Website Compliance Audit Pricing & Tiers
One service, offered at three depths. Every tier is a human-led review of what your public-facing website actually does in the browser, checked against the risk areas UK GDPR and PECR care about most, with fixed scope and pricing agreed up front. Choose the depth that fits, then get in touch. There is no online checkout; every engagement begins with a conversation.
Human-led. Evidence-based. Clear fixed pricing.
What we look at
- Cookies and browser storage: the cookies your pages set, plus Local Storage, Session Storage and IndexedDB, checked in the browser's own developer tools.
- Consent banner and preferences: whether a banner is present and, in the Standard Audit, how it behaves across accept, reject and preference choices.
- Trackers, scripts and network activity: in the Standard Audit, the observable third-party scripts and network requests loading on each page, including whether trackers fire before consent.
- Policy and transparency signals: whether your privacy and cookie policy links are present and reachable.
- Evidence: supporting screenshots captured by hand where they back up an observation.
Every tier reports what was actually observed in the browser, as information to support your decisions. It is not legal advice and does not certify compliance.
| Basic Snapshot | Standard Audit | Enterprise | |
|---|---|---|---|
| Price | £395 + VAT | £2,995 + VAT | Custom scoped & quoted |
| Turnaround | Typically 3 to 5 business days from payment and URLs | Up to 15 business days from deposit and URLs | By agreement |
| Pages reviewed | Up to 3 public pages | Up to 5 public pages, up to 3 for deeper review | Scoped to your environment |
| Depth | A fast, tightly scoped screen of visible warning signs | A full, evidence-led review | Tailored to complex or multi-part estates |
| You receive | Concise Executive Snapshot Report and limited supporting screenshots | Structured findings, a Supporting Evidence Pack and a remediation action plan with indicative budgetary guidance where appropriate | Defined during scoping |
| Payment | Payable to begin | 50% deposit to begin, 50% before the final report is released | Agreed in the quote |
| Best for | A quick first look at whether there is likely a problem | The detail, the evidence, and what to do about it | Multiple domains, logged-in areas, checkout flows or server-side tagging |
The paperwork, up front
Most providers show you the contract after you've said yes. Ours are published here, next to the prices, so you can read exactly what you're buying before you ever get in touch.
Basic Website Compliance Risk Snapshot
£395 + VAT · 3–5 business days · up to 3 pages. A fast, tightly scoped screen that flags visible warning signs across cookies, consent, storage and policy links, delivered as a concise executive snapshot report with limited supporting screenshots. It is a quick first look, not a full audit: it indicates whether there is likely a problem worth a closer look.
Enquire About the Basic SnapshotStandard Website Compliance Risk Audit
£2,995 + VAT · up to 15 business days · up to 5 pages. A full, evidence-led audit, with up to three pages chosen for deeper review. You receive structured findings, a Supporting Evidence Pack and a remediation action plan with budgetary guidance. Where Basic indicates whether there is a problem, Standard shows you the detail and what to do about it. A 50% deposit begins the work, with the balance due before the final report is released.
Enquire About the Standard AuditEnterprise Website Compliance Risk Assessment
Custom scoped & quoted. For larger or more complex environments that fall outside the fixed Basic and Standard scopes, such as multiple domains or subdomains, authenticated or logged-in areas, e-commerce checkout flows, or complex and server-side tagging. Scoped and priced to your specific requirements after an initial conversation.
Enquire About Your Enterprise AssessmentWhich tier is right, and where Enterprise begins
The Basic and Standard tiers are fixed-scope reviews of public-facing pages on a single website. They suit most business marketing sites, where the compliance risk sits on pages anyone can reach.
Some environments fall outside that fixed scope by their nature: multiple domains or subdomains, anything behind a login such as member or account areas, e-commerce checkout flows, and complex or server-side tagging setups. These are not a poor fit for the fixed tiers so much as a different job, and they are handled through Enterprise scoping so the work and the price match what is actually involved. If you are not sure which applies to you, get in touch and we will point you to the right tier honestly, even if that is the smaller one.
Stalytics reports what your website is observably doing and frames it as information for your decisions. It is not legal advice, a compliance certificate, or a guarantee of a regulatory outcome.
Not sure where to start?
Tell us the website and we will help you pick the right tier before anything is agreed.
Talk to Us First