WEBSITE & SYSTEM RENOVATION
First, we check your current site
from the outside, free of charge.
We don't open with a proposal to rebuild everything. Looking only at publicly available information, we put what we noticed onto a single A4 page and hand it to you. If you read it and decide you don't need anything right now, that's where it ends.
The check is free. Once we hand over the results, we will not contact you with sales follow-ups.
From the check through to the quote, our founder handles it personally. We explain everything without jargon.
External Check / a sample of the results
A ○ does not mean "safe" — it means "nothing was visible from the outside."
Who this is written for
- Companies and sole proprietors who already have a website online
- It's fine if the site was built by another company
- Anyone who can no longer reach the company that built their site
- Companies with no in-house IT staff, or only one person
Requests we don't take on
- Investigating a site you do not manage yourself
- Requests from fellow web production companies
- Those who don't have a site yet (we'll guide you to new-build options)
- One check per company
01ISSUES
Is that site of yours
actually doing its job right now?
Is your contact form really delivering messages right now?
Is a page you made five years ago still sitting there, published?
Open your own site on a phone — can you tap the phone number straight away?
If the site went down for a week, do you have a backup you could restore from?
Can you still get in touch with the company that built it?
Are your auto-reply emails landing in people's spam folders?
Do you have to ask an outside firm every time something needs updating?
Are you typing the same figures into two places by hand?
Settings that were correct on launch day drift out of place as time passes.
Before deciding whether to fix anything, why not start by seeing where things actually stand today?
02EXTERNAL CHECK
The External Check.
Give us the URL, and we'll look into the rest.
The usual free diagnostics ask you to answer dozens of questionnaire items. With the External Check, you don't fill in a questionnaire. Just give us your site's URL, and we'll do the looking using only publicly available information.
01Who does the looking
Our founder does it personally. We don't paste tool output straight into a document and send it. The job isn't finished until the results have been cross-checked across all 12 areas and put into an order of what to fix first.
02What we use to look
We use public tools that anyone can use for free. We don't hide their names either.
- Mozilla HTTP Observatory (communication-related settings)
- Qualys SSL Labs (state of encrypted communication)
- PageSpeed Insights (display speed)
- Google Safe Browsing (dangerous-site verdicts)
Anyone can try the same tools themselves. What we do is cross-check the results and put them in order of priority.
03What you receive
- A single-page A4 PDF (the overall picture, and the order to fix things in)
- A results list by area (○ / △ / ×, with the grounds for each judgement)
- Priorities sorted into three levels: "right away," "within this term," and "keep an eye on it"
We don't produce thick reports. Rather than adding to your reading pile, we hand you one page you can act on.
04What happens after that
Once the PDF is sent, we'll walk you through it online for 30 minutes if you'd like. If you'd rather not, that's the end of it. You're welcome to simply take the document without any meeting.
Whether to fix anything, where to start, and which company to ask — those are yours to decide. That includes deciding not to hire us.
03WHAT WE LOOK AT
We look at 12 areas, in this order.
Since the terminology gets difficult, we describe each one by "what happens as a result" first. Read them by what occurs, not by the name of the cause.
AAre enquiries slipping through the cracks?
- Enquiries aren't getting throughWhat happens: messages are sent but never reach anyone in your company, or land in the spam folder. / What we look at: the number of input fields, the screen shown after sending, auto-replies, and how easy the phone number is to tap.
- Are you listed correctly on Google?What happens: searching your company name brings nothing up. The same page is registered twice. / What we look at: search results, robots.txt, noindex, canonical, and the sitemap.
- Is the site slow to display?What happens: people close the page before it opens. Ad spend goes to waste. / What we look at: load time on a phone, how heavy the images are, and server response.
BDoes it look trustworthy?
- Is communication encrypted?What happens: the browser shows a "not secure" warning. / What we look at: certificate expiry, pages still served over http, and redirect settings.
- Are the safety settings in place?What happens: it becomes harder to prevent impersonation and eavesdropping. / What we look at: the settings a browser receives when it opens your site (HSTS, CSP and so on).
- Age of the tools in useWhat happens: one day the site simply stops displaying. A client's audit flags it. / What we look at: the generation of PHP, CMS and plugins, as far as public information allows us to estimate.
