Services and pricing
Start with the question you need answered. I can check a Shopify store, audit a website or API, help implement the findings, or support your team over time.
You work directly with me, in writing. I reply within one business day. All prices exclude VAT.
Choose a starting point
- Shopify agent storefront check. €999. Do your selected products show the same price and availability across the shopping interfaces your store exposes? I check one store, one market and up to three named product and variant pairs. Delivered as one package of four written deliverables within 48 hours of the agreed written kickoff. One retest of up to two corrected items follows within 14 days of that first package, or of the delivered corrections when the correction add-on is bought.
- Website and API agent-readiness audit. €4,300. Find out what automated clients can access and what selected AI assistants say about your product. I combine a technical scan, manual review and a recorded set of AI questions, and include one re-scan within 30 days of the report, or within 30 days of the delivered corrections when the correction add-on is bought. Delivered within two weeks of the agreed written kickoff.
See the sample audit report and the sample Shopify report before choosing a service.
Shopify agent storefront check
€999. 48 hours. Fixed scope. Price valid until 2026-12-31.
What an AI shopper receives from one live Shopify store, across the three agent interfaces this check covers, with the evidence attached. One store, one market, up to three product and variant pairs.
Four written deliverables within 48 hours of the agreed written kickoff, and a fifth, one retest of up to two corrected items within 14 days of that first package, or of the delivered corrections when the correction add-on is bought. A further retest is bought as a new check. The audit is not a prerequisite. Read the full scope, the exclusions, the preflight and the refund terms.
Website and API agent-readiness audit
€4,300. Two weeks. Fixed scope. Price valid until 2026-12-31.
A technical scan, a manual review of your website and API surfaces, and a recorded question set put to selected AI assistants. The report keeps the technical findings and the observed AI answers apart.
The audit is delivered within two weeks of the agreed written kickoff. You receive the findings, a correction plan with acceptance checks, one round of written follow-up questions submitted within 14 calendar days of the report and answered within five business days, and one re-scan within 30 days of the report, or within 30 days of the delivered corrections when the correction add-on is bought. The written scope agreed before kickoff sets how many questions that round covers. Read the full scope and the deliverables.
Implementation
€1,500 per day, scoped separately. €499 for the complete fix list from an audit or a Shopify check, bought together with that service, with its report, or after the report and before implementation starts.
Your team can implement the report. If you want me to do it, the €499 add-on covers the complete fix list from the audit or the Shopify check. It is sold only with that service and can be bought together with it, with its report, or after the report and before implementation starts. It applies when the required access is arranged in advance. Access counts as arranged when the named account works.
The fixed price covers the whole list, whatever the number of corrections. Work outside that list is agreed separately at the day rate. When the add-on is bought, the included retest or re-scan window starts on the day the corrections are delivered, so the check reads the finished work.
For a Shopify check, I need collaborator access to the store. For an audit, I need an edge runtime in front of your origin, deployment access and any other access the listed fixes require, such as DNS. If the required access cannot be arranged, the add-on is not sold. Your team still receives the correction instructions.
I estimate about two days to implement the fixes an audit identifies, based on the kind of fixes the sample report lists. This is not a fixed quote or a limit on the €499 add-on.
Separately scoped implementation days
For website and API implementation, the audit comes first, so I understand the work before implementation starts. I estimate about two days for the identified fixes. New agent-ready infrastructure is scoped in days too.
I deploy an edge worker in front of your origin. It changes what the site serves without changing your application code. Deployment access must be ready before work starts.
Cloudflare Workers is the default. Other supported edge runtimes can be agreed when we scope the work, including Fastly Compute, Akamai EdgeWorkers, AWS Lambda@Edge, Netlify and Vercel.
Typical work includes
- Head metadata and /.well-known/ files.
- AI crawler rules, Content Signals and a Web Bot Auth directory.
- Markdown responses alongside the existing HTML pages.
- An agent skills index, auth.md and an API catalog.
- JSON-LD for products, organisations and articles.
- ai.txt and llms.txt.
- Signed content and agent authentication patterns.
- Discovery cards for an MCP or agent-to-agent server that already runs.
A separately scoped day does not include DNS changes, tool declarations inside your application, agent payment flows or building the MCP server itself. These need their own scope. This day-rate boundary does not reduce the complete fix list covered by an agreed €499 add-on.
Repository write access is limited to the task. There is no retainer.
We check technical changes with the relevant scanner or a direct test. A scanner result is recorded with its check set and date. No particular readiness level is promised.
Change plan, deadline and billable day
For separately scoped implementation days, I deliver a written change plan before the work day starts, listing each correction, its target system, dependencies and acceptance check. For the €499 add-on, the audit report or the Shopify check's correction plan is the change plan, and I do not promise a separate one.
Before that kickoff, I agree the completion deadline as a stated number of business days from kickoff, covering the whole add-on list or the separately scoped work. I use a separate implementation kickoff after the report and required access are ready, and obtain written approval before deploying production changes.
At that deadline, I deliver the changes with test results, deployment instructions, rollback instructions and a list of any unresolved external dependencies.
