An agency built your website. Who looks after it now?
Most web contracts cover building the site and say nothing about the years after. What falls in the gap, where responsibility sits, and what to ask.
Read articleHow email authentication, uptime monitoring, certificates, brand protection and website quality actually work — written for the people responsible for keeping them healthy, in plain language with concrete steps.
Twenty plain-language guides across everything TrustCtrl watches — websites and checkout, certificates, email and brand — plus the basics every business owner should know. Nineteen deeper technical guides follow below.
Most web contracts cover building the site and say nothing about the years after. What falls in the gap, where responsibility sits, and what to ask.
Read articleUsually your domain isn't proving the mail is really from you, or the message trips a spam filter. The common causes — and how to fix each one.
Read articleWhat that browser warning means in plain English, why it appears, what it costs you in lost customers, and how to get rid of it for good.
Read articleHow to tell a harmless lookalike from a dangerous one — and the concrete steps to get a fake copy of your site shut down.
Read articleYour homepage can load fine while checkout is quietly broken. How to know before customers can't buy — with test orders and automatic checks.
Read articleDNS is the internet's address book, linking your domain to your server. Why it matters for your site and email — and what breaks when it's wrong.
Read articleA plain-language checklist for small businesses: cookie banner, privacy policy, forms, a secure site and more — no legal jargon, just what to do.
Read articleDead links quietly lose you customers and chip away at your Google rankings. Why they happen — and how to find and fix them.
Read articleYour password plus one more check, usually a code from a phone app. Why it stops most account break-ins, and how to switch it on.
Read articleIt's more than a few lost sales. The real business math — lost orders, wasted ad spend, support and trust — with a worked example.
Read articleMost of your customers browse on a phone. What mobile-friendly really means, how to check yours, and the common problems to fix.
Read articleAnyone can put your domain in an email From field. DMARC is the record that decides what happens next — and its reports show who really sends as you.
Read articleExample records, the 10-DNS-lookup limit and the mistakes that silently break authentication — a working SPF and DKIM setup from scratch.
Read articleA page can return 200 OK while checkout is broken. Content checks, synthetic browser journeys and protocol monitors close the gap.
Read articleMost lookalike domains are harmless parked pages. How to tell the benign ones from an active phishing setup — and when to act.
Read articlePublic TLS certificate lifetimes are heading towards 47 days. What that means for manual renewal routines — and how to stay ahead of expiry.
Read articleLCP, CLS and INP measure how fast your site feels to real visitors. What each metric means for conversion and search — in business terms.
Read articleCSP, HSTS, X-Frame-Options and the rest: what each header protects against and which ones every production site should send.
Read articleWhat GDPR and ePrivacy actually require from a cookie banner — and the common consent mistakes that set trackers before anyone clicks accept.
Read articleThe European Accessibility Act now applies to many businesses selling in the EU. What WCAG conformance involves and how to find your gaps.
Read articleDeeper material on the software supply chain and vulnerability management — the ground CodeControl and VulnControl cover. Written for whoever will be asked whether the tooling is any good.
Three questions get skipped when AI coding agents arrive: what the agent may reach, what data leaves the building, and who checks the code that ships.
Read articlePermissive, copyleft, and the network clause that catches SaaS. Which licences oblige you to publish your own source — and why it surfaces during due diligence.
Read articleAn abandoned package will never be fixed, so the next vulnerability in it is permanent. How to tell abandoned from finished, and the four options.
Read articleMost software companies are not directly covered and get the requirements anyway — through their customers' contracts. What arrives, and what to have ready.
Read articleCore is well maintained; almost every compromise arrives through a plugin or theme — including ones removed from the directory without telling you.
Read articleAttack one package, reach thousands of companies. The five routes in, what the well-known incidents actually teach, and the defences that hold up.
Read articleA developer needs a task finished, not a security review. Why telling them to be more careful has never worked, and what to do instead.
Read articleAn ingredients label for software: what goes in one, how SPDX and CycloneDX differ, and why the question is arriving in ordinary companies' inboxes.
Read articleAn SBOM says what your software contains. A VEX says what you decided about each known flaw — and why most of them do not affect you.
Read articleCVSS says how bad a flaw would be, not whether anyone is exploiting it. How KEV and EPSS turn 31 findings into 3 that matter this week.
Read articleAI assistants confidently import packages that never existed, and attackers register those names. Why typosquatting checks are blind to it.
Read articleIf your build asks a public registry for an internal package name, anyone can claim it — and your next build may install theirs.
Read articleAttackers publish packages named one keystroke from the real thing and wait. Why the payload usually runs before you import anything.
Read articleA credential removed in a later commit stays readable in git history forever. Why rotation is the only fix that actually works.
Read articleYou declared forty packages and installed six hundred. Where the rest came from, and how to find the single upgrade that fixes the vulnerable one.
Read articleUnpinned actions, pull_request_target with a checkout, and write-all permissions — what each one risks, and how to close it.
Read articleA CVE is a catalogue number, not a severity rating. What the identifier means, how scoring works, and the three questions the numbers can't answer.
Read articleMost false criticals come from one mistake — and the same mistake makes scanners miss real flaws in the other direction.
Read articleAn exposed database breaks nothing, which is why it stays open for years. The services that should never face the public internet.
Read articleTrustCtrl runs more than 80 checks across your domains — email authentication, uptime, certificates, website quality and lookalikes — and explains every finding in plain language.
Free during early access · No credit card