- Is anything showing that shouldn't be?What happens: documents meant to be private, or internal information, end up visible to anyone. / What we look at: search results, published pages, and the contents of error messages.
CWill it stay up, and will mail arrive?
- Does your email reach the recipient?What happens: replies to enquiries get treated as spam. Emails impersonating your company go unnoticed. / What we look at: your domain's public settings (SPF, DKIM, DMARC).
- Domain and certificate expiry datesWhat happens: on the day they expire, both the site and your email stop working. / What we look at: the publicly listed expiry dates.
- Can you restore things if the site goes down?What happens: you can't recover, and end up rebuilding from scratch. / What we look at: this one can't be seen from the outside. We'll ask you about it.
DIs it creating extra work in-house?
- Is anything being measured?What happens: you keep spending without knowing which efforts worked. / What we look at: whether GA4 and GTM are installed, whether completed enquiries are tracked, and double counting.
- Can everyone use it?What happens: older customers, or applicants for public tenders and job openings, can't use the site. / What we look at: text legibility, form field labels, keyboard operation, and image descriptions.
A few things to tell you upfront, about this check.
- We look only at publicly available information. Search results, published pages, the information a browser receives when it opens your site, files meant to be public such as robots.txt, and your domain's public settings. That's the whole scope.
- Some things won't be found. This is not a guarantee that every problem will be discovered.
- We don't state things as certainties. Because information visible from the outside can be altered, we phrase every point consistently as "… is suggested" or "… could not be confirmed." Confirming anything for certain requires checking the live environment.
- A ○ does not mean "safe." It means "nothing of concern was found within what is visible from the outside."
- If we find something that appears to be confidential. We write neither the URL nor the values themselves anywhere in the proposal documents. We tell the person in charge directly.
04WHAT WE DON'T DO
Without permission,
we go no further than this.
Please be aware that investigating more than necessary may lead to trouble with the website operator, or may run afoul of laws such as Japan's Unauthorized Computer Access Law.
From the FAQ on reporting vulnerability-related information, Information-technology Promotion Agency, Japan (IPA)
That's a national agency saying it. So without permission, this is as far as we go.
What we absolutely never do without permission
- Hunting for admin panels or login pages by trying address after address
- Entering IDs and passwords to see whether we can log in
- Running vulnerability-scanning tools against your site
- Sending large volumes of requests to APIs or search functions
- Applying load to see how much the site can withstand
- Gathering employees' personal information from multiple sources and compiling it
Without permission, we stay within this scope only
- Looking at search results
- Opening published pages normally and reading them
- Looking at the information a browser receives when it opens the site
- Looking at files meant to be public, such as robots.txt and sitemap.xml
- Looking at the domain's public settings (DNS)
We simply look at pages anyone can see, in the way anyone can see them. We never perform any operation that involves entering an ID or password. The number of times we access the site is just a few, the same as ordinary browsing.
Why we ask for permission in writing
Under Japan's Unauthorized Computer Access Law, certain acts carried out by the access administrator or with the relevant administrator's consent are excluded from the definition of unauthorized computer access. That does not mean consent permits anything. We document the target, period, work, exclusions and emergency contacts, and work only within that scope.
The 6 items written into the permission document
- Identification of the target system (production, staging or development, plus the URL)
- The period of work (start and end dates and times)
- What will be carried out (what we will do, and what we will not)
- What is out of scope (we state in writing what we won't touch)
- Confirmation of what could occur (such as the site temporarily slowing down)
- Emergency contacts (the people in charge at both companies, and how to reach them at night)
We'll send a template of this permission document free of charge to anyone who wants one. That's fine even if you never place an order with us.
05THREE STEPS
Start at US$0,
and stop wherever you've had enough.
This doesn't jump straight into a large contract. At every stage, you choose whether to go on or stop.
-
STEP 0
US$0Permission: not required
External Check
We look only at publicly available information and sum it up on a single A4 page. You're welcome to stop right here.
-
STEP 1
From US$650Permission: order only
Fix what was found
We fix things starting with the highest priority. What will be built and what won't are both fixed in writing before work begins.
-
STEP 2
Individual quotePermission: in writing
Check the live environment
We look inside the server and the admin panel to verify what couldn't be established from the outside. We exchange the 6-item permission document before starting.
