where data moves and decisions matter · independently verified

Audits and advisory for products that AI agents read and act on

Agent-readiness is the measurable starting point, scored by independent scanners. The wider work is the data those agents depend on and the decisions you let them make. Both are measured before they are promised.

  • 99/100 · A+ · #1 on startuphub.ai
  • 100/100 · Level 5 on isitagentready.com

Business ID 3600281-7 · registered in Finland

turva@audit · verify
turva verify --source startuphub.ai
✓ startuphub.ai · 99/100 · A+ · #1 ranked
✓ isitagentready.com · 100/100 · level 5 · agent-native
independent agent-readiness scan of turva.dev scanner: startuphub.ai · 3rd-party ↗
discoverability100/100
content100/100
access-control100/100
capabilities100/100
commerce100/100
quality96/100
verified 99/100 #1 ranked A+

Why 99 and not 100? The one deduction is the rate_limit_headers check: it reports no RateLimit headers while this site sends RateLimit-Policy, the field the active IETF draft defines. The full story, with the measurements, is in the rate limit post.

What an agent sees on this page

Every page on this site is also served as plain markdown to any agent that asks for it, at the same URL, at a fraction of the token cost of the HTML. The block below is generated from the same markdown an agent receives.

curl -H "Accept: text/markdown" https://turva.dev/

# Audits and advisory for products that AI agents read and act on

Agent-readiness is the measurable starting point, scored by independent scanners. The wider work is the data those agents depend on and the decisions you let them make. Both are measured before they are promised.

#1 of publicly-scanned sites on the startuphub.ai agent-readiness leaderboard, 99/100 and A+. 100/100 and Level 5 on isitagentready.com. Business ID 3600281-7, registered in Finland.

## Audits, advisory, and implementation for product teams

An AI agent does not browse a site the way a person does. It reads machine-readable surfaces and acts on the parts it can reach, once it trusts what it found. I measure how a site, an API or a product holds up to that, fix what the measurement names, and stay on as the product changes.

The measurable core is agent-readiness, scored by independent scanners and provable on the next scan. The wider work begins where readability ends. The data an agent acts on has to arrive intact, and the decisions it is allowed to make have to sit inside a boundary you set. The first makes an agent able to read you. The second makes it safe to let one act.

## Independent agent-readiness scan of turva.dev

How markdown content negotiation works.

Audits, advisory, and implementation for product teams

An AI agent does not browse a site the way a person does. It reads machine-readable surfaces and acts on the parts it can reach, once it trusts what it found. I measure how a site, an API or a product holds up to that, fix what the measurement names, and stay on as the product changes.

The measurable core is agent-readiness, scored by independent scanners and provable on the next scan. The wider work begins where readability ends. The data an agent acts on has to arrive intact, and the decisions it is allowed to make have to sit inside a boundary you set. The first makes an agent able to read you. The second makes it safe to let one act.

Where this applies

The pattern is narrow, but where it fits is not. Anywhere data moves and a decision follows, an agent can be the thing that reads the data and makes the call, as long as the inputs are clean and the envelope is set. A few examples:

An agent reading a product catalog and completing a checkout for a buyer.
An agent watching an API and acting the moment a threshold is crossed, without waiting for a person.
An agent guiding a technician in the field, working from the same data the expert would.
An agent triaging incoming requests and resolving the routine ones on its own.
An agent operating a remote system over a link that drops, holding its last safe state until the data returns.

These are examples. The same discipline carries from one case to the next, so the question is rarely whether an agent could do the work. It is whether the data reaching it and the limits set around it are good enough to trust.

Evidence

turva.dev is my own reference build. It is ranked #1 of publicly-scanned sites on the startuphub.ai agent-readiness leaderboard, with 99/100 there and Level 5 on isitagentready.com. Measured 2026-07-17.

99/100 · A+ · #1of publicly-scanned sites on startuphub.ai
100/100 · Level 5agent-native on isitagentready.com

isitagentready.com and Cloudflare Agent-Ready are the same scanner on two domains, and this site runs on Cloudflare Workers. Independent means independent of turva.dev: neither scanner is run or influenced by this business. Two isitagentready commerce checks, x402 and mpp, read FAIL on purpose. Commerce here is quote-on-request, there is no machine payment rail, and declaring one would be a fake checkmark. The reasoning is written out in the commerce checks post.

Both agent-readiness scanners are public and can be run again at any time, by a person or by an agent. The scanner is the source. This page only reports what it returned. To check the numbers independently, run isitagentready.com and startuphub.ai against turva.dev and compare.

turva.dev publishes its own web security scans too, on the same principle that the result should be measurable rather than asserted. Measured 2026-07-16.

The Cloudflare Worker that produces these results is open source: codeberg.org/erekola/turva-worker. You can read every line before you hire me.

Backed by a registered business, publicly verifiable: Business ID 3600281-7, registered in Finland. PRH/YTJ business register: tietopalvelu.ytj.fi/yritys/3600281-7

The process has three stages and no surprises

01 Measurement

For agent-readiness, two independent scanners read the current state of the site or API and produce a numeric baseline with a categorized list of what is missing. For the wider work, the data path and the decision envelope are tested the way an agent would hit them, so the starting point is a fact rather than an opinion.

02 A written report

Three to ten priority fixes in order of impact, with technical reasoning written so the reader does not need a background in any of this to follow it.

03 The fixes

I implement them, or your engineering team does the work with the report as the spec. Both routes are supported and the choice is yours.

Services

fixed scopeAudit

Fixed scope. Two to three weeks. Two independent scanners run against the site or API. Written report with a prioritized fix list. You receive a measured baseline and a clear "do this first" plan.

monthlyAdvisory

Monthly retainer, async-only. Ongoing review as the site, API or product evolves. Each scanner cycle reads higher than the last, or the report explains why a tradeoff was kept on purpose.

on requestImplementation

On request. Worker-level changes, well-known manifests, MCP server work, JSON-LD and Schema fixes. The improvement is verifiable against the audit baseline in the next scan.

on requestAgent operations

On request. The work beyond readiness: the data an agent acts on, and the decision envelope of permissions and thresholds that bounds what it is allowed to do.

on requestMCP server design

On request. Read-only discovery tools and streamable HTTP transport. No auth surface and no logging by default. The endpoint stays readable for agents and does not turn into an abuse vector.

Who I am

The work is done by one person under a registered business. My background is engineering: measurement, testing, and reducing things to what actually matters. I have worked in international companies for years, and I keep only the tools and methods that hold up when the output is checked line by line.

The work stays measurable on purpose. Agent-readiness is a property a scanner reads, higher next week than this week or not. The wider work holds to the same test. The data an agent acts on either arrives intact or it does not, and the boundary you set either holds or it does not. Measurable either way.

Contact me

Seeing where your site, API or product stands with AI agents starts with a measured baseline, a written report, and a prioritized list of what to fix first. For agent-readiness that baseline comes from two independent scanners. For the wider work it comes from testing the data path and the decision envelope directly. Async-only engagement. No calls and no calendar links. The first reply lands in writing within one business day.

info@turva.dev
Signal @turva.19
LinkedIn