Your website has faults you cannot see from the inside
208 checkpoints. Eight documents. Ten working days.
Bought separately AED 32,500–77,000
In one engagement AED 19,900
You keep AED 12,600 to 57,100. Ten companies at this rate, then it ends.
Three engagements in this market, three invoices, three reports that never meet. Here: one of each.
Half the fee comes back if the report closes with fewer than five findings that carry a named remedy.
Security, findability in search and in AI answers, and the data-protection articles your pages touch — examined together, in one engagement, with the evidence attached to every finding.
The problem, in three specifics
Each of these runs for months on a live site without anyone inside the company noticing.
-
A contact form that discards submissions
No error message, no bounce. The enquiries simply stop, and everyone assumes the market has cooled.
-
An Arabic page that breaks halfway down
Half the visitors see a sentence that ends mid-word. Nobody in the office reads the site in Arabic.
-
An AI assistant describing the company wrongly
Asked what the firm does, it answers with a business the company left two years ago, because the old description is still sitting in three directories.
You look at your own site every week. That is exactly why you stop seeing it.
What one finding looks like
Not a mock-up. A real finding, from our own first audit.
Open directory listing under /images/
- Category
- Application exposure
- Severity
- Medium, lower bound — the documented range runs to critical, depending on what the folder holds
- Observed
- Apache served a complete file index at
/images/. Nothing on the site itself linked to the folder or used it. - Evidence
curl -sSL https://…/images/ | grep -ci 'Index of 'matched. The same probe against five comparison paths on the same server returned 404, which is what rules out a server-wide setting and points at this one folder.- Business exposure
- Anyone who requested the path was handed the file list, no credentials needed, no scanner required. What it meant depended entirely on the contents — a hygiene defect if the folder held only images, a notifiable exposure if it held anything not meant to be public.
- Recommended remedy
- Switch the listing off in the server configuration, not in a single
.htaccess, so a folder created next month is covered too. Then review the contents file by file and remove what should never have been public. - Closure test
- The same
curlprobe now returns zero matches and an HTTP 403. Verified again 3 September 2026.
From our own first audit of ffiniti.ai, 8 August 2026 — catalogue reference EXP-001, checkpoint EXP-05. The full finding, with all fourteen mandatory fields, sits in Document 2 of the eight you receive.
What is examined
The 208 is not a round number. It is three catalogues, added up.
Findability
93
Check points
Whether search engines can read your pages at all, and whether AI assistants name you when a buyer asks. Search visibility, visibility in AI answers, the local and Arabic market, paid search integrity, loading speed, accessibility.
Security
65
Check points
Measured from outside: transport and certificates, HTTP hardening, exposed files and applications, the software you depend on, and whether someone can send email in your name.
Law and operations
50
Check points
Which data protection regime your licence puts you under, the duties that follow for the pages themselves, consent and where data actually travels, the paths that carry an enquiry, and how the site is governed internally.
93+65+50=208 Counted, not rounded
Twelve of the 208 are active checks: they interact with the site rather than only observing it. They run only against your own site, only with your written permission, and never against a real account. Without that permission they are recorded as not run.
What you receive
Eight documents, each written for one reader.
The delivery register
| Ref | Document and what it answers |
|---|---|
| 0Read Me First | What is here, in what order, and what was not examined |
| 1Executive & Risk ReportFor the board | How bad it is, what it costs, what you decide this week, with the risk matrix your board can sign |
| 2Security FindingsFor IT and developers | What is open, how to reproduce it, and how you know it is closed |
| 3Performance & Accessibility | How fast and how usable, measured against what, and which duty is breached |
| 4Content & Trust | Whether a stranger believes the site and where it loses them |
| 5SEO, SEA & AI VisibilityFor marketing | Why you are not found, in search and in AI answers |
| 6Action ChecklistFor whoever runs the fixes | What to do first, how long it takes, who you need |
| AEvidence Appendix | The command, the raw output, the timestamp, and the coverage register |
Read this one first
The coverage register is the page we like least and the one you should read first.
It names every checkpoint that did not run and why: “not applicable, because there is no checkout”, or “not examined, because access was not granted”. Without it you cannot tell a check that passed from a check that never ran.
