Aevum Security logo Aevum SecurityAgent Readiness Audit

crawl-only route

3.4 → 100/100 with ZERO code access: the crawl-tier onboarding

before
3.4/100
not agent-ready
after
100/100
agent-ready

A business that shares nothing

A React single-page app. We were given no source code, no repository, no backend, no secrets — only the public URL. The main site scored 3.4/100 (audit v1.0): /llms.txt returned the app shell, there was no manifest, and every probe came back as the same HTML shell. Because content appears only after JavaScript runs, an agent (which doesn't run the page's JS) sees an essentially empty document. None of this is a criticism of the site as a human product — it's simply invisible to agents.

Crawl, don't touch

On the crawl-only route the business shares nothing but the URL. We read the public rendered pages as any visitor would and built a read-only surface on a separate subdomain: discovery, machine-readable docs and distilled context, a changelog, and read actions derived from the public content. Nobody changed a line of code. The main site keeps its original number by design; the agent surface is a separate sidecar, kept fresh by a scheduled re-crawl — and it scored 100/100.

The lesson: you don't need to rebuild your site, or even give anyone access to it, to become agent-ready. Want agents to act, not just read? That's the full-access route — see the other case study.

Run a free Agent Readiness Audit on your site →  ·  ← all case studies  ·  the Content Firewall →

Audit versions: v1.0 (20 checks, 5 layers) produced the original numbers; v2.0 (25 checks, 6 layers) added the weighted Security & Trust layer; v3.0 (27 checks) added the structured-data and AI-crawler-access GEO checks; v4.0 (28 checks — adds the deprecation-signals lifecycle check) is the current yardstick. Layer scores are not directly comparable across versions.