-
—
ReferralWe point you elsewhere
We don't perform full vulnerability assessments
If login attempts or attack-simulating tests are needed, we'll introduce you to a specialist firm. That's more reliable than us taking it on halfway.
06SELF CHECK
Before applying,
try checking just these eight yourself.
If three or more apply to you, we think a check is worth requesting.
- Open your own site on a phone — can you tap the phone number straight away?
- Does your contact form have five input fields or fewer?
- When did you last send a test message to yourself through the contact form?
- If the site went down for a week, do you have a backup you could restore from?
- Can anyone inside your company log in to the server and domain control panels?
- Do you have to ask an outside firm every time something needs updating?
- When you search your company name, do unintended files turn up?
- Can you still get in touch with the company that built the site?
If you'd rather look into it yourself first: Japan's Information-technology Promotion Agency (IPA) publishes free materials such as the "5-Minute Information Security Self-Check." You can use them without asking us. What those tell you is a self-declared picture of your internal setup; what the External Check looks at is the actual state of things as seen from the outside. They serve different purposes.
07WHAT WE FIX
There are two places we fix.
Fixing the site
- Rebuilding the contact form and cutting down the input fields
- How it looks on a phone, and the path to calling you or finding you on a map
- Encrypted communication, and adding the settings that keep things safe
- Moving old machinery up a generation (PHP, CMS, plugins)
- Fixing pages that don't appear in search, and clearing out unneeded ones
- Lightening images and improving display speed
- Settings that get your email delivered (SPF, DKIM, DMARC)
- Installing GA4 and GTM, and measuring completed enquiries
Fixing how things work in-house
- Bringing spreadsheet-based management together onto one screen
- Building systems for bookings, orders, stock and customer management
- Requests and approvals, and separating permission levels
- Linking up with the tools you already use (API) so nothing is retyped
- Feeding enquiries from the site straight into your internal admin screen
- Ending the situation where only one person can touch it (manuals and handover)
- Building an online shop, and selling overseas
- Making recovery possible when things go down (backups and monitoring)
08PRICING
We show you the prices right from the start.
Since a figure on its own tells you little, we always list the number of pages covered, the timeframe, and what's included right beside it.
Check only
For those who want to know where things stand
US$0
- All 12 areas covered
- A single-page A4 PDF
- Within 3 business days
- No sales follow-ups afterwards
Fix it
For those who want to keep their current site
FromUS$650+
- Scope: around 5 pages
- Timeframe: 3–4 weeks
- Adjusted while keeping the current shape
- Includes 3 months of defect fixes after delivery
Rebuild it
For those who want to change the look as well
FromUS$3,200+
- Scope: around 10 pages
- Timeframe: 6–8 weeks
- Original design
- English support and update features included
Build the whole system
For those who want to change how the work itself is done
QuoteIndividual quote
- Developing booking, stock and customer management
- Integration with existing tools
- Timeframe and cost decided in discussion
- Maintenance can be discussed alongside
- For those who don't have a site yet, new builds start from our Light plan (from US$650). The "from US$650" on this page is a guide for checking an existing site and fixing the highest-priority areas first. We provide a formal quote after confirming the scope.
- Three things decide the price. (1) How many pages need fixing, including the top page; (2) how many contact forms there are; (3) whether it runs on WordPress or a bespoke system. Once we know those three, we can give you a rough figure.
- Payment is split into two: one at the start of work, one on delivery. There are no extra charges billed by the hour.
- What will be built is fixed in writing before work starts. We write down what won't be built too, so interpretations don't diverge later.
- The above are guide prices. We issue a formal quote after seeing the results of the check. If it looks likely to exceed the guide, we always tell you before work begins.
09AFTER
Once it's fixed,
leaving it alone brings it back.
Maintenance isn't compulsory. You can also choose to have work done only in the months you need it. That said, if you do put us on a monthly retainer, we write out everything it covers upfront.
What the monthly plan covers
- Uptime monitoring (we watch automatically for outages)
- Backups taken at least once a day
- Updates to the core, plugins and themes
- A separate environment from production, for testing updates
- Server-side maintenance (keeping PHP and the like up to date)
- A monthly report of what was done
Not included: design changes, adding pages, and recovery after an attack. Those are quoted separately. We write that in the same place.
