where data moves and decisions matter · independently verified
Audits and advisory for products that AI agents read and act on
Agent-readiness is the measurable starting point, scored by independent scanners. The wider work is the data those agents depend on and the decisions you let them make. Both are measured before they are promised.
- 99/100 · A+ · #1 on startuphub.ai
- 100/100 · Level 5 on isitagentready.com
Business ID 3600281-7 · registered in Finland
Why 99 and not 100? The one deduction is the rate_limit_headers check: it reports no RateLimit headers while this site sends RateLimit-Policy, the field the active IETF draft defines. The full story, with the measurements, is in the rate limit post.
What an agent sees on this page
Every page on this site is also served as plain markdown to any agent that asks for it, at the same URL, at a fraction of the token cost of the HTML. The block below is generated from the same markdown an agent receives.
curl -H "Accept: text/markdown" https://turva.dev/
# Audits and advisory for products that AI agents read and act on
Agent-readiness is the measurable starting point, scored by independent scanners. The wider work is the data those agents depend on and the decisions you let them make. Both are measured before they are promised.
#1 of publicly-scanned sites on the startuphub.ai agent-readiness leaderboard, 99/100 and A+. 100/100 and Level 5 on isitagentready.com. Business ID 3600281-7, registered in Finland.
## Audits, advisory, and implementation for product teams
An AI agent does not browse a site the way a person does. It reads machine-readable surfaces and acts on the parts it can reach, once it trusts what it found. I measure how a site, an API or a product holds up to that, fix what the measurement names, and stay on as the product changes.
The measurable core is agent-readiness, scored by independent scanners and provable on the next scan. The wider work begins where readability ends. The data an agent acts on has to arrive intact, and the decisions it is allowed to make have to sit inside a boundary you set. The first makes an agent able to read you. The second makes it safe to let one act.
## Independent agent-readiness scan of turva.dev
Audits, advisory, and implementation for product teams
An AI agent does not browse a site the way a person does. It reads machine-readable surfaces and acts on the parts it can reach, once it trusts what it found. I measure how a site, an API or a product holds up to that, fix what the measurement names, and stay on as the product changes.
The measurable core is agent-readiness, scored by independent scanners and provable on the next scan. The wider work begins where readability ends. The data an agent acts on has to arrive intact, and the decisions it is allowed to make have to sit inside a boundary you set. The first makes an agent able to read you. The second makes it safe to let one act.
Where this applies
The pattern is narrow, but where it fits is not. Anywhere data moves and a decision follows, an agent can be the thing that reads the data and makes the call, as long as the inputs are clean and the envelope is set. A few examples:
These are examples. The same discipline carries from one case to the next, so the question is rarely whether an agent could do the work. It is whether the data reaching it and the limits set around it are good enough to trust.
Evidence
turva.dev is my own reference build. It is ranked #1 of publicly-scanned sites on the startuphub.ai agent-readiness leaderboard, with 99/100 there and Level 5 on isitagentready.com. Measured 2026-07-17.
- startuphub.ai leaderboard: #1 of publicly-scanned sites, 99/100 (A+). Discoverability, Content, Access Control, Capabilities and Commerce: 100/100 each. Quality: 96/100, because the rate_limit_headers check reports no RateLimit headers while this site sends RateLimit-Policy, the field the active IETF draft defines. startuphub.ai/agent-readiness
- isitagentready.com: 100/100, Level 5 (Agent-Native). isitagentready.com
isitagentready.com and Cloudflare Agent-Ready are the same scanner on two domains, and this site runs on Cloudflare Workers. Independent means independent of turva.dev: neither scanner is run or influenced by this business. Two isitagentready commerce checks, x402 and mpp, read FAIL on purpose. Commerce here is quote-on-request, there is no machine payment rail, and declaring one would be a fake checkmark. The reasoning is written out in the commerce checks post.
Both agent-readiness scanners are public and can be run again at any time, by a person or by an agent. The scanner is the source. This page only reports what it returned. To check the numbers independently, run isitagentready.com and startuphub.ai against turva.dev and compare.
turva.dev publishes its own web security scans too, on the same principle that the result should be measurable rather than asserted. Measured 2026-07-16.
- Hardenize: all 13 categories passed. hardenize.com/report/turva.dev
- Internet.nl: 98/100. IPv6, DNSSEC and RPKI pass in full. The single deduction is one HTTPS sub-test, the hash function for key exchange. internet.nl/site/turva.dev
The Cloudflare Worker that produces these results is open source: codeberg.org/erekola/turva-worker. You can read every line before you hire me.
Backed by a registered business, publicly verifiable: Business ID 3600281-7, registered in Finland. PRH/YTJ business register: tietopalvelu.ytj.fi/yritys/3600281-7
The process has three stages and no surprises
For agent-readiness, two independent scanners read the current state of the site or API and produce a numeric baseline with a categorized list of what is missing. For the wider work, the data path and the decision envelope are tested the way an agent would hit them, so the starting point is a fact rather than an opinion.
Three to ten priority fixes in order of impact, with technical reasoning written so the reader does not need a background in any of this to follow it.
I implement them, or your engineering team does the work with the report as the spec. Both routes are supported and the choice is yours.
- All communication runs async. No calls and no calendar links. Live meetings are not part of how this work is done. Short questions go through Signal, longer documents through email and CryptPad. Everything stays in writing, which means the work and the trail are auditable end-to-end.
- Production credentials are not requested. Write access to repositories is not taken by default. Read access is enough for the audit, and write access is scoped per task if implementation is purchased separately.
- The result is checkable, not asserted. For agent-readiness that is the scanner number, higher on the next scan in the categories and by the dates the report named. For the wider work it is the same test, the data path holding under load and the envelope doing exactly what it claims. Either the next measurement confirms it or it does not.
Services
Fixed scope. Two to three weeks. Two independent scanners run against the site or API. Written report with a prioritized fix list. You receive a measured baseline and a clear "do this first" plan.
Monthly retainer, async-only. Ongoing review as the site, API or product evolves. Each scanner cycle reads higher than the last, or the report explains why a tradeoff was kept on purpose.
On request. Worker-level changes, well-known manifests, MCP server work, JSON-LD and Schema fixes. The improvement is verifiable against the audit baseline in the next scan.
On request. The work beyond readiness: the data an agent acts on, and the decision envelope of permissions and thresholds that bounds what it is allowed to do.
On request. Read-only discovery tools and streamable HTTP transport. No auth surface and no logging by default. The endpoint stays readable for agents and does not turn into an abuse vector.
Who I am
The work is done by one person under a registered business. My background is engineering: measurement, testing, and reducing things to what actually matters. I have worked in international companies for years, and I keep only the tools and methods that hold up when the output is checked line by line.
The work stays measurable on purpose. Agent-readiness is a property a scanner reads, higher next week than this week or not. The wider work holds to the same test. The data an agent acts on either arrives intact or it does not, and the boundary you set either holds or it does not. Measurable either way.
Contact me
Seeing where your site, API or product stands with AI agents starts with a measured baseline, a written report, and a prioritized list of what to fix first. For agent-readiness that baseline comes from two independent scanners. For the wider work it comes from testing the data path and the decision envelope directly. Async-only engagement. No calls and no calendar links. The first reply lands in writing within one business day.