For separately scoped work, I count one billable day as seven and a half hours of work, including implementation, testing and handover.
I do not include recurring hosting, ongoing monitoring or maintenance after handover in the implementation fee.
What implementation needs from you
Before kickoff, I need your confirmed source facts, required business decisions, deployment approver and permission to run the agreed acceptance tests.
Checking and follow-up
I run an acceptance check for every implemented correction, verify source changes separately from edge changes, and leave failed or unverified items open. A fix that fails the re-check is redone at no charge in the same follow-up round.
I include one round of implementation handover questions submitted within 14 calendar days of delivery and answer that round within five business days. The written scope agreed before kickoff sets how many questions that round covers.
Ongoing advisory
€3,000 per month. Minimum three months.
If you are not satisfied with the first month, you can end the retainer by email sent at any time during the first month, up to the day before the second month starts. The retainer then ends when the first month ends, and the second and third months are not charged. Notice given in the second or third month ends the retainer at the end of the three-month minimum, and the months up to that end are charged. After the three-month minimum the retainer runs month to month, and either party can end it by email before the next month starts.
Keep track of what changes after the audit. I repeat the measurements, review relevant work your team ships and help you decide what to do next.
You receive
- A monthly re-scan with the same scanner and profile, shown beside the previous result.
- A monthly repeat of the AI question set across the same assistants.
- Written review of agent-readiness changes your team ships, within one business day, up to four reviews per service month.
- Recommendations for the roadmap.
- Questions and answers by email or a shared document.
- A monthly written summary that reads the month's measurements next to the previous month's and names the changes observed. The monthly summary is delivered within five business days after the month ends.
- A quarterly summary of measured changes, including unchanged or worse results.
The written baseline agreed before kickoff sets how many reviews, questions or review pages the month covers. Work beyond it is quoted separately at the day rate.
Each review explains what changed and what the evidence supports. If the method changes, I record that too. A higher score or an AI mention is not guaranteed.
Evidence and scope
I attach the dated per-check results and recorded AI questions and answers to each monthly summary.
Before kickoff, I record the included sites, APIs, markets, languages, scanner profile, assistants and question set in a written baseline. The service month starts on the agreed written kickoff anniversary, and the quarterly summary follows within five business days after every third one.
I include up to four written change reviews per service month, each covering one named deployment within that baseline, with unused reviews expiring at month end. Each month's scan and AI run finish by its final business day, on dates recorded in the kickoff plan.
I exclude implementation, continuous monitoring, incident response and operating your production systems from this retainer.
Advisory kickoff
I need the agreed audit baseline, your priority questions, a named written contact and the URLs and release notes for each requested change review. At kickoff, I confirm the measurement dates, review submission channel, service-month boundaries and first reporting deadlines in writing.
Checking and ending
If a source or assistant cannot be checked, I record the missing result and obtain written agreement before replacing it in the comparison.
When the engagement ends, I deliver the final paid month's summary on its normal deadline and hand over the measurement history and open recommendations with it.
Agent operations
Price agreed for the engagement.
I review the data and permissions an agent relies on, the decisions it can make, and when a person needs to take over.
The work can cover
- Where data can be lost, delayed or misread.
- The actions the agent is allowed to take.
- Thresholds that require a human decision.
- How control passes between the agent and a person.
- Records and checks that help you review what happened.
The price depends on the systems involved, whether the agent can move money or delete data, and whether I am reviewing existing limits or helping define and implement them. The written scope agreed before kickoff states which of the two the price covers.
This service covers the controls around an agent. It does not include building the agent itself or certifying that it is safe.
Review deliverables
Within five business days of the agreed written kickoff, I deliver a draft map of the workflow, data sources, connected systems and points where information can be lost, delayed or misread.
Within ten business days of kickoff, I deliver a written control specification listing allowed actions, permission boundaries, human-decision thresholds and handover rules. With that specification, I deliver a findings table with evidence, an owner, a proposed correction and an acceptance check for each finding.
I also deliver the results of ten agreed test scenarios, with the input, expected control behaviour, observed result and any part that could not be tested.
If the engagement includes control implementation, I name each change and its delivery deadline in business days from kickoff before work starts.
Review scope
The review package covers one existing agent, one named workflow, up to three connected systems and up to ten action types.
The review package excludes production changes, penetration testing, continuous monitoring and incident response unless the written engagement explicitly adds them. A repurchased service covers the same scope as the original purchase.
Review kickoff requirements
I need the workflow description, permission configuration, representative redacted traces, intended action limits and a named owner who can approve those limits in writing. The review also needs an agreed test environment or replay dataset and written permission for the specific tests, with real money movement and real deletion excluded from the review tests.
I ask your named owner to confirm the intended limits against the draft map before I finalise the control specification. Dates in the written scope move by the business days spent waiting for that approval.
Review acceptance checks
I distinguish controls verified in the system from proposed controls and simulations, and leave failed or untested acceptance checks open. Acceptance checks compare delivery with the agreed workflow, action list, documents and ten scenarios, without treating successful tests as a safety certification.