What this costs, and what it costs elsewhere
Bought as separate engagements in this market, the same ground runs AED 32,500 to 77,000.
| Engagement | Price in this market |
|---|---|
| A security audit | AED 15,000 – 25,000 |
| A 360-degree SEO audit | AED 2,500 – 12,000 |
| A PDPL gap analysis | AED 15,000 – 40,000 |
| The three added together | AED 32,500 – 77,000 |
Those corridors come from 204 documented price sources across the UAE and internationally, compiled in July 2026. Accessibility and AI visibility are not in that figure at all. Our own price research turned up no UAE market rate for either, so there is nothing honest to add.
Ten parallel research passes across the wider pricing project, one per service category, of which the three rows above are what feed this comparison — 517 searches and page fetches in total, 25 July 2026. Every entry carries a source, a date and a tier. The security corridor above compares against fixed-scope audits of similar depth, not penetration tests; the two are priced apart in the source data because they are different products. Two independent counter-reviews went through the 204 entries afterwards, briefed to refute rather than confirm. They found real problems and corrected them: a cited regulation that does not exist, a misquoted retainer figure, and a freelancer rate that was off by a factor of eight. A synthesis round then built the corridors from what survived. Currency throughout is AED at USD 1 = 3.67; the source figures carry whatever tax the issuing firm charges, which is a separate question from our own fee, stated above without VAT because we hold no registration to charge it.View pricing methodology
The integration is the product, not the discount. One evidence set, cross-referenced: a security gap that also weakens what search engines and AI systems can find, or a data-protection duty that follows directly from a technical fault, shows up once — not in three reports that never talk to each other.
Founding client rate
AED 19,900
Ten companies, then it ends
- Scope
- Up to 40 pages, one language, no shop, no logged-in area. Larger sites, a second language, a shop or a member area are quoted on top and shown as separate lines, never folded in silently.
- Payment
- Payable in full before the work begins.
- Delivery
- Ten working days from the day the payment clears.
Ten places, open now. When they are taken, the audit is priced against the corridor above. It is not a timer and it does not reset.
What it is worth to you
We do not put a revenue promise in front of you, because we cannot know your numbers before we see them.
What we do instead is ask for two figures at the start, and then carry them through every finding in the report.
- How many enquiries the site produces in a month.
- What one enquiry is worth to you on average.
- What share of those enquiries a single undetected fault could plausibly put at risk. The audit finds the fault. Where you give us the first two figures, that third one can be modelled against it.
A worked example, not a promise
Thirty enquiries a month, an average value of AED 8,000, and one quiet fault costing you ten percent of them: that is AED 24,000 a month, and the fee is back within a month of that fault being closed.
Your numbers will be different, and they come from you: the form below asks for the first two, and both fields are optional. Where you leave them blank, the report says so and the finding carries no figure at all rather than an invented one. A finding with a made-up price attached is worse than a finding with none.
What this is not
The five things we will not pretend to sell you.
-
Not a penetration test
We establish that a weakness exists. We do not exploit it, extract data, or test how far it reaches.
-
Not a redesign
This engagement judges, it does not build. Remediation is quoted separately, and we are equally content handing the list to your existing agency.
-
Not legal advice
We establish facts about your pages and name the article they touch. What follows from those facts is a legal judgement and it belongs to your lawyer. Every legal point leaves the report already written as a question you can hand to counsel.
-
No guaranteed position, in search or in AI answers
AI answers are personalised and they change daily. Anyone selling a guaranteed ranking inside ChatGPT cannot deliver it.
-
Not everything, ever
Anything behind a login, inside your servers, or in your contracts sits outside an external audit unless you grant access. Whatever we could not reach is named in the coverage register rather than quietly omitted.
Who is doing this
The person on the call is the person who runs the audit.
- Company
- Ffinitibyte Technology L.L.C, Dubai mainland
- Licence
- Department of Economy and Tourism, number 1642222
- Office
- 507-5, Business Avenue, Port Saeed, Deira, Dubai
- Group
- A member of The Royal Group of Companies, with access to a delivery network of 600+ engineers across five centres should a finding need a second set of eyes.
