agent-Native

What an agent sees on this page

Every page on this site is also served as plain markdown to any agent that asks for it, at the same URL, at a fraction of the token cost of the HTML. The block below is the opening of that markdown, generated from the same string an agent receives.

curl -H "Accept: text/markdown" https://turva.dev/

# Audits and advisory for products that AI agents read and act on

Agent-readiness is the measurable starting point, scored by an independent scanner. The wider work is the data those agents depend on and the decisions you let them make. Both are measured before they are promised.

100/100 and Level 5, Agent-Native, on isitagentready.com, Cloudflare’s agent-readiness scanner. Business ID 3600281-7, registered in Finland.

## Audits, advisory, and implementation for product teams
[Truncated. The full document continues in markdown.]

How markdown content negotiation works.

Audits, advisory, and implementation for product teams

An AI agent does not browse a site the way a person does. It reads machine-readable surfaces and acts on the parts it can reach, once it trusts what it found. I measure how a site, an API or a product holds up to that, fix what the measurement names, and stay on as the product changes.

The measurable core is agent-readiness, scored by an independent scanner and provable on the next scan. The wider work begins where readability ends. The data an agent acts on has to arrive intact, and the decisions it is allowed to make have to sit inside a boundary you set. The first makes an agent able to read you. The second makes it safe to let one act.

Where this applies

The pattern is narrow, but where it fits is not. Anywhere data moves and a decision follows, an agent can be the thing that reads the data and makes the call, as long as the inputs are clean and the envelope is set. A few examples:

An agent reading a product catalog and completing a checkout for a buyer.
An agent watching an API and acting the moment a threshold is crossed, without waiting for a person.
An agent guiding a technician in the field, working from the same data the expert would.
An agent triaging incoming requests and resolving the routine ones on its own.
An agent operating a remote system over a link that drops, holding its last safe state until the data returns.

These are examples. The same discipline carries from one case to the next, so the question is rarely whether an agent could do the work. It is whether the data reaching it and the limits set around it are good enough to trust.

Evidence

turva.dev is my own reference build. It reaches 100/100 and Level 5, Agent-Native, on isitagentready.com. Measured 2026-07-20.

isitagentready.com is Cloudflare's agent-readiness scanner, and this site runs on Cloudflare Workers. Independent means independent of turva.dev: the scanner is not run or influenced by this business. Commerce here is quote-on-request. turva.dev declares its payable services in both the 402 challenge and the OpenAPI discovery, priced in USDC on Base via x402, and settlement is confirmed out of band rather than executed automatically, so the site serves a real payment surface and claims no capability it does not have.

The agent-readiness scanner is public and can be run again at any time, by a person or by an agent. The scanner is the source. This page only reports what it returned. To check the number independently, run isitagentready.com against turva.dev.

turva.dev publishes its own web security scans too, on the same principle that the result should be measurable rather than asserted. Measured 2026-07-20.

The Cloudflare Worker that produces these results is open source: github.com/erekola/turva-worker. You can read every line before you hire me.

Backed by a registered business, publicly verifiable: Business ID 3600281-7, registered in Finland. PRH/YTJ business register: tietopalvelu.ytj.fi/yritys/3600281-7

The process has three stages and no surprises

01 Measurement

For agent-readiness, an independent scanner reads the current state of the site or API and produces a numeric baseline with a categorized list of what is missing. For the wider work, the data path and the decision envelope are tested the way an agent would hit them, so the starting point is a fact rather than an opinion.

02 A written report

Three to ten priority fixes in order of impact, with technical reasoning written so the reader does not need a background in any of this to follow it.

03 The fixes

I implement them, or your engineering team does the work with the report as the spec. Both routes are supported and the choice is yours.

Services

fixed scopeAudit

Fixed scope. Two to three weeks. An independent scanner runs against the site or API. Written report with a prioritized fix list. You receive a measured baseline and a clear "do this first" plan.

monthlyAdvisory

Monthly retainer, async-only. Ongoing review as the site, API or product evolves. Each scanner cycle reads higher than the last, or the report explains why a tradeoff was kept on purpose.

on requestImplementation

On request. Worker-level changes, well-known manifests, MCP server work, JSON-LD and Schema fixes. The improvement is verifiable against the audit baseline in the next scan.

on requestAgent operations

On request. The work beyond readiness: the data an agent acts on, and the decision envelope of permissions and thresholds that bounds what it is allowed to do.

on requestMCP server design

On request. Read-only discovery tools and streamable HTTP transport. No auth surface and no logging by default. The endpoint stays readable for agents and does not turn into an abuse vector.

Who I am

The work is done by one person under a registered business. My background is engineering: measurement, testing, and reducing things to what actually matters. I have worked in international companies for years, and I keep only the tools and methods that hold up when the output is checked line by line.

The work stays measurable on purpose. Agent-readiness is a property a scanner reads, higher next week than this week or not. The wider work holds to the same test. The data an agent acts on arrives intact or the test says where it broke, and the boundary you set holds to exactly what it claims.

Contact me

Seeing where your site, API or product stands with AI agents starts with a measured baseline, a written report, and a prioritized list of what to fix first. For agent-readiness that baseline comes from an independent scanner. For the wider work it comes from testing the data path and the decision envelope directly. Async-only engagement. No calls and no calendar links. The first reply lands in writing within one business day.

info@turva.dev
Signal @turva.19
LinkedIn