Review follow-up and price
I include one round of written questions submitted within 14 calendar days of the review package and answer it within five business days. The written scope agreed before kickoff sets how many questions that round covers.
Before kickoff, I confirm the amount, currency, VAT treatment, payment milestones and any third-party costs in the written quote.
MCP server design
Price agreed for the engagement.
Give agents a supported way to read your product data. I design and build an MCP interface with agreed tools, data sources and access rules.
The default is a read-only server using Streamable HTTP. For public, non-sensitive data, authentication and logging are off by default. Authentication and an audit trail are added where the data and misuse risks call for them. The written scope agreed before kickoff records that decision and any resulting price change.
Typical work includes read-only tools, a server card at /.well-known/mcp/server-card.json, and submission to one agreed MCP registry.
The price depends on the number of tools and data sources, whether an API already exists, and whether write capabilities are required. Writes are scoped separately and are not included by default.
Read-only tools cannot modify the source through that interface. Data exposure, bulk extraction and availability still need to be considered for each tool.
Server deliverables
Within five business days of the agreed written kickoff, I deliver a written design covering tool names, input and output schemas, data fields, examples, errors and access rules.
Within fifteen business days of kickoff, I deliver the working server in the agreed hosting environment, its source code, deployment configuration and server card. At the same time, I deliver test results and an operating guide covering dependencies, credentials, limits, deployment, rollback and the person responsible after handover.
Within the same fifteen-business-day window, I submit the server to one agreed MCP registry and record whether the listing is accepted, pending or rejected.
Server scope
This starter scope covers one server, up to three read-only tools, one existing API, one hosting environment and compatibility checks with two named MCP clients.
Before kickoff, I agree the exposed fields, response-size and request-rate limits, authentication decision and logging policy in writing.
The starter scope excludes building or repairing the source API, correcting source data, recurring hosting charges and maintenance after handover. I do not promise that a registry will accept a submission or that an external assistant will use the server.
Server kickoff requirements
I need API documentation, representative data, permission to expose the agreed fields, access to the agreed repository, access to the hosting environment and a named owner for access decisions.
Design approval in writing comes before deployment, and I record any resulting scope or schedule changes. Dates in the written scope move by the business days spent waiting for that approval.
Server acceptance checks
For every tool, I record tests for a valid request, invalid input, missing data, an unavailable source and the agreed access and response limits.
I check the returned data against the source API, confirm that the interface exposes no write capability, compare the server card with the running endpoint and deliver the two named clients' connection and tool-call results with their versions, leaving failed or untested acceptance checks open. The work is done when the checks named in the written plan pass. Payment does not depend on an outside scanner's result.
Server follow-up and price
I include one round of written handover questions submitted within 14 calendar days of delivery and answer it within five business days. The written scope agreed before kickoff sets how many questions that round covers.
Before kickoff, I confirm the amount, currency, VAT treatment, payment milestones and third-party costs in the written quote.
Work you can inspect
My published research includes a scan of 567 selected company websites, 193 answers to fifty buyer questions across four AI assistants, and a thirty-day follow-up with 201 comparable site readings from a 210-site cohort.
These are research observations, not client results. Each article records its method and limits. The follow-up does not establish an effect from the briefs.
Sites that complete an audit, or score 100/100 on isitagentready.com, may display the self-declared agent-ready badge. Read the eligibility criteria before using it.
Frequently asked
Do I need the audit before the Shopify check?
No. They are separate services. The Shopify check examines selected products and shopping interactions in one store. The audit covers up to two targets named in the written scope, each a website or an API, for example a Shopify store and a B2B site. Each hostname named in the written scope is one target, so a site and its API on different hostnames are two targets and on the same hostname one.
Will you sign our NDA?
Yes. I sign your own NDA as it stands, at no charge, before material is shared.
How is our material handled?
Client material is kept only on systems needed for the work and deleted within thirty days of closure, as the legal page defines closure, unless the law requires retention. Four kinds of copy follow their own rules: bookkeeping material, which is kept for six years, what the AI tool's provider keeps under its own terms, an encrypted backup copy until the rotation replaces it, and a private version-history copy that lasts as long as the backups. Every backup is overwritten within one month at most. Engagement email and its attachments are deleted under the same closing rule. The legal page explains each. The workstation uses full disk encryption. Credentials are stored in an encrypted vault, and backups are encrypted before upload.
Do you use AI tools?
Yes. Files needed for a task are processed by the provider of the AI tool in use. The tools work with a local workspace, not directly with your systems. Material you want excluded is named in the NDA and kept out. Vault storage and a tool's runtime permissions are separate controls.
Full detail is in the terms and data handling.
Tell me what you need
Email info@turva.dev with the URL and your question. I'll reply within one business day with a proposed scope, price and start date.
We work in writing. There are no calls or calendar links.
All prices exclude VAT. 25,5% for Finnish customers, reverse charge for EU B2B customers with a valid VAT ID, 0% for non-EU.