We put the terms out before you order
- The rights to what we build are yours (transferred on delivery)
- For 3 months after delivery, we fix defects caused by us at no charge
- The server and domain are held in your company's name (never ours)
- We subcontract to outside parties only after obtaining your consent in advance
- We never supply information entrusted to us as training data for AI
- A confidentiality agreement is signed before work starts. Your own template is fine
- We hand everything over in a form you can pass to another company at any time
Judge us by how we work, not by how many projects we've done.
We're a young company. On the number of past projects we can point to, we can't match the large firms. We're not going to hide that.
What we can do instead is set out what we look at, what we don't look at, what it costs, and how we proceed — all of it, right here on this page, so you can read it before ever contacting us.
From the first conversation through to delivery, our founder handles it personally. The person you talk to and the person doing the building are never different people.
10FAQ
Questions we're often asked, before you apply.
It's free. There's no billing later. The check costs us nothing but our own time — no outside payments are involved. That's also why we cap it at five companies a month.
We only examine a site after you've applied. And what we look at is limited to what anyone can see: search results, published pages and the like. We never enter IDs or passwords, never hunt for admin panels, and never run vulnerability-scanning tools. If any of that is needed, we do it only after receiving permission in writing.
Yes. In fact, this is written with exactly that kind of company in mind. We explain things without jargon. All you need to decide is what's giving you trouble, and all you need to prepare is your site's URL.
Yes. In fact that's the most common request. We can help even when you've lost contact with the company that built it. It does have to be a site your own company manages, though — we don't take on requests to examine another company's site without their knowledge.
No. Once the results are sent, we make no sales contact and no sales calls. Only if you want to know the costs, tick "I'd also like a rough cost estimate" on the form. If you don't tick it, we won't send you any pricing.
We tell you: "Within what is visible from the outside, there was nothing of concern." That is a result in itself. We don't invent problems to report. But remember that a ○ doesn't mean "safe" — it means "nothing was visible from the outside." We're honest about that in writing.
The check is US$0. Fixing your current site starts at US$650, rebuilding it from the look upwards starts at US$3,200, and building the whole internal system is quoted individually. The figure is set largely by three things: how many pages need fixing, how many forms there are, and whether it runs on WordPress or a bespoke system.
The check is done within 3 business days of your application. For the work itself, fixing your current site takes about 3–4 weeks and rebuilding it about 6–8 weeks. We issue a schedule before starting, and we work to the dates written on it. We don't put down dates we can't keep.
From the outside, the most we can say is that use of an older version is suggested — we can't state it as fact, because that information can be altered. That said, if you are still running a generation whose official support has ended, no fixes are being issued for it, so we'd recommend updating. Establishing it for certain requires checking the live environment, and for that we obtain permission in writing.
We write neither the URL nor the values anywhere in the proposal documents. We simply say there's something we'd like to discuss urgently, and pass it to the person in charge directly. If we cannot reach anyone and determine that it qualifies for IPA's vulnerability-reporting scheme, we follow that scheme.
Left alone, it will. That's why we offer monthly maintenance. It isn't compulsory, though. You can choose to have work done only in the months you need it, and if you'd rather run it in-house we'll hand over the manuals. We won't tie you to us.
We don't perform full vulnerability assessments that simulate attacks. We'll introduce you to a specialist firm, because that's more reliable than us taking it on halfway. What we do is check what's visible from the outside, and fix what turns up there.
11APPLY
Just the URL is enough to apply.
It takes a minute to fill in. No documents to prepare.
- There is no cost whatsoever, and no obligation to sign anything.
- Once the results are sent, we will not contact you with sales follow-ups.
- One application per company.
- We don't take on investigations of sites you don't manage yourself, or requests from fellow web production companies.
In the "Message" field of the contact form, please write the URL of the site to be checked. If you also tell us what's worrying you most right now (no enquiries coming in, slow loading, uneasy about security, and so on), we'll start there.
—RELATED
Decide whether to fix it
after you've seen it.
The check is US$0. If you read the results and decide you don't need anything right now, that's the end of it. Replies are written by a human.