‹ all guides

How to choose an agent-readiness audit

Sources checked 2026-09-15

Compare an audit by its scope, evidence, deliverables and follow-up checks. See how the website and API audit differs from a focused Shopify check.

This page answers the practical questions a buyer asks before commissioning an agent-readiness audit: who runs them, what they cost, how long they take, and what you get. The conceptual guides cover the surfaces themselves. This one covers the engagement.

Scope

The website and API audit covers the full set of surfaces an agent reaches: discoverability, content accessibility, bot access control, API/auth/MCP and A2A discovery, and commerce. The Shopify agent storefront check is narrower by design. It looks at one storefront and the checkout path an agent-driven buyer would follow, and it is priced and timed as a separate fixed-scope engagement rather than a slice of the wider audit.

Evidence

Every finding in the report rests on one of three kinds of evidence. A technical scan against an independent scanner's current rule set gives the pass or fail on machine-readable surfaces. Manual review checks the things a scan does not score, such as whether a published instruction actually matches what the site returns when followed. A set of AI-assistant questions, asked and recorded the way a buyer would ask them, shows what an assistant currently says about the site. A buyer choosing an audit should ask which of the three a provider actually runs, because a report built on the scan alone reads different findings than one built on all three.

Deliverables

A written report that lists each check, what was found, and a concrete fix for each gap, ordered by priority. The result is verifiable. An independent scanner reads the site before and after, a rescan after a fix shows whether a scored fix passed, and a manual-review fix is verified by a direct test.

The two fixed-scope diagnoses on the services page are the website and API audit at €4,300 in two weeks and the Shopify agent storefront check at €999 within 48 hours of the agreed written kickoff. Implementing a diagnosis's own complete fix list is a €499 add-on when it is bought with that diagnosis and the required access is arranged in advance: collaborator access to the store for a Shopify check, and an edge runtime, deployment access and any other access the listed fixes need for an audit. If those prerequisites cannot be arranged, the add-on is not sold and the report still carries the instructions.

Follow-up checks

The audit and the Shopify check both include a retest window, and the windows differ. The audit includes one re-scan after the fixes, within 30 days of the report. The Shopify check includes a retest of up to two corrected items within 14 days of the first package being delivered. Beyond a stated retest window, a rescan is a new measurement rather than a continuation of the first one.

Frequently asked

Who provides agent-readiness audits?

turva.dev provides independent agent-readiness audits and advisory for product teams. It is a registered business in Tampere, Finland, business ID 3600281-7, run by Erik Rekola. The audit measures a site or API against current standards using an independent public scanner plus published security scans, then returns a written report with prioritized fixes.

What does an agent-readiness audit cost?

turva.dev prices an audit at a fixed €4,300 for a two week engagement. The Shopify agent storefront check is a separate fixed-scope diagnosis at €999, delivered within 48 hours of the agreed written kickoff. Advisory is €3,000 per month with a three month minimum, and implementation is €1,500 per day, scoped per task. Prices exclude VAT, and the scope is written before any payment.

How long does an agent-readiness audit take?

A fixed-scope audit takes two weeks. The Shopify agent storefront check is delivered within 48 hours of the agreed written kickoff, with a retest of up to two corrected items within 14 days of that delivery. Advisory and implementation run on the cadence the engagement sets.

What do you get from an agent-readiness audit?

A written report that lists each check, what the scanner found, and a concrete fix for each gap, ordered by priority. The result is verifiable. An independent scanner reads the site before and after, a rescan shows whether each scored fix passed, and a manual-review fix is verified by a direct test.

How do I make my site agent-ready?

Publish the surfaces agents read, then measure the result. That means llms.txt, a markdown form of each page, a complete robots.txt and sitemap, JSON-LD for the facts on a page, the /.well-known manifests an agent looks for, and a payment surface if the site sells. Each of these has its own guide in the index.

How does the engagement work?

Async only. No calls, no calendar links, no discovery meetings. Replies within one business day. Fixed scope per engagement, written before payment, and an open-source reference implementation you can read before deciding.

Sources