# Research and field notes

Dated studies, technical investigations and build notes from turva.dev. Each article explains what was observed, how it was checked and what the result does not establish.

## Start with the research

- [Website agent-readiness across 567 company sites](/blog/website-agent-readiness-567-sites): one scanner over a selected prospecting sample of 567 company sites in ten weeks, with the changing check set recorded as a limitation.
- [What four AI assistants call an agent-readiness audit](/blog/what-ai-assistants-call-an-agent-readiness-audit): fifty buyer questions, 193 answers, one day's conditions.
- [Thirty-day follow-up: 201 comparable site readings](/blog/thirty-days-after-the-brief): a 210-site cohort, 201 comparable readings, four changed level, and no effect from the briefs established.

## All posts

- [HTML and Markdown can disagree](/blog/html-and-markdown-can-disagree). 2026-09-12.
- [I rebuilt turva.dev around the report](/blog/i-rebuilt-turva-dev-around-the-report). 2026-09-07.
- [What 19 identity vendors publish for agents](/blog/agent-readiness-identity-vendors). 2026-09-05.
- [Two files called auth.md, and they disagree on the field names](/blog/two-auth-md-dialects). 2026-09-04.
- [Thirty-day follow-up: 201 comparable readings from 210 sites](/blog/thirty-days-after-the-brief). 2026-09-03.
- [What four AI assistants call an agent readiness audit](/blog/what-ai-assistants-call-an-agent-readiness-audit). 2026-09-03.
- [Website agent readiness, measured on 567 company sites](/blog/website-agent-readiness-567-sites). 2026-09-03.
- [TRACE signs how an agent ran, not what it was allowed to reach](/blog/trace-runtime-attestation). 2026-08-30.
- [I scanned fourteen code hosts. Not one served an MCP server card.](/blog/agent-readiness-code-hosts). 2026-08-22.
- [It would be cheating to keep the old price](/blog/cheating-to-keep-the-old-price). 2026-08-21.
- [I thought it was a small job](/blog/i-thought-it-was-a-small-job). 2026-08-16.
- [My gate could not see a sixth](/blog/my-gate-could-not-see-a-sixth). 2026-08-04.
- [A red reading that measured my own client](/blog/red-reading-that-measured-my-own-client). 2026-07-30.
- [The checks that pass for the wrong reason](/blog/checks-that-pass-for-the-wrong-reason). 2026-07-29.
- [Finishing the optional commerce checks](/blog/finishing-the-optional-commerce-checks). 2026-07-20.
- [The twin is the page](/blog/the-twin-is-the-page). 2026-07-19.
- [Every response promised a rate limit. Nothing enforced it.](/blog/enforcing-the-rate-limit-i-advertised). 2026-07-18.
- [Microsoft said the patches would get bigger. I measured how much bigger.](/blog/measuring-the-ai-patch-surge). 2026-07-15.
- [Reducing secret exposure in coding-agent workflows](/blog/agent-secret-hygiene). 2026-07-12.
- [How agent-ready are Finnish B2B sites? I scanned sixteen](/blog/agent-readiness-finnish-b2b). 2026-07-07.
- [When honesty and the checker disagree](/blog/honesty-and-the-checker). 2026-07-06.
- [Four AI agents re-checked the guides](/blog/re-checking-the-guides). 2026-07-04.
- [The page grew, the agent bill did not](/blog/cheaper-pages-revisited). 2026-07-04.
- [Moving the source from GitHub to Codeberg](/blog/moving-source-to-codeberg). 2026-07-04.
- [A free llms.txt validator](/blog/free-llms-txt-validator). 2026-07-02.
- [Agent access is now a setting](/blog/agent-access-is-now-a-setting). 2026-07-02.
- [Publishing an ai-catalog.json for agentic discovery](/blog/publishing-an-ai-catalog). 2026-06-29.
- [What the Open Knowledge Format is, and what it is not](/blog/open-knowledge-format). 2026-06-27.
- [What an agent pays to read your site](/blog/cheaper-pages-for-agents). 2026-06-26.
- [When an agent can prove it is Claude](/blog/verifiable-agent-identity). 2026-06-25.
- [What makes an AI agent's decisions reliable](/blog/reliable-agent-decisions). 2026-06-22.
- [Owning your fediverse identity](/blog/owning-your-fediverse-identity). 2026-06-21.
- [Moving turva.dev off prerender.io](/blog/moving-off-prerender). 2026-06-20.