- Managing Director
- Dimitri Scholochow, who runs the audit himself and is the person on the call. scholochow@ffiniti.ai+971 50 153 9990
Standards the catalogue is built against
Named rather than implied.
- OWASP Web Security Testing Guide 4.2
- WCAG 2.2
- UAE Federal Decree-Law 45/2021
- DIFC Data Protection Law No. 5 of 2020
- ADGM Data Protection Regulations 2021
- UAE Federal Decree-Law 34/2021
Before you ask
Eleven questions, answered in the same words the rest of this page uses.
What access do you need?
None by default. The standard run only touches publicly reachable pages — no logins, no analytics, no server access. Twelve of the 208 checkpoints are active ones and need your written permission first, naming the domain, the window and the person granting it; without that signature they do not run and are recorded as not run.
Do you need my Google Analytics to work out the commercial-impact figures?
No. Those figures come from what you tell us on the form — enquiries a month and their average value, both optional. Where you leave them blank, the finding carries no figure rather than an invented one.
Is this a penetration test?
No. We establish that a weakness exists. We do not exploit it, extract data, or test how far it reaches.
Will you make changes to my website?
No. This engagement judges, it does not build. Remediation is quoted separately, and we are equally content handing the list to your own developer or agency.
Which platforms can you audit — WordPress, Shopify, a custom build?
Any of them. The audit runs from outside your site against what a visitor, a search engine or an AI assistant actually sees, so the platform underneath makes no difference to the 208 checkpoints. What can change is whether a fault has a named, platform-specific fix — the report says so either way.
What happens if part of the site cannot be tested?
It is named in the coverage register, not silently dropped. Document A lists every checkpoint that did not run and why.
How does the 50% refund work?
If the report closes with fewer than five findings that carry a named remedy, half the fee comes back. We would rather carry that risk than pad a report to justify an invoice.
When do the ten working days start?
From the day the payment clears, not from the day you submit the form.
Can my own developer implement the fixes, or do you?
Your developer can. Every finding carries the exact command that produced it, so it can be reproduced and verified without us. We quote implementation separately if you want us to do it instead.
Who owns the report, and how is sensitive information handled?
The report and everything in it belong to you. The evidence appendix is redacted before it is rendered — personal data, keys or session tokens are masked in the report, with the unredacted material kept in our evidence store and handed over separately only if you ask for it.
Does the audit constitute legal advice or a compliance certificate?
Neither. We establish facts about your pages and name the article they touch. What follows from those facts is a legal judgement for your lawyer, and every legal point in the report is already written as a question you can hand to them.
Your data
Terms you should see before you sign, not after.
The audit covers publicly reachable pages only. No logins, no analytics access, no server access. If you offer credentials we will decline them until a non-disclosure agreement and a data processing agreement are signed.
The evidence appendix is redacted before it is rendered. Any personal data, key or session token that a check produces is masked in the report; the unredacted material stays in our evidence store and is handed over separately if you want it.
The report and everything in it belong to you. We keep no copy of your data beyond the retention period stated in the engagement letter, and the raw evidence store is deleted on your written request at any time.
Our liability is capped at the fee paid. An audit establishes what is visible from outside on the day it runs; it is not a warranty that your site cannot be compromised afterwards, and no audit anywhere can be. The twelve active checkpoints run only after you have signed a written authorisation naming the domain, the window and the person granting it. Without that signature they do not run and they are recorded as not run.
If the audit finds little
If we close with fewer than five findings that carry a named remedy, we refund half the fee.
On a well-maintained site a thin report is a real outcome, and you should not pay full price for a clean bill of health you already suspected. We would rather carry that risk than pad a report to justify an invoice.
The ask
Buy the audit
You give us the address and written permission for the twelve active checkpoints. We run all 208 and deliver the eight documents in ten working days from the day the payment clears.
Every finding arrives with the command that produced it, the raw output and the timestamp, so you can reproduce it without us. What did not run is named in the coverage register rather than quietly omitted.
Or write directlyscholochow@ffiniti.ai+971 50 153 9990