Scanning policy
How our automated checker behaves, exactly what it looks at, and how to be excluded permanently.
Version 1.0 · effective August 2026
If you have arrived here from a line in your server logs, this page is why. Our scanner identifies itself and links here on every request, because a business owner who sees an unfamiliar bot in their analytics deserves a straight answer rather than a mystery.
What we do
We check small business websites against a published accessibility and security checklist, and we contact some of the owners whose sites score poorly to offer a paid audit. The scan is free, unsolicited, and produces a score we are willing to show you.
The rules our scanner follows
These are enforced in the code, not merely stated here.
- Your home page onlyAn unsolicited scan loads exactly one page. We do not crawl your site, follow internal links, or visit anything you have not linked from the page we loaded. Deeper crawling happens only after a client has signed an agreement authorising it.
- We identify ourselvesEvery request carries a user-agent naming us and linking to this page.
- We honour robots.txt and X-Robots-TagIf either tells us not to, we stop, and we record that we stopped.
- We are rate limitedNo more than one request every four seconds to any single domain, with a hard ceiling on total requests. Our scan is lighter than a single human visitor loading your page twice.
- We look, we do not touchWe read the page your server sends to any visitor. We do not submit forms, attempt logins, test for vulnerabilities, or probe for hidden pages. No active security testing of any kind.
- We cache for 30 daysOnce we have scanned a domain we do not scan it again for at least a month.
- We log every requestDomain, URL, timestamp, and result. If you ask what we did and when, we can tell you precisely.
How to recognise us
Our requests carry this user-agent string:
Mozilla/5.0 (compatible; UditusBot/0.1.0; +https://REPLACE-WITH-DOMAIN/scanning-policy)To block us in robots.txt, add:
User-agent: UditusBot
Disallow: /We check for this before every scan and we respect it immediately.
What we collect
Only what your server sends to any visitor: the HTML of your home page, its scripts and stylesheets, the response headers, and the results of running standard accessibility tests against it. We record which technologies we detected and how the page scored.
We do not collect personal information from your website, and we do not collect anything about your visitors. We are not able to and we do not try.
How to be excluded, permanently
Email hello@uditus.com with your domain name and we will add it to our suppression list. That list blocks both scanning and any contact, and it is permanent — we do not expire opt-outs or ask again later.
No explanation is needed and none will be requested. Blocking us in robots.txt has the same effect immediately, without emailing anybody.
What this scan is not
A scan is an assessment against a published checklist, observed on one date. It is not a certification, not a legal opinion, and not a statement about whether your website complies with the Americans with Disabilities Act or any other law. We are not a law firm and we do not give legal advice.
Automated testing can only detect a portion of possible accessibility issues — a large share of them require human judgment. Nothing we send you predicts whether you will face any legal claim, and any message from us that reads that way is one we should not have sent. If you receive one, please tell us.
Who we are
Uditus is a trading name of Air2U LLC, an Indiana limited liability company. Our postal address and contact details are